29.2 Component 2: Risk Assessment
Key Takeaways
- Internal controls provide reasonable rather than absolute assurance, recognizing human limitations, management override risk, and the control-design principle that expected benefits should justify the costs; this cost-benefit idea is not a universal statutory formula.
- Control activities require the fundamental segregation of incompatible duties (authorization, recording, custody, and reconciliation) alongside robust Information Technology General Controls (ITGCs) and application controls.
- Internal control is a dynamic, continuous process effected by an entity's oversight body, management, and personnel, designed to provide reasonable assurance regarding operations, reporting, and compliance objectives.
Component 2: Risk Assessment
Management must identify and evaluate the internal and external risks that threaten the achievement of entity objectives, establishing a systematic basis for determining how those risks should be managed.
- Principle 6: Specifies Suitable Objectives: Objectives must be defined with sufficient clarity and specificity to enable the identification and assessment of risks relating to operations, reporting, and compliance.
- Principle 7: Identifies and Analyzes Risks: Management systematically identifies operational, financial, IT, and compliance risks across the entire entity, assessing both the likelihood of occurrence and the magnitude of impact to determine appropriate risk responses.
- Principle 8: Assesses Fraud Risk: Management explicitly considers the potential for fraud, waste, and abuse across transactions, contracts, and grant programs. This requires analyzing the Fraud Triangle:
- Incentive / Pressure: Financial difficulties, unrealized performance quotas, or political pressure.
- Opportunity: Weak internal controls, lack of supervision, or unsegregated duties.
- Rationalization / Attitude: Justifying unethical behavior (e.g., "the agency owes me," "it's just government money").
- Principle 9: Identifies and Analyzes Significant Change: Management proactively anticipates and evaluates external changes (economic conditions, legislative amendments, cybersecurity threats) and internal changes (reorganizations, new executive leadership, enterprise ERP implementations) that could significantly impact the internal control system.
Component 3: Control Activities
Control Activities are the policies, procedures, techniques, and mechanisms established by management to enforce directives and mitigate identified risks to acceptable levels. They occur throughout all levels, stages, and technology environments of the entity.
- Principle 10: Selects and Develops Control Activities: Management designs control activities to mitigate risks. These activities can be categorized by timing and operational nature:
- Preventive Controls: Designed to prevent errors, irregularities, or fraud before they occur (e.g., pre-approval of purchase requisitions, system input validation rules, dual authorization for disbursements).
- Detective Controls: Designed to detect and correct errors, irregularities, or fraud after they have occurred (e.g., monthly bank and FBWT reconciliations, physical inventory counts, budget-to-actual variance analysis, internal audit spot-checks).
- Principle 11: Selects and Develops General Controls over Technology: Management designs Information Technology (IT) controls across two major classes:
- Information Technology General Controls (ITGCs): Entity-wide controls over the IT infrastructure that support the reliable operation of all applications. These include logical access security (multi-factor authentication, least privilege access), system change management (testing and authorizing code updates before release), computer operations, and disaster recovery/backup protocols.
- Application Controls: Automated controls configured directly within business software applications to ensure transaction validity, completeness, and accuracy. Examples include input field checks, range limits, automated matching of three-way documents (purchase order, receiving report, vendor invoice), and batch total verification.
- Principle 12: Deploys through Policies and Procedures: Management establishes control expectations through documented policies and operational procedures, ensuring that staff understand the purpose and execution of each control.
The Critical Doctrine of Segregation of Duties (ARC)
A cornerstone of Principle 10 is the Segregation of Incompatible Duties. No single individual should ever possess end-to-end control over an entire transaction lifecycle. At a minimum, four key functional responsibilities must be segregated among different employees:
+-----------------------------------------------------------------------------------+
| THE INCOMPATIBLE DUTIES SEPARATION MANDATE (A - R - C - R) |
+-----------------------------------------------------------------------------------+
| 1. AUTHORIZATION (A) |
| • Approving purchase orders, contract awards, travel authorizations. |
+-----------------------------------------------------------------------------------+
| 2. RECORDING / ACCOUNTING (R) |
| • Posting journal entries, entering vendor vouchers, maintaining ledgers. |
+-----------------------------------------------------------------------------------+
| 3. CUSTODY OF ASSETS (C) |
| • Handling cash, signing checks, managing warehouse inventory, issuing tags. |
+-----------------------------------------------------------------------------------+
| 4. RECONCILIATION / VERIFICATION (R) |
| • Monthly bank reconciliations, physical inventory counts, variance review. |
+-----------------------------------------------------------------------------------+
Exam Rule: If resource constraints or small office staffing make full segregation impossible, management must implement compensating controls, such as mandatory secondary supervisory reviews, detailed analytical reviews, or surprise internal audit inspections.
Component 4: Information and Communication
Management must ensure that relevant, reliable, and timely information flows throughout the organization, enabling personnel to carry out their internal control responsibilities and supporting external accountability.
- Principle 13: Uses Relevant, Quality Information: Management identifies information requirements and obtains high-quality data from internal and external sources. Data must be timely, accurate, complete, accessible, and verifiable.
- Principle 14: Communicates Internally: Management establishes internal communication channels that operate upward, downward, and horizontally across organizational divisions. Employees must have a clear avenue to report suspected fraud, noncompliance, or operational failures (e.g., anonymous hotlines).
- Principle 15: Communicates Externally: Management conducts external communication with oversight bodies (Congress, state legislatures, OMB), regulatory entities, taxpayers, contractors, and external auditors regarding matters affecting internal control.
