Internal Control Advisory

Most financial loss inside a company does not come from a wrong decision — it comes from a process with no control point. ASTC advises on the design and strengthening of internal control systems under the COSO Internal Control — Integrated Framework.

Internal Control Advisory

The five COSO components

Component What we review
Control environment Organisational structure, assignment of responsibility, standards of conduct, management’s commitment
Risk assessment Risk identification by process cycle, with likelihood and impact assessment
Control activities Segregation of duties, approval limits, reconciliations, stock counts, system access control
Information and communication Information flows supporting management, and channels for reporting exceptions
Monitoring Periodic self-assessment and tracking of remediation

Our services

1. Internal control review and management letter

We review the key cycles — purchase-to-pay, order-to-cash, inventory, fixed assets, cash and payroll — and issue a management letter containing:

  • A description of each weakness identified
  • The specific risk it creates (asset loss, reporting error, compliance exposure)
  • Remediation recommendations, ranked by priority
  • The responsible function and a suggested timeline

2. Process design

  • Mapping of the as-is and to-be processes
  • An approval authority matrix by limit and transaction type
  • A RACI responsibility matrix for each process step
  • The accompanying control forms and documents

3. Accounting policy manual

We prepare the company’s accounting policy manual: recognition, measurement and presentation principles for each material item, consistent with Vietnamese Accounting Standards (VAS) and the prevailing accounting regime, and compatible with the parent company’s reporting requirements.

4. Digitalising approval workflows

Advice on moving manual approvals onto a digital platform: full audit trail, overdue alerts, and processing-time reporting by step.

A typical implementation path

Stage Content Deliverable
1. Survey Interviews, process observation, collection of existing documentation Current-state report
2. Gap analysis Compare the current state against COSO and legal requirements Prioritised control gap schedule
3. Design Build the processes, authority matrix and forms Process documentation set
4. Handover Train the relevant functions and support the trial run Training records and issue log
5. Post-implementation review Assess compliance with the new processes after one operating cycle Review report with recommended adjustments

Division of responsibility: establishing, maintaining and operating the internal control system is the responsibility of the company’s management. ASTC advises on design and makes recommendations; we do not substitute for the management function and we do not conclude on fraud — such conclusions rest with the company and with the licensed practitioner under the relevant engagement.