scieee AI-readable full text Open interactive document viewer

Adoption of the COSO methodology for internal Sharīʿah audit

Bouheraoua, Said,Fares Djafri

Abstract

EconStor is a publication server for scholarly economic literature, provided as a non-commercial public service by the ZBW.

Full text

Bouheraoua, Said; Fares Djafri Article Adoption of the COSO methodology for internal Sharīʿah audit ISRA International Journal of Islamic Finance Provided in Cooperation with: International Shari'ah Research Academy for Islamic Finance (ISRA), Kuala Lumpur Suggested Citation: Bouheraoua, Said; Fares Djafri (2022) : Adoption of the COSO methodology for internal Sharīʿah audit, ISRA International Journal of Islamic Finance, ISSN 2289-4365, Emerald, Bingley, Vol. 14, Iss. 2, pp. 221-235, https://doi.org/10.1108/IJIF-04-2020-0071 This Version is available at: https://hdl.handle.net/10419/302032 Standard-Nutzungsbedingungen: Die Dokumente auf EconStor dürfen zu eigenen wissenschaftlichen Zwecken und zum Privatgebrauch gespeichert und kopiert werden. Sie dürfen die Dokumente nicht für öffentliche oder kommerzielle Zwecke vervielfältigen, öffentlich ausstellen, öffentlich zugänglich machen, vertreiben oder anderweitig nutzen. Sofern die Verfasser die Dokumente unter Open-Content-Lizenzen (insbesondere CC-Lizenzen) zur Verfügung gestellt haben sollten, gelten abweichend von diesen Nutzungsbedingungen die in der dort genannten Lizenz gewährten Nutzungsrechte. Terms of use: Documents in EconStor may be saved and copied for your personal and scholarly purposes. You are not to copy documents for public or commercial purposes, to exhibit the documents publicly, to make them publicly available on the internet, or to distribute or otherwise use the documents in public. If the documents have been made available under an Open Content Licence (especially Creative Commons Licences), you may exercise further usage rights as specified in the indicated licence. https://creativecommons.org/licenses/by/4.0/ Adoption of the COSO methodology for internal Shar ıʿah audit Said Bouheraoua and Fares Djafri ISRA Research Management Centre, INCEIF University, Kuala Lumpur, Malaysia Abstract Purpose –Islamic financial institutions (IFIs) are required to establish a Shari ıʿah Governance Framework (SGF) to strengthen their Shar ıʿah-compliance mechanism and ensure that all relevant IFI regulations are in line with Shar ıʿah rules and principles. Effective implementation of the Shari ıʿah-compliance function will further promote stakeholder confidence, as well as the integrity of IFIs, by reducing Shari ıʿah non-compliance risks. This study aims to examine the internal control framework developed by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) and explore the extent to which it can be incorporated in the Shar ıʿah-compliance function of IFIs. Design/methodology/approach –This study adopts a qualitative method of inquiry, utilizing the inductive method and content analysis to build comprehensive knowledge that will assist in exploring the framework of COSO methodology and the extent to which it can be adopted by IFIs. Findings –The findings indicate that the existing frameworks of Shar ıʿah governance, whether that of the Accounting and Auditing Organization for Islamic Financial Institutions (AAOIFI) or Bank Negara Malaysia (BNM), need to be further developed. Therefore, the adoption of COSO methodology in the internal Shar ıʿah audit of IFIs, as suggested by AAOIFI, is not only possible but desirable. The study also finds that the COSO framework places the highest priority on risk management in that it makes it an integral part of the decisionmaking process in all the institution’s activities. As a result, incorporating the comprehensive COSO risk management structure within the Shar ıʿah-compliance function will enhance risk management in IFIs. Originality/value –This study highlights the importance of the COSO internal control framework and examines its components, principles and the possibility of its adoption by IFIs. The findings of this study are expected to contribute to enhancing the Shar ıʿah-compliance function of IFIs. Keywords COSO, IFIs, Internal control, Shar ı‘ah audit, Shar ı‘ah compliance, Shar ı‘ah governance Paper type Research paper Introduction The development of the Islamic finance industry has led to the progression of the organisational structure of Islamic financial institutions (IFIs), especially in strengthening the concept of adherence to the principles and provisions of Shar ı‘ah (Islamic law). Shar ı‘ah supervision and Shar ı‘ah audit are forms of administrative control to ensure that all operations and transactions carried out by IFIs are Shar ı‘ah-compliant. Given this importance, the Accounting and Auditing Organization for Islamic Financial Institutions (AAOIFI), in its ninth standard on governance, paid special attention to the Shar ı‘ahcompliance function, calling for the adoption of a comprehensive and integrated control system to manage the risks that IFIs may face. The standard identifies the Committee of Sponsoring Organizations of the Treadway Commission (COSO) model as one of the advanced