Delegation of Authority Matrix Validator
Regime

COSO Internal Control, Integrated Framework: what it asks of an approval matrix

The internal control framework most financial controllers are audited against. Principle 3 asks management to define, assign and limit authority; Principle 10 asks for control activities that address segregation of duties; Principle 12 asks for policies that are reassessed.

Quoted for every matrix.

Approval families anchored here

40
FamilyClause
Purchase ordersCOSO P3 · COSO P10
Invoices with no purchase orderCOSO P3 · COSO P10
Capital expenditureCOSO P2 · COSO P3 · COSO P10
Leases and rental commitmentsCOSO P3 · COSO P10
Spend over budget and budget transfersCOSO P3 · COSO P10
Payment run releaseCOSO P8 · COSO P10
Urgent and manual paymentsCOSO P10
Bank account opening and changesCOSO P10
Vendor master data changeCOSO P8 · COSO P10
Employee expense claimsCOSO P10
Payroll releaseCOSO P10
Customer and sales contractsCOSO P3
Supplier contractsCOSO P3
Contracts signed for the companyCOSO P3
Confidentiality agreementsCOSO P3
Guarantees, indemnities and letters of creditCOSO P2 · COSO P3
Journal entriesCOSO P10
Accruals and prepaymentsCOSO P10
Provisions and reservesCOSO P10
Write-offsCOSO P10
Reconciliation sign-offCOSO P10 · COSO P16
FX, hedging and treasury dealsCOSO P10
Price and price list changesCOSO P10
Discounts and rebatesCOSO P10
Credit notesCOSO P10
Customer refundsCOSO P10
Customer credit limitsCOSO P10
New hires and headcountCOSO P3 · COSO P5
Pay changesCOSO P3 · COSO P5
Terminations and severanceCOSO P3 · COSO P5
Bonuses and incentivesCOSO P5
Privileged system access grantsCOSO P11
User access review sign-offCOSO P11 · COSO P16
Changes to production systemsCOSO P11
Changes to approval workflows and limits in the systemCOSO P9 · COSO P11
Acquisitions, disposals and borrowingCOSO P2 · COSO P3
Related-party transactionsCOSO P2 · COSO P3
Donations, sponsorships, gifts and hospitalityCOSO P2 · COSO P3
Litigation and claim settlementsCOSO P2 · COSO P3
Changes to the delegation of authorityCOSO P2 · COSO P3 · COSO P9

COSO Internal Control, Integrated Framework: every clause cited, quoted

10 of the 17 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

COSO P2 Principle 2: Exercises oversight responsibility

The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control. Points of focus: Establishes oversight responsibilities; Applies relevant expertise; Operates independently; Provides oversight for the system of internal control. The board identifies and accepts its oversight responsibilities for internal control, applies relevant expertise (including through committees and advisers), operates with enough independent members to be objective in evaluations and decisions, and retains oversight of management's design, implementation and conduct of the system across the five components.

What an auditor asks to see: Board and committee charters with internal control oversight responsibilities; Independence and expertise evidence; minutes of oversight
Where matrices usually fall short: Board oversight limited to the audit committee's financial reporting brief; No independent directors or no relevant expertise
Source: COSO Internal Control, Integrated Framework
COSO P3 Principle 3: Establishes structure, authority and responsibility

Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives. Points of focus: Considers all structures of the entity; Establishes reporting lines; Defines, assigns and limits authority and responsibilities. Management and the board consider the entity's multiple structures (operating units, legal entities, geographies, outsourced providers) in supporting objectives, establish reporting lines that enable the flow of information across activities, and define, assign and limit authorities and responsibilities at each level, including segregation of duties.

What an auditor asks to see: Organization charts, reporting lines and documented authorization policies revised for change
Where matrices usually fall short: Outsourced providers outside the structure considered; Authorities defined without limits
Source: COSO Internal Control, Integrated Framework
COSO P5 Principle 5: Enforces accountability

The organization holds individuals accountable for their internal control responsibilities in the pursuit of objectives. Points of focus: Enforces accountability through structures, authorities and responsibilities; Establishes performance measures, incentives and rewards; Evaluates performance measures, incentives and rewards for ongoing relevance; Considers excessive pressures; Evaluates performance and rewards or disciplines individuals. Management and the board establish mechanisms that hold individuals accountable for internal control responsibilities across the entity and through outsourced providers, establish performance measures, incentives and rewards aligned with responsibilities at all levels, evaluate those measures for ongoing relevance, consider and relieve excessive pressures that could drive undesirable behavior, and evaluate performance and reward or discipline individuals accordingly.

What an auditor asks to see: Performance measures and incentives reviewed for control effect; disciplinary and reward records
Where matrices usually fall short: Incentives that reward results without regard to control responsibilities; Pressure from targets never considered as a control risk
Source: COSO Internal Control, Integrated Framework
COSO P8 Principle 8: Assesses fraud risk

The organization considers the potential for fraud in assessing risks to the achievement of objectives. Points of focus: Considers various types of fraud (applicable to ICFR); Assesses incentives and pressures; Assesses opportunities; Assesses attitudes and rationalizations. The assessment of risks to objectives considers the potential for fraud in its various types (fraudulent reporting, misappropriation of assets, corruption, management override), assesses the incentives and pressures, the opportunities from control weaknesses, and the attitudes and rationalizations that could lead individuals to commit fraud.

