Institutional high-quality accreditation link stiky-sticky

▲ Back to Top

Internal Control System

0257a3ce9972123d55ce20e5417f2658d9119c53

The Internal Control System is integrated into the Integrated Planning and Management Model, through the MECI, as one of the 7 dimensions of the MIPG, becoming the fundamental factor to reasonably guarantee the fulfillment of institutional objectives, as provided by Decree 1499 of 2017.

The objective of the MECI is to provide a management control structure that specifies the necessary elements to build and strengthen the Internal Control System, through a model that determines the necessary parameters (self-management) for entities to establish actions, policies, methods, procedures, prevention, verification and evaluation mechanisms in pursuit of their continuous improvement (self-regulation), in which each of the entity's employees becomes an integral part (self-control).

Internal Control Policy established by the MIPG

Develop an organizational culture based on information, control and evaluation, for decision-making and continuous improvement, through actions, guidelines and procedures for risk control and management, as well as mechanisms for risk prevention and evaluation.

Source: Operational Manual of the Integrated Planning and Management Model (MIPG), version No. 4.

Scope and Components

Internal control

The new MECI structure seeks alignment with the best control practices referenced from the COSO Model, which is why the MECI structure is based on five components, namely:

  • Control environment.
  • Risk management.
  • Control activities.
  • Information and communication.
  • Monitoring activities.

This structure is accompanied by a scheme for assigning responsibilities and roles for risk management and control, which is distributed across various servers of the entity, and is not an exclusive task of the internal control offices:

 

  • Strategic line, made up of senior management and the management team.
  • First Line, made up of public managers and process leaders.
  • Second Line, made up of servers responsible for monitoring and evaluating controls and risk management (planning managers, supervisors and auditors of contracts or projects, risk committees where they exist, contracting committee, among others).
  • Third Line, made up of the Internal Control office.
4F3

Control environment

To have the minimum conditions in place for the exercise of internal control. This is achieved through the commitment, leadership, and guidelines of senior management and the Institutional Committee for Internal Control Coordination.
Psychology

Risk assessment

This exercise, carried out under the leadership of the management team and all employees of the entity, allows for the identification, evaluation, and management of potential events, both internal and external, that may affect the achievement of institutional objectives.
Administrative staff in the office

Control activities

Implementing controls involves establishing the necessary mechanisms to address institutional risks. This includes defining actions to mitigate these risks, incorporating specific ICT controls, and applying operational policies through procedures or other instruments that ensure compliance within the control system.
administrative staff in dialogue

Information and Communication

It is verified that the policies, guidelines and mechanisms for obtaining, capturing, processing and generating data within and in the environment of each entity, satisfy the need to disseminate the results, to show improvements in administrative management and to ensure that the information and communication of the entity and of each process is adequate to the specific needs of the value groups and interest groups.
Woman in office

Monitoring activities

The purpose of conducting periodic evaluations, such as self-assessments and audits, is to assess the effectiveness of internal controls, the efficiency and effectiveness of processes, and the level of implementation of plans, programs, and projects. These evaluations allow for the analysis of management results, the identification of deviations, the recognition of trends, and the formulation of recommendations to guide the public entity's continuous improvement efforts.

MERCI

MERCI

MERCI

MERCI