▲ Back to Top
MACROPROCESS OF MONITORING, MEASUREMENT, ANALYSIS AND EVALUATION INTERNAL CONTROL MANAGEMENT
INTERNAL CONTROL MANAGEMENT PROCESS
CHARACTERIZATION
PROCESS OWNER

Carolina Gómez Fontecha
Director of Internal Control
- Continuously improve process performance through the implementation of institutional best practices and the application of the mechanisms established by the University of Cundinamarca, with the goal of creating a smart university organization with heart and soul.
- Inform and educate the community of the University of Cundinamarca and its stakeholders, both at its main campus and its regional branches and extensions, regarding the guidelines of this Institutional Environmental Policy.
- Establish environmental management programs with a focus on continuous improvement that allow for strengthening the IEMP (Institutional Environmental Management Plan) of the University of Cundinamarca, annually reformulating environmental objectives and goals with principles of prevention and proactivity.
- Ensure the understanding, evaluation, and compliance of current environmental legislation and regulations, as well as other requirements voluntarily acquired within the framework of the PIGA (Institutional Environmental Management Plan) and the University's Institutional guidelines.
- To promote the comprehensive protection of the physical and mental health of officials and contractors who contribute to the fulfillment of the institutional mission, through the prevention and control of occupational hazards.
- Identify the hazards, evaluate, assess, and intervene in the risks present in the processes developed by the University Community and other stakeholders, establishing the respective controls, with the purpose of avoiding and minimizing incidents, work-related accidents, and occupational illnesses that may arise as a result thereof.
- Manage risks with each process of the institution based on the confidentiality, integrity, and availability criteria of the Information Security Management System – ISMS information, starting from Information Asset Management, associated in Annex A of the ISO 27001 standard, for their treatment and mitigation, according to the prioritization of the criticality of the identified information assets.
- Define and implement incident management involving the activities of prevention, identification, and management of events and/or incidents that threaten the confidentiality, integrity, and availability of information assets, in accordance with the resources provided by the institution, promoting the continuous improvement of the ISMS.
STAGES
1. PLAN
2. DO
3. VERIFY
4. ACT
OBJECTIVES
GENERAL OBJECTIVE
Perform timely and systematic verification, monitoring, evaluation, and control of the macro-processes that make up the University's operating model through mechanisms and instruments that guarantee compliance with applicable regulations and continuous improvement.
SPECIFIC OBJECTIVES
1. Manage the total number of plans added at the close of the immediately preceding term that have been in execution during the current term, conducting periodic monitoring of the internal control personnel in charge of the process.
2. Meet the institutional improvement level indicator in correspondence with the processes.
3. Detect the materialization of risk to strengthen internal control from the third line of defense.
SCOPE
It applies to all Macroprocesses and the systems referenced in the Internal Control manual (Management Systems, Internal Control System) of the University of Cundinamarca, starting from the planning and execution of the audit, evaluations of the systems, and reporting to internal and external users according to their nature, up to the fulfillment of the process objective.
PROCESS OPERATION POLICY
The operation of the process is inspired by:
- Rector's Plan.
- Action Plan.
- Strategic Plan.
- Development Plan
- CISNA Matrix (Initial Conditions for Entering the National Accreditation System).
- Management Systems.
- Standard Internal Control Model MECI.
Based on the Plan-Do-Check-Act cycle of continuous improvement and compliance with current regulations, the actions of the public servants involved in the process are consistent with the code of ethics and other control environments of the University of Cundinamarca.
| ENTRIES | PROCEDURES | EXITS |
| – Internal, External Audit Report and Independent Evaluations | SCIP02 – Corrective and Improvement Actions | - Improvement plans and follow-up on corrective and improvement actions. – Reports generated by the “Corrective and Improvement Actions” Internal Control Application: |
| – Internal Audit Program – Request for Special Audits | SCIP04 – Internal Audit | – Audit Plans - Audit Reports - Audit Evaluations |
| – Request for Support, Advisory, and Monitoring by Internal Control | SCIP11 – Support, Advisory and Monitoring by Internal Control | – Minutes and Attendance Records – Monitoring Reports |
| - Audit Report by the Control Body | SCIP16 – Development and Monitoring of Improvement Plans with External Control Entities | - Implementation and Closure of preventive, corrective, and improvement actions |
| – Requirements of the Comptroller's Office of Cundinamarca | SCIP18 – SIA Observa and SIA Contraloría Accountability Reporting | – Monthly SIA Observa reporting – Annual SIA Contraloría reporting |

Verification and follow-up of the various reports resulting from the different activities carried out by the Internal Control Directorate, as well as the measurement of Management System indicators.
Establishment of Corrective and Improvement Actions.
ICS Process Documents
There are no documents for this filter.
Digital Operating Model
Digital Operating Model
Digital Operating Model
Digital Operating Model
