1.4.2 Monitoring and Improving Internal Accounting and Administrative Controls
1.4.2.1 (05-31-2002)
Implementing the Federal Managers’ Financial Integrity Act - an Overview
- The Budget and Accounting Procedures Act of 1950 requires the head of each Federal department and agency to establish and maintain adequate systems of management controls. Further, the Federal Managers’ Financial Integrity Act (FMFIA) of 1982 (also known as the Integrity Act) requires, among other things:
- That each executive agency conduct annual evaluations of its systems of internal accounting and administrative control, using guidelines established by the Director of the Office of Management and Budget (OMB); and
- That each executive agency submit an annual statement to the President and Congress on the status of the agency’s system of management controls.
- Office of Management and Budget (OMB) Circular A-123 (revised) dated June 21, 1995, provides guidance to federal managers on improving the accountability and effectiveness of Federal programs and operations by establishing, assessing, correcting, and reporting on management controls. OMB Circular A-123 also requires agencies and individual federal managers to take systematic and proactive measures to develop and implement appropriate, cost-effective management controls for results-oriented management; to assess the adequacy of management controls in Federal programs and operations; to identify needed improvements and take corresponding corrective action; and to report annually on management controls.
- Treasury Directive 40-04, dated January 4, 2001, provides guidance to Treasury managers on the Treasury Internal (Management) Control Program. Treasury confirmed by a memorandum dated August 30, 2001, that this Directive continues to apply to all Bureaus until a revision is made.
- In addition, the Federal Financial Management Improvement Act of 1996 (FFMIA) requires agency heads to assess and report annually and in accordance with Federal accounting standards and the US Standard General Ledger (SGL) on whether their financial management systems:
- can prepare required financial statements and reports,
- can provide reliable and timely financial information for managing operations, and
- can account for assets.
- The Internal Revenue Service intends to maintain an effective management controls program that complies with legislative requirements and related regulations and directives.
- Management controls are the organization, policies and procedures used by management to assure the efficient and effective accomplishment of its mission and program objectives; and to ensure that the use of resources is done in accordance with the mission; programs and resources are protected from waste, fraud, and mismanagement; laws and regulations are followed; and reliable, timely information is obtained and used for decision making.
- The Service’s management controls are most often published in the IRM, but they may also be published in the form of standard announcements, Chief Officer memoranda, Division Commissioner memoranda, and the like.
- IRS managers at all levels are expected to understand the risks associated with their operations, to ensure that controls are in place and operating effectively to mitigate known risks, and to provide candid, reliable, and supportable annual reports on the status of those controls.
- This guidance applies to all IRS managers, in both Operating Divisions and Functions.
- Detailed guidance on Servicewide procedures for assessing risk, evaluating and improving the effectiveness of management controls, and reporting requirements are provided in Exhibit 1.4.2–1, Management Controls Accountability Program (MCAP) Handbook for Managers.
- Specific instructions for preparing required reports will be provided as needed by memoranda issued by the Chief Financial Officer.
- The Commissioner and Deputy Commissioner of Internal Revenue have overall responsibility for the Service’s system of management controls and for ensuring that the Service has an effective management controls program.
- The Financial and Management Controls Executive Steering Committee (FMC ESC) provides policy guidance and oversight for the Service’s management controls program and makes recommendations to the Commissioner on the contents of the Service’s annual assurance statement to the Secretary of the Treasury.
- The Chief Financial Officer (CFO) is IRS’s Management Controls Officer, and has operational responsibility for the Service’s management controls program.
- The Office of Management Controls (OMC), on behalf of the CFO, administers the Service’s management controls program. The OMC is responsible for:
- Recommending policy and procedures for the management controls program;
- Providing administrative support to the FMC ESC;
- Managing the annual assurance process and preparing the Commissioner’s annual assurance letter to the Secretary of the Treasury;
- Monitoring the completion of corrective actions for material weaknesses and for audit corrective actions, and providing periodic reports to Treasury;
- Providing advice and assistance to Service managers and their coordinators, as needed; and
- Developing training content and assuring proper training is available to Service managers and their coordinators.
- The Director, Legislative Affairs, is responsible for advising the CFO of recent or planned General Accounting Office (GAO) or Treasury Inspector General for Tax Administration (TIGTA) audit work.
- The Division Commissioners, Chiefs, and National Taxpayer Advocate are responsible for:
- Establishing adequate and effective controls for all operations and activities in their area of mission responsibility, Servicewide;
- Ensuring that established controls are followed throughout their organization;
- Conducting a self-assessment and reporting on the status of management controls in their organization to the FMC ESC annually: (NOTE: Managers throughout the Service are responsible for participating in this annual assessment in accordance with the annual guidance issued.)
- Evaluating Chief and Division Commissioners’ reports of significant control deficiencies and providing comments to the FMC ESC;
- Providing adequate resources to correct identified control deficiencies; and
- Designating a Senior Management Controls Coordinator to serve as a single point of contact for the assurance process and for FMFIA corrective actions and audit follow-up for their organization. The position occupied by the coordinator should have sufficient organizational stature to command the attention of managers throughout the Executive’s organization and the ability to focus resources to correct identified deficiencies.