and comprehensive internal control methodologies and calls for incorporating the Shar ı‘ah-compliance function within the comprehensive COSO risk management structure (AAOIFI, 2019). This suggestion by AAOIFI triggered the concerns of industry experts on Internal Shar ıʿah audit 221 © Said Bouheraoua and Fares Djafri. Published in ISRA International Journal of Islamic Finance. Published by Emerald Publishing Limited. This article is published under the Creative Commons Attribution (CC BY 4.0) licence. Anyone may reproduce, distribute, translate and create derivative works of this article (for both commercial and non-commercial purposes), subject to full attribution to the original publication and authors. The full terms of this licence may be seen at http:// creativecommons. org/licences/by/4.0/legalcode The current issue and full text archive of this journal is available on Emerald Insight at: https://www.emerald.com/insight/0128-1976.htm Received 8 April 2020 Revised 30 August 2020 7 August 2021 26 April 2022 3 June 2022 Accepted 3 June 2022 ISRA International Journal of Islamic Finance Vol. 14 No. 2, 2022 pp. 221-235 Emerald Publishing Limited e-ISSN: 2289-4365 p-ISSN: 0128-1976 DOI 10.1108/IJIF-04-2020-0071 the implementation of the COSO framework for Shar ı‘ah audit. Several questions arise in this regard, including: (1) How efficient and effective is the COSO methodology in achieving Shar ı‘ah oversight objectives? (2) Is COSO’s methodology in harmony with Shar ı‘ah principles and objectives? (3) Is it possible to integrate COSO’s methodology within the internal Shar ı‘ah audit process? This research aims at explaining the COSO methodology, its components and principles and the extent to which it can be adopted within the internal Shar ı‘ah audit process of IFIs. For this purpose, this paper is organised as follows: the next section provides a review of the literature on the COSO methodology for internal Shar ı‘ah audit. It is followed by a discussion on Shar ı‘ah governance and its role and principles. The next section then deliberates on the COSO internal audit framework, its components and principles. Thereafter, Shar ı‘ah audit and its applications in IFIs are discussed. The key contribution of the paper lies in the deliberation on the extent to which the COSO methodology can be applied to the internal Shar ı‘ah audit processes of IFIs. The final section presents the conclusion and recommendations of the study. Literature review Significant literature is already in place regarding the application of the COSO framework of internal control in conventional finance. For instance, Rezaee (1995) explained the importance of a COSO report for internal auditors and urged them to work closely with management and external auditors. The findings revealed that COSO reports have a significant positive impact on the better recognition of the proactive role of internal auditors. Lawson et al. (2017) surveyed United States (US) accounting professionals, principally from large publicly traded firms, to examine views related to the framework and its impact on key areas related to internal controls. The results revealed that respondents view the COSO framework and its 17 principles as a set of rules for achieving effective internal controls. Likewise, Udeh (2019) explored the effectiveness of the COSO framework. The findings showed that timely adopters of the COSO framework continued to demonstrate fewer instances of auditor-reported material weaknesses than late-adopters. Besides, comparative studies conducted on the implementation of the COSO framework show that major regulatory and standard-setting bodies’presentations of their internal controls are drafted based on the COSO model. This is reflected in the model developed by The Basel Committee on Banking Supervision for internal control of financial institutions and the Cadbury Commission’s report; both models are mainly based on the COSO framework for internal audit (Briciu et al., 2014). IFIs have also recognised the importance of benefiting from the COSO framework in establishing internal Shar ı‘ah control. This realisation is supported by AAOIFI and other regulatory and supervisory bodies. AAOIFI decided to incorporate the framework in its Shar ı‘ah Standard of Governance Standard No. 9 on “Shar ı‘ah Compliance Function”. AAOIFI stated explicitly that the Shar ı‘ah compliance chart is “developed in line with the five key pillars of the COSO integrated framework”(AAOIFI, 2019). The standard also stated in clause 38: “IFIs shall consider adopting a comprehensive internal control or enterprise risk management framework (e.g. those developed by COSO)”. The same consideration of the COSO framework was presented in the AAOIFI Exposure Draft of Waqf Governance Standard, clause 56. The draft states: “The custodian shall also establish and cause to implement and follow a control framework in line with global best practices (e.g. the IJIF 14,2 222 Committee of Sponsoring Organizations of the Treadway Commission’s (COSO’s))”(AAOIFI, 2018). This is in addition to the incorporation of the framework by many IFIs in their Shar ı‘ah Governance Framework (SGF) and