Beruflich Dokumente
Kultur Dokumente
Call to action
Familiarize the Board of Directors (especially the Audit Committee and Independent Directors) and Senior Management Personnel
with respect to their enhanced responsibilities regarding IFC.
Assess the controls set-up in your organization using the following grid:
Policies/Guidelines
Operating Procedures
Technology
Several controls are preventive in nature and
automated. Detective controls and monitoring
processes are technology enabled with one
version of truth
Assess the
current state of
IFC
Behaviour
| Companies Act
Entity
Controls
Control Governance
& Standards
Control Design
Risk Identication
Capacity to Deliver Objectives
Control Operation
Control Systems
Continuous Improvement
Compliance Monitoring
Control Monitoring
Management
Assurance (Ongoing
Controls Monitoring)
| Companies Act
Regulators
External Audit
Questions to be considered
by a CXO
Structure/Framework
Do we have a structure/program to train our employees on their role in the overall internal
controls process?
Do we have relevant skills (skills around fraud risks, IT controls, analytics for continuous
controls monitoring etc.), focused teams and bandwidth to the support the IFC agenda?
Do we have entity level controls w.r.t policies and procedures, risk assessment, whistle
blowing, ethics etc. that are clearly established, communicated and monitored?
Do we periodically review, assess and refresh our controls framework in line with emerging
guidance around applicable standards like COSO?
Implementation
Are authority, responsibility and accountability clearly (delegation of authority and segregation of
duties) defined such that decisions are made and actions taken at an appropriate level?
Do we periodically assess and optimize controls to improve effectiveness, reduce costs and
support business performance?
Do we have policies and procedures covering all domains such as Finance and Accounts, Business
Operations and Compliance?
Are our policies and procedures easy to access and comprehend? Are these maintained and
updated on the technology platform on a regular basis?
Do we regularly up-skill our employees to address the emerging needs of your organisation in
areas such as GRC, IT controls, fraud risks etc.?
Do we have common understanding on the Risk that Matter among relevant stakeholders?
Do we consider fraud risks as part of the risk management exercise and address them with clear
action, accountability and ownership?
Do we pay adequate focus on safeguarding of assets, fraud indicators and perform periodic
independent verification in this area?
Do we effectively track and proactively monitor our compliance agenda around domestic/
international footprint, covenants, compliance with guidelines etc.?
Well
prepared
Requires
consideration
Structure/Framework
Implementation
Notes
| Companies Act
Do I need support?
Train Board members (including Audit Committee and Independent Directors) on IFCrelated requirements of the Act
Establish internal controls framework covering both Entity Level Controls and Process
Controls (covering finance and accounts, business processes, compliance and IT) in line
with leading industry/controls practices
Benchmark controls against leading practices; IT controls, prevent v. detect, manual v.
automated
Establish a comprehensive Risk Management Framework and/or targeted intervention in
areas such as:
Identifying and prioritizing risks that matter
Automating the risk monitoring process
Defining value at risk and/or risk impact
Monitoring and management of fraud risks
Continuous controls monitoring and fraud risk analytics through Data Analytics lab
Design and implement controls self-assessment
Design and assist in implementation of delegation of authority, segregation of duties etc.
Implementation support for GRC rollout
Develop standard operating procedures including relevant policies and guidelines
Rationalize and automate current controls portfolio to reduce overall cost of control while
improving effectiveness
Design MIS and board reporting pack to facilitate evaluation of IFCs
Train employees on their role in the overall internal controls process and on leading
practices for managing emerging risks in areas such as IT, fraud, contract compliance etc.
Compliance Management
Controls Transformation
To measure the gap that you need to bridge to comply with the Act and understand more about how we are assisting our clients
with IFCs, please contact us at ifcsolutions@in.ey.com
7
EY offices
Ahmedabad
2nd floor, Shivalik Ishaan
Near C.N. Vidhyalaya
Ambawadi
Ahmedabad - 380 015
Tel: + 91 79 6608 3800
Fax: + 91 79 6608 3900
Bengaluru
12th & 13th floor
UB City, Canberra Block
No.24 Vittal Mallya Road
Bengaluru - 560 001
Tel: + 91 80 4027 5000
+ 91 80 6727 5000
Fax: + 91 80 2210 6000 (12th floor)
Fax: + 91 80 2224 0695 (13th floor)
1st Floor, Prestige Emerald
No. 4, Madras Bank Road
Lavelle Road Junction
Bengaluru - 560 001
Tel: + 91 80 6727 5000
Fax: + 91 80 2222 4112
Chandigarh
1st Floor, SCO: 166-167
Sector 9-C, Madhya Marg
Chandigarh - 160 009
Tel: + 91 172 671 7800
Fax: + 91 172 671 7888
Chennai
Tidel Park, 6th & 7th Floor
A Block (Module 601,701-702)
No.4, Rajiv Gandhi Salai, Taramani Chennai 600113
Tel: + 91 44 6654 8100
Fax: + 91 44 2254 0120
Hyderabad
Oval Office, 18, iLabs Centre
Hitech City, Madhapur
Hyderabad - 500081
Tel: + 91 40 6736 2000
Fax: + 91 40 6736 2200
Kochi
9th Floor, ABAD Nucleus
NH-49, Maradu PO
Kochi - 682304
Tel: + 91 484 304 4000
Fax: + 91 484 270 5393
Kolkata
22 Camac Street
3rd floor, Block C
Kolkata - 700 016
Tel: + 91 33 6615 3400
Fax: + 91 33 2281 7750
| Companies Act
Mumbai
14th Floor, The Ruby
29 Senapati Bapat Marg
Dadar (W), Mumbai - 400028
Tel: + 91 022 6192 0000
Fax: + 91 022 6192 1000
NCR
Golf View Corporate Tower B
Near DLF Golf Course
Sector 42
Gurgaon - 122002
Tel: + 91 124 464 4000
Fax: + 91 124 464 4050
Ernst & Young LLP is one of the Indian client serving member firms of
EYGM Limited. For more information about our organization, please visit
www.ey.com/in.
Ernst & Young LLP is a Limited Liability Partnership, registered under the
Limited Liability Partnership Act, 2008 in India, having its registered office
at 22 Camac Street, 3rd Floor, Block C, Kolkata - 700016
2014 Ernst & Young LLP. Published in India.
All Rights Reserved.
EYIN1402-012
ED None
Pune
C-401, 4th floor
Panchshil Tech Park
Yerwada
(Near Don Bosco School)
Pune - 411 006
Tel: + 91 20 6603 6000
Fax: + 91 20 6601 5900
ifcsolutions@in.ey.com