Section:
Effective: 02/29/2024
Supersedes: New
Next Review Date: 02/28/2027
Issuance Date: 02/29/2024
Issuing Office:  Controller’s Offices for Campus, Health, & Foundation

Internal Controls Policy

 
 
 

SCOPE

This policy establishesUC San Diego&s procedures and standards regarding internal controls overfinancial transactions, responsibilities, and requirements for a system ofinternal controls. This applies to all staff of UC San Diego.

 

POLICY SUMMARY

Internal controls arethe processes that help ensure that the University&s business is carried out inaccordance with the Standardsof Ethical Conduct,University policies and procedures, applicable laws and regulations, and soundbusiness practices. They help to promote efficient operations, accuratefinancial reporting, protection of assets, and responsible fiscal management.

Individual financialtransactions roll up to the campus and the University of California system-widefinancial statement reporting. Internal controls are necessary to ensure thatthe lowest level of transactions through the roll-up consolidation of thosetransactions are being reported accurately and appropriately.

 

DEFINITIONS

Control Deficiencies

Control deficienciesexist when the design or operation of a control does not allow management oremployees, in the normal course of performing their assigned functions, toprevent or detect misstatements in a timely manner.  The materiality of thecontrol deficiency is not just determined by the actual misstatement (i.e., thedollar amount of the error), but by the potential dollars that could also beincorrect. Examples of control deficiencies include but are not limited to:

 

      Lack of timeliness ofcash deposits and account reconciliation.

      Lack of review andreconciliation of departmental expenditures.

      Lack of overdraft fundsmonitoring.

      Lack of physicalinventory and equipment management.

      Lack of separation ofduties.

 

DepartmentAdministrators

The dean, chair, ordirector (also known as Department Heads) of each school or department, whileresponsible for managing the department's financial resources, will normallydelegate the overall administration of financial resources to a Department Administrator.The Department Administrator is responsible for establishing procedures toprovide reasonable assurance that financial transactions are appropriate,accurately recorded, and comply with applicable laws, regulations, and internalpolicies and procedures.

Financial Reporting

Financial reporting isthe consolidation of financial transactions into financial statements.Financial transactions are recorded in compliance with applicable financialreporting requirements, including, but not limited to Accounting PrinciplesGenerally Accepted in the United States of America (US GAAP), GovernmentalAccounting Standards Board (GASB) Statements, Cost Accounting Standards Board(CASB) Statements, and applicable policies, external regulations, and standardsof the University and its campuses, foundations, and medical centers.

Financial Stewardship

Financial stewardshipis the responsibility for managing University financial resources wisely,executing these duties with integrity and ethical conduct. These financialresources include time, monetary assets, people, and physical property. WhenUniversity employees manage public resources efficiently, economically, andethically, the result will be better achievement of the University's overallmissions of teaching, research, and public service. Financial stewardshipincludes the responsibility for establishing and monitoring the system ofinternal control.

Internal Controls

Organizational plansand procedures implemented by management that provide reasonable assurance thatorganizational objectives will be achieved through effective and efficientoperations, that University assets are safeguarded, that financial data isaccurate and reliable, and that the University adheres to applicable laws, regulations,and internal policies and procedures

Materiality

Materiality is assessedby determining how much of a department&s financial information could bemisstated, by error or fraud, without affecting the decisions of reasonablefinancial information users. Materiality is informed by management&s riskappetite and tolerance, considering quantitative as well as qualitativefactors, which may include perceived reputational risk or compliance withregulations.

 

Risk Assessment

The Risk Assessmentidentifies and prioritizes risks based on their likelihood and the potentialimpacts on the department&s progress toward achieving its strategic objectivesand priorities. Department Heads and delegated Department Administrators considerfinancial risks according to their established risk tolerance. Common financialrisks include:

 

      Financial misstatementsdue to error or fraud.

      Misappropriation offinancial and physical assets.

 

POLICY STATEMENT

The University ofCalifornia has adopted the principles of internal controls published by theCommittee of Sponsoring Organizations (COSO) of the Treadway Commission.

 

This Policy is intendedto foster the following internal control principles:

 

  1. Authorization and approval - a delegated individual with approval authority ensures a transaction is consistent with applicable policy, and is allowable, accurate, and reasonable before approval.

 

  1. Review and reconciliation - departmental accounting records, transactions, and documentation are compared with University financial system reports to verify their reasonableness, accuracy, and completeness.

 

  1. Separation of duties - financial responsibilities are divided between different people so that a single person does not perform or have complete control over every aspect of a function or activity (common activities include authorizing, approving, certifying, disbursing, receiving, or reconciling).

 

  1. Security and custody - University assets, including equipment, inventories, property, cash and cash equivalents, personally identifiable information (PII), and information systems, are safeguarded and protected from unauthorized access, risk of loss, or misappropriation.

 

RESPONSIBILITIES

All members of theUniversity community are responsible for internal controls.

 

Individuals entrustedwith funds and resources are responsible for ensuring that adequate internalcontrols exist over the use and accountability of such funds.  They areresponsible for applying University policy and procedures to ensure theefficient and effective use of resources and to prevent and detect fraud in theareas in which they are involved.  Those individuals must separate tasks amongdifferent people to reduce the risk of error and inappropriate or fraudulentactions. Proper separation of duties requires division of responsibility forrecording, approving transactions, managing financial resources, and reviewingand reconciling data.

Individuals who haveaccess to financial data and fail to adhere to the University&s policies and proceduresmay be subject to appropriate corrective action as provided in the applicablepersonnel policies.