policy documents. Despite the importance given to the COSO framework, not much literature concerning its applications in Shar ı‘ah audit and control has been produced by researchers and industry practitioners. In the Islamic arena, the studies conducted on the COSO framework can be divided into two categories. The first category stresses the general importance of COSO in Shar ı‘ah audit and its position in the internal Shar ı‘ah control undertaking. Hidayah (2014) proposed a modified triple line of defense for IFIs based on the COSO framework. Similarly, Zakaria et al. (2019) highlighted the importance of the implementation of the COSO framework in internal Shar ı‘ah control and cited the study of Shafii and Salleh (2010) as one of the first to discuss the Shar ı‘ah internal control system and to adopt the COSO framework in defining internal Shar ı‘ah control. However, the study did not comprehensively explain the framework, nor did it present any assessment from the Shar ı‘ah perspective (Zakaria et al., 2019). The second category is concerned with practical examination of the COSO framework either by evaluating its application in specific products or conducting empirical studies by interviewing stakeholders to assess its importance and the extent of its implementation in internal Shar ı‘ah audit. For instance, Aden Abdi (2017) examined the possibility of the implementation of the COSO framework in Islamic finance. The research concluded that although the COSO framework is useful for Islamic finance, it misses some essential elements related to internal Shar ı‘ah control, especially the Shar ı‘ah-compliance aspect and the party responsible for Shar ı‘ah compliance as well as the Shar ı‘ah supervisory board (SSB) as a line of defense. Yazkhiruni et al. (2018) interviewed chiefs of internal audit, managers of internal audit department, Shar ı‘ah committee members, external auditors and academicians on the implementation of the COSO framework in enterprise risk management and found that some respondents confirmed they are adopting the COSO framework. Likewise, Abd Rahman et al. (2018) stated that the COSO framework is considered an effective methodology as it contains all facets for ensuring an effective internal control system. This was supported by the final statement and recommendations of the Shura Eighth Shar ı‘ah Audit Conference, which was held in the Sultanate of Oman in 2019. The conference recommended the adoption of the COSO Shar ı‘ah audit framework as one of the most advanced and comprehensive internal control frameworks. Furthermore, the conference recommended that the entities working in the field of Shar ı‘ah consultancy and audit should provide professional support to Islamic financial institutions on how to adopt the COSO methodology in the internal Shar ı‘ah control system, develop the professional capabilities of the institutions’staffs by holding workshops and training programs and carry out the necessary technical studies that illustrate the practical application of the COSO framework (Shura, 2019). From the above studies, it can be concluded that the efforts undertaken by researchers have focused on examining the efficiency of the COSO internal control framework and its importance for internal Shar ı‘ah control; however, they have not addressed its compliance to Shar ı‘ah requirements and how to incorporate it within the existing SGF of IFIs. This gap was highlighted in CIBAFI’s comments on the “AAOIFI Exposure Draft on Governance Standard No. 9 on Shar ı‘ah Compliance Function”as follows: The COSO’s pillars are defined in a purely secular context. If they are to be cited, therefore and in order to educate the SSB members and those charged with governance about their application to the Shar ıʿah-compliance function, the standard should elaborate more on linking the COSO components to Shar ıʿah requirements (CIBAFI, 2017, p. 5). The present study goes beyond CIBAFI’s concern about the secular context. It aims to undertake an in-depth examination of the extent to which the COSO framework complies with Shar ı‘ah principles and fundamentals and the possibility of adopting it within the SGF of IFIs. Internal Shar ıʿah audit 223 Shar ı‘ah governance: its role and principles Many definitions have been provided for governance in the conventional law context, including: the system by which companies are managed and their activities controlled (Alamgir, 2007). The National Bank of Egypt (2003) defined it as the aggregate “rules of the game”that are used to oversee the business from within and by which the board of directors (BOD) supervises it to protect the interests and financial rights of the shareholders. It is worth noting that there is no difference between Shar ı‘ah governance and the governance of conventional companies except in terms of the law that governs them. Shar ı‘ah governance, as the name suggests, is derived from Islamic law while conventional governance is based on statutory laws. IFIs are required to have an SGF to strengthen their Shar ı‘ah-compliance mechanism and ensure that all relevant IFI regulations comply with Shar ı‘ah rules and principles. Successful implementation