| Jim Kaplan's |
|
|
|
AuditNetDan's Internal Audit CornerCompliance and Ethics 101
Each month Dan Swanson, a senior security and internal
audit professional will provide his list of recommended resources for
AuditNet readers. If you have questions about this page or the links, you
can reach Dan at
www.securitybenchmark.com and
dswanson_2005@yahoo.com.
Compliance and Ethics Broadly understood, compliance with an organization’s policies and procedures is a very important activity that helps make organizational governance effective. Monitoring and maintaining compliance is not just to keep the regulators happy; compliance with regulatory requirements and the organization’s policies and procedures is a critical component of an effective enterprise-wide risk management program. It can also be an important way in which an organization achieves its business goals, sustains its ethical health, works towards long-term prosperity, and preserves and promotes its values. An effective C&E program is best implemented as integrated processes that are owned by designated functions and managed by senior executives who have overall responsibility and accountability. Today, compliance is a daunting challenge, but it also provides a significant opportunity to establish and promote “operational effectiveness” throughout the organization. A periodic health checkup is vital The board and management periodically need to evaluate the design and operating effectiveness of the company’s C&E program, and to assess its overall performance. Such an evaluation supplements the ongoing, day-to-day monitoring of C&E related activities. An internal audit provides for a more in-depth analysis of the C&E program, including its design, effectiveness, and performance. Some leading resources to assist your efforts are provided below. Compliance and Audit Resources (resource sidebar) Auditing compliance and ethics program efforts is not for the uninformed. The internal audit team, and chief compliance and ethics officers should review the extensive guidance available, and in particular review closely the OCEG internal audit guide for auditing a compliance and ethics program (see item 1 below).
Key resources 1. The OCEG Internal Audit Guide (IAG) for the audit of a compliance and ethics program. 2. The OCEG Framework and Foundation-level and Domain-level guidelines by the Open Ethics and Compliance Group (OCEG). 3. Auditing ethics and compliance programs article 4. Some excellent presentations on ethics and ethical self assessment and in 'resources' ethical dilemmas. 5. The NACD web site - 6. The “Expressing Opinions on Internal Control” resource repository. 7. “Organizational Governance - Guidance for Internal Auditors” 8. An Ethics & Philosophy repository Ethics resources UK Institute of Business Ethics - www.ibe.org.uk Ethics & Philosophy (resources) National Business Ethics Survey - Business Ethics http://www.web-miner.com/busethics.htm United States Office of Government Ethics Ethics and Compliance Officers Association 164-page CD-based publication "A Practitioner's Guide to Corruption Auditing" by Muhammad Akram Khan - see Compliance resources The Open Compliance and Ethics group (OCEG) Expressing Opinions on Internal Control - “Internal Auditing’s Role in Sections 302 and 404 of the Sarbanes-Oxley Act” American National Standard - Guidelines for Quality and/or Environmental Management System Auditing Governance resources The IIA:
NACD: 1. NACD BRC on Board Evaluation-2005 Edition 2. The NACD BRC on Board Leadership 3. The NACD BRC on Director Compensation 4. The NACD BRC on Audit Committees 5. The NACD BRC on Director Professionalism 6. The NACD BRC on Role of the Board in Corporate Strategy 7. The NACD BRC on Risk Oversight COSO:
Audit Internal and IT Audit guidance – The Institute of Internal Auditors, Inc. (IIA) www.theiia.org/guidance and www.theiia.org/technology IT Audit and Control – Information Systems Audit and Control Association (ISACA)
Federal Financial Institutions Examination
Council (FFIEC)
American Society for Quality (ASQ)
U.S. General
Accountability Office (GAO) -
http://www.gao.gov/aac.html Auditing Ethics Ethics Audit Essential for Every Business City of Austin Citywide Ethics Audit Report Do the Big Four Need an Ethics Audit? Ethics Audit Kicks Off (at Northrupp Grumman) The opinions, beliefs and viewpoints expressed by the various authors and forum participants on this web site do not necessarily reflect the opinions, beliefs and viewpoints of AuditNet® |