1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

19
1 Into -

Transcript of 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

Page 1: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

1

Into-

Page 2: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

2

What is IntoSAINT?

Intosai Self Assessment INTegrity

vulnerabilities Integrity controls

Page 3: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

3

Two day workshop

With cross section of employees

Page 4: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

4

Utilises knowledge and experience of employees

Promotes integrity awareness

!

Page 5: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

5

Quick results

Practical and applicable recommendations

Page 6: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

6

Ownership

Integrity

Page 7: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

7

SAI leads by example

Integrity in public sector

Page 9: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

9

Mini-workshop

Page 10: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

10

Assessment methodology

Object definition- organisation

- processes

Assessment vulnerabilities

Assessment Maturity level

Integrity Control System

Gap analysis

Recommendations - Reducing vulnerability - Strengthening controls

Page 11: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

11

Vulnerabilities

• Vulnerable processes exist in all government organisations

• Some activities and processes are inherently more vulnerable than others

• Some factors can make processes more vulnerable

Page 12: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

12

Inherent vulnerabilitiesElements Vulnerable areas /activities /actions

Relationship of the entity with its environment

Contracting procurement, tenders, orders, assignments, awards

Payment subsidies, benefits, allowances, grants, sponsoring

Granting / Issuance

permits, licenses, identity cards, authorizations, certificates

Regulating conditions of permits, setting standards / criteria

Inspection / audit

supervision, oversight, control, inspection, audit

Enforcement prosecution, justice, sanctioning, punishment

Managing public property

Information national security, confidential information, documents, dossiers, copyright

Money treasury, financial instruments, portfolio management, cash/bank, premiums, expenses, bonuses, allowances, etc.

Goods handling, management and consumption (stocks, computers)

Real estate buying / selling

Page 13: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

I nherent vulnerabilities

0,00

0,50

1,00

1,50

2,00

2,50

3,00

Contr

act

ing

Paym

ent

Gra

nti

ng /

issu

ance

Regula

ting

Insp

ect

ion /

audit

Enfo

rcem

ent

Info

rmati

on

Money

Goods

Real Est

ate

1 2 3 4 5 6 7 8 9 10

Sco

re AverageStDev

I nherent vulnerabilities

0,00

0,50

1,00

1,50

2,00

2,50

3,00

Contr

act

ing

Paym

ent

Gra

nti

ng /

issu

ance

Regula

ting

Insp

ect

ion /

audit

Enfo

rcem

ent

Info

rmati

on

Money

Goods

Real Est

ate

1 2 3 4 5 6 7 8 9 10

Sco

re AverageStDev

I nherent vulnerabilities

0,00

0,50

1,00

1,50

2,00

2,50

3,00

Contr

act

ing

Paym

ent

Gra

nti

ng /

issu

ance

Regula

ting

Insp

ect

ion /

audit

Enfo

rcem

ent

Info

rmati

on

Money

Goods

Real Est

ate

1 2 3 4 5 6 7 8 9 10

Sco

re AverageStDev

MR Average

Page 14: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

14

Vulnerability enhancing factors

1. Complexity

2. Change / dynamics

3. Management

4. Personnel

5. Problem history

Page 15: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

Vulnerability enhancing factors

0,000,200,400,600,801,001,201,401,601,802,00

Com

ple

xit

y

Ch

an

ge/d

yn

am

ics

Man

ag

em

en

t

Pers

on

nel

Pro

ble

m h

isto

ry

1 2 3 4 5

Score Average

StDev

Vulnerability enhancing factors

0,00

0,50

1,00

1,50

2,00

2,50

3,00

Com

ple

xity

Change/d

ynam

ics

Managem

ent

Pers

onnel

Pro

ble

m h

isto

ry

1 2 3 4 5

Sco

re AverageStDev

Vulnerability enhancing factors

0,00

0,50

1,00

1,50

2,00

2,50

3,00

Com

ple

xity

Change/d

ynam

ics

Managem

ent

Pers

onnel

Pro

ble

m h

isto

ry

1 2 3 4 5

Sco

re AverageStDev

Page 16: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

16

Assessment maturity level Integrity Control System

What is the maturity level of the integrity control system?• Existence of controls• Operation of controls• Effectiveness of controls

Object definition

- organisation

- processes

Assessment

vulnerabilities

Assessment

Maturity level Integrity Control System

Gap analysis

Recommendations

- Reducing vulnerability - Strengthening controls

Page 17: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

17

Integrity Control System General controls

1. Integrity policy framework Hard controls 2. Vulnerability / risk analysis Soft controls

3. Responsibilities 8. Values and standards

4. SAI legal framework 13. Recruitment and selection 9. Professional SAI standards

5. Integrity legislation and regulations

10. Integrity awareness

6. Administrative organisation / internal

control

14. Response to integrity violations

11. Management attitude

7. Security 12. Organisational culture

15. Accountability and transparency

16. Audit and monitoring

Page 18: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

18

Maturity levelsLevel Criteria

0 - The measure does not exist

1 - The measure exists

- The measure is not implemented / observed

2 - The measure exists

- The measure is implemented / observed

- The measure is not effective

3 - The measure exists

- The measure is implemented / observed

- The measure is effective

Page 19: 1 Into-. 2 What is IntoSAINT? Intosai Self Assessment INTegrity vulnerabilities Integrity controls.

19

IntoSAINT webpage

http://www.courtofaudit.nl/IntoSAINT