- Senior Management Controls Coordinators are responsible for assisting their organization’s top management in the basic direction and emphasis of its management controls program and serve as its primary liaison with the Office of Management Controls. Their responsibilities include:
- Managing their organization’s annual assurance review process and preparing its assurance certification memorandum;
- Providing technical assistance to management and review teams in the evaluation of controls;
- Preparing and submitting to the OMC verification of completion of corrective actions for significant control deficiencies, material weaknesses, and GAO and TIGTA audit reports;
- Monitoring the status of corrective actions for material weaknesses, control deficiencies, and audits, as well as reporting that status to the OMC.
- The Financial and Management Controls Executive Steering Committee consists of 14 members (or their assigned alternates):
- Deputy Commissioner of the IRS (Chairperson)
- IRS Chief Financial Officer (Co-Chairperson)
- Deputy Chief Financial Officer, Treasury Department
- National Executive President, National Treasury Employees’ Union (NTEU)
- Associate Chief Counsel (Finance/Management)
- Assistant Deputy Commissioner
- Four Division Commissioners (Large & Mid-Size Business, Small Business/Self-Employed, Tax Exempt & Government Entities, Wage & Investment)
- Four Chiefs (Agency-Wide Shared Services, Criminal Investigation, Communications & Liaison, Information Officer).
- The FMC ESC meets, on average, ten times a year to review the Service’s progress in correcting identified control deficiencies and audit findings, resolve cross-functional and funding or priority issues, and determine whether corrective actions have been effective.
- The Service’s annual assurance statement is due to Treasury either by the end of October or upon the conclusion of GAO’s audit of the IRS Financial Statements each year, whichever is later.
- The Chief Financial Officer will issue guidance each Spring to govern the annual self-assessment of management controls. Guidance will be issued to Chiefs and Division Commissioners, and will include the Self-Assessment Tool for Managers, which is provided asExhibit 1.4.2–2.
- The self-assessment will address all aspects of the organization’s activities and report any significant control deficiencies that are found. The assessment should be based on the programmatic knowledge of managers and should consider the results of any reviews that have been conducted during the fiscal year.
- Corrective action plans will be prepared for all control deficiencies identified during the self-assessment. Significant control deficiencies will be reported to the next higher level of management.
- Corrective action plans for deficiencies identified in the previous fiscal year will be updated. Deficiencies that have been corrected will be submitted with a certificate of completion describing the validation process and the Results Indicator data that verifies that the deficiency has been corrected.
- The results of the self-assessment are reported in an Assurance Certification Memorandum, which is due in early Summer.
- The Assurance Certification Memorandum required by the Integrity Act will briefly describe the process used to verify the status of the organization’s management controls and explain the basis for the executive’s conclusions. The memorandum must contain a specific statement describing the condition of those management controls that takes one of the following three forms:
- There is reasonable assurance that the organization’s controls are effective and operating as intended, or
- There is qualified assurance that the organization’s controls are effective and operating as intended, considering the exceptions described in the report, or
- The organization does not have reasonable assurance that its controls are effective.
- Corrective action plans for newly-identified significant control deficiencies will be included in the report, as will updated corrective action plans or certificates of completion for deficiencies that were identified in previous fiscal years.
- In addition, the memorandum must address the compliance of the Service’s financial management systems with the provisions of FFMIA and also provide assurance regarding the reliability of data and the status of the Service’s Continuity-of-Operations plans.
- The Financial and Management Controls Executive Steering Committee will evaluate these reports, and based on this and other relevant information, recommend to the Commissioner what level of assurance should be submitted in the Service’s annual assurance statement, and any newly-identified material weaknesses.
- As noted above, the FFMIA requires agency heads to assess and report annually whether their financial management systems can prepare required financial statements and reports, provide reliable and timely financial information for managing operations, and account for assets, all in accordance with Federal accounting standards and the US Standard General Ledger.
- Agencies that are not in substantial compliance with FFMIA must develop a Remediation Plan to achieve compliance. The plan must include remedies, the resources required for implementation, and proposed implementation dates.
- Agencies that are not in substantial compliance with FFMIA must bring their financial management systems into substantial compliance within three years; if this cannot be achieved, a waiver for a longer period must be requested from OMB.
- The Deputy Commissioner has overall responsibility for IRS’ Remediation Plan. The Plan is monitored by the FMC ESC and tracked in Treasury’s Inventory Tracking and Closure System (ITCS) by the Office of Management Controls.
- Area of Concern - An instance of weak or missing controls that is important enough to be disclosed in the Commissioner’s report to the Secretary, but which does not merit formal status as a material weakness.
- Control Objective - the specific purpose for which a management control is established (i.e., to reasonably assure that a specific risk does not become a negative occurrence).
- Material Weakness - A control deficiency that significantly impairs the fulfillment of the Service’s mission or that the Commissioner determines to be significant enough to be reported outside the Service (i.e., be included in the annual Integrity Act report to the Secretary and, therefore, to the President and the Congress).
