Management Letter for the Core Control Audit of the Financial Consumer Agency of Canada
May 2018
Office of the Comptroller General
Management Letter
This management letter is presented to the management of the Financial Consumer Agency of Canada. It provides the detailed findings and recommendations against all criteria tested and aligns recommendations with the criteria to which they relate.
Transactions were selected from the period of April 1 to December 31, 2016.
As a result of this audit, the Financial Consumer Agency of Canada is required to develop a management action plan to address the recommendations provided in this management letter.
I thank you in advance for your timely cooperation.
Mike Milito, MBA, CIA, CRMA
Assistant Comptroller General
Internal Audit Sector
Office of the Comptroller General
Detailed Findings and Recommendations
Legend of Compliance ThresholdsFootnote 1
Met – Greater than or equal to 98% compliance
Partially Met – Greater than or equal to 80% and less than 98% compliance
Not Met – Less than 80% compliance
Criteria |
Findings |
Compliance |
---|---|---|
i) Delegation of Financial Authorities for Disbursements Delegation instruments are appropriate, current, approved in accordance with the directive. |
The Delegation of Financial Signing Authorities Matrix was approved by the Commissioner on December 4, 2015, and was approved by the Minister of Finance. Although the Minister of Finance approval was not dated, FCAC received the approval on February 11, 2016 which is within the required 90-day period from the arrival of a new minister. In addition, the Financial Signing Authorities Matrix aligns with the Directive on Travel, Hospitality, Conference and Event Expenditures. It also aligns with Contracting Policy limits. Furthermore, controls over signature cards were reviewed based on the signature cards that were part of the sample. The following exceptions were noted:
|
Not Met |
ii) Learning, Training and Development Employees receive appropriate training in accordance with requirements pertaining to financial management, contracting and human resources. |
For 9 of 23 applicable files reviewed, employees had received appropriate delegations training. The following exceptions were noted:
|
Not Met |
Recommendations: 1. The FCAC should ensure that delegation business processes are improved and are consistently performed in compliance with the Treasury Board Directive on Delegation of Financial Authorities for Disbursements, and that sufficient documentation is retained on file to ensure that:
|
||
Overall Compliance: Not Met |
Criteria |
Findings |
Compliance |
---|---|---|
i) The department has established a sound financial management governance structure that fosters prudent stewardship of public resources in the delivery of the mandate of the organization. |
The department has established a sound financial management governance structure that fosters prudent stewardship of public resources in the delivery of its mandate. An organizational budget was established for fiscal year 2016-17; it aligns with the Business Plan and directly relates to the FCAC’s strategic outcome. The budget for fiscal year 2016-17 was approved through FCAC’s Business Plan. The Agency develops its three-year Business Plan, which identifies priorities, strategies and strategic actions. Based on the Business Plan, branches develop their strategic deliverables, supporting activities and budgets. The budget is broken down by departmental responsibility centre and further broken down by expense items. Variances between actual and budgeted amounts are analyzed by each responsibility centre, and the monthly variance analysis is reported to the CFO. At mid-year, a revised budget based on actual figures and anticipated needs to the end of the fiscal year is presented for approval to the Commissioner. The FCAC also uses a salary forecasting tool that breaks salaries down by responsibility centre and by full-time equivalents. Departmental risks are reviewed periodically in an informal manner, and formally every year as part of FCAC’s Enterprise Risk Management Framework and in view of its Corporate Planning exercise. |
Met |
Recommendation: None |
||
Overall Compliance: Met |
Criteria |
Findings |
Compliance |
---|---|---|
i) Acquisition cards attribution is controlled and cardholders have acknowledged their responsibility in writing. |
For the one cardholder transaction reviewed, there was no acquisition card request form on file and no documentation to evidence that the cardholder acknowledged the responsibilities and obligations prior to receiving the acquisition card from the coordinator. |
Not Met |
ii) Funds commitment availability is certified by an individual with the delegated authority, prior to the expenditure initiation at the value expected to be incurred (section 32 of the Financial Administration Act). |
For 23 of 29 applicable transactions reviewed, funds commitment availability was certified by an individual with the delegated authority, prior to the expenditure initiation at the value expected to be incurred. The following exceptions were noted:
Please see Recommendation 7 |
Not Met |
iii) The performance of account verification is performed by an individual with the delegated authority, is accomplished on a timely basis and verifies the correctness of the payment requested (section 34 of the Financial Administration Act). |
For 38 of 40 applicable transactions reviewed, account verification was performed by an individual with the delegated authority, was accomplished on a timely basis and verified the correctness of the payment requested. The following exceptions were noted:
Please see Recommendation 8 |
Partially Met |
iv) The payment and settlement is carried out by an individual with the delegated authority, for the correct dollar amount and to the right vendor on a timely basis (section 33 of the Financial Administration Act).
