Pasdec Holdings Berhad (Assignment)
Pasdec Holdings Berhad (Assignment)
Pasdec Holdings Berhad (“PASDEC”), based in Pahang, has been listed on the Main
Board of Bursa Malaysia Securities Berhad (Stock Code: 6912) under the property counter
since 27 October 1997. The State Government of Pahang (via Perbadanan Kemajuan Negeri
Pahang) and Jasa Imani Sdn. Bhd have major shareholdings in PASDEC.
1
The name of person that we interview was Mr. Mustapha Bin Hussein. He graduated
Bachelor of Science (major in Biology). After completed his studies, he gets a job opportunity
to continue as an internal auditor at Plantation Company because that time he did not have job
vacancy that related to his degree. He starts to learn auditing from his seniors from internal
audit department. Then, he also starts to have an interest in internal audit so, he learns auditing
and accounting by itself to improve his skills and knowledge in that. He was work around 2
years in that plantation company. After improve his skills in auditing, he become a member of
Institute Internal auditor (IIA) now he works as a head of internal audit department in Pasdec
Holdings Bhd. He works around 9 years in Pasdec Holdings Bhd.
The code of Ethics states the principles and expectation governing the behaviour of
individuals and organizations in the conduct of internal auditing. It describes the minimum
requirements for conduct, and behavioural expectations rather than specific activities. Besides,
internal auditor should add value to the organization by implementing rules of conduct under
IPPF which is competency. Competency is referring to internal auditors apply the knowledge,
skills, and experience needed in the performance of internal audit services. According to IPPF
standard 1210 internal auditors must possess the knowledge, skills and other competencies
needed to perform their individual responsibilities. The internal audit activity collectively must
possess or obtain the knowledge, skills and other competencies needed to perform its
responsibilities. In addition, based on IPPF standard 1220 as an internal auditor must apply the
care and skill expected of a reasonably prudent and competent internal auditor.
Based on our interviewee the Pasdec Holdings Berhad had apply the IPPF standard by
providing external training to their staffs in internal audit department. The internal auditor has
to attend external training at least once a year. This training is provided by Institute Internal
Auditor (IIA). It also low cost and the speaker also so quality in term of their knowledge and
experience. They also know all the requirements that must comply by the internal auditors.
Next, Pasdec Holdings Berhad also provide on the job training. For example, most of
the fresh graduates they are lack of experience in internal auditing so, as a head of internal
auditor he will provide simple assignment to them. After get some experiences the head of
internal audit will provide complicated assignment to them to become more expected in internal
audit. Then, the head of internal audit of PASDEC will explain audit skills and knowledge to
his staffs. Next, besides audit skills he also briefs his staffs about the background of company.
2
CONCLUSION
Team Team
Leader Member
Moreover, from the organizational chart of PASDEC we can said that this company
have three persons to organize the internal audit department. Their internal audit department is
so small. The head of internal audit is responsible all matters that related to internal audit
department, audit committee, annual planning and budget planning. He will check all the work
done by the team leader and team member. He has to report whatever that happens in internal
audit department to the audit committee and board of directors.
Then, the duties of team leader are they have to follow the instructions that given by
the head of internal audit department. They involve in planning, scheduling, and reviewing
audit program and reporting results, and give some guidance. They also perform the special
projects. Finally, the team member should follow the instructions that given by team leader.
They also communicate with audit clients to develop the audit plans. For example, the team
3
leader will check assets, stocks, vehicles and he ask the team member to focus on fixed assets
only. It means overall assignment did by team leader and assist by team member to complete
the assignment successfully. We can conclude that, head of department have more experience
compared with team leader and team member.
CONCLUSION
CONCLUSION
As conclude, internal audit tools and techniques is a very importance for the Pasdec
Holdings Berhad. The job of internal auditors in regard to an IT audit is very challenging as it
involves reviewing and reporting audit findings that are highly technical. To perform audit
procedures effectively, internal auditors should possess adequate IT knowledge, technical skills
and experiences. This would also enable internal auditors to translate the audit findings into
4
value added recommendations that could assist an organization in achieving its business
objectives.
Most organization have different type of method to detect fraud. Anti-fraud education,
establish zero tolerance are some example of method to find out the wrongdoing of employee.
This method are entitle as whistleblowing. Whistleblowing is an effective method for the
authority to identify the company wrongdoing. Institute of internal auditor define whistle
blowing as the unauthorized disclose by internal auditor. Normal whistleblowing comprise
with audit result, findings, and opinion of the performance it also a voluntary act of reporting
on misconduct within an organization.
