First Reference company logo

Inside Internal Controls

News and discussion on implementing risk management

machine cogs image

Internal controls for gift giving this holiday season

In this holiday season, you need to be more vigilant in your compliance around gift giving. This article outlines how.

gift givingThanksgiving and the start of the holiday season is upon us. I thought a review of internal controls around gifts was in order. Many companies effectively minimize the risk of inappropriate gifts through stringent pre-approval requirements because a sufficiently robust and enforced pre-approval policy can reduce the number of gifts simply because of the headache of getting the pre-approval. This has the added benefit of ensuring enforcement of internal controls, largely because of the reduced volume of gifts being included in expense reports.

In considering the effectiveness of controls, you must always keep in mind the most frequently used method for defeating an internal control, which is driven by a dollar amount criteria, is splitting the item into multiple parts in order to appear to stay under the limit and to avoid the defined approval authority based on the amount of the gift.

A key analysis is whether there are controls in place to enforce the policies and whether those controls are documented. To help to answer this query, there are four issues to evaluate:

  1. Is the correct level of person approving the payment/reimbursement for the gift?
  2. Are there specific controls, including signoffs, to demonstrate that the gift had a proper business purpose?
  3. Are the controls regarding gifts sufficiently preventative, rather than relying on detect controls?
  4. If controls are not followed, is that failure detected by other internal controls or the compliance protocols?

While many compliance practitioners believe that employee expense reports are a sufficient internal control regarding gifts, because there are other ways in which a gift can be presented, there need to be other controls.

Understand the internal controls for expense reports

Once your company policy on gifts has been finalized, the internal controls over expense reports fall into three basic areas:

  1. The expense report format, including what information it requires
  2. Controls over the submitting employee and the preparation of the expense report
  3. Controls to ensure the approvers do their review process properly

The format of an expense report can go a long way towards prevention of violations of company policy. First it is important to have preprinted representations and certifications within the form because these can lead to “stop and think” type of controls, meaning the person submitting the expense report has to at least consider the information being submitted. The form can be signed without reading the preprinted representations, but if the employee and reviewers have been trained on how to review the expense report, it can be difficult to say later that the submitting employee did not understand what they were signing.

You should also consider two forms of representation, the Preparer’s representations and the Approver’s representations.

The Preparer’s representations ensure that all items representing a proper business purpose comply with the company’s code of conduct, comply with local law and custom, and comply with all applicable company policies regarding Foreign Corrupt Practices Act (FCPA) compliance.

The Approver’s representations ensure that all supporting documentation has been examined and that all documentation complies with applicable company policies, including the submission of original receipts. Further, the Approver should certify that they have complied with all company policies regarding the review and approval of the expense report.

Consider the types of expense reports your company uses

Many companies have two basic forms of expense reports. One is for situations in which all items pertain to U.S. locations and do not involve any expenses incurred outside the U.S. or for benefit of persons outside the U.S. The second is for items involving locations or persons outside the U.S. The international reporting form might have more stringent requirements and should provide for more detailed disclosures. It could require reporting, in a separate section of the expense report, all items that involve government officials, so that these items are not “buried” elsewhere in the expense report.

As an added measure, the expense report should include a column which requires the submitter to check “Government Official YN?” this type of format should require sufficient disclosure of information regarding each item involving government officials.

Ensure proper & thorough expense approval

The next step in such an enhanced protocol would require a senior officer from the business unit to approve any reimbursements that meet certain criteria, for example, certain geographical areas or countries. Finally, such an enhanced representation could also include separate sections for each item requiring a description of the business purpose of meals, entertainment, names and business affiliation of all attendees, description of gifts and their business purpose, etc. A typical expense report requires this information to be on the receipt.

Moving beyond simply requiring receipts and requiring such detail to be incorporated directly onto the expense reimbursement forms highlights the presence or absence of proper documentation much more readily. It is also incumbent to ensure reviewers sign off that each item has documentation that required pre-approvals were obtained, if necessary.

In this holiday season, you need to be more vigilant in your compliance around gift giving. By having robust internal controls around gift giving, you can help to prevent such violations.

By Tom Fox

Follow me

Ethics &Compliance Matters ™, Navex Global ®

Ethics & Compliance Matters™ is the official blog of NAVEX Global®. All articles posted on the Inside Internal Controls blog originally appeared on NAVEX Global’s Ethics and Compliance Matters Blog. The blog leverage the news, insights and best practices you find here to stay ahead of GRC trends, and take your compliance program to the next level. Read more
Follow me

Latest posts by Ethics &Compliance Matters ™, Navex Global ® (see all)

Send to Kindle

, , , ,

Leave a Reply

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

This site uses Akismet to reduce spam. Learn how your comment data is processed.