|
This criterion was not assessed as it is performed by OSFI. |
Not Applicable |
v) Cards are to be used solely for authorized government business-related purchases of goods, services and pre-approved hospitality expenditures. |
For 38 of 40 applicable transactions reviewed, cards were used solely for authorized government business-related purchases of goods, services and pre-approved hospitality expenditures. The following exception was noted:
|
Partially Met |
Recommendation: 2. The FCAC should ensure that sufficient documentation is retained on file for acquisition cards to substantiate their issuance, approval, modification, and acknowledgment of responsibilities by the cardholder, and to support that acquisition card purchases are government business-related expenses. |
||
Overall Compliance: Partially Met |
A total of 37 contracting files were reviewed. Out of these, 8 were non-competitive, 3 were competitive, 20 procurement files pertained to the use of Public Services and Procurement Canada standing offers, supply arrangement or were awarded by Shared Services Canada, and 6 files were without a contract paid by an acquisition card. |
||
Criteria |
Findings |
Compliance |
---|---|---|
i) Procurement strategy: non-competitive (non-competitive method of supply include sole-source) There is documentation on file to support the justification for non-competitive procurement contracts in accordance with section 6 of Government Contracts Regulations. |
For 1 of 8 applicable non-competitive contracting files reviewed, there was documentation on file to support the justification for non-competitive procurement in accordance with section 6 of the Government Contract Regulations. Some files had multiple compliance issues:
|
Not Met |
ii) Procurement strategy (methods of supply include contracts, standing offers and supply arrangements) Appropriate tendering processes for bids are used in the proper circumstances. |
For 28 of 37 contracting files reviewed, appropriate tendering process for bids were used in proper circumstances. The following exception was noted:
|
Not Met |
iii) Procurement strategy: competitive (methods of supply include contracts, standing offers and supply arrangements) Bid evaluation criteria were provided on request for proposal (RFP) documents and were used for contractor selection in an open, fair and transparent manner. |
For 2 of 3 applicable competitive contracting files reviewed, the bid evaluation criteria were provided on Request for Proposal (RFP) documents and were used for contractor selection in an open, fair and transparent manner. The following exception was noted:
|
Not Met |
iv) Funds commitment availability is certified by an individual with the delegated authority, prior to the expenditure initiation at the value expected to be incurred (section 32 of the Financial Administration Act). |
For 31 of 35 applicable contracting files reviewed, funds commitment availability was certified by an individual with the delegated authority, prior to the expenditure initiation and at the value expected to be incurred. The following exceptions were noted:
Please see Recommendation 7 |
Partially Met |
v) Contract management Contracts and contract amendments were approved prior to the receipt of any goods or services or the expiration of the original contract and supporting documentation is retained on file. |
For 23 of 31 applicable contracting files reviewed, the contract and amendments were approved prior to the receipt of any goods or services or the expiration of the original contract and supporting documentation was retained on file. Some files had multiple compliance issues:
|
Not Met |
vi) The performance of account verification is performed by an individual with the delegated authority, is accomplished on a timely basis and verifies the correctness of the payment requested (section 34 of the Financial Administration Act). |
For 29 of 36 applicable contracting files reviewed, account verification was performed by an individual with the delegated authority, supported by proof of execution and accomplished on a timely basis. Some files had multiple compliance issues:
Please see Recommendation 8 Please note the audit found that two transactions were approved by an individual who had performed incompatible duties. For contracting and contract amendments, two instances were noted where the contracting delegated authority had completed account verification, which resulted in a lack of segregation of duties based on the Directive on Delegation of Financial Authorities for Disbursements. FCAC stated that due to the organization size and the limitation of roles and responsibilities, the Agency has a standby responsibility for the Administrative Services Manager in the event of emergencies to ensure continuous operations. FCAC has also been monitoring this segregation of duties conflict on an annual basis and preparing annual declarations. There was no impact on compliance; however, a recommendation was included to address the conflict of duties. |
Not Met |
