Home About Us Services ↳ Canada PR Visa (Permanent Residency) ↳ Work Permit Canada ↳ LMIA — Labour Market Impact Assessment ↳ Spouse & Family Sponsorship Visa ↳ Student Visa Canada ↳ Visitor Visa ↳ Business Visa Provinces ↳ 🏙️ Ontario ↳ 🏔️ British Columbia ↳ 🌾 Alberta ↳ 🌻 Saskatchewan ↳ 🌊 Manitoba ↳ ⚓ Nova Scotia ↳ 🍁 New Brunswick ↳ 🦞 Prince Edward Island ↳ 🐟 Newfoundland & Labrador ↳ 🌊 Atlantic Immigration Program Healthcare Blog FAQ Careers Canadian Latest policies Contact

Public Services and Procurement Canada
Annex A: Assessment of internal controls over financial management for year ended March 31, 2019

1. Introduction

This document provides a summary of measures taken by Public Services and Procurement Canada (PSPC) to maintain an effective system of internal control over financial management (ICFM), which includes information on internal control over financial reporting (ICFR), assessment results and related action plans.

Detailed information on the department's authority, mandate and program activities can be found in its most recent Departmental Plan and Departmental Results Report.

2. Departmental system of internal control over financial management

2.1 Internal control management

PSPC has a well-established governance and accountability structure to support departmental assessment efforts and oversight of its system of internal control. This structure is formalized in the Departmental Internal Control Framework, which includes:

  • organizational accountability and oversight structures to support sound financial management, including roles and responsibilities of departmental senior managers in their areas of responsibility for internal control management
  • semi-annual monitoring of, and regular updates on, internal control management, as well as provision of related control assessment results and action plans to the Departmental Audit Committee (DAC)
  • values and ethics, which provide educational and awareness programs and have developed a departmental code of conduct
  • leveraging the work of audit and advisory services for internal audits on the effectiveness of risk management, control and governance processes, where appropriate
  • risk-based management practices

The DAC provides advice to the deputy head on the adequacy and functioning of the department's risk management, control and governance frameworks and processes. It meets approximately 5 times a year, and is comprised of the Deputy Minister, the associate deputy minister and the 4 members external to the federal public administration, one of whom is the chair. Its meetings are also attended by the chief financial officer.

To provide reasonable assurance that financial controls are in place and operating as intended and adequately, PSPC conducts risk-based assessments, leverages ongoing monitoring programs and conducts specific year-end reviews, including:

  • information technology general controls (ITGCs) monitoring, for the financial management system, including feeder systems
  • financial advisor review of program management budgets and forecasts
  • performance management assessments based on the Financial Management Framework
  • awareness and monitoring of internal financial control audits and assessments performed by program management
  • results of control audits and management accountability framework assessments by the Office of the Comptroller General
  • documentation and assessment of internal controls by common service provider entities

These activities help ensure that:

  • financial arrangements or contracts are entered into only when sufficient funding is available
  • payments for goods and services are made only when the goods and services are received or the conditions of contracts or other arrangements have been satisfied
  • payments have been properly authorized

In addition, PSPC leverages results and findings from audits performed by external auditors, and the Office of Audit and Evaluation, as input in its assessments of the control environment, as follows:

  • annual financial statement audits of the revolving funds performed by an independent auditor
  • public accounts audits performed by the Office of the Auditor General

2.2 Service arrangements relevant to financial statements

PSPC relies on other organizations for processing certain transactions that are recorded in its financial statements as follows:

Common service arrangements

PSPC provides common services to other organizations for processing certain transactions that are recorded in their financial statements. In addition, PSPC relies on services provided by other organizations:

  • the Treasury Board of Canada Secretariat provides services related to public sector insurance for employees of PSPC and centrally administers payment of the employer's share of contributions toward statutory employee benefit plans (in other words, the Public Service Pension Plan, Employment Insurance Plan, Canada Pension Plan, Quebec Pension Plan and Public Service Supplementary Death Benefit Plan) on behalf of PSPC
  • the Department of Justice Canada provides legal services to PSPC
  • Shared Services Canada provides information technology infrastructure services to PSPC in the areas of data centre and network services. The scope and responsibilities are addressed in the interdepartmental arrangement between Shared Services Canada and PSPC

Readers of this annex may refer to the annexes of the above-noted organizations for a greater understanding of the systems of internal control over financial reporting related to these specific services.

PSPC provides common services, in the areas of procurement, accommodation, contract security, and translation, as well as pay and pension administration to other federal government departments, agencies and public service pensioners. In addition, the Receiver General for Canada administers several systems on behalf of the Government of Canada, including: Standard Payment System, Payroll System-General Ledger, and Receiver General-General Ledger.