- Qualified Assurance -a description of the condition of an organization’s controls that is intermediate between “reasonable assurance” and “no assurance”. It is assurance that is qualified because of the number or severity of the specific control deficiencies that are reported in the Head of Office’s assurance memorandum.
- Reasonable assurance - An informed judgment by the head of an organization, based upon all available information, regarding the adequacy and effectiveness of the organization’s management controls. Reasonable assurance recognizes that the cost of controls should not exceed the benefits derived from them. It equates to a satisfactory level of confidence that resources and mission accomplishment are adequately protected within the context of program-specific risks balanced against the costs and benefits of mitigating those risks.
- Significant Control Deficiency - A specific instance of weak or missing controls that is of sufficient importance to be reported to the next level of management. Criteria for recognizing when to report a significant control deficiency include conditions that:
- Could lead to a serious injury or loss of life;
- Could exist in other parts of the organization/Service;
- Could cause higher levels of management to be questioned by Congress or the media;
- Could take more than three months to correct;
- Could have potential for significant loss of government resources;
- Could cause significant financial loss, either through misuse of appropriated funds or under collection of revenues;
- Could break laws or violate regulations;
- Could have potential liability to employees or third parties;
- Could cause ethical violations by organizational personnel;
- Could provide inaccurate information to be reported/used for management decisions;
- Could lead to an audit qualification on a Financial Statement.
- Chapter 35 of Title 44, U.S.C., known as the Paperwork Reduction Act.
- Federal Managers Financial Integrity Act of 1982 (P.L. 97-255) codified at 31 U.S.C. 3512.
- Chief Financial Officers Act of 1990 (P.L. 101-576).
- Government Performance and Results Act of 1993 (P.L. 103-62).
- Federal Financial Management Improvement Act of 1996, Title VII of Section 101(f) of Title I, Division A of P.L. 104-208, as codified at 31 U.S.C. 3512 note.
- OMB Circular A-11, Part 2, Preparation and Submission of Strategic Plans, Annual Performance Plans, and Annual Program Performance Reports (Revised November 8, 2001).
- OMB Circular A-123, Management Accountability and Control (Revised June 21, 1995), prescribes policies and standards for evaluating, improving, and reporting on management controls for program, administrative, and financial activities.
- OMB Circular A-127, Financial Management Systems (Revised July 13, 1999), prescribes policies and standards for developing, operating, evaluating and reporting on financial management systems.
- OMB Circular A-130, Management of Federal Information Resources (Revised February 8, 1996) establishes policy for the management of Federal information resources and gives guidance for implementing those policies.
- OMB Circular A-50, Audit follow-up (September 29, 1982) establishes requirements for responding to audit reports.
- GAO’s Standards for Internal Control in the Federal Government (GAO/AIMD-00-21.3.1 of November 1999) establishes government-wide standards for management controls that apply to both program management and financial management.
- Treasury Directive 40-04, Treasury Internal (Management) Control Program (January 4, 2001), assigns responsibilities and provides guidance for establishing, evaluating, improving, and reporting on management controls for all program and administrative activities in the Department of Treasury.
- Treasury Directive 40-03, Treasury Audit Resolution, Follow-Up, and Closure (February 2, 2001), assigns responsibilities and provides guidance for evaluating, resolving, tracking, and closing audit reports for all activities in the Department of Treasury.
- Department of the Treasury’s Federal Managers’ Financial Integrity Act Guidelines for Section 2 and Section 4 (April 1988), offers guidance that may be helpful in planning for evaluations of management controls and financial management and accounting systems.
- Management Controls Accountability Program (MCAP) Handbook for Managers, Version 2.01 of February 23, 2001, provided as Exhibit 1.4.2–1, contains detailed guidance for the Service’s management controls program, as well as many of the above-listed references.