vii) The payment and settlement is carried out by an individual with the delegated authority, for the correct dollar amount and to the right vendor on a timely basis (Section 33 of the Financial Administration Act). |
This criterion was not assessed as it is performed by OSFI. |
Not Applicable |
viii) Proactive disclosure Contracts valued at over $10,000 are publicly disclosed. |
For 17 of 19 applicable contracting files reviewed, the contracts (including amendments) valued at over $10,000 were publicly disclosed. The following exceptions were noted:
|
Partially Met |
ix) Payable at year-end (PAYE) A PAYE was properly set up, and the transactions were identified as such. |
PAYEs were not assessed because the audit covered the period from April 1 to December 31, 2016. |
Not Applicable |
Recommendation: 3. The FCAC should ensure that business processes are improved and are consistently performed in compliance with the Treasury Board Contracting Policy, and that sufficient documentation is retained on file to ensure that:
|
||
Overall Compliance: Not Met |
Criteria |
Findings |
Compliance |
---|---|---|
i) Government business travel expenses are managed to achieve fair, reasonable and modern travel practices. |
For 20 of 29 transactions reviewed, government business travel expenses were managed to achieve fair, reasonable and modern travel practices. The following exceptions were noted:
|
Not Met |
ii) Funds commitment availability is certified by an individual with the delegated authority, prior to the expenditure initiation at the value expected to be incurred (section 32 of the Financial Administration Act). |
For all 29 applicable transactions reviewed, funds commitment availability was certified by an individual with the delegated authority, prior to the expenditure initiation at the value expected to be incurred. |
Met |
iii) The performance of account verification is performed by an individual with the delegated authority, is accomplished on a timely basis and verifies the correctness of the payment requested (section 34 of the Financial Administration Act). |
For all 30 transactions reviewed, account verification was performed by an individual with the delegated authority, was accomplished on a timely basis and verified the correctness of the payment requested. |
Met |
iv) The payment and settlement is carried out by an individual with the delegated authority, for the correct dollar amount and to the right vendor on a timely basis (section 33 of the Financial Administration Act). |
This criterion was not assessed as it is performed by OSFI. |
Not Applicable |
v) All travel expenses for designated senior-level Government of Canada employees are proactively disclosed. |
For all ten applicable transactions reviewed, the travel expenses for the designated senior-level employees were properly recorded and proactively disclosed. |
Met |
vi) Total annual expenditures for travel for the department are disclosed on its website, including a brief description of the main variances from the previous year’s actual expenditures. |
Total annual travel expenditures for the department were disclosed on its website, including a brief description of the main variances from the previous year’s actual expenditures. |
Met |
vii) Travellers cheques and advances are used in valid circumstances. |
None of the selected transactions included travel advances or travellers cheques. |
Not Applicable |
Recommendation: 4. The FCAC should ensure that travel business processes are improved and are consistently performed in compliance with the National Joint Council Travel Directive, and that sufficient documentation is retained on file to ensure that:
|
||
Overall Compliance: Partially Met |
Criteria |
Findings |
Compliance |
---|---|---|
i) Hospitality events are planned and conducted in an economical and appropriate way to facilitate government business, consistent with event circumstances. |
For 2 of 9 applicable transactions reviewed, hospitality events were planned and conducted in an economical and appropriate way to facilitate government business, consistent with the event circumstances. The following exceptions were noted:
|
Not Met |
ii) Funds commitment availability is certified by an individual with the delegated authority, prior to the expenditure initiation at the value expected to be incurred (section 32 of the Financial Administration Act). |
For 4 of 9 applicable transactions reviewed, funds commitment availability was certified by an individual with the delegated authority, prior to the expenditure initiation at the value expected to be incurred. Some transactions had multiple compliance issues:
Please see Recommendation 7 |
Not Met |
iii) The performance of account verification is performed by an individual with the delegated authority, is accomplished on a timely basis and verifies the correctness of the payment requested (section 34 of the Financial Administration Act). |
For 4 of 9 applicable transactions reviewed, account verification was performed by an individual with the delegated authority, was accomplished on a timely basis and verified the correctness of the payment requested. The following exceptions were noted:
Please see Recommendation 8 |
Not Met |
iv) The payment and settlement is carried out by an individual with the delegated authority, for the correct dollar amount and to the right vendor on a timely basis (section 33 of the Financial Administration Act). |
This criterion was not assessed as it is performed by OSFI. |
Not Applicable |
v) Hospitality expenses for designated senior-level employees are properly recorded and proactively disclosed. |
For 3 of 6 applicable transactions reviewed, the hospitality expenses for designated senior-level employees were properly recorded and proactively disclosed. The following exception was noted:
|
Not Met |
vi) Total annual expenditures for hospitality for the department are disclosed on its website, including a brief description of the main variances from the previous year’s actual expenditures. |
Total annual hospitality expenditures for the department were disclosed on its website, including a brief description of the main variances from the previous year’s actual expenditures. |
Met |
Recommendation: 5. The FCAC should ensure that hospitality business processes are improved and are consistently performed in compliance with the Directive on Travel, Hospitality, Conference and Event Expenditures, and that sufficient documentation is retained on file to ensure that:
|
||
Overall Compliance: Not Met |
Criteria |
Findings |
Compliance |
---|---|---|
Casual Employees |
||
i) Casual (non-EX) Key terms and conditions requirements for casual employees are administered correctly. |
For all three casual employee files reviewed, key terms and conditions requirements for casual employees were administered correctly. |
Met |
ii) Employee security screening is managed properly and subject to proper delegated authority. |
For all three casual employee files reviewed, employee security screening was managed properly and subject to proper delegated authority. |
Met |
Performance Pay |
||
iii) EX group and excluded employees Performance pay is administered correctly and approved by the appropriate delegated authority. |
Not applicable; the FCAC is a separate employer and not subject to the relevant Treasury Board Directives. |
Not Applicable |
All Pay Administration Files |
||
iv) Funds commitment availability is certified by an individual with the delegated authority, prior to the expenditure initiation at the value expected to be incurred (section 32 of the Financial Administration Act). |
For 15 of 18 applicable transactions reviewed, funds commitment availability was certified by an individual with the delegated authority, prior to the expenditure initiation. Commitments were recorded at the value expected to be incurred at the beginning of the fiscal year. The following exceptions were noted:
Please see Recommendation 7 |
Partially Met |
v) The performance of account verification is performed by an individual with the delegated authority, is accomplished on a timely basis and verifies the correctness of the payment requested (section 34 of the Financial Administration Act). |
For 17 of 19 applicable transactions reviewed, account verification was completed by an individual with the delegated authority, was accomplished on a timely basis and verified the correctness of the payment requested. The following exception was noted:
Please see Recommendation 8 |
Partially Met |
vi) The payment and settlement is carried out by an individual with the delegated authority, for the correct dollar amount and to the right vendor on a timely basis (section 33 of the Financial Administration Act). |
For all 24 applicable transactions reviewed, payment and settlement was carried out for the correct dollar amount and to the right vendor. Note that sub-criteria relating to an individual with the delegated authority and timeliness were not assessed, as Section 33 responsibilities are completed by Canadian Human Rights Commission (CHRC). |
Met |
vii) Adequate segregation of duties, such as ensuring the custody and distribution of cheques and direct deposit payment statements, exists in pay administration roles. |
Adequate segregation of duties exists in pay administration roles. |
Met |
viii) Departure procedures for the department are followed. |
For the two applicable transactions reviewed, the departure procedures for the department were not followed as there was no evidence on file of departure forms signed by all concerned parties prior to leaving the organization. |
Not Met |
Recommendation: 6. The FCAC should ensure that departure forms are completed by all applicable authorities and kept on file. |
||
Overall Compliance: Partially Met |
Criteria |
Findings |
Compliance |
---|---|---|
i) Departmental mechanisms exist to ensure the appropriate use of accounts receivable. |
Departmental mechanisms exist to ensure the appropriate use of accounts receivable. Results-based measurement mechanisms were established and monitored. Periodic reports on the financial and non-financial activities of the portfolio, including receivable ageing reports, were prepared and distributed to management. Appropriate division of duties exists in relation to collections, write-offs, the maintenance of accounting records, and the handling and reconciling of money. |
