COSO In 1975 it was created in the United States, the National Commission on Fraudulent Financial Reporting (National Commission on Fraud in Financial Reports), an i

ndependent initiative to study the causes of the occurrence of fraud in financial reports / statements. This committee was composed of representatives of major trade associations of professionals involved in the financial area. His first object of study were the internal controls. In 1992 he published the work Internal Control - Integrated Framework (Internal Controls - An Integrated Model). This publication has become a world reference for the study and application of internal controls. It subsequently peanut in Committee, which became known as COSO - The Comitee of Sponsoring Organization (Committee of Sponsoring Organizations). The COSO is a nonprofit organization dedicated to improving financial reporting through ethics, effective internal controls and corporate governance. It is sponsored by five leading trade associations of professionals connected to the financial district in the United States, namely: AICPA American Institute of Certified Public Accounts American Accounting Association Financial Executives International The Institute of Internal Auditors Institute of Management Accountants American Institute of Certified Public Accountants . American Association of Accountants Financial Executives International Institute of Internal Auditors Institute of Management Accountants FEI AAA IIA IMA The Committee works independently, for their funders. Its members are representatives from industry, accountants, investment firms and the Stock Exchange of New York. Job Purpose The COSO - Internal Control. It is understood by the Internal Control a process developed to ensure, with reasonable certainty to be achieved the company objectives in the following categories: efficiency and operational effectiveness - goals and strategy and performance: This category relates to the basic objectives of the entity, including the objectives and goals of performance and profitability, as well as the safety and quality of assets;

Confidence in the accounting records / financial - goals of information: all transactions must be recorded, all records must reflect actual transactions as reflected by the values and frameworks correct. Compliance - compliance objectives: the laws and regulations applicable to the entity and its area of operation. By COSO, Internal Control is a process consisting of five elements, which are interrelated and present throughout the internal controls: • • • • • Control Environment, Risk Assessment and Management, Active Control, Information and communication Monitoring. Control Environment is the awareness of control of the entity, its culture of control. Environment Control is effective when people of authority know what their responsibilities, the limits of their authority and have the awareness, competence and commitment to do what is right the right way. Control Environment involves technical competence and ethical commitment, is an intangible factor, essential to the effectiveness of internal controls. The attitude of top management plays a decisive role in this component. She must make clear to his men what are the policies, procedures, the Code of Ethics and Code of Conduct to be adopted. These settings can be done formally or informally, the important thing is that they are clear to officials of the organization. The main functions of the Internal Control are related to the fulfillment of the objectives of the entity. Therefore, the existence of goals and objectives is vital to the existence of internal controls. If the entity does not have clear objectives and goals, there is no need for internal controls. Assessment and risk management is the identification and analysis of the risks associated with not meeting the goals and operational o

bjectives, reporting and compliance. This set forms the basis for how risks are managed. Administrators should define levels of operational risk, information and compliance that are willing to take. Risk assessment is a management responsibility, but it is for Internal Audit to make a proper evaluation of risks, comparing it with the assessment made by administrators.

Identification and management of risks is a proactive action that prevents unpleasant surprises. Risk is the probability of loss or uncertainty associated with the fulfillment of a goal. For each objective proposed to be made a process of identifying risks. Analysis Once you have identified the risks, we must evaluate them, taking into account the following aspects: What is the probability (frequency) to occur? In the event of what would be its impact on operations, considering the quality and quantity? Check in your opinion, what actions would be needed to manage the identified risks. Control activity are those activities that when implemented on time and properly, allow the reduction or management of risks. Can be of two kinds: the prevention and detection. The main activities of control and their natures are listed below: • heave (prevention) are the limits determined to be an official, as to whether this amounts to approve or take positions on behalf of the institution.

Examples: Establishing maximum value for a cash payment of a check; Establishment of roofs made by a trader for each investment horizon; Establishment of authority for operating the Credit Committee of the agency. • Commitments (prevention) administration determines the activities and transactions that require approval from a supervisor to take effect. The approval of a supervisor in a manual or electronic means that he checked and validated the activity or transaction, and ensured that it complies with the policies and procedures. Those responsible for the authorization should check the relevant documentation, to question unusual items and ensure that the information necessary for the transaction were checked, before giving its authorization. Conciliation (detection) is the confrontation of the same information with data from different bases, taking corrective actions when necessary. Performance reviews (detection): monitoring of an activity or process to evaluate its suitability and / or performance against goals, objectives and benchmarks outlined, as well as continuous monitoring of the financial market (for banks) in order to anticipate changes that may negatively impact the entity. Examples: monitoring the behavior of credit card users (unusual places, different products, etc..) Monitoring and questioning of abrupt fluctuations in the results of agencies, products, proprietary trading and third parties; Monitoring realized values and budgeted in units with the aim of identifying problems / issues; monitoring the competition, aiming to launch new products. • • •

Physical Security (prevention and detection): the values of an entity should be protected from use, purchase or sale is not authorized. One of the best controls to protect assets is physical security, which includes access control, control of entry and exit of staff and materials, passwords to electronic files, call-back for remote access, encryption, and others. Included in this control, the processes of inventory of the items most valuable to the entity (eg, conference cash).

• Segregation of duties (prevention): segregation is essential for the effectiveness of internal controls. It reduces both the risk of human error as the risk of unwanted actions. Accounting and reconciliation, reporting and authorization, custody and inventory, procurement and payment, management of own resources and others, normalization (risk management) and monitoring (audit) should be segregated among employees. Computer systems (detection and prevention): controls made through computerized systems are divided into two types: General Controls: Controls require the centers of data processing and controls the acquisition, development and maintenance of programs and systems. Examples: Organization and maintenance of back-up files, log file system, contingency planning; Controls the applications: are the controls that exist in enterprise applications, which are intended to ensure the integrity and veracity of data and transactions. Examples: validation of information (check the information with records stored in databases). • • Internal standardization (prevention) is the definition of a formal, internal rules for the operation of the entity. Standards should be easily accessible to employees and the organization should define responsibilities, corporate policies, operational flows, functions and procedures. Control activities should be implemented on a weighted, conscious and consistent. Pointless to implement a control procedure if it is executed in a mechanical way, without focusing on the conditions and problems that motivated its deployment. Information and Communication Communication is the flow of information within an organization, understanding that this flow occurs in all directions - the hierarchical levels above the lower hierarchical levels, the lower and upper levels and horizontal communication between hierarchical levels equivalent. Monitoring is the evaluation of internal controls over time. He is the best indicator of whether internal controls are being effective or not. It is done both through the ongoing monitoring of activities as for occasional assessments such as self-assessment, review and any internal audit. The function of monitoring is to ensure that internal controls are adequate and effective. Adequate controls are those in which the five elements of control (environmental assessment

risks, control activities, information & communication and monitoring) are present and functioning as planned. Controls are effective when senior management has a reasonable certainty: • • • The degree of achievement of operational objectives proposed, a statement that the information provided by the reports and corporate systems are reliable, and What laws, regulations and standards are being met.