of the SGF will further elevate stakeholder confidence as well as the trustworthiness of the Islamic finance industry by decreasing Shar ı‘ah non-compliance risks. That will ultimately contribute to maintaining financial stability. Bank Negara Malaysia (BNM) provides a good benchmark in this regard as it places increased emphasis on ensuring that the operations of the Islamic financial system are in line with the SGF. Indeed, BNM has developed the SGF for IFIs with the main objective of enriching the function of the board, the Shar ı‘ah committee and the management in discharging their duties in matters relating to Shar ı‘ah. AAOIFI also confirmed that governance in IFIs far exceeds the limits of governance in conventional institutions, given the additional social and religious dimensions of the former (AAOIFI, 2004). Likewise, the Islamic Financial Services Board (IFSB, 2009) expressed the concept thus: a set of legislative measures through which IFIs confirm that there is independent and effective Shar ı‘ah supervision for each of the following structures and processes: (1) Issuing fatwas and related decisions governing the work of the financial institutions. (2) Disseminating information related to these fatwas and decisions among the employees in Islamic financial services institutions who are responsible for monitoring daily activities. (3) Internal Shar ı‘ah review and audit to verify the compliance of the transactions conducted in the financial institution with the Shar ı‘ah provisions. (4) A yearly Shar ı‘ah review to confirm that the internal Shar ı‘ah supervision and audit were implemented appropriately and as required. The mandatory nature of Shar ı‘ah governance in Islamic financial institutions The mandatory nature of Shar ı‘ah governance for IFIs means that the decisions of the SSB are binding in Shar ı‘ah issues related to the bank, as is the achievement of the Shar ı‘ah principles included in Shar ı‘ah governance. These include justice, honesty, trustworthiness, accuracy, clarity, the prevention of inequity and the preservation of rights. Therefore, the SSB’s role is more than consultative; rather, it includes guidance, supervision and oversight. This is clearly stated in the revised SGF for IFIs issued by BNM (2019). SGF 2019 obliges the SSB to be accountable for the soundness and accuracy of decisions related to business and risk practices. In this regard, the Shar ı‘ah committee shall inform the SSB about any Shar ı‘ah issue or matter that may affect the safety and soundness of the IFI. It is worth noting that the basic principle in Shar ı‘ah supervision of Islamic banks is oversight of the bank’s business. It is not limited to developing products or following up on their implementation. Rather, it makes sure that all business and all aspects of the bank are in compliance with the principles and provisions of the Shar ı‘ah. IJIF 14,2 224 Similarly, AAOIFI has issued governance standards on SSBs which state that the SSB is assigned with the responsibility of reviewing, managing and supervising the activities of the IFI in order to ensure that its financial products and services are in compliance with the principles and precepts of Shar ı‘ah (AAOIFI, 2015). Likewise, it is stated in AAOIFI Shar ı‘ah Standard No. 29 that it is the duty of the SSB to submit fatwas to the bank based on the relationship that exists between them and that it is the duty of the institution to refer to the board on Shar ı‘ah matters. In principle, the seeker of a fatwa, in this case the bank, can exert the utmost effort to choose the best fatwas or opinions; however, the laws of these institutions require them to accept and implement the fatwas issued by their own SSBs (AAOIFI, 2007). AAOIFI (2007) emphasised that the bank is obligated to follow the decisions of the SSB and cannot refer to and adopt the decisions of other fatwa bodies without the permission of its own Shar ı‘ah board. Based on the above, Shar ı‘ah governance is concerned with practices, systems, policies, procedures and measures by which the institution’s performance is controlled and monitored and its problems addressed. This is where the interaction between governance and internal Shar ı‘ah oversight becomes apparent. It is a crucial part of the governance of IFIs that aims to ensure that the transactions undertaken by the institution are in compliance with the provisions of Shar ı‘ah. It also aims to reduce the risks of Shar ı‘ah non-compliance that Islamic banks may face. In this respect, Mashal (2015) stated that governance represents an evolution of oversight and is based on three main axes: moral behavior, the risk management process and the process of oversight and accountability. In addition, internal SSBs are vigilant in identifying Shar ı‘ah non-compliance risks, dealing with them and minimizing them. Since internal control is an important part of corporate governance, ensuring that the approved goals are achieved and that risks facing the institution are reduced, the next topic will address what internal control is and its principles and goals according to the COSO concept. COSO internal audit framework COSO was established