| GUIDING PRINCIPLES
Achieving the IRS’ strategic goals will require change at every level of the organization, from front-line employees to top managers. During this process, it is helpful to articulate principles that guide our actions. These five guiding principles are a link between our goals and the actions we take to achieve them. |
| PURPOSE AND SCOPE
Purpose of the Management Controls Accountability Program Handbook for Managers As IRS managers, you are responsible for ensuring that your programs and organizations are managed effectively, and that financial, information, property, and human resource assets are protected and used wisely. The purpose of the Management Controls Accountability Program (MCAP) Handbook is to provide managers with a methodology for implementing management controls within their program to ensure effective management and protection of assets. The Service’s Guiding Principles emphasize that managers must be accountable, acknowledge and address problems, and perform with integrity. The MCAP supports these principles as well. The MCAP fits the Service’s overall Management Model. The Management Model and the MCAP are based on a linked system of management processes (Plan, Do, Review, and Revise). Both the MCAP and the Management Model support the new mission, strategic goals, and guiding principles of the Service and offer a framework for managing in a Balanced Measurement System environment. |
| Scope of the Management Controls Accountability Program Handbook
The Handbook provides an overview of the MCAP, which supports the Federal Managers Financial Integrity Act (FMFIA) process. It was developed for managers at all levels of the organization and takes a “one-size-fits-all” approach. It is designed to help managers understand their responsibility for implementing, maintaining, and reporting on management controls. Management controls are the programs, policies, and procedures established to ensure that: This Handbook conforms with the General Accounting Office (GAO) Standards for Internal Control in the Federal Government, issued November 1999 and describes and explains the: All IRS managers must have a copy of this Handbook. This Handbook refers to the duties of the MCAP Coordinator. The MCAP Coordinator provides support and guidance to executives and managers on conducting the MCAP. Placement and extent of involvement of the MCAP Coordinator may vary depending on the structure, size, and complexity of your organization. This Handbook is not intended as a desk guide or manual for the Coordinator. A separate document and training materials will be developed specifically to meet the needs of MCAP Coordinators. Where the Handbook uses the term “Head of Office,” it refers to the appropriate executive level within your organization. |
| CHAPTER 1. OVERVIEW
The importance of management controls cannot be overstated. As IRS transitions into the re-engineered core business activities and our modernization plans become a reality, all managers must continue their commitment to implementing effective and efficient management controls. Without effective controls, the Service risks wasting program dollars, and worse, losing public confidence. In addition, Treasury and GAO continue to mandate that IRS vigorously pursue management control strategies that mitigate risk in program and administrative operations. There are numerous risks to the organization if proper controls are not in place. These include the possibility of: Management controls are often misrepresented to be the sole responsibility of financial, procurement, or other organizations managing processes with tangible dollar assets. This is not the case; management controls are the responsibility of every manager. You are accountable for, and have stewardship of, all IRS operations within your organization, including program, administrative, and financial areas under your control. Your responsibilities include: The MCAP is designed to enable managers to identify and promptly correct management control deficiencies. A continuing assessment of management controls will help you identify opportunities to prevent and solve problems, improve your products, and provide quality customer service. Managers’ Accountability It is beneficial to both the Service and managers to be proactive in identifying problem areas and taking appropriate corrective actions before external audit sources, such as GAO and Treasury Inspector General for Tax Administration (TIGTA), issue findings or before problems escalate into serious control weaknesses. However, you must strike an appropriate balance of controls in your programs and operations. For example, an over-controlled process or program may be costly to implement and interfere with program accomplishment. Similarly, an uncontrolled or under-controlled situation may allow problems to go unnoticed and assets to be wasted. Being focused and aware of management controls should be an integral part of the daily activities of all IRS managers and employees. By fostering open, honest communications and promoting problem-solving within your organization, you create an environment where management controls are acknowledged as tools to achieving our goals. Legal Background In addition to being a good business practice, management control accountability is mandated by law. In 1982, Congress passed the FMFIA requiring: Since the Act was established, all federal agencies have been required to report annually to the President and the Congress as to whether their management controls comply with the GAO’s standards. Although the FMFIA reporting requirements changed at the end of FY 1999, Treasury bureaus are still mandated to evaluate and report annually on their management controls. Congress enacted other statutes that provide a framework for management accountability. These include the Chief Financial Officers (CFO) Act of 1990, as expanded by the Government Management Reform Act (GMRA) of 1994; the Government Performance and Results Act (GPRA) of 1993; and the Federal Financial Management Improvement Act (FFMIA) of 1996. |
| CHAPTER 2. ROLES AND RESPONSIBILITIES
The following defines specific manager and employee responsibilities for maintaining effective management control systems. Managers at all levels Heads of Office In addition to the above responsibilities for all managers, Heads of Office must also: MCAP Coordinators Office of Management Controls (OMC) Chief Financial Officer/Director, Financial Analysis Financial and Management Controls Executive Steering Committee (FMC ESC) Commissioner of Internal Revenue The Secretary of the Treasury |
| CHAPTER 3. MCAP PROCESS
The MCAP process is an ongoing practice that encompasses all aspects of IRS operations. The MCAP process steps are: This chapter addresses each step and explains use of the MCAP process to: |
| 3A. IDENTIFY RISK
