AnEducationalComputerBasedTrainingProgramCBTEffectivelyControllingRiskUTSouthwesternGeneralComplianceTrainingEffectivelyControllingRiskInordertoachievethegoalsofprovidingthehighestlevelsofmedicaleducation,biomedicalresearchandpatientcare,UTSouthwesternmusthaveeffectiveinternalcontrols.Thereneedstobeanappropriatebalancebetweencontrolsandrisksisnecessarytoprovidereasonableassurancethatthemedicalcenter’soperationswillbeeffective,efficientandincompliancewithlawsandregulations.EffectivelyControllingRiskWhatisthepurposeofthistraining?Whyisitnecessary?Whatisinternalcontrol?Whatarethecomponentsofinternalcontrol?WherecanIlearnmore?EffectivelyControllingRiskWhatisthepurposeofthistraining?Provideemployeeswiththetrainingandtoolstoevaluateinternalcontrolattheactivity,processanddepartmentlevels.Twotoolsavailabletoachievethisgoalarethe:RiskandControlSelf-AssessmentGuidelineRiskAssessmentandControlActivitiesWorksheetEffectivelyControllingRiskWhyisitnecessary?HighlypublicizedfraudsatotherpublicinstitutionshavecausedconcernsamongUTSystemandcomponentadministrators.Whatwasdeterminedtobetheproblem?WEAKINTERNALCONTROLSEffectivelyControllingRiskWhatisinternalcontrol?:Internalcontrolisaprocess,effectedbyUTSouthwestern’sgoverningboard,administration,faculty,andstaff,designedtoprovidereasonableassuranceregardingtheachievementofobjectivesinthefollowingcategories:–Effectivenessandefficiencyofoperations,–Reliabilityoffinancialreporting,and–Compliancewithapplicablelawsandregulations.EffectivelyControllingRiskInternalControlProcess5ComponentsEstablishControlEnvironmentPerformRiskAssessmentImplementControlActivitiesCommunicateInformationMonitorPerformanceInternalControlProcessEstablishControlEnvironmentThecontrolenvironmentisthecontrolconsciousnessofanorganization.Thecontrolenvironmentincludestheintegrityandethicalvaluesofitspeople,theircompetence,andthewaytheydobusiness.InternalControlProcessElementsoftheControlEnvironmentStandardsofConductGuideRegents’Rules,BusinessProceduresMemorandums,etc.DepartmentstandardsofconductHumanresourcespoliciesandproceduresDepartmentpoliciesandproceduresConflictsofinterest--disclosureformsEthicsGuideHonestyZerotoleranceInternalControlProcessPerformRiskAssessmentRiskassessmentistheidentificationandanalysisofrisksassociatedwithachievingyourobjectives.Riskassessmenthelpstoformabasisfordetermininghowtomanageidentifiedrisks.InternalControlProcessWhatisourrisk?Withinternalcontrols,RISKis...ThepossibilitythattheorganizationwillNOT:–Achieveitsgoals–Operateeffectivelyandefficiently–Protectitselffromloss–Providereliablefinancialdata(reports)–Complywithapplicablelaws,regulations,policies,andproceduresInternalControlProcessPerformRiskAssessmentComponentsandDepartmentsmustdefinetheirgoalsandobjectivesinrelationtotheir:–Mission,–Operations,–Financialreporting,–Compliance,and–Significantactivitiesorprocesses.Then,theymustidentifyandanalyzepotentialrisksbyaskingcertainquestions:–Whatcouldgowrong?–Whatmustgoright?–Whatisthesignificanceofourrisks?–Whatisthelikelihoodofoccurrence?InternalControlProcessPerformRiskAssessmentQuestionsemployeesshouldconsider:Whatbusinessareyouin?Whoareyourcustomers?Whatdotheyneedandwant?Whatdoesthatsayaboutwhatyouaretryingtoaccomplish?Howwillyouknowyouhavebeensuccessful?InternalControlProcessPerformRiskAssessmentAriskisANYTHINGthatcouldjeopardizetheachievementofagoalorobjective.Foreachgoalorobjective,identifyyourrisks.Becomprehensive,byconsideringexternalandinternalfactors.InternalControlProcessPerformRiskAssessmentForeachidentifiedrisk,estimatethepotentialsignificance(cost,safety,institutionalimage)andlikelihoodofoccurrence.Focusonthemajorrisks,anddeterminehowthoserisksshouldbemanagedandminimizedtoacceptablelevels.InternalControlProcessImplementControlActivitiesControlactivitiesarethepoliciesandproceduresthathelpensurethatactionsidentifiedasnecessarytomanagerisksarecarriedoutproperlyandinatimelymanner.Controlactivitiesshouldbeproactive,value-added,andcosteffective.InternalControlProcessImplementControlActivitiesRisksControlsProperlybalancingrisksandcontrolsmakesgoodbusinesssense!InternalControlProcessImplementControlActivitiesExamplesofControlActivitiesatUTSouthwestern:Approvals,authorizations,andverifications–HavingwrittenpoliciesandproceduresandlimitstoauthorityReconciliations–ExplanationsofthedifferencebetweentwosetsofdataANDtakingcorrectiveactionInternalControlProcessImplementControlActivitiesExamplesofControlActivitiesatUTSouthwestern,continued...Reviewsofperformance–Forcomponents,departments,andindividualemployeesSecurityofAssets–Limitingaccess,keepingrecords,andmakingperiodiccountstocomparetoourrecordsInternalControlProcessImplementControlActivitiesExamplesofControlActivitiesatUTSouthwestern,continued...SegregationofDuties–Makesurenoonepersoncaninitiate,approve,recordandreconciletransactionsControlsoverInformationSystems–Generalcontrolsoveraccessanddevelopment,aswellasspecificcontrolswithinapplicationsInternalControlProcessCommunicateInfor