Canada Revenue Agency Annual Report to Parliament 2012-2013

Summary of the assessment of effectiveness of the systems of internal control over financial reporting and the action plan of the Canada Revenue Agency

Fiscal year 2012-2013

1. Introduction

This document provides summary information on the measures taken by the Canada Revenue Agency (CRA) to maintain an effective system of internal control over financial reporting (ICFR) including information on internal control management, assessment results, and related action plans.

It is important to note that the system of ICFR is not designed to eliminate all risks, but rather to mitigate risk to a reasonable level with controls that are balanced with, and proportionate to, the risks they aim to mitigate.

The system of ICFR is designed to mitigate risks to a reasonable level based on an ongoing process of identifying key risks, assessing the effectiveness of associated key controls, as well as adjusting and monitoring them to support continuous improvement. As a result, the scope, pace, and status of the CRA's assessments of the effectiveness of their systems of ICFR will vary by engagement type based on risks and the unique circumstances of the CRA's agency and administered programs.

Detailed information on the CRA's authority, mandate, and programs can be found in Departmental Performance Report at www.cra-arc.gc.ca/gncy/prfrmnc_rprts/menu-eng.html and Report on Plans and Priorities www.cra-arc.gc.ca/gncy/rprts/menu-eng.html.

Audited financial statements

For financial reporting purposes, the activities of the CRA have been divided into two sets of financial statements: agency activities and administered activities:

The CRA has issued annual audited financial statements since 1999-2000 and has consistently received an unmodified opinion from the Auditor General of Canada.

2. CRA system of internal control over financial reporting

2.1 Internal control management

The CRA has a well-established governance and accountability structure to support departmental assessment efforts and oversight of its system of internal control, which includes:

a) CRA Policy on Financial Management Governance (approved in 2010), which includes the:

(i) need to maintain an effective internal control framework and management's responsibility over their financial controls;

(ii) roles and responsibilities of the Commissioner/Chief Executive Officer (CEO), the Chief Financial Officer (CFO), Chief Audit Executive (CAE), Chief Information Officer (CIO), Assistant Commissioners, and other senior managers with respect to financial management and control within the CRA; and

(iii) role and responsibility of the Audit Committee of the Board of Management to review and provide direction.

b) CRA Policy on Internal Financial Control (approved in 2010), which includes the need to maintain an effective risk-based system of internal controls over financial reporting to document, test, and assess controls on an ongoing basis, including taking timely corrective measures when issues arise. It also describes the roles and responsibilities of the CEO, CFO, CAE, Assistant Commissioners, and the Audit Committee of the Board of Management regarding how they are to maintain and strengthen the effectiveness of the CRA's internal controls.

2.2 Service arrangements relevant to financial statements

2.2.1 CRA reliance on other Government service providers

The CRA relies on other organizations for the processing of certain transactions that are recorded in its financial statements as follows:

Common arrangements:

Specific arrangements:

2.2.2 CRA services that other departments and agencies rely on

Other Government departments rely on the CRA for the processing of certain transactions or information that affect financial statements as follows:

3. CRA assessment results during fiscal year 2012-2013

During 2012-2013, the CRA completed the ongoing monitoring testing of its agency activities, and the operating effectiveness assessment of its administered corporation income tax program as planned.

It is important to note that the CRA's assessments related to its internal controls over financial reporting for its administered activities that fall under the Tax Collection Agreements (TCAs) with provinces and territories for the individual (T1), corporation (T2), and trust (T3) income tax programs are also audited by the Office of the Auditor General (OAG).

3.1 Ongoing monitoring of key controls

In the current year, the CRA completed its second ongoing monitoring (OGM) testing exercise to assess the ongoing design and operating effectiveness of its Agency activities as follows:

As a result of this extensive OGM testing, the CRA found that for the most part, the key controls tested performed as intended, and identified these remediation requirements:

3.2 Operating effectiveness testing of key controls

The CRA completed its readiness assessment of the operational effectiveness for the T2 income tax program. This included full testing of all activities related to the following control objectives:

The key controls tested by CRA were found to be operating effectively, except for the following control objectives:
a) logical security tools and techniques are designed and implemented to restrict access to authorized users of programs, data, and other information resources;

b) documentation exists to demonstrate that modifications to existing application systems and data structures are appropriately tested and approved by management before implementation; and

c) system access is restricted to prevent unauthorized access and segregation of duty is appropriate.

Remediation action plans were developed for all key controls where exceptions were noted with some action plans having been already implemented to address the exceptions.