Risk is nothing more than the probability of a negative, unanticipated occurrence. Risk is inherent in every activity; therefore, it is essential that you identify the probability of risk within your operations and activities. Unacceptable or highly undesirable risk becomes the basis for establishing and maintaining management controls. You should be primarily concerned with the risk areas within your program authority. This can vary from manager to manager, even within the same function. For example, all Collection managers would identify the timely filing of Federal tax liens as a potential risk area. However, the manager of the Offers-in-Compromise group would have an additional risk associated with maintaining proper documentation to support the acceptance or rejection of an offer that other managers would not. Some areas or occurrences with higher potential for risk include: Research Sources to Identify Risk The assessment of risk is based on your organizational knowledge, knowledge gained from other organizations, and communication with your employees. Risk can often be identified in previous reviews of the organization rather than requiring the manager to perform a new review. To identify risk, you must: b. Ensure that organizational processes are performed in accordance with written policies and procedures, such as: c. Involve your employees in identifying risk. Since employees are often closest to the organization’s daily operations, they may become aware of risks and can alert you to problems as they arise. Examples of actions a manager might take to identify risks include: Assess Level of Risk You need to make informed judgments in order to determine the level of risk for the activities within your organization. Depending on the impact of negative occurrences, the level of risk will vary from activity to activity. For instance, an activity that violates statutory or regulatory requirements would be assessed at a high level of risk while missing one step in standard operating procedures might have lesser consequences. Your assessment of the level of risk will guide you in determining where management controls need to be strengthened or established. |
| 3B. DETERMINE EXISTING CONTROLS Once risk areas have been identified, determine what management controls exist for those areas. A management control is the method by which an organization governs its activities. Controls provide ‘reasonable assurance’ that programs and administrative activities are efficient, effective, and pose the lowest level of potential risk. Management controls provide “reasonable assurance” that: Controls are not separate systems or processes; they are tools routinely used by managers to manage their operations. The focus is not to have more controls but to have effective controls that mitigate risks. Some examples of management controls are: To determine existing controls, begin by comparing current practices and processes against existing procedures, policies and guidelines. Also consult your peers and employees to ensure that existing controls have been identified and that they do not overlap or conflict with other controls that are in place. It is as important to eliminate unnecessary or duplicative controls as it is to establish new controls. Some “red flags” that may indicate a need for assessing existing controls are: Examples of control methods for specific areas of concern are listed below. |
| Area of Concern | Control Method |
| Inventory Controls | Physical inventory reconciliation is performed |
| Procedures | Procedures are disseminated on a timely basis to the proper employees |
| Delegation of Authority | Authority to approve critical processes is delegated to the appropriate level and is documented |
| Limit system access | User profiles for systems access are appropriate for the requirements of the job |
| Separation of Duties | Duties are separated to avoid having one employee or a small group of employees handling all steps of a process |
| Supervision | Adequate supervision to ensure organizational goals are achieved |
| Quality Reviews | Workload reviews are conducted to ensure quality work products |
| Data Security | Sensitive information is protected from unauthorized access |
| Physical Asset Security | Assets (laptops, etc.) secured to protect against theft |
| The GAO Standards contain additional examples of control activities, including specific control activities for information systems.
If controls are needed and none currently exist, you may be responsible for establishing them (see Chapter 3.C). In cases where you determine that the level of risk does not justify establishing a formal control mechanism, you should still document your findings and decisions for future reference and use in the Annual Assurance Review Process (see Chapter 4). |
| 3C. ESTABLISH NEW MANAGEMENT CONTROLS OR REVISE EXISTING CONTROLS
Once you have decided that a process needs a control, determine whether you own the process. If you do not own the process at risk but it impacts your operation, proactively coordinate with the process owners or other stakeholders to encourage them to improve those management controls. You may also find it necessary to elevate the issue to higher levels. The control you are using may be a standardized control for your organization. However, if you find that it is not working properly, you should still inform the next higher organizational level although you may not have the authority to change the control. A lack of controls in one process may be impacting other processes, and a change to procedures may benefit several parts of the organization. Once you have determined what controls exist or have established new controls, the next step is to assess their effectiveness (see Chapter 3.D). The assessment and review of your management controls is an ongoing process. If you do own the process, determine the appropriate method of control to mitigate the risk (see Chapter 3.B). In selecting control methods, consider the following criteria: Ensure that control costs do not exceed the benefit to be derived. It may be cost prohibitive to implement a control that fully eliminates risk, but a cost-effective control could be implemented that mitigates risk to an acceptable level. For instance, it would not be cost effective to buy a $500 locking cabinet to protect $300 worth of calculators. Although that might fully eliminate the risk of theft, you could, at no cost, store the calculators in a locked office each night, thereby mitigating the risk to an acceptable level. On the other hand, if you have purchased ten laptops valued at $2,500 each, it might be appropriate and cost effective to purchase a $500 locking cabinet to secure the laptops. |
