ABC Private Limited: Entity Level Controls (ELC)
ABC Private Limited: Entity Level Controls (ELC)
Board does not clearly define C01 Board powers are clearly 1. Confirm the documentation
authority to be exercised at defined of Board powers and
Board level and authority delegation of authority done by
delegated to other Directors the Board.
Board does not acknowledge its C02 1. Board minutes includes a 1. Verify that formal guidelines
responsibility towards oversight statement acknowledging its have been provided by the
for establishing and responsibility for ICFR Board.
performance of internal controls
2. Board provides broad 2. Verifiy that specific
Board does not formally delegate guidelines for internal responsibility has been
the responsibility for controls and records formal allocated for establishing
establishment of internal delegation of authority for internal financial controls
financial controls and for establishment of controls.
ensuring effective performance
thereof.
Board does not have a C07, Board of Directors review the 1. Verify Board meeting
mechanism to review ICFR C08 performance of the company minutes where adequacy and
adequacy and performance and adequacy of internal effectiveness of internal
controls through regular controls have been reviewed.
interactions with the Finance
Manager 2. Confirm that there are
regular interactions between
Budgets are established on Board members and Finance
yearly basis Manager through CFO, and
other key management
Monthly reporting is done by personnel to assess quality of
Finance Manager to the Group controls and review business
CFO who in turn reports to performance.
BOD.
3. Review budget variances,
exceptional items to assess
internal control gaps, if any.
Board of Director does not set C03 Policies are framed by the 1.Verify minutes of Board
the right tone at the top to Board wrt ethical conduct, meeting and Admin Manual/
encourage ethics and integrity. anti-bribery and corruption, directions issued by the Board
anti-fraud. of Directors from time to time.
Board of Directors does not set C02 Directions are given by the Verify minutes of Board
the right tone at the top to Board to encourage process- meeting and
encourage institution of controls driven conduct, automation policies/directions issued by
and systems and ensure and effective monitoring the Board of Directors from
accountability for lapse of across the organization. time to time.
controls
Ambiguity in delegation of C01 1. Financial powers in terms of Confirm that
financial powers reduces the signing /effecting banking authorization/approvals of
control over financial transactions is with the Directors is in place, review
transactions and increase the Director. Board resolution to define
risk of financial losses powers of Director
2. Also, all the major contracts,
agreements, Purchase Orders
are signed/approved by the
Directors.
Flawed performance incentive/ C03, 1. Admin Manual gives a 1. Verify Admin Manual to
compensation policy not in line C19 reference to ethical standards ensure all updations are
with ethical tone and standards expected from employees. included.
may increase the risk of
compromise / non compliance to 2. Appointment Letter 2. Verify Appointment Letter of
ethical standards of conduct includes relevant clauses employee
If management does not take C03 Management takes 1. Verify the mechanism for
timely and appropriate disciplinary action for recording non-adherences/
disciplinary action, it would violations/ non-adherence, in violations.
encourage non-adherence to a timely and appropriate
established policies and manner. 2. Verify the evidence of action
procedures being taken.
Applicant screening procedures C05, 1.Adequate background Review the appointment
do not adequately consider C09 verification is done for letters on sample basis for the
integrity and ethical values employees (Police Clearance, declarations obtained
Experience letter, etc.)
Lack of adequate talent or C05, 1. A rigorous recruitment and 1. Confirm the no. of exits and
mismatches in requirements and C06, selection process is adopted to the principal underlying
skill sets may severely impact C09 ensure selection of right reason/s.
achievement of objectives employees for the right job.
2. Confirm that key positions
2. Majority of office staff is are not left vacant for a long
hired through a placement time.
agency which is selected by
the management
In absence of a proper work C10, 1. Promotions are based on 1. Review the appraisal
environment the company may C12 well defined Performance process for appropriateness
have to deal with high attrition Evaluation system. and confirm that there is due
levels process for redressal of
2. Management ensures a very appraisal related grievances.
low attrition rate.
2. Review attrition rate and
related analysis
A robust system of monitoring C07, 1. Internal audits are done 1.Verify Internal audit scope
through periodic internal audits C15 quarterly as per pre-defined and reports
or control Self Assessments has scope which is approved by
not been established the management. 2.Review Board Minutes
Absence of enterprise-wide risk C04 Formal risk management Review the risk management
assessment and absence of policy is presented to the policy adopted by the
documented risk management Board and approved by the Company
policy Board of Directors.
Absence of BCP/DRP may lead to C22, C23 1. Business Continuity Plan 1. Review the BCP and DRP.
business interruptions and may (BCP) and Disaster Recovery
jeopardize business continuity Plan(DRP) are in place. 2. Review the data recovry
plan.
2. Data recovery plan is
established and operational.
Regulatory changes impacting C17 1. Regulatory changes are Verify formal assessment of
business, financial conduct or understood and assessed for key regulatory changes.
reporting requirements are not their impact on business.
understood, analyzed or
internalized. 2. Compliance tracker is filled
in at defined frequency and
updated periodically for
amendments.
Non identification of changes in C13, C25 1. Defined and documented Review financial statements
accounting principles or financial Financial Statement Closure and all other relevant
reporting requirements may lead Process is in place. information.
to non-compliance and the
financial statements will not 2. Periodic updates are
show true and fair figures or may received from professional
not include disclosures as consultants.
required.
Absence of an appropriate C20, C26 1. Various compliances under Verify Board noting and
mechanism of related party different statutes in relation to approval of related party
transactions identification can transactions with related transactions.
lead to regulatory non- party (transfer pricing related
compliance and/ or financial compliance and return filing)
misstatements are verified.