Met |
ii) The department enters into an agreement with each debtor which defines the type(s) of goods and services that can be provided on credit, seeks security for debts due and informs the debtor of their obligations under applicable acts and regulations. |
Debtors were informed of their obligations under the applicable acts and regulations. Documented procedures provide details on how initial accounts receivable transactions and subsequent cash payments/final settlements for all types of revenue are to be recorded in the financial system. Procedures detailing the calculation and notification of interest on overdue accounts for all types of revenue are documented. Procedures for the collection of administrative monetary penalties are also documented. |
Met |
iii) Receivable transactions are recorded accurately and are accompanied by complete audit trails. |
For 46 of 47 transactions reviewed, the account receivable was recorded accurately and was accompanied by a complete audit trail. The following exception was noted:
|
Met |
Recommendation: None |
||
Overall Compliance: Met |
Criteria |
Findings |
Compliance |
---|---|---|
i) Funds commitment availability is certified by an individual with the delegated authority, prior to the expenditure initiation at the value expected to be incurred. |
For 102 of 120 transactions reviewed, funds commitment availability was certified by an individual with the delegated authority, prior to the expenditure initiation at the value expected to be incurred. The results of these findings are rolled up from expenditure initiation findings found under the following:
|
Partially Met |
Recommendation: 7. The FCAC should ensure that expenditure initiation (pre-approval and commitment) is properly documented and performed by an individual who has the appropriate delegated authority before expenses are incurred, specifically in relation to acquisition card purchases, hospitality expenditures, contracting and pay administration actions. |
||
Overall Compliance: Partially Met |
Criteria |
Findings |
Compliance |
---|---|---|
i) The performance of account verification is performed by an individual with the delegated authority, is accomplished on a timely basis and verifies the correctness of the payment requested. |
For 118 of 134 transactions reviewed, the performance of account verification was performed by an individual with the delegated authority, was accomplished on a timely basis and verified the correctness of the payment requested. The results of these findings are rolled up from account verification findings found under the following:
|
Partially Met |
ii) The payment and settlement is carried out by an individual with the delegated authority, for the correct dollar amount and to the right vendor on a timely basis. |
For all 24 transactions reviewed, payment and settlement was carried out by an individual with the delegated authority, for the correct dollar amount and to the right vendor on a timely basis. The results of these findings are rolled up from payment and settlement findings found under the following:
|
Met |
Recommendation: 8. The FCAC should ensure that account verification is performed by the appropriate delegated authority on a timely basis, and is supported by complete documentation (proof of execution and cost), specifically in relation to acquisition card purchases, hospitality expenditures, contracting and pay administration actions. |
||
Overall Compliance: Partially Met |
Appendix 1: Policies and Directives Tested
Areas Tested
Directive on Delegation of Financial Authorities for Disbursements (tested)
Policy on Financial Management Governance (tested)
Directive on Loans and Loan Guarantees
Directive on Losses of Money or Property
Directive on Payment Requisitioning and Cheque Control
Directive on Departmental Bank Accounts
Directive on Expenditure Initiation and Commitment ControlFootnote 2 (tested)
Directive on Receivables Management (tested)
Directive on Specified Purposes Accounts
Directive on Account VerificationFootnote 3 (tested)
Directive on Fleet Management: Light-Duty Vehicles
Directive on Acquisition Cards (tested)
Directive on Accountable Advances
Directive on Year-End Recording of Payables
Contracting Policy (tested)
National Joint Council Travel Directive (tested)
Directive on Travel, Hospitality, Conference and Event Expenditures (tested)
Performance Pay AdministrationFootnote 4
Directive on Leave and Special Working Arrangements
Directive on Financial Management of Pay Administration (tested)
Policy on Transfer Payments
Directive on Transfer Payments
Term Employment Policy (Casual Employees)
Directive on Terms and Conditions of Employment (Casual Employees)
Appendix 2: Risk Ranking of Recommendations
The following table presents the recommendations and their assigned priority ranking. Rankings were determined based on the relative importance of the recommendations and their potential to motivate long-term change and reduce risk in Financial Consumer Agency of Canada.