in 1985 under the chairmanship of James Treadway, the former Commissioner of the US Securities and Exchange Commission. The Committee includes professional bodies working in the accounting and financial field in the United States of America (USA). It includes the five largest private sector organisations in the USA: the American Institute of Certified Public Accountants (AICPA), the Institute of Internal Auditors (IIA), the Financial Executives International (FEI), the American Accounting Association (AAA) and the Institute of Management Accountants (IMA). Collectively, they are called COSO in consideration of their funding provision to the Committee. The Committee was commissioned to produce an integrated and comprehensive design for internal control that came to be widely adopted in the USA (Uwadiae, 2015). This framework, known as the COSO framework, was designed to assist companies in establishing, correcting and improving the internal control system. Internal control, according to this framework, is considered important for the organisation’s operations and financial reports and cannot be neglected because it determines the quality of the financial statements. It provides “reasonable assurance”that the amounts presented in the financial statements are correct and establish a reliable basis for making sound decisions (COSO, 2013). The application of the internal control framework, according to the COSO concept, provides a solid basis for determining the degree of assurance provided by the regulatory controls designed at the institutional level. COSO defines internal control as: a process, effected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting and compliance (COSO, 2013, p. 3). Internal Shar ıʿah audit 225 This definition reflects some of the basic concepts of internal control, namely: (1) It is not an end in itself but a means to achieve goals. (2) It is not just policies, procedures and systems but the actions that people take at every level of the organisation to affect internal control. Hence, it must be accomplished by competent and qualified persons. (3) It does not provide an absolute assurance but, rather, a reasonable assurance regarding the institution’s achievement of its objectives to the management and the BOD. Besides, the objectives of internal control, according to the COSO framework, are as follows: Operations objectives: They relate to the efficient and effective use of all the entity’s resources, including operational and financial performance goals and safeguarding assets against loss. Reporting objectives: They relate to internal and external financial and non-financial reporting directed at the use of what is produced and its documentation with reliable and transparent reports submitted to the management. Compliance objectives: They relate to compliance with the laws and regulations that the organization is subject to (COSO, 2013, p. 3). In light of the above, it is clear that internal control, according to the COSO framework, is a comprehensive system designed to help achieve the entity’s goals through the efficient and effective use of all the institution’s resources. It does so through specific criteria, concepts and principles that are used to evaluate the internal control system. The next section examines the development of the COSO framework. Development of the COSO framework As previously mentioned, the main work assigned to COSO is to design an integrated framework to help companies establish, evaluate and improve the internal control system. The first version of the internal control framework was issued in 1992 and became widely accepted, particularly in the USA. In 2013, a revised and refined version of the COSO internal control framework was issued, containing the components applied under the COSO framework of 1992 with the addition of a set of principles and concepts. With regard to risk management, in 2004 COSO issued the integrated risk management framework. An updated version was issued in 2017 titled “Enterprise Risk Management (ERM) Integration of Strategies and Performance”(COSO, 2017). Since the subject of this research relates to internal control, it will focus on the stages of the development of internal control for the COSO framework. COSO internal control framework 1992 edition The first version of COSO framework for evaluating and activating the system of internal control, issued in 1992, was based on five interrelated components: control environment, risk assessment, control activities, information and communication and monitoring activities. The overall objective of this framework was to provide reasonable assurance of achievement of the institution’s goals at the following levels: effectiveness and efficiency of operational processes, reliability of financial reports and compliance with laws and regulations. COSO internal control framework 2013 updated version Since the introduction of the first COSO framework in 1992, several amendments have occurred in the working environment and the organisational and operational laws of IJIF 14,2 226 institutions. This prompted COSO to review and amend the COSO framework in accordance with developments