TheKPMGReviewInternalControl:APracticalGuideThisbookhasbeenpreparedtoassistclientsandothersinunderstandingtheimplicationsoftheICAEWpublicationInternalControl:GuidanceforDirectorsontheCombinedCode.Whilsteverycarehasbeentakeninitspreparation,referencetotheguidanceshouldbemade,andspecificadvicesoughtwherenecessary.NoresponsibilityforlossoccasionedtoanypersonactingorrefrainingfromactionasaresultofanymaterialinthispublicationcanbeacceptedbyKPMG.KPMGisregisteredtocarryonauditworkandauthorisedtocarryoninvestmentbusinessbytheInstituteofCharteredAccountantsinEnglandandWales.cKPMGOctober1999Allrightsreserved.Nopartofthispublicationmaybereproduced,storedinanyretrievalsystem,ortransmittedinanyformorbyanymeans,electronic,mechanical,photocopying,recording,orotherwise,withoutthepriorpermissionofthepublisher.DesignedandproducedbyServicePoint(UK)LimitedPrintedbyServicePoint(UK)LimitedFromdiscussionswithmanyBoarddirectorsovertheyearssincetheCadburyandtheRuttemanguidelineswereissued,therehasbeenmuchcriticismofregulatorsandconsultantsalikethatorganisationsarebeingdriventocreatebureaucraticprocesses-divorcedfrommanagingthebusiness-withthesolepurposeofcomplyingwithregulations.ThespiritofCadburywasright,theenactmentwasflawed.Bytakingtheeasyoptionofreportingoninternalfinancialcontrolcompaniescreatedanannualreviewprocessdisconnectedfrommanagingthebusiness.TheCombinedCodeandTurnbullguidancerecognisethatthiswasneitherbeneficialfororganisations,norprovidedthecomfortsoughtthatgovernancewasbeingenhanced.Therehasalwaysbeenanopportunitytoenhancebusinessperformancethroughbettermanagementofrisk.WithTurnbull,theconnectionbetweenmanagingthebusinessandmanagingriskisnowexplicit.Thisguidehasbeenwrittenwiththisobjectiveinmindandrecognisesthatwhilstonesizedoesnotfitall,theprinciplesandpracticalissuesarecommon.IthasrelevancetotheBoardmemberandlinemanageralike.Iowemythankstothosewhohaveprovidedmewiththechallengeovertheyearstoprovidepracticalsolutions.Ibelievethisbookmeetsthosechallengesbyprovidinggenuinelypracticalguidancewhich,inmyview,isasmuchaboutenablingperformanceasitisaboutembeddingriskandcontrol.MythanksinparticulartoTimothyCopnellandChristopherWicks,withoutwhoseeffortsthisbookcouldnothavebeenproduced.MarkStockHeadofCorporateGovernanceServicesKPMGForewordExecutivesummary..............................................11Introduction...............................................101.1Background................................................101.2Objectives..................................................111.3Groups....................................................121.4Effectivedate...............................................132Theimportanceofinternalcontrolandriskmanagement.........143Maintainingasoundsystemofinternalcontrol..................183.1Responsibilityforthesystemofinternalcontrol....................183.2Thesystemofinternalcontrol..................................193.3Understandingthenatureandcontextofcontrol...................224Reviewingtheeffectivenessofinternalcontrol...................274.1Responsibilityforreviewingtheeffectivenessofinternalcontrol......274.2Theprocessforreviewingeffectiveness..........................304.3Businessobjectives..........................................314.4Riskidentificationandassessment..............................334.5Identificationofappropriatecontrols............................384.6Monitoringofcontrols........................................405Disclosure.................................................495.1Thenewrequirements........................................495.2Implementation.............................................545.3Specimenstatementsoninternalcontrol..........................546Internalaudit..............................................566.1Background................................................566.2Therevisedrequirements......................................576.3Theroleofinternalaudit......................................586.4Otherassuranceproviders.....................................607TheKPMGmethodology....................................61ContentsAppendicesIRecommendedimmediateactionsanddecisions.................65IISpecimenstatements........................................69IIIInternalcontrolbenchmarking...............................74IVBoardtimetable............................................77VCriteriaforreviewingtheeffectivenessofinternalcontrol.........80VIQuestionstoaskwhenassessingtheeffectivenessofinternalcontrol..........................................84VIIKPMGofficesintheUK.....................................87DespitespeculationinthefinancialpressthatthefinalguidanceoninternalcontrolwouldbeessentiallysimilartoApril’sconsultativedocument,thefinalguidancewassignificantlytightenedbytheremovaloftheoptionforasingleannualreview.Thisshouldacttodiscouragebureaucraticproceduresthatprovideneitherthedepthnorqualityofinformationprovidedbythenowrequiredregularreviewprocess.AtKPMGweareparticularlypleasedtoseethatthefinalguidancereflectsmanyoftherecommendationsmadeino