What an auditor asks to see: Fraud risk assessment covering types, incentives, opportunities and rationalizations, including management override
Where matrices usually fall short: Fraud risk considered only for misappropriation; Management override never assessed
Source: COSO Internal Control, Integrated Framework
COSO P9 Principle 9: Identifies and analyzes significant change

The organization identifies and assesses changes that could significantly impact the system of internal control. Points of focus: Assesses changes in the external environment; Assesses changes in the business model; Assesses changes in leadership. The organization identifies and assesses changes that could significantly affect the system of internal control: changes in the external environment (regulatory, economic, physical), changes in the business model (new lines, acquisitions, rapid growth, foreign operations, new technologies) and changes in leadership and their effect on attitudes to internal control.

What an auditor asks to see: Change assessment integrated into risk assessment with the external, business model and leadership changes considered
Where matrices usually fall short: Acquisitions integrated without reassessing controls; Leadership change with no reassessment of tone
Source: COSO Internal Control, Integrated Framework
COSO P10 Principle 10: Selects and develops control activities

The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels. Points of focus: Integrates with risk assessment; Considers entity-specific factors; Determines relevant business processes; Evaluates a mix of control activity types; Considers at what level activities are applied; Addresses segregation of duties. Control activities are selected and developed integrated with the risk assessment, considering entity-specific factors (environment, complexity, nature, scope), the relevant business processes, a mix of control activity types (preventive and detective, manual and automated), the level at which activities are applied, and segregation of duties where practical, with alternative controls where not.

What an auditor asks to see: Control matrices linking risks to control activities across processes and levels, with segregation of duties analysis
Where matrices usually fall short: Controls not traceable to assessed risks; Segregation conflicts unmitigated
Source: COSO Internal Control, Integrated Framework
COSO P11 Principle 11: Selects and develops general controls over technology

The organization selects and develops general control activities over technology to support the achievement of objectives. Points of focus: Determines dependency between the use of technology in business processes and technology general controls; Establishes relevant technology infrastructure control activities; Establishes relevant security management process control activities; Establishes relevant technology acquisition, development, and maintenance process control activities. Management determines the dependency between the use of technology in business processes and technology general controls, and establishes the control activities over the technology infrastructure, over security management (access to the technology by role and function), and over technology acquisition, development and maintenance, appropriate to the technology in use.

What an auditor asks to see: General IT controls over infrastructure, access and change, mapped to the business processes that depend on them
Where matrices usually fall short: Application controls relied on with no general controls over the platform; Access reviews absent
Source: COSO Internal Control, Integrated Framework
COSO P12 Principle 12: Deploys through policies and procedures

The organization deploys control activities through policies that establish what is expected and procedures that put policies into action. Points of focus: Establishes policies and procedures to support development of management’s directives; Establishes responsibility and accountability for executing policies and procedures; Performs in a timely manner; Takes corrective action; Performs using competent personnel; Reassesses policies and procedures. Policies establish what is expected and procedures put the policies into action; management establishes responsibility and accountability for executing them in the relevant units, personnel perform control activities in a timely manner, take corrective action on the matters identified, perform the activities with competence and diligence, and management periodically reassesses the policies and procedures for continued relevance.

What an auditor asks to see: Documented policies and procedures with owners; evidence of timely performance, corrective action and periodic review
Where matrices usually fall short: Procedures documented but not performed on schedule; Policies never reassessed after process change
Source: COSO Internal Control, Integrated Framework
COSO P16 Principle 16: Conducts ongoing and/or separate evaluations

The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning. Points of focus: Considers a mix of ongoing and separate evaluations; Considers rate of change; Establishes baseline understanding; Uses knowledgeable personnel; Integrates with business processes; Adjusts scope and frequency; Evaluates objectively. Management includes a balance of ongoing evaluations built into business processes and separate evaluations performed periodically, considers the rate of change in the business, establishes a baseline understanding of the system's design and current state, uses evaluators with sufficient knowledge, integrates ongoing evaluations with business processes, adjusts the scope and frequency of separate evaluations by risk, and evaluates objectively.

What an auditor asks to see: Monitoring plan combining ongoing and separate evaluations with scope and frequency by risk; evaluator competence
Where matrices usually fall short: Monitoring limited to the annual SOX test cycle; Ongoing evaluations that nobody records
Source: COSO Internal Control, Integrated Framework
COSO P17 Principle 17: Evaluates and communicates deficiencies

The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate. Points of focus: Assesses results; Communicates deficiencies; Monitors corrective actions. Management and the board assess the results of ongoing and separate evaluations, deficiencies are communicated to the parties responsible for corrective action and to senior management and the board as appropriate, and management tracks whether deficiencies are remediated on a timely basis.

What an auditor asks to see: Deficiency log with severity, ownership, communication to the board and remediation tracking
Where matrices usually fall short: Deficiencies found by monitoring not escalated; Remediation never tracked to closure
Source: COSO Internal Control, Integrated Framework