in the internal control system. In 2013, the revised and improved COSO internal control framework was issued. It contains the same components applied in the COSO 1992 framework along with the addition of a set of 17 principles that represent the basic concepts of the five control components that are relied upon in evaluating the internal control system (COSO, 2013). Table 1 summarises the five components and 17 principles of internal control according to the COSO 2013 framework. The COSO 2013 framework assumes that these 17 principles work with one another in an integrated dynamic framework to reduce risks to reasonable and acceptable levels. The 17 principles are further supported by a set of 87 points that must also be given due attention. They represent the instructions that help design the implementation of the internal control procedure and evaluation of whether these principles have been adopted and used (Deloitte, 2014). It thus results in an effective internal control system. The revised COSO 2013 thus focused on the risk management process. This reflected the realisation that it is important to shift risk management from a separate or occasional activity distributed among a number of the institution’s units to an efficient, integrated management activity. In addition, the COSO 2013 framework indicated that risk management is an integral part of the decision-making process in an entity’s activities and is crucial for achieving goals and improving performance. It indicated that an effective internal control system is not simply a matter of strict adherence to policies and procedures; rather, it goes beyond that to the exercise of judgement and discretion. This is a relative matter that requires competence on the part of those carrying out the work. The BOD, executive management and employees throughout the institution need to use their judgement to define the necessary and effective control limits. Likewise, their exercise of judgement and assessment of matters are used on an ongoing basis to develop the control system at the institutional level. Shar ı‘ah audit and its applications in Islamic financial institutions Before evaluating the COSO methodology or framework for Shar ı‘ah audit, it is necessary to present the methodologies of the most prominent supervisory and oversight bodies regarding internal Shar ı‘ah audit. As the limitations of this paper do not allow for the study of many models, only AAOIFI’s and BNM’s methodologies on Shar ı‘ah audit will be presented. AAOIFI’s internal Shar ı‘ah audit approach AAOIFI has examined Shar ı‘ah audit in its Governance Standard for Islamic Financial Institutions (GSIFI No. 3). It defines internal Shar ı‘ah audit as the examination and evaluation of the institution’s commitment to the provisions and principles of Shar ı‘ah and the fatwas, guidelines and instructions issued by the institution’s SSB. Accordingly, internal Shar ı‘ah audit is an essential part of the organs of governance of the IFI and it is based on a set of general requirements that include: Independence and objectivity: the organisational status of the internal Shar ı‘ah control shall be sufficient to accomplish its responsibilities. This is achieved by placing internal Shar ı‘ah control in the organisational structure at a position no lower than the level of the Internal Control Department. Further, the internal Shar ı‘ah control personnel are to receive full and continuous support from the management and the BOD. On the other hand, objectivity includes independence of thought and attitude that assist internal Shar ı‘ah audit to reach objective conclusions based on the work the internal Shar ı‘ah auditors have performed and its results. Therefore, the independence and objectivity of the internal Shar ı‘ah auditors are vital for public confidence. This will ultimately promote the objectives of Shar ı‘ah (maq as _id al-Shar ı‘ah) which aim at realizing human wellbeing Internal Shar ıʿah audit 227 (mas _lah _  ah) and preventing harm and difficulties (m afs ad ah and m ash aqq ah) to the public and the economy (Algabry et al., 2020). In line with this, IIA in its standards has considered independence and objectivity as part of the internal auditors’framework. According to IIA (2017), independence means freedom from incidents that intimidate the ability of internal Components Description of the components Principles Control Environment Control environment represents the philosophy and vision of the institution, or it is the governance culture of management, which impacts on the effectiveness of the other components of internal control. It denotes a set of standards, processes and structures that the organisation relies on to implement internal control. It includes the integrity and ethical values of the institution and the standards that enable the board of directors to carry out its responsibilities in overseeing the governance and organisational structure and in defining powers and responsibilities (1) The organisation demonstrates a commitment to integrity and ethical values (2) The BOD demonstrates independence from management (3) The BOD establishes structures, reporting lines