Video summary

Limitaciones de control interno - COSO

Main summary

Key takeaways

Business

Business-focused summary (COSO internal control limitations)

Internal control systems—even when designed, documented, and continuously evaluated—have inherent limitations due to factors related to objectives, risk assessment, people, and the control environment.

Key limitations identified (COSO-aligned)

  • Non-specific or poorly deployed objectives

    • Objectives may not be deployed throughout the organization to be implemented at all levels.
  • Objectives not properly verified

    • Doubts exist about whether objectives are appropriate given current circumstances, facts, and applicable laws/regulations/standards.
  • Risk assessment based on “understood but not authorized” objectives

    • Organizations may assess risk using objectives that people understand, but which are not formally authorized.
  • Limits of professional judgment

    • Controls are less effective when decisions rely on judgment in operational activities.
    • Example: during an inventory count, the inventory manager uses different counting methodologies for the same items, leading to material differences in financial statements.
  • External events can disrupt control effectiveness

    • Even if internal controls are effective, external factors can still impact operational outcomes.
    • Example: COVID-19 pandemic.
  • Management override

    • Senior personnel can override/disable policies or procedures for illegitimate purposes (e.g., personal gain).
    • Example: senior management uses a scheme to show fictitious income.
  • Collusion

    • Two or more people (inside or outside the organization) may cooperate to commit wrongdoing (e.g., fraud, manipulation of financial/management information).
    • Example: an employee responsible for a control collaborates with a stakeholder/employee from an operating division to circumvent controls to hit a pre-set target.

Mitigation approaches / playbook-style recommendations

  • Adopt a holistic, cross-company risk view

    • Prevent silos, duplication, and wasted effort.
  • Use a structured, workflow-based control testing approach

    • Test controls regularly using a simple approach tied to workflows.
    • Produce reports covering all elements of the operation (end-to-end visibility).

Additional limiting factors mentioned

  • Insufficient resources allocated to internal control
  • Reactive risk culture (tendency to respond after issues arise rather than proactively managing risk)

Metrics / KPIs

  • No specific financial or operational KPIs (e.g., revenue, margin, CAC, LTV, churn) or targets/timelines are provided in the subtitles.

Presenters / sources

  • No individual presenter is named in the provided subtitles.
  • Source framework referenced: COSO (Internal Control framework).

Original video