| 3D. REVIEW/ASSESS MANAGEMENT CONTROLS Because organizational conditions are constantly changing, you will need to assess your management controls continuously. Be alert to the potential impact of changing organizational structure, objectives, processes and procedures, personnel, and systems on your operations and initiate required reviews as necessary. Circumstances that should cause you to initiate a review are: When conducting control reviews, determine the dependencies or effects the control has on other areas of the organization. Identifying dependencies often reflects a need for input from other organizations and/or personnel. Conducting Review To test the adequacy of management controls, determine whether they are: There are various techniques for testing the adequacy of controls. However, before applying any of these techniques, examine the results of past reviews that address the adequacy of your controls. These include both internal reviews (e.g., operational reviews of records/cases/processes; reviews for compliance with OMB Circulars A-127 and A-130, Management of Federal Information Resources, (Rev. February 1996)); and external reviews (e.g., reviews conducted by GAO, TIGTA). Other techniques for testing the adequacy of controls are: Walk-Through - A walk-through of operations is made to observe how the control functions in actual practice. During the walk-through, determine how the control is meeting the objective. Any facet of operations that raises a concern should be identified for further analysis as to whether a control deficiency exists. Individual and/or Group Interviews - Interviews are an important testing technique to facilitate an understanding of how controls are functioning. Often, the best sources of information are personnel performing the operation. Combining inquiry and observation can often provide valuable insights into problem areas, such as a lack of financial and personnel resources necessary to effectively meet control objectives. Sampling - If there are a considerable number of documents or transactions performed, you may review a sample of them. If no discrepancies are noted, then a reasonable conclusion is that the control is adequate. If discrepancies are identified, you should examine additional documents/transactions to confirm whether the control is functioning as designed. Analysis of Source Document Processing - Select a sample of source documents and follow them through each step of the process. Source document analysis can often disclose improper procedures, failure to follow procedures, or breakdowns among processing steps. A combination of test procedures - You may want to combine several methods of review to ensure that your controls are adequate. Assessing Review Results At the conclusion of your review, assess whether the existing control: For each deficiency identified, assess the degree of seriousness using one of the categories explained below. This assessment is critical in helping you determine the next step in the process. Control Deficiency - Significant Control Deficiency - If you are in doubt about the significance of the deficiency, elevate the issue as a potential significant control deficiency to the next level of management and inform your MCAP Coordinator. Material Weakness - |
| 3E. DOCUMENT RESULTS OF REVIEWS
If no deficiencies have been identified in the course of your review, document the results of your reviews and retain them for use in preparing your Annual Assurance Certification Letter (see Chapter IV). The documentation can be as simple as a memorandum explaining the review methods and results. It normally does not require a separate formal report. Your documentation may also be incorporated into other management reports as long as it is identified as the results of a management control review. If deficiencies have been identified and you are able to correct them, take the appropriate action and retain the documentation for the Annual Assurance Certification Letter. If you determine that the deficiency falls into the category of a significant control deficiency and must be elevated to the next level of management, additional documentation is required (see Chapter 3.F). |
| 3F. DOCUMENT, REPORT, AND CORRECT SIGNIFICANT CONTROL DEFICIENCY
Documenting and Reporting Significant Control Deficiencies All significant control deficiencies or potential significant control deficiencies should be reported as soon as identified on a Report of Significant Control Deficiency form (see Exhibit 3-F-1). These issues are then elevated to the next level of management with a copy to the MCAP Coordinator. Your report will provide management with the information necessary to clearly understand the problem and assess the level of risk. In some instances, you may identify a potential significant control deficiency but have no control over the actions necessary to correct it. In this case, you would elevate the issue to the next level of management for possible action and review. For example, you become aware of deficiencies in the clearance process for separating employees. You do not own the process, but the issue should be provided to the owner of the process for appropriate action. In this case, you only need to submit Part I of the Report of Significant Control Deficiency to the next level of management with as much information as is available. You may not have the expertise to provide all the information in detailed, technical terms. Once the issue is shared with the appropriate program area, they may consult with you and others for additional information. If the deficiency is determined to be valid and requires a Corrective Action Plan, the process owner will be responsible for finalizing Part I and preparing Part II of the Report of Significant Control Deficiency. If it is appropriate to develop the corrective action plan at your level, your proposed plan will include all the actions needed to correct the deficiency. (see Exhibit 3-F-2) When preparing the corrective action plan: Once the Report of Significant Control Deficiency is completed, elevate it to the next level of management, and provide a copy to the MCAP Coordinator. If you are the manager at the next level, you are responsible for reviewing the report and determining the validity of the issue, based on your knowledge and expertise. As a second-level manager, you will need to decide which one of the following actions is appropriate: Correcting Significant Control Deficiencies Approved plans will be returned to the appropriate-level manager for implementation. The manager must then monitor and regularly report progress to the approving official. Periodically, the manager must also assess whether the Corrective Action Plan is achieving the desired goal(s) and continues to be relevant under current operational conditions. Managers must document and obtain the appropriate level of approval to complete or revise an action or reschedule a target date. Provide a copy of all approved documentation to the MCAP Coordinator for tracking purposes. |
| Exhibit 3-F-1 REPORT OF SIGNIFICANT CONTROL DEFICIENCY (Part 1) |
|