There are two forms of whistleblowing that are internal and external whistleblowing.
Firstly, internal whistleblowing is a process for employee to be suspect wrongdoing incident
within entity. Next, external whistleblowing occur if the internal whistle-blower fails to detect
the fraud.
For Pasdec Holding Bhd have whistleblowing policies and procedures. For example,
whistle-blower can report to audit department if they does not believe means they can report
directly to audit committee or chairman. If they are honest person they must meet auditor to
hide their identity. Besides, if they are does not believe means they not report but if they are
believe means they should be report and also their identity must be hide. After we get reports
from whistle blower the management have to do investigation based on the report. Next, after
conduct investigation by management they should submit report to audit committee. The audit
committee will review the report that involves any inappropriate items and then they should do
domestic inquiry based on the report. Domestic inquiry refers to the people have problem at
their company. For example, abusing drug, late comer’s issues and stealing company property.
Audit committee will decide whether they want to do domestic inquiry or not. If they do illegal
activity so the company maybe dismiss from job, salary deduction and warning letter depends
on the illegal activities.
CONCLUSION
In conclusion, that are numerous ways to solve the problem at Pasdec Holdings Berhad.
In term of whistleblowing, the management can appoint an internal auditor as whistle-blower.
5
This is helpful to the management to avoid any fraud to be occur. As an internal auditor they
must have professionalism and code of ethics to become as whistle-blower.
Code of conduct basically tells that what you can do and what you can’t do. For
example, as an employee you cannot have conflict of interest. If there have conflict of interest,
they have to declare. For example like if one of their sibling want to join the organisation, they
have to declare.
CONCLUSION
To sum up, fraud can occur at various level in organization. Furthermore, the middle,
senior management and executive must understand about the fraud. However, the risk of fraud
can be reduced through prevention and detection.
Internal auditor need to communicate engagement results as stipulated by IPPF Standard 2400.
Therefore, the communication of audit results may take several phases as well as use several
means, including a written report. Basically, in process of preparing an audit communication,
as an internal auditor they have to highlight what is their finding and must be a quality. Next,
the report must be clear, accurate and sufficient. Other than that, usually the report consists of
5 to 6 pages including scope and objective. As an internal auditor, they have to promote
recommendation, highlight a risk area and not to make any decision.
6
Turning now to PASDEC where the report usually based on quality of audit. If audit process
has quality, return report will get quality also. If analysis and data is not enough then the report
is not quality. In addition, to produce a good report, writing skills most important.
The time taken to complete audit report usually it takes two weeks based on assignments and
experience conduct of audit. In terms of fraud prevention, the story is about if you notice there
is a fraud, what you should do so it will relate to whistle blowing. There have policy because
they may not tolerate in this serious matter.
CONCLUSION
In conclusion, PASDEC follow all the internal audit process where is strategic planning until
follow-up. This is to ensure effectiveness of the internal audit functions.
Internal control can be defined as activities that can mitigate and controls the amount of
risks. Internal control will come with high prices that will incurred by the company. The
internal control also can effect expenses of the company because of the high prices. This
internal control can help the company to less the risk and become more efficiency. The internal
control cannot eliminate the risk only can minimize in any company.
Moreover, segregation or separation of duties also include in the internal control. The
purpose of segregating responsibilities is to prevent occupational fraud in the form of asset
misappropriation and intentional financial misstatement. The basic idea underlying segregation
of duties is that no employee or group of employees should be in a position both to perpetrate
and to conceal errors or fraud in the normal course of their duties. In general, the principal
incompatible duties to be segregated are:
Custody of assets.
7
As for Pasdec Holdings Berhad they have implement the segregation of duties in their
contact department. In Diagram 2 had shown the organizational chart of contract department.
The department consist of 6 people. The team is called quantity survivor.
Senior Manager
Manager
Diagram 2
For the small purchases example mouse, milk, glass and others it will by admin
department. For example, the internal auditor department need to buy a mouse so the will fill
the form then pass to admin. The admin department will find quotation then being approve by
the managing director.
CONCLUSION
I can conclude that internal control is a very important for the company to protect or
minimize the risk of the company. One of the internal control is segregation of duties and
Pasdec Holdings Berhad has being implemented this internal control in their company. They
had use this control to minimize the misconduct in Pasdec Holdings Berhad.
8
10.0 RISK AND CONTROL
Risk is the possibility of an event occurring that would have an impact on achievement
of objectives. Risk may be threat to an organization or it can also an opportunity. Risk can be
identified and measured by its impact and likelihood.