DepartmentAdministrators

DepartmentAdministrators are responsible for ensuring that internal controls areestablished, properly documented, and maintained for activities within theirjurisdiction and areas of responsibility.

DepartmentAdministrators are responsible for ensuring that members of their teams haveadequate knowledge, skills, and abilities to function within, and contributeto, an effective internal control environment. This includes providing accessto appropriate training on topics relevant to their job responsibilities.

DepartmentAdministrators are responsible for periodic review of departmental key controlsand procedures to ensure that the general principles of internal control are inplace and are being followed. Management is responsible for strengtheninginternal controls when weaknesses are detected, including addressing errors,omissions, inconsistencies, and exceptions.  Department administrators andmanagers are responsible for taking prompt and effective corrective action oninternal control findings, implementing remediation or action plans, andrecommendations from internal and external auditors.

 

DepartmentAdministrators must communicate internal control weaknesses and correctiveactions to those charged with governance over the school or department.

Controllers& Offices

The Controllers&offices at each of the entities-UC San Diego Foundation, UC San Diego, and UCSan Diego Health-partner with Audit and Management Advisory Services (AMAS) toapply a risk-based approach during compliance assessments and through periodicreviews and monitoring of departments and their control activities, to ensurethe system of internal controls at UC San Diego has been appropriately designedand operating effectively.

Audit and ManagementAdvisory Services (AMAS)

Audit and ManagementAdvisory Services (AMAS) is responsible for performing reviews and audits ofinternal controls across the University as requested by management, or asdetermined by AMAS, and for communicating any findings and recommendations tothe appropriate levels of management.

 

PROCEDURES

Establish a System ofDepartmental Internal Controls

To establish and maintaina system of departmental internal controls, Department Heads or DepartmentAdministrators must do the following:

 

       Review keycontrols in Blink. Then use the provided checklist to understand thetiming and extent of key controls that must be performed by all departments,regardless of size and complexity.

       Perform key controls and monitor them to ensure they are workingas designed.

       Document evidence of review by someone other than the preparer (bysignature on the documentation, e-mail, or checklist sign-off).

o   A bestpractice is for the reviewer to be designated by the department&s leadership.

o   If a keycontrol is not applicable to the department, the department must proactivelydocument that the key control is not applicable.  For example, if a departmentdoes not have petty cash, the department must document that there is no pettycash and that the control activity is not applicable.

       Fix and follow up when a control deficiency or weakness isidentified, and document timely corrective action.

       Retain evidence (i.e., documentation) of corrective action foraudit purposes.

o   Preferablyin electronic format.

o   See the UCOP Records Retention Schedule todetermine how long to retain records.

       Department Heads and Department Administrators must also completea risk assessment to identify any financial risks that warrant additional keycontrols from those described in Blink and the provided checklist.

 

Examples of KeyControls

Examples of keycontrols include, but are not limited to, the following:

 

     Implementseparation of duties controls where duties are divided among different peopleto reduce the risk of error or inappropriate actions so that no one person hascontrol over all aspects of any financial transaction.

     Makesure transactions are authorized by a person delegated approval authority whenthe transactions are consistent with policy and funds are available.

     Ensurerecords and transactions are routinely reviewed and reconciled, by someoneother than the preparer or person who initiated the transaction, to determinethat transactions have been properly processed.

     Ensuretransactions are processed promptly and within any required timeframes.

      For example, costtransfers on sponsored projects must be done in compliance with award terms andconditions, and regulations.

     Reviewasset, liability, expense, and revenue balances frequently to ensure accuracyduring the fiscal year.

     Makesure that equipment, inventories, cash, and other property are securedphysically, counted periodically, and compared with item descriptions shown oncontrol records.

     Identifyand document the process for onboarding and off-boarding employees andaffiliates.

     Provideemployees and affiliates with appropriate training and guidance to ensure theyknow how to carry out their job duties, are provided with an appropriate levelof direction and supervision, and know the proper channels for reportingsuspected improprieties.

     EnsureUniversity and departmental policies and operating procedures are formalizedand communicated to employees and other stakeholders.

      Documenting policiesand procedures and making them accessible helps provide day-to-day guidance andpromotes continuity of activities during prolonged employee absences orturnover.

 

FORMS

 

Checklistfor Internal Controls

 

RELATED INFORMATION

 

A.     ElectronicCode of Federal Regulations, Title 2, Subtitle A, Chapter II, Part 200, Section200.62: Internal control over compliance requirement for Federal awards

 

B.     CaliforniaGovernment Code (GOV) Title 2, Division 3, Part 3, Chapter 5, The StateLeadership Accountability Act [13400 - 13407].

 

C.    RegentsPolicy 1111: Policy on Statement of Ethical Values and Standards of EthicalConduct

 

D.    University of California -Policy BFB BUS-10: Principles of Accountability with Respect to Financial Transactions

 

E.     Universityof California Whistleblower Policy

 

F.     UC Officeof the President - Ethics, Compliance and Audit Services, Internal Controls

 

G.    Committee of SponsoringOrganizations (COSO) of the Treadway Commission: Internal Control - IntegratedFramework

 

H.    UC SanDiego SAS 115 Overview Blink Webpage

 

I.       UC SanDiego Internal Controls Blink Webpage

 

J.     UC SanDiego Administrative Responsibilities Webpage

 

K.     UC SanDiego Delegations of Authority Webpage

 

L.     UCOP Records Retention Schedule

 

M.    Checklistfor Departments With New Employees (ucsd.edu)

 

FREQUENTLY ASKED QUESTIONS(FAQ&S)

 

None.

 

REVISION HISTORY

02/29/2024       Policyissued.