| Control Number | The MCAP Coordinator will assign a control number. |
| Title | Enter a short but descriptive title of the deficiency |
| Responsible Official | The title of the official(s) accountable for correcting the deficiency. If you are not sure who this is, leave it blank. (Also identify a contact person who will maintain continuing knowledge of the issue.) |
| Description | Describe the deficiency in terms of its effect on mission accomplishment, lost revenue, error rates, or impact on compliance, taxpayer burden, operating efficiency, etc. |
| Source of Discovery | How was the deficiency identified? Sources usually include, but are not limited to, Management Controls Accountability Program (MCAP) or Annual Assurance Review (AAR) Processes, operational reviews, Special Assurance Reviews, performance assessments/appraisals, GAO or TIGTA audits, process analyses, etc. |
| Correction Strategy | Briefly summarize the proposed approach or course of action to correct the deficiency. |
| Desired Outcome | Briefly describe the goal and desired outcome that will be achieved once all corrective actions have been completed. |
| Results Indicator/Effectiveness Measures | Briefly describe what indicators will be used to evaluate whether the actions taken have corrected the underlying cause of the deficiency. Indicators must be specifically related to the deficiency and be based on observable performance measures, either qualitative or quantitative. (See discussion on Exhibit 3-F-2) |
| Validation Process | Describe how data will be collected to support the Results Indicator. Possible methods include using existing management information (reports) or business data, special surveys, sampling and analyzing data, special assurance reviews, audits, interviews, etc. |
| Target Correction Date | Enter the date by which all corrective actions are expected to be completed and validated. |
| Other Issues | Use this space to briefly explain anything else that requires top management’s assistance or attention, including any related concerns such as resource needs, dependencies with other organizations, cross-functional ownership, etc. |
| Prepared by: Name, Org Code Address Location & Phone Number Date of Preparation |
|
| Include the name, office codes and phone number of the manager who has identified the deficiency. (The submitting official is not necessarily the Responsible Official for correcting the deficiency) | |
| Exhibit 3-F-1 REPORT OF SIGNIFICANT CONTROL DEFICIENCY (Part 2) |
|||
| Title –Use same short descriptive title as on previous page | |||
| Major Milestones | Milestone Completion Dates | ||
| Original Plan | Revised Plan | Actual Date | |
| List all actions needed to correct the deficiency, including those that have been completed. | |||
| List actions in chronological order. | |||
| Update the plan as necessary to reflect revised or actual completion dates. | |||
| Prepared by: Name, Org Code Address Location & Phone Number Date of Preparation |
|||
| Exhibit 3-F-2 |
| Additional Guidance on Setting Goals and Selecting Results Indicators
Indicators Indicators (or measures) assist in determining how well the process is now working compared to past performance. They can also help you identify positive/negative factors affecting program and administrative performance/effectiveness. In developing an appropriate Results Indicator (or performance measure), first consider the deficiency you are trying to correct or improve, such as timeliness of certain actions, reduction in the error rate of a particular process, decrease in the number of security lapses at a site, etc. Examples of an appropriate Results Indicator include: If the Results Indicator selected does not directly tie to the specific deficiency, the corrective actions may fix the problem but may not be reflected in the performance results. Therefore, ensure that the Results Indicator is relevant to the problem being fixed and is based on observable performance measures, either quantitative or qualitative. Goals Goals are used to tie the Results Indicator to the improvement of a particular product, process, or Service deficiency. Goals can be qualitative or quantitative. Qualitative goals are general in nature and suggest a desired direction but do not establish a specific numeric target (e.g., “Improve timely filing of travel vouches” ). Qualitative goals may be appropriate for new processes or processes for which no baseline data exists. However, without baseline data and quantitative measures, it will be difficult to assess whether your goals have been met. Quantitative goals are more focused and establish a specific numeric target (e.g., “Travel Vouchers will be filed within five business days after the end of the month.” ). Quantitative goals should be based on statistically valid results of previous reviews or a compilation of information or numerical/quantitative recordation. In establishing quantitative goals, consider the anticipated level of available resources to implement your corrective action plan, organizational priorities and initiatives, and the interaction between multiple organizational goals. For instance, raising the quality level as a goal may inadvertently decrease timeliness unless additional resources are provided to accomplish the task. Examples of Results Indicators with quantitative goals include: |
| 3G. VALIDATE OUTCOMES
When all corrective actions are completed, apply the validation process in your plan to evaluate whether the actions taken achieved the desired outcome as indicated by your Results Indicator. If the measure of the Results Indicator implies that the deficiency has not been corrected, examine whether the corrective actions were effective and/or the validation process was appropriate. If the Corrective Action Plan was not effective, review, revise, and implement a new plan. Once your Results Indicator validates that your corrective actions have effectively cured the significant control deficiency, forward documentation to the approving official for concurrence. This concurrence represents management’s assurance that the problem/deficiency has been successfully corrected. A copy should be submitted to the MCAP Coordinator and retained for use in preparing the Annual Assurance Certification Letter. Under no circumstances should management concur that a deficiency has been corrected until they are certain the risk has been mitigated to an acceptable level. This process is continuous; periodically reassess your risks against current conditions to ensure that controls are effective. |
| CHAPTER 4. ANNUAL ASSURANCE REVIEW (AAR) PROCESS
