Monitoring, Auditing, and Internal Reporting Systems Flashcards
1
Q
Internal Reporting
A
- Protect anonymity and confidentiality within legal and practical limits for those reporting
- Publicize the reporting system to employees, vendors, and third parties
- Ensure systems exist to enable employees, vendors, and third parties to report any noncompliance and seek advice (e.g., hotline)
- Assure processes exist to respond to compliance and ethics concerns expressed through internal reporting
- Include compliance and ethics questions in exit interviews
2
Q
Auditing
A
- Audit compliance and ethics related risks
- Analyze compliance and ethics audit results (e.g., track, trend, evaluate, benchmark)
- Ensure audit results from external entities (e.g., outside counsel, government,
consultants) are addressed
3
Q
Monitoring
A
- Monitor compliance and ethics related risks
- Monitor compliance and ethics related activities (e.g., hotline calls, training, and investigations)
- Monitor for organizational misconduct (e.g., violations of applicable laws, regulations, policies and procedures)
- Evaluate the effectiveness of the compliance and ethics program on an ongoing basis
4
Q
Differences between Auditing and Monitoring
A
Auditing
* Formalized method
* Independent from management
Provides objective assurance to
board and others
* Concurrent vs. retrospective
Monitoring
* Day to day process by management
* Not required to be independent
5
Q
Independent Monitors
A
Independent Monitors -
* When are they useful?
* Proactively identify problems
* In response to a pattern of complaints
* During or after a regulatory sanction
6
Q
Compliance Plan
A
- Develop a periodic risk-based audit compliance plan
- Assess the existing risk-based audit compliance plan to address dynamic changes in risk priorities