Changes in the procedure C27 Periodic review of process 1. Verify that the manuals are
manual of a particular manual is done and updates periodically reviewed.
department without the are communicated to all
knowledge of its employees employees concerned. 2. Verify evidence of
leads to dilution of the impact of communication of changes to
the changes implemented employees.
Risk of recurrence of issues if not C15 Periodic internal audit is done Verify internal audit reports
evaluated and policies/ by an external agency and available, and record of
procedures not modified changes made basis agreed resolution of agreed actions.
accordingly actions.
Risk of financial loss and/ or C16, 1. Physical verification of fixed 1. Verify fixed asset
financial misstatement in the C20 assets, cash is done. verification report and check
absence of an established for periodicity
physical verification of assets 2. Third party and bank (CARO, 2015)
mechanism balance confirmations
statements are taken. 2. Verify third party
confirmations.
3. Board discusses findings of
physical verification of assets/ 3. Verify records showing full
discrepancy resolution particulars - quantitative
details and situation of fixed
assets
(CARO, 2015)
4. Verify Board meeting
minutes
Absence of policies will lead to C03 All financial policies relating Verify remuneration structure
reimbursement/ allowance of to employees are in place for financial policies relating to
non agreed expenses to the along with defined level of employees.
employees or reimbursement of approvals.
expenses over and above the set
limit to the employees.
May result in C03 1. Clear identification of Verify the Admin Manual for
reputational/financial/reporting persons authorized to communicating with external
risk due to erroneous communicate with external parties
communications to external parties on relevant company
parties/ external reporting matters.
2. A formal social media policy
is in place.
In the absence of clear C03, C18 There are properly identified Review grievance mechanism
communicating channels for communication channels and sexual harassment policy
external parties, employee/ (email ids) for third parties
management malpractices may under grievance mechanism,
not come to light, may have a sexual harassment policy
reputation risk with respect to
third parties
Absence of clear communication C28 Clear communication of the Verify the communication for
on performance measures may Key Result Areas in the the KRAs
lead to ambiguities and increase evaluation process
in attrition levels
Risk events, exceptional and C07, 1. Formal communication 1. Verify periodic MIS on
unusual events remain C08, C29 process established for sample basis
unreported to the management escalating disruption to
and hence the risk management operations, occurrence of risk 2. Verify management and
framework is not duly enhanced. events and any material Board meeting minutes
exceptional event.
3. Board meeting,
management review meeting
discuss unusual events.
Inadequate process for obtaining C16 1. Third party confirmations Verify confirmations obtained
third party confirmations to obtained from banks, debtors, from counter parties and
validate financial figures and to related parties Government website (such as
detect financial frauds. Income Tax) for reconciling
2. Web based review done to statutory figures and other
assess tax status, TDS status, balances.
regulatory compliance related
numbers.
Absence of review of the C07, Monthly MIS consisting of Verify financial statements/
financials by management C08 financial statements and other reports, periodic MIS and
operations, reconciliations reconciliations
prepared by Finance Manager
are reviewed and analyzed by
Group CFO
Inappropriate grievance C03 Employee grievance policy (to Verify policy to resolve
processes may lead to delay in resolve complaints and complaints and grievances, as
detection of frauds, misreporting grievances) forms part of stated in Admin Manual
of financial figures, need for Admin Manual
provisioning due to disputes
Process gaps, errors and C03, 1. Internal audit function 1. Verify Internal Audit reports
misstatements may not be C07, reports to Board of Director
identified by the management C15 and highlights deficiencies 2. Verify meeting minutes
which may also lead to fraud or observed.
non-compliance due to absence 3. Verify sample policies and
of well established risk and 2. Polices and processes are process notes
internal audit review system introduced and revised from
time to time to plug identified
gaps and controls lapses.
Absence of communication of C21 Formal roll out of ICFR policy 1. Check ICFR framework and
deficiencies and monitoring and testing process for control documented RCMs
corrective action may lead to design and effectiveness
unremediated deficiencies and 2. Check the process adopted
resultant control gaps wrt ICFR for testing control design and
operational effectiveness
Key or Control Type of Nature Control
Non Key? exists? Control Frequency
Board minutes for FY 2015-16, Admin Manual, various Certain SOPs have not been
other documented policies such as CSR documented
Board resolution defines power of Director and for -
signing authority
IA Reports -
3. Board Minutes
Remuneration Structure (CTC Sheet) -
Admin Manual -
Defined KRA -
1.Board Minutes -
2.Internal Audit scope & reports
1. RCMs documented -
Board Minutes -
1.Admin Manual -
2.Appointment letter
1.Appointment -
letters of employees
2.Admin Manual
Admin Manual -
1.Appointment letter -
of office staff
2.Police Clearance
Certificate(PCC),
Experience
Certificate, Salary
Slip
Performance -
Appraisal Form
1.Board Minutes -
2.Internal Audit
scope & Reports
Training Provide training related to regulatory changes, financial
Certificates/ Course reporting regulations etc. to Accounts & Finance staff
Certificates
Risk Management -
Policy
- -
- -
- -
Board Minutes -
List of user-ids with Restrict access to public sites and domains.
access rights
IA Reports reviewed -
1. Fixed Asset -
Register
2. Third party
confirmation
3. Board Minutes
Remuneration -
Structure (CTC
Sheet)
Admin Manual -
Defined KRA -
Admin Manual -
1.Board Minutes -
2.Internal Audit
scope & Reports
- -
Remarks
-
The established process of regular reporting is
sufficient in view of the size of the company
and nature of its operations.
-
-
-
-
-
-
-
-