The Commissioner is required to provide an Assurance Statement as part of the Annual Report to the Secretary of the Treasury. The Annual Assurance Statement includes information on open and closed material weaknesses and Servicewide management accountability issues. To begin the Annual Assurance Review process, the Chief Financial Officer issues a call letter each spring requiring Heads of Office to: The response must contain a specific statement describing the level of assurance for the organization. The Head of Office must select the appropriate level of assurance from the following: Managers’ responses are rolled up to the Head of Office, through the MCAP Coordinator, for submission to the Chief Financial Officer. At the discretion of the Head of Office, individual certifications may be required from subordinate managers to support their level of assurance. The manager’s ongoing review of management controls is vital to the Service’s assurance process, as depicted below. |
| CHAPTER 5. SERVICEWIDE TRACKING OF NATIONAL SIGNIFICANT CONTROL DEFICIENCY AND MATERIAL WEAKNESS CORRECTIVE ACTION PLANS
All Corrective Action Plans require local tracking and follow-up. However, some Significant Control Deficiency and all Material Weakness Corrective Action Plans are tracked by the CFO’s Office of Management Controls for periodic reporting to Treasury. These Corrective Action Plans are entered into Treasury’s Inventory, Tracking and Closure System (ITCS). The information is used by Treasury to assess the Service’s effectiveness and progress in correcting weaknesses. The ITC entries are updated monthly to reflect current status. |
| REFERENCES |
| Related References and On-line Locations |
| Legislation: |
| Federal Managers’ Financial Integrity (FMFIA) Act of 1982 |
| Chief Financial Officer’s Act of 1990 — http://www.gao.gov/special.pubs/af12194.pdf |
| Government Performance and Results Act of 1993 — http://www.whitehouse.gov/OMB/mgmt-gpra/gplaw2m.html |
| Government Management Reform Act of 1994 |
| Federal Financial Management Improvement Act of 1996 |
| Office of Management and Budget (OMB): |
| OMB Circular A-123: Management Accountability and Control — http://www.fin.irs.gov/omc/A123.htm |
| OMB Circular A-127, Financial Management Systems — http://www.whitehouse.gov/OMB/circulars/index.html |
| OMB Circular A-130, Management of Federal Information Resources — http://www.whitehouse.gov/OMB/circulars/index.html |
| OMB Circular A-50, Audit Follow-Up — http://www.whitehouse.gov/OMB/circulars/index.html |
| U. S. Treasury Department |
| Treasury Directive 40-01, Responsibilities of and to the Inspector General — http://www.treas.gov/regs/td40-01.htm |
| Treasury Directive 40-02, Coordination of Responses to General Accounting Office Reports — No longer available |
| Treasury Directive 40-03, Treasury Audit Follow-Up Monitoring System — http://www.treas.gov/regs/td40-03.htm. |
| Treasury Directive 40-04, Treasury Internal (Management) Control Program — http://www.treas.gov/regs/td40-04.htm |
| General Accounting Office (GAO) |
| GAO’s Standards for Internal Controls in the Federal Government (GAO/AIMD-00-21.3.1) — http://www.fin.irs.gov/omc/gao-stds.pdf |
| GLOSSARY |
| Annual Assurance Certification Letter -A letter from each Head of Office certifying the status of management controls, including reports of Significant Control Deficiencies and/or Material Weaknesses. |
| Annual Assurance Statement - A Statement by the Commissioner provided to the Department of Treasury, which includes information on material weaknesses, and other information on Servicewide management accountability issues. |
| Annual Report - A consolidated report, required by the Government Management Reform Act of 1994, that includes a discussion of the IRS organization, mission, objectives, goals, performance indicators, operational highlights, significant issues, financial statements, and auditors opinions. It also includes the Commissioner’s Annual Assurance Statement. |
| Control Deficiency - The absence of effective and efficient methods or procedures within an activity to control risk, that causes negative consequences. |
| Control Review - A process used by management to determine whether controls are functioning efficiently and effectively. Control review techniques include sampling, walk-throughs, flowcharting, etc. |
| Corrective Action Plan - A sequence of actions developed/identified to correct a control deficiency. |
| Correction Strategy -The approach or course of action used by management to correct the deficiency. |
| Desired Outcome - The goal to be achieved by implementing a Corrective Action Plan. |
| Level of Risk - A judgment by management as to the severity of risk related to programs, processes, or administrative operations. |
| Management Accountability -The expectation that managers are accountable for the quality and timeliness of program performance, productivity, quality service to customers, and assuring that programs and administrative operations are managed with integrity and in compliance with all applicable law. |
| Management Controls - Management controls are an integral component of an organization’s management. They are the programs, policies, and procedures established to ensure that the organization is managed efficiently and effectively and protected from waste, fraud, abuse, mismanagement, and misappropriation of funds. Management controls are synonymous with internal controls. |
| Material Weakness - A significant control deficiency of sufficient importance to be reported annually to the Department of Treasury and, ultimately, to the President and Congress, until corrected. |
| Management Controls Accountability Program (MCAP) Process - The process to assist managers in establishing, assessing, and reporting on management controls. |
| Management Controls Accountability Program (MCAP) Coordinator - Provides support and guidance to executives and managers on the MCAP process. |
| Management Model - A linked system of management processes (Plan, Do, Review, and Revise) that supports the new mission strategic goals and guiding principles of the Service. |
| Qualified Assurance - Organizational statement indicating that management controls are effective and operating as intended, with identified exceptions |
| Reasonable Assurance -Organizational statement indicating that management controls are effective and operating as intended, without exception. |
| Results Indicators - Performance Measures used to evaluate whether the planned actions corrected the control deficiency. |
| Risk - Risk is the probability of a negative, unanticipated occurrence that is inherent in every activity. |
| Risk Factors - Areas to be considered in identifying potential risk, such as budget activity, procurement activity, stakeholder interest, level of reliance on computerization, etc. |
| Significant Control Deficiency - A control deficiency that is of sufficient importance to be reported to the next level of management. |
| Target Correction Date - The date by which all the actions in a corrective action plan will be completed and validated. |
| Validation Process -The use of Results Indicator(s) as performance measures that the control deficiency has been corrected. |