Control is any action taken to mitigate risk and increase the likelihood of achieving the
organizational objectives. Controls are developed for specific risks. Control cannot eliminate
all risk but only minimize risk so that the effects of risk do not jeopardize the attainment of
organizational objectives. COSO (2013) defines internal control as ‘a process, effected by an
entity’s board of directors, management and other personnel, designed to provide reasonable
assurance regarding the achievement of objectives relating to operations, reporting and
compliance.
For Pasdec Holdings Berhad the internal audit had been find the risk for the company
they will tell the respective department that involved with the risk. After that, the internal
auditor will leave it to the department how to handle the risk. This is because Pasdec Holdings
Berhad do not do use control self-assessment. The internal auditor in Pasdec Holdings Berhad
said to control the risk is the each department duties because they have their own standard
operating procedure (SOP). The internal auditor will only fix their SOP if the SOP have
weaknesses.
CONCLUSION
I can conclude that the internal auditor in the Pasdec Holdings Berhad is align with the
IPPF. The internal auditor cannot making any decision for the company but only can give
recommendation for their control.
The roles and responsibilities of internal audit have been cover for three areas which is
organization risk management, control and governance. The internal audit department should
provide an objective or unbiased report to audit committee.
9
An internal auditor should have six phases to do the internal audit process which is:
Strategic audit planning – During the planning process, the internal audit members will
specify the scope and objective, which (e.g., laws, regulations, industry standards,
company policies and procedures, etc.), review the results from previous audits, set a
timeline and budget for the audit, create an audit plan to be executed, identify the
process owners to involve, and schedule a kick-off meeting to commence the audit.
Fieldwork – Fieldwork is the actual act of auditing. Throughout this phase, the internal
audit members will execute the audit plan. This usually includes interviewing key
personnel to confirm an understanding of the process and controls, reviewing relevant
documents and artefacts for an example execution of the controls, testing the controls
for a sample over a period of time, documenting the work performed, and identifying
exceptions and recommendations.
Reporting – As you might guess, internal audit will draft the audit report during the
reporting phase. The report should be written clearly and succinctly to avoid
misinterpretation and to encourage the intended audience to actually read and
understand the report. Findings should be accompanied by recommendations that are
actionable and lead directly to process improvements. The process of issuing an internal
audit report should include drafting the report, review the draft with management to
ensure the accuracy of findings, and issuance and distribution of the final report.
Follow-up – The final stage is an important one that is often overlooked and neglected.
Following up is critical to ensure that the recommendations have been implemented to
address the findings identified. This process should include appropriate follow-up with
process owners needing to implement the recommendations as well as Board oversight
of the company’s overall status in addressing findings identified by internal audit. If an
organization fails to follow-up on the implementation of recommendations, it is
unlikely that the changes will be made.
10
Diagram 3
Pasdec Holdings Berhad also do the internal audit process that have been mention in
above. In this discussion will more focus on the last step which is follow up. The internal
auditor will always follow up the issue until the issue will closed and every assignment must
do the report. For example, there is project that behind schedule the company will want to
know what is the status right now. So if the project still not done then have to ask to the
department or project manager what the reason and if the project is done the issue will be
closed.
CONCLUSION
I can conclude that Pasdec Holding Berhad has follow all the internal audit procedure.
They also will follow up any issue that arise until the issue have been closed. They always
gives the report to the audit committee for them to know the updates. The internal auditor is
follow all the rules that been stated in IPPF.
11
Transcription
Interviewee
Kogilavani: What is the background of name of person that we interview was
Pasdec Holdings Bhd? Mr. Mustapha Bin Hussein
graduated Bachelor of Science
(major in Biology)
After completed his studies, he gets a
job opportunity to continue as an
internal auditor at Plantation
Company because that time he did
not have job vacancy that related to
his degree
He starts to learn auditing from his
seniors from internal audit
department
He learns auditing and accounting by
itself to improve his skills and
knowledge in that.