and appropriate responsibilities in the pursuit of objectives (4) Commitment to attract, develop and retain competent individuals (5) Holding individuals accountable for their internal control responsibility Risk Management It is the possibility that an event will occur and adversely affect the achievement of [an organisation’s] objectives. It indicates that each organisation may face a variety of risks, external and internal. The assessment of risks, according to the COSO concept, is a continuous dynamic process for identifying and assessing the risks that threaten the achievement of the institution’s goals (6) Specifying objectives with sufficient clarity to identify and assess risks (7) Identifying risks across the entity and analyzing them to determine how they should be managed (8) Considering the potential for fraud as a possible risk (9) Identifying, evaluating and analyzing changes that could significantly impact the system of internal controls Control Activities Control activities are procedures established through policies and arrangements that help ensure the implementation of management directives to mitigate risks related to the achievement of the entity’s goals (10) Selection and development of control activities to mitigate risks (11) Selection and development of technology-dependent general control activities (12) Deployment of policies that define what is expected and procedures that implement them Information and communication It refers to the continuous and iterative process of providing, sharing and obtaining the necessary information. Communication is the means by which information is disseminated to all departments of the institution (13) Obtaining and using relevant and credible information (14) Internal communication by disseminating information internally (15) External communication on matters affecting the conduct of internal control Monitoring activities Monitoring activities are carried out by either a continuous or discontinuous evaluation process, or a combination of them, to ensure that each of the five internal control components exists and works appropriately (16) Conducting continuous or separate evaluations (17) Evaluating and communicating deficiencies of internal control Source(s): COSO (2013) Table 1. Components and principles of COSO 2013 framework IJIF 14,2 228 Lawson, B.P., Muriel, L. and Sanders, P.R. (2017), “A survey on firms’implementation of COSO’s 2013 internal control–integrated framework”,Research in Accounting Regulation, Vol. 29 No. 1, pp. 30-43. Mashal, A. (2015), “The integrated framework for the governance of the Islamic financial industry”, Paper Presented at the 14th AAOIFI Conference on Shar ıʿah Boards for Islamic Financial Institutions, Bahrain. National Bank of Egypt (2003), “The method for exercising good corporate governance in companies: corporate governance”,Economic Bulletin, Vol. 56 No. 2, p. 7. Rezaee, Z. (1995), “What the COSO report means for internal auditors”,Managerial Auditing Journal, Vol. 10 No. 6, pp. 5-9. Shafii, Z. and Salleh, S. (2010), “Enhancing governance, accountability and transparency in Islamic financial institutions: an examination into the audit of Shari’a internal control system”, Malaysian Accounting Review, Vol. 9 No. 2, pp. 23-42. Shura (2019), “Final statement and recommendations of the 8th Shura Sharia Audit Conference”,6–8 October 2019, Grand Millennium Hotel, Muscat, Oman. Udeh, I. (2019), “Observed effectiveness of the COSO 2013 framework”,Journal of Accounting and Organizational Change, Vol. 16 No. 1, pp. 31-45. Uwadiae, O. (2015), “COSO –an approach to internal control framework”, available at: https://www2. deloitte.com/ng/en/pages/audit/articles/financial-reporting/coso-an-approach-to-internal-controlframework.html (accessed 6 April 2019). Yazkhiruni, Y., Nurmazilah, M. and Haslida, A.H. (2018), “A review of Shar ıʿah auditing practices in ensuring governance in Islamic financial institution (IFIs) –a preliminary study”,Advances in Social Sciences Research Journal, Vol. 5 No. 7, pp. 196-210. Zakaria, N., Mohd Ariffin, N. and Zainal, H. (2019), “Internal Shar ıʿah audit effectiveness and its determinants: case of Islamic financial institutions in Malaysia”,Kyoto Bulletin of Islamic Area Studies, Vol. 12 No. 1, pp. 8-28. About the authors Said Bouheraoua, PhD, is currently a Senior Researcher and Director of Research Development and Innovation Department at ISRA Research Management Centre (ISRA RMC) and a lecturer at INCEIF University, Kuala Lumpur, Malaysia. Fares Djafri, PhD, is an Islamic finance Researcher at ISRA RMC, INCEIF University, Kuala Lumpur, Malaysia. He is an AAOIFI-Certified Shariah Advisor and Auditor (CSAA). He has published many chapters in books and several articles in the area of Islamic finance, tak aful, Islamic banking regulations, and Shar ıʿah governance. Fares Djafri is the corresponding author and can be contacted at: fares-isra@ inceif.org,[email protected] For instructions on how to order reprints of this article, please visit our website: www.emeraldgrouppublishing.com/licensing/reprints.htm Or contact us for further details: [email protected] Internal Shar ıʿah audit 235