coso 2013 implementation at nysdotnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4....

15
Implementation at NYSDOT E N T E R P R I S E R I S K M A N A G E M E N T B U R E A U NEW YORK STATE DEPARTMENT OF TRANSPORTATION COSO 2013

Upload: others

Post on 30-Mar-2021

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

Implementation at

NYSDOT E N T E R P R I S E R I S K M A N A G E M E N T B U R E A U

NEW YORK STATE DEPARTMENT OF TRANSPORTATION

COSO 2013

Page 2: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

Pre- COSO 2013

Self-Assessment Approach for IC Reviews

Improvement Opportunities/ Business Planning

KPMG Overview of COSO 2013 Framework

Page 3: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

NYSDOT’s Game Plan

Satisfy Multiple Objectives • Perform gap analysis: COSO 2013

• Incorporate payment process controls review: OSC Certification

• Implement Internal Control and Risk Database System (ICARDS):DOB Certification

Page 4: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

COSO 2013 Gap Analysis

Used tools from KPMG Study Guidance and COSO

Assessed existing IC program

Mapping worksheet comparing IC Review to COSO’s 17 principles

Identified improvement opportunities

Page 5: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

Improvement Opportunities

Incorporate COSO 2013 changes into IC Reviews Modified IC Review form

Expanded questions to align with 17 principles: fraud, system security and data quality

Document Internal Control Improvements

Page 6: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

Improvement Opportunities

Policies &Procedures

Separation of Duties

Authorization & Approvals

Verification & Reconciliation

Monitoring

Documentation

Data Quality

Quality Assurance

Develop IC Review – Payment Process

Page 7: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

Comprehensive Documentation

Page 8: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

NYSDOT Mapping Worksheet

Page 9: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

COSO 2013 Compliance

Page 10: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

Improvement Opportunities

Improved Risk Management •Risk form & guidance documents

•Meetings to discuss risks

•Corrective Action Plans

•Enterprise Risk Management Program

•NYS Cyber Security Risk Management Initiative

Page 11: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

Improvement Opportunities

Improved QA/QC Program Monitoring Met w/managers: document objectives, controls and risks

Annual reports: Improvement recommendations

Facilitated meetings and Action Plans to monitor initiatives

Page 12: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

Improvement Opportunities Implemented ICARDS (database)

•Functions/Objectives •Risks (program area & enterprise) •IC Improvements •CAPs & Status Updates •QA/QC Program Information •Tracking of IC Reviews •Easy Reporting Capabilities

Page 13: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

Next Steps 2016 Fraud Risk Assessment Program

•Identify functions in NYSDOT Inventory

•Assess threats and opportunities

•Evaluate controls

•Manage risk

Page 14: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

Questions?

Page 15: COSO 2013 Implementation at NYSDOTnysica.com/uploads/3/4/8/5/34855847/coso2013... · 2016. 4. 29. · review: OSC Certification •Implement Internal Control and Risk ... Incorporate

Contact Information:

Kimberly Joy Doran

NYS Department of Transportation

Enterprise Risk Management Bureau

(518) 457-1590

[email protected]