Specific arrangements

PSPC relies on other external service providers for the processing of certain transactions or information that are recorded in its financial statements, as follows:

  • PSPC provides facilities management and services through a contract with an external service provider responsible for property and facility management government-wide. It also establishes third-party leases and agreements and provides lease administration and project delivery for all PSPC Crown-owned and leased sites across Canada. The external service provider is responsible for their own internal controls to help ensure compliance
  • PSPC provides Shared Services Canada with a System, Applications and Products (SAP) based financial management system platform to capture and report all financial transactions
  • an external service provider, pursuant to a contract with the Government of Canada, administers the travel management application used by PSPC to provide shared travel services to various departments
  • an external service provider, pursuant to a contract with the Government of Canada, administers the relocation program provided to public service employees across the federal public service

3. Departmental assessment results for the fiscal year ending March 31, 2019

PSPC's ongoing financial control monitoring program assesses, on a cyclical basis, the state of key financial control processes performed by PSPC's Finance Administration Branch, and the financial control activities conducted directly by branches delivering programs. This combined approach leads to a more robust and holistic view of the department's overall financial control environment and further supports assertions made in the Statement of Management Responsibility.

For the mature processes and sub-processes, testing is conducted on a 4 year cycle. Annually, a risk assessment of the business processes for key financial reporting controls is performed, which indicates if there is a residual risk of material misstatement. This risk-based approach supports PSPC's decisions as to the scope and extent of operational effectiveness testing that is required. In the current fiscal year, efforts were concentrated on sub-processes for which a medium or high risk of material misstatement was assessed, prior to controls or mitigation strategies.

As part of ongoing monitoring, sub-processes documentation is reviewed, and design effectiveness and operations effectiveness testing is conducted on select key controls. In addition to the ongoing monitoring of the financial controls processes, and operating effectiveness testing, corroborative procedures are performed in all of the control environments to obtain sufficient reliable evidence to support PSPC's assertion that the financial control environment in place is sound.

3.1 Mature business processes

The following table summarizes the progress of the ongoing monitoring activities performed as part of the internal control review of mature business processes, for the fiscal year ending March 31, 2019. This review is consistent with the previous year's rotational plan.

Table 1: Ongoing monitoring activities of mature business processes
Key control areas Number of sub-processes Number of sub-processes tested Remedial action required
Internal control over financial reporting
Entity level controls 5 5 Yes
Information technology general controls 10 3 Yes
Sales to settlement 12 1 Yes
Procurement to payment 13 2 Yes
Departmental payroll 13 3 Yes
Capital assets and capital leases 11 2 Yes
Other significant financial statements items 8 2 Yes
Year-end financial close and financial statement presentation 8 2 Yes
Common services
Pension servicestable 1 note 1 39 29 Yes
Receiver general services To be determined 4 Yes
Translation services 3 3 Yes
Contract security services 2 1 Yes
Other common servicestable 1 note 2 To be determined 0 Nil

Table 1: Ongoing monitoring activities of mature business processes notes: Table 1 Notes

Table 1 Note 1

The pension services include 3 distinct plans as follows: the Public Service Pension Plan, Canadian Armed Forces Pension Plan and Royal Canadian Mounted Police Pension Plan.

Return to table 1 note 1 referrer

Table 1 Note 2

Although procurement and accommodation are considered mature processes, they were not assessed during the fiscal year ending March 31, 2019, but will be part of the ongoing monitoring plan.

Return to table 1 note 2 referrer

Remedial action summary

As a result of design and operating effectiveness testing of key controls for mature business processes reviewed, no significant control deficiencies, which would expose the department to an elevated risk of material misstatement of its financial statements, have been identified. There are, however, areas that continue to require remediation:

  • roles and responsibilities need to be clearly defined, documented and communicated to ensure accountability and adherence to the established processes and procedures
  • training and standardized tools/procedures are needed to support responsibility center managers and staff in performing their work more effectively and efficiently
  • documentation of the performance of certain key controls needs to be improved
  • strengthen the review, monitoring and reporting of information to senior management

3.2 New business processes

Consistent with the requirements of the April 1, 2017 Treasury Board Policy on Financial Management, PSPC adds several areas of review due to their significance on the financial management of the department or that of other departments in which PSPC has a role as a common service provider.

Table 2: Ongoing monitoring activities of new business processes
Key control areas Number of sub-processes Number of sub-processes tested Remedial action required
Other significant financial management control areas
Planning To be determined 1 Yes
Budgeting To be determined 1 Yes
Forecasting To be determined 1 Yes
Integrated investment plan 5 1 Yes
Common services
Pay administration services To be determined 2 Yes

Summary of work performed and results

The planning, budgeting, forecasting and Integrated Investment Plan processes are currently in the early stages of review, which to date has involved the formal documentation of certain sub-processes and the assessment of the design effectiveness of their key controls.

PSPC is leading a significant effort to address and resolve pay issues. Progress is ongoing as it continues to work closely with other departments, central agencies, bargaining units and stakeholders. Given the current context, the departmental payroll process has been enhanced to address the challenges of reporting pay expenditures resulting from Phoenix Pay System issues, PSPC implements significant additional internal controls, such as:

  • a pre and post-payment account verification process for pay
  • enhanced analytical review procedures to corroborate pay expenditures and associated assets and liabilities at year-end

As a result of the assessment of the new business processes, the following remedial actions have been identified:

  • more consistent documentation on the performance of key controls
  • additional training to clarify the roles and responsibilities among key stakeholders for pay administration activities
  • enhanced monitoring controls of departmental pay services' performance
  • update of the control framework and guidelines to reflect changes to internal pay processes and controls
  • design and implementation of certain key validation controls, such as review by manager, to ensure the accuracy and completeness of information to meet pay-related legislative requirement

4. Departmental action plan for next fiscal year and subsequent years

4.1 Ongoing monitoring for mature business processes internal control reviews

For the fiscal year ending March 31, 2020, cyclical reviews of mature internal control processes will continue, along with ongoing improvement of internal controls assessment methodology for enhanced effectiveness and greening of operations. The approach leverages risk-based assessments to identify best mitigation strategies and internal control testing techniques for greater cost efficiency and assurance.

Furthermore, remediation strategies identified in management action plans for the fiscal year ending March 31, 2018 and March 31, 2019 will continue to be monitored.

4.2 Other significant financial management processes

The plan for the assessment of the other significant financial management processes will be determined after a risk-based assessment is completed. The current 4 year plan is as follows:

Table 3: Other significant financial management processes planning
Key control areas Planning and documentation
Fiscal year ending March 31
Design effectiveness testing and remediation
Fiscal year ending March 31
Operational effectiveness testing and remediation
Fiscal year ending March 31
Ongoing monitoring rotationtable 2 note 1
Future years
Budgeting 2020 2020 2021 2022
Forecasting 2020 2020 2022 2023
Investment planning 2020 2020 2020 2023
Costing To be determined To be determined To be determined To be determined
Cabinet submissions To be determined To be determined To be determined To be determined
Financial reporting 2020 2020 2021 2023
Chief financial officer attestation To be determined To be determined To be determined To be determined

Table 3: Other significant financial management processes planning: Table 2 Notes

Table 2 Note 1

The frequency of the ongoing monitoring of key control areas is risk-based and may occur over a multi-year cycle.

Return to table 2 note 1 referrer

4.3 Common service processes

As a common service provider of pay, pension, treasury, banking, procurement, translation and interpretation, accommodations and security in contracting, PSPC completes annually a risk-based assessment of the internal controls related to some of these services. The results of the assessment of certain sub-processes within the Pay Administration services are provided in sections 3.1 and 3.2.

The action plan for this annual assessment for the next and subsequent years is detailed below.

Table 4: Common service processes planning
Key control areastable 3 note 2 Planning and documentation
Fiscal year ending March 31
Design effectiveness testing and remediation
Fiscal year ending March 31
Operational effectiveness testing and remediation
Fiscal year ending March 31
Ongoing monitoring rotationtable 3 note 1
Future years
Pension services No planned assessment No planned assessment 2020 Annual
Pay administration servicestable 3 note 3 2020 2020 2020 Annual
Receiver general 2020 2020 2020 Annual
Procurement 2020 and 2021 2020 To be determined To be determined
Contract security No planned assessment No planned assessment 2020 2024
Accommodations 2021 or 2022 2021or 2022 To be determined To be determined

Table 4: Common service processes planning : Table 3 Notes

Table 3 Note 1

The frequency of the ongoing monitoring of key control areas is risk-based and may occur over a multi-year cycle.

Return to table 3 note 1 referrer

Table 3 Note 2

All key control areas will include a review of ITGCs when applicable.

Return to table 3 note 2 referrer

Table 3 Note 3

Each year, as new pay administration processes become stabilized, they will be added to the review process.

Return to table 3 note 3 referrer

Page details

2024-07-05

Quick Enquiry

We usually reply within a few hours
By submitting you agree to be contacted about your enquiry.
Call us Chat on WhatsApp
M

Migova AI Assistant

Online now
Hi 👋 I'm the Migova AI assistant, powered by OpenAI. Ask me about PR, study visas, work permits, LMIA, family sponsorship, provinces, or healthcare immigration to Canada.
Canada PR
Study Visa
LMIA / Work Permit