4. CRA action plan

4.1 Progress during fiscal year 2012-2013

During 2012-2013, the CRA has continued to make significant progress in documenting, assessing, and improving its key controls. Below are two tables summarizing the progress made regarding the documentation of the control frameworks for upcoming assessment engagements, and the remediation of action plans from previous engagements. The actual results for the two assessments completed this year are described in section 3.

All commitments were completed as planned and on schedule. These tables describe the progress and status of each engagement type based on the plans identified in the 2011-2012 annex.

Element in previous year's action plan Status
Document the scope and control framework for the goods and services tax (GST) programs Scope has been determined, risks have been assessed, and the control framework has been documented as planned for the GST programs (i.e., GST Rebates, GST Returns, and GST Credits). Design effectiveness testing plans are in place to conduct the assessment as planned in 2013-2014.
Document the scope and control framework for the T1 unapplied taxes/source deduction programs Scope has been determined, risks have been assessed, and the control framework has been documented as planned for the T1 unapplied tax and source deductions. Design effectiveness testing plans are in place to conduct the assessment as planned in 2013-2014.
Document the scope and control framework for the T3 trust income tax Scope has been determined, a preliminary risk assessment has been done, and documentation of the control framework has begun as planned in 2012-2013.
Follow-up testing of activities requiring remediation from previous assessments

The CRA has followed up on all the action plans from the:

  • 2011-2012 agency activities testing as part of ongoing monitoring;
  • T2 design effectiveness assessment and OAG audit report as at November 30, 2008; and
  • T1 design effectiveness assessment and OAG audit report as at November 30, 2010.

Overall results have been positive and approximately 75% of the recommendations made have been implemented.

4.2 Status and action plan for the next fiscal year and subsequent years

The CRA's plan, based on an annual validation of the high-risk processes and controls related to the control assessments required for its agency and administered activities, is shown in the following three tables.

4.2.1 - Agency activities

The CRA rotational ongoing monitoring plan to assess its agency activity controls over the next three years is based on an annual validation of the high-risk controls and related adjustments to the ongoing monitoring plan as required.

Rotational ongoing monitoring plan for the CRA's internal control over financial reporting related to its Agency activities
Operating effectiveness testing rotation
Key control areas 2013-2014 2014-2015 2015-2016
Entity level controls
IT general controls under CRA management
Capital assets
Procurement and vendor master data
Payroll
Budget and projections

Financial close and reporting

4.2.2 - Administered activities assessment not related to the Tax Collection Agreements (TCA)

Assessment elements
Assessment engagements Document framework Design effectiveness testing and remediation Operational effectiveness testing and remediation Ongoing monitoring rotation
Goods and services tax

Completed 2012-2013
(Footnote 1)

2013-2014
(Footnote 2)
2016-2017
(Footnote 3)
Will annually test new, changed, remediated controls. Once each assessment engagement reached the on-going monitoring stage, each tax program will be fully reassessed on a rotational three year basis
Non-resident income tax 2014-2015
(Footnote 3)
2015-2016
(Footnote 3)
To be determined
(Footnote 4)
Will annually test new, changed, remediated controls. Once each assessment engagement reached the on-going monitoring stage, each tax program will be fully reassessed on a rotational three year basis
Excise tax To be determined
(Footnote 4)
To be determined
(Footnote 4)
To be determined
(Footnote 4)
Will annually test new, changed, remediated controls. Once each assessment engagement reached the on-going monitoring stage, each tax program will be fully reassessed on a rotational three year basis
Benefits To be determined
(Footnote 4)
To be determined
(Footnote 4)
To be determined
(Footnote 4)
Will annually test new, changed, remediated controls. Once each assessment engagement reached the on-going monitoring stage, each tax program will be fully reassessed on a rotational three year basis

4.2.3 - Administered activities assessments, which are TCA related and audited by the OAG

For TCA related engagements the CRA performs the readiness testing and submits the results along with a controls assessment report to the OAG who audit them in accordance with Canadian Standard on Assurance Engagements 3416.

Once the audit results are completed and the audit opinion is signed, the report is provided to the federal, provincial, and territorial Ministers of Finance as required under the tax collection agreements. The distribution of this protected report is very limited due to the sensitive nature of its contents.

TCA related control assessment do not go into a regular ongoing monitoring phase because complete re-assessment engagements are required to fully test all control activities to ensure that the selected income tax program is still designed and operating effectively. As such, the timing and frequency of these complete control assessment audits are determined in conjunction with the OAG and will continue to be conducted on a rotational annual basis as long as the tax collection agreements are in place.

The high-level results of these assessments are also used to fulfil the Treasury Board and CRA Internal Financial Control policy requirements