Recommendations |
Priority |
---|---|
1. The FCAC should ensure that delegation business processes are improved and are consistently performed in compliance with the Treasury Board Directive on Delegation of Financial Authorities for Disbursements, and that sufficient documentation is retained on file to ensure that:
|
High |
2. The FCAC should ensure that sufficient documentation is retained on file for acquisition cards to substantiate their issuance, approval, modification, and acknowledgment of responsibilities by the cardholder, and to support that acquisition card purchases are government business-related expenses. |
Medium |
3. The FCAC should ensure that business processes are improved and are consistently performed in compliance with the Treasury Board Contracting Policy and that sufficient documentation is retained on file to ensure that:
|
High |
4. The FCAC should ensure that travel business processes are improved and are consistently performed in compliance with the National Joint Council Travel Directive, and that sufficient documentation is retained on file to ensure that:
|
Medium |
5. The FCAC should ensure that hospitality business processes are improved and are consistently performed in compliance with the Directive on Travel, Hospitality, Conference and Event Expenditures, and that sufficient documentation is retained on file to ensure that:
|
High |
6. The FCAC should ensure that departure forms are completed by all applicable authorities and kept on file. |
Low |
7. The FCAC should ensure that expenditure initiation (pre-approval and commitment) is properly documented and performed by an individual who has the appropriate delegated authority before expenses are incurred, specifically in relation to acquisition card purchases, hospitality expenditures, contracting and pay administration actions. |
Medium |
8. The FCAC should ensure that account verification is performed by the appropriate delegated authority on a timely basis, and is supported by complete documentation (proof of execution and cost), specifically in relation to acquisition card purchases, hospitality expenditures, contracting and pay administration actions. |
Medium |
Appendix 3: Links to Applicable Legislation, Policies and Directives
Applicable Legislation, Policies, and Directives – Website Reference (links current as of January 12, 2016)
- Financial Administration Act
- Policy on Internal Control
- Directive on Delegation of Financial Authorities for Disbursement
- Policy on Learning, Training and Development
- Policy on Financial Management Governance
- Directive on Loans and Loan Guarantees
- Directive on Losses of Money or Property
- Directive on Payment Requisitioning and Cheque Control
- Directive on Departmental Bank Accounts
- Directive on Expenditure Initiation and Commitment Control
- Directive on Specified Purposes Accounts
- Directive on Account Verification
- Directive on Fleet Management: Light-Duty Vehicles
- Directive on Acquisition Cards
- Directive on Accountable Advances
- Accountable Advances Regulations
- Directive on Year-End Recording of Payables
- Contracting Policy
- Government Contracts Regulations
- Policy on Government Security
- Guidelines on the Proactive Disclosure of Contracts
- National Joint Council Travel Directive
- Special Travel Authorities
- Guidance Document: Proactive Disclosure of Travel and Hospitality Expenses (not available in the public domain)
- Directive on Travel Cards and Travellers Cheques
- Directive on Travel, Hospitality, Conference and Event Expenditures
- Policy on the Management of Executives
- Directive on Executive Compensation
- Performance Pay Administration Policy for Certain Non-Management Category Senior Excluded Levels
- Directive on the Performance Management Program for Executives
- Directive on Terms and Conditions of Employment for Certain Excluded/Unrepresented Employees
- Directive on Leave and Special Working Arrangements
- Directive on Financial Management of Pay Administration
- Public Service Employment Act
- Collective Agreement for Program and Administrative Services
- Policy on Transfer Payments
- Directive on Transfer Payments
- Term Employment Policy
- Directive on Terms and Conditions of Employment
Page details
- Date modified: