•
The Company’s risk assessment process did not adequately identify (1) risks of misstatement due to error or fraud related to its financial reporting processes and (2) risks related to the use of information technology (IT) systems as part of its financial reporting processes, and design adequate controls to address those risks.
•
As a consequence of the ineffective risk assessment process, the Company did not design, implement, and maintain effective control activities at the transaction level over significant accounts to mitigate the risk of material misstatement in its financial reporting processes.
•
The Company did not design and maintain effective general information technology controls (GITCs) over key IT systems. Specifically, the Company did not establish (1) effective user access controls to provide for an appropriate segregation of duties and to adequately restrict user and privileged access to appropriate financial and IT personnel and (2) program change management controls to provide reasonable assurance that all program changes were subject to appropriate approval before the deployment of the program changes into live production. As a result, automated process-level controls and manual controls that are dependent upon the information derived from these IT systems related to all processes were also determined to be ineffective.
•
The Company did not design and maintain effective controls over segregation of duties relating to general ledger entries and the accuracy of those entries. Further, the Company did not sufficiently monitor user access to certain IT systems to assess appropriate access or the effectiveness of journal entry review controls.
•
The Company did not design and maintain effective controls over the accuracy and presentation of the statement of cash flows.