Component 5: Monitoring
The internal control system must be continuously monitored to assess the quality of performance over time, identify operational breakdowns, and implement corrective actions.
- Principle 16: Conducts Ongoing and/or Separate Evaluations: Management monitors the internal control system through two distinct evaluation methods:
- Ongoing Evaluations: Routine monitoring activities built directly into recurring, day-to-day operations (e.g., supervisory approvals, automated exception dashboards, continuous audit software).
- Separate Evaluations: Periodic, non-routine assessments conducted at specific intervals by independent parties (e.g., internal audit reviews, peer reviews, management self-assessments).
- Principle 17: Evaluates and Communicates Deficiencies: Management evaluates identified deficiencies and communicates findings promptly to responsible parties, senior leadership, and oversight bodies for corrective remediation.
Effectiveness Criteria: "Present and Functioning" and "Operating Together"
Under both COSO and the GAO Green Book, an internal control system is deemed effective if management can conclude that all five components and all relevant principles are:
- Present: The component and principles exist in the design and implementation of the entity's internal control structure.
- Functioning: The component and principles continue to operate effectively in the day-to-day execution of the entity's operations.
- Operating Together: The five components are not treated as independent silos; they operate in an integrated, coordinated, and synergistic manner. A failure in one component (e.g., a toxic Control Environment or inadequate Risk Assessment) compromises the integrity of the entire internal control system.
Reasonable Assurance and Cost-Benefit Balancing
A central tenet of both COSO and the Green Book is that internal control provides reasonable assurance, not absolute assurance. No matter how well designed, an internal control system cannot guarantee zero errors, zero fraud, or 100% mission achievement.
Inherent Limitations of Internal Control
Internal control systems are subject to five unavoidable inherent limitations:
- Faulty Human Judgment: Personnel may make flawed decisions under pressure or based on incomplete information.
- Human Error and Fatigue: Mistakes, clerical errors, inattention, or misunderstanding of directives.
- Collusion: Two or more individuals working together can circumvent the most sophisticated segregation of duties controls.
- Management Override: Senior leaders possessing legitimate administrative authority may improperly bypass controls for personal or political motives.
- Resource Constraints and Unforeseen External Events: Natural disasters, geopolitical shifts, or sudden pandemics that disrupt normal operating environments.
The Cost-Benefit Principle
Government resources are finite. Management has a statutory and fiduciary duty under the Green Book to balance control rigor against operational costs. The fundamental rule states:
The cost of an internal control (including financial outlays, staff hours, technology procurement, and operational delays) must not exceed the benefit derived (loss avoidance, fraud deterrence, enhanced reliability, and public trust). Management must accept a certain level of residual risk when the cost of total risk elimination is prohibitive.
Practical Public Finance Scenario: City of Metroville Grants & Procurement Internal Control Overhaul
Scenario: The City of Metroville receives $60,000,000 annually in federal Community Development Block Grants (CDBG). An independent single audit uncovers major deficiencies:
- In the procurement division, a single senior buyer routinely creates vendor records, solicits bids, signs purchase contracts up to $250,000, approves receiving documents, and schedules payment vouchers.
- The City's financial software permits buyers to bypass supervisor approval if invoice lines are split into increments under $25,000.
- The City Council has never established an independent audit committee or code of conduct, and employee fraud allegations are routed directly to the procurement director.
- To eliminate all purchase card fraud, the City Manager proposes spending $750,000 to purchase and install biometric iris scanners on all employee mobile devices, in an agency where annual historical card fraud has averaged $4,200.
Professional Internal Control Evaluation & Remediation
-
Component Analysis & Principle Violations:
- Control Environment (Principles 1, 2, 5): Failure of leadership tone, absence of an independent audit committee, lack of an anonymous whistleblower channel, and absence of an enforceable code of conduct.
- Risk Assessment (Principle 8): Inadequate fraud risk assessment regarding procurement split-requisitions and ghost vendors.
- Control Activities (Principles 10, 11): Severe violation of segregation of duties (the senior buyer exercises authorization, custody, recording, and reconciliation). Critical IT application control failure (absence of split-invoice detection algorithms).
-
Cost-Benefit Balancing Resolution:
\text{Proposed Biometric Control Cost} &= \$750,000 \text{ upfront} + \$80,000 \text{ annual maintenance} \\ \text{Annual Benefit (Risk Reduction)} &= \$4,200 \text{ historical annual loss} \end{aligned}$$ *Decision*: **Reject the biometric proposal**. The cost wildly exceeds any derived economic benefit. Instead, management must implement automated credit card transaction limits, block unauthorized merchant category codes (MCCs), and institute a monthly supervisory audit of purchase card statements—costing less than $5,000 annually while providing reasonable assurance. -
Segregation of Duties Remediation:
- Reassign vendor setup to an independent finance specialist.
- Restrict the buyer to bid solicitation and contract negotiation.
- Require receiving reports to be certified by warehouse receiving staff.
- Require payment voucher approval by the accounting division chief.
An internal control review at a state transportation department reveals that a single senior accountant enters vendor invoices into the financial management system, approves the automated electronic disbursement voucher, and reconciles the monthly bank statements. Which core internal control principle and control activity has been violated?
A federal agency director proposes installing biometric palm scanners and hiring armed security guards at every regional warehouse to completely eliminate inventory shrinkage of low-cost office supplies valued at $15,000 annually. The security system will cost $450,000 to install with an annual recurring operating expense of $120,000. Under the internal control doctrine of reasonable assurance and cost-benefit balancing, how should the Chief Financial Officer evaluate this proposal?