work around 2 years in that plantation
company
12
become a member of Institute
Internal auditor (IIA)
works as a head of internal audit
department in Pasdec Holdings Bhd
around 9 years in Pasdec Holdings
Bhd
Kogilavani: What are the training and skills External training
provided to internal auditor? internal auditor has to attend external
training at least once a year
training is provided by Institute
Internal Auditor (IIA)
low cost and the speaker also so
quality in term of their knowledge
and experience
know all the requirements that must
comply by the internal auditors
On the job training
fresh graduates they are lack of
experience in internal auditing so, as
a head of internal auditor he will
provide simple assignment to them
After get some experiences the head
of internal audit will provide
complicated assignment to them to
become more expected in internal
audit
the head of internal audit of Pasdec
will explain audit skills and
knowledge to his staffs
audit skills he also briefs his staffs
about the background of company
13
Kogilavani: How sir segregate the duties in this company have three persons to
internal audit departments? organize the internal audit
department
internal audit department is so small
Mr. Mustapha Bin Hussein is the
head of the internal audit department
in this company
responsible all matters that related to
internal audit department, audit
committee, annual planning and
budget planning
heck all the work done by the team
leader and team member
to report whatever that happens in
internal audit department to the audit
committee and board of directors
duties of team leader are they have to
follow the instructions that given by
the head of internal audit department
involve in planning, scheduling, and
reviewing audit program and
reporting results, and give some
guidance
perform the special projects
the team member should follow the
instructions that given by team leader
communicate with audit clients to
develop the audit plans
the team leader will check assets,
stocks, vehicles and he ask the team
member to focus on fixed assets only
14
overall assignment did by team leader
and assist by team member to
complete the assignment successfully
head of department have more
experience compared with team
leader and team member
Sathurshinni: What system and software have used system and software
did your company use? some system that used by Pasdec
company such as accounting system,
property system, stars property and
data base system
For accounting system named as
distract
Property system used for collections
use Power Point and Microsoft Word
as their audit software
The company does not use Computer
Assisted Audit Techniques (CAATs)
because they have limited data in
system, limited turnover and also
limited customers.
Pasdec Holding Bhd not much
sophisticated compare to big
company
Big companies are not use distract
but they are used Enterprise
Resources Planning (ERP)
Sathurshinni: How your company with have whistleblowing policies and
whistleblowing? procedures
whistle-blower can report to audit
department if they does not believe
means they can report directly to
audit committee or chairman
15
they are honest person they must
meet auditor to hide their identity
if they are does not believe means
they not report but if they are believe
means they should be report and also
their identity must be secret
After we get reports from whistle
blower the management have to do
investigation based on the report
. Next, after conduct investigation by
management they should submit
report to audit committee
The audit committee will review the
report that involves any inappropriate
items and then they should do
domestic inquiry based on the report
Domestic inquiry refers to the people
have problem at their company such
as abusing drug, late comer’s issues
and stealing company property
Audit committee will decide whether
they want to do domestic inquiry or
not
They do illegal activity so the
company maybe dismiss from job,
salary deduction and warning letter
depends on the illegal activities.
Raja Noor Najeeha: What is the policy When the fraud case happen, they
system to handle fraud? Is there any have prevention manual
prevention or detection? similar to whistle blowing but they
have policy
16
there is a related between prevention
manual, whistle blowing and also
code of conduct
Code of conduct basically tells that
what you can do and what you can’t
do
an employee you cannot have
conflict of interest
If there have conflict of interest, they
have to declare
If one of their sibling want to join the
organisation, they have to declare
Raja Noor Najeeha: How actually you report usually based on quality of
spent time to prepare report? Is there any audit
challenges when preparing the report? audit process has quality, you return
report will get quality also
Analysis and data is not enough then
your report is not quality.
produce a good report, writing skills
most important
The time taken to complete audit
report usually it takes two weeks
based on assignments and
experience conduct of audit
if you notice there is a fraud, what
you should do so it will relate to
whistle blowing
have policy because they may not
tolerate in this serious matter
Izazi: How many person in charge in implement the segregation of duties
purchases department? What are each person in their contact department
duties? department consist of 6 people
17
The team is called quantity survivor
a developer company to builds a
house so they have to choose
contractor and consultant
open the tender to public then they
will evaluate the contractor by the
price & experience in handling a
project
To approve the contractor, the Board
of Director will choose if the amount
is high but the amount is below Rm
300,000 can be choose by general
managing director
the internal auditor department need
to buy a mouse so the will fill the
form then pass to admin
Find quotation then being approve
by the managing director
Izazi: If you detect any fraud in purchases internal audit had been find the risk
what is your action/internal control that you for the company they will tell the
use? respective department that involved
with the risk
leave it to the department how to
handle the risk
do not do use control self-assessment
control the risk is the each
department duties because they have
their own standard operating
procedure (SOP)
Fix their SOP if the SOP have
weaknesses
Izazi: How the internal auditor follow up if also do the internal audit process
there is any issue that occur?
18
more focus on the last step which is
follow up
follow up the issue until the issue
will closed and every assignment
must do the report
project that behind schedule the
company will want to know what is
the status right now
project still not done then have to
ask to the department or project
manager what the reason
If the project is done the issue will be
closed.
19
Appendices
20
21
22