How internal controls compliance reporting runs, step by step

Reporting on internal controls compliance starts with the people who operate each control and works outward. Owners confirm their controls. A central controls team gathers evidence and rates any failures. Management reviews and signs. External auditors test the result. Statements then go out to regulators, investors, lenders and other outside parties.

The steps in order

  1. Control owners attest to their own controls. The people who run each control confirm that it operated as designed during the period. They flag anything that slipped. In most organisations this is a sub-certification signed by process heads in finance, procurement, payroll and IT.
  1. The internal controls team collects test results. Whoever coordinates the programme pulls together management testing, internal audit work and the owner attestations. Gaps in evidence surface here. Chasing missing screenshots and approvals takes up a large share of this stage.
  1. Deficiencies are evaluated and rated. The controls lead and the controller judge how serious each failure is. They also consider whether several small failures in one area combine into something larger. This judgement drives everything downstream, so it deserves the most senior attention.
  1. Owners document remediation and any adjustments. Where a failure caused a misstatement, the accounting team books or proposes the correction. Owners write up what they changed and when the fix was tested. Findings from the prior audit get closed out or carried forward.
  1. Internal management receives the report. The CFO and controller see a summary first. A disclosure committee, if one exists, reviews it next. The audit committee gets the version that matters most, usually presented by the head of internal audit or the controls lead.
  1. The auditor package is assembled. The controls team answers the external auditors' prepared-by-client request list. That means updated cycle memos, process narratives, sample populations and the supporting documents for each selected item. Late or incomplete packages are the commonest cause of friction with the audit firm.
  1. External auditors test and challenge. The audit team reperforms selected controls and reviews management's deficiency ratings. Disagreements about severity are negotiated between the audit partner and the controller. Any change in rating sends the work back to step three.
  1. Executives certify. The chief executive and CFO sign management's assessment and any required personal certifications. Legal counsel normally reviews the wording before signature.
  1. Outside statements are filed and published. Financial reporting and legal teams include the controls assessment in the annual filing for regulators and the securities exchange. Investor relations prepares answers for shareholders and debt holders if a weakness is disclosed.
  1. Third parties receive what their agreements require. Treasury sends compliance confirmations to lenders under covenant terms. Commercial or service teams provide assurance reports to customers who depend on the organisation's controls. Insurers and grant bodies sometimes ask for their own confirmations.
  1. Lessons feed the next cycle. The controls team updates the control library, retires redundant tests and adjusts the risk assessment. This step is often skipped, and the same findings return the following year.

Where the documented process and the real one tend to differ

On paper, attestations come in on time and are backed by evidence. In practice many owners sign from memory and the controls team discovers the gaps during auditor sampling.

Deficiency ratings are another soft spot. The written method may be precise, yet the final rating is frequently settled in a conversation with the audit partner.

Third-party reporting is usually the least visible part. Lender and customer obligations sit in contracts held by treasury or sales, and the controls team may not know they exist.

Questions to ask the people who run it

  • When an owner signs an attestation, what do they actually check before signing?
  • Who decides a deficiency's rating, and has that decision ever been overturned by the auditors?
  • Which prepared-by-client requests arrive every year, and why are they not ready in advance?
  • Are cycle memos updated when a process changes, or only when the auditors ask?
  • Who keeps the list of lenders, customers and other outside parties expecting a controls confirmation?
  • What happens if a control owner leaves partway through the period?
  • Which reports to the audit committee get rewritten at the last minute, and who rewrites them?
  • Where does remediation evidence live, and could someone outside the team find it?
  • Which controls are tested only because they always have been?

Points to settle before changing anything

Confirm who owns the deficiency rating method and who can change it. Agree with the external auditors on any revised evidence format before rolling it out, since they may reject it mid-audit. Map every outside reporting obligation to a named person. A redesign that speeds up internal reporting but leaves a covenant certificate unowned creates a worse problem than it solves.

Sources

APQC's Process Classification Framework® (PCF) is an open standard developed by APQC, a nonprofit that promotes benchmarking and best practices worldwide. To download the full PCF or to view definitions and measures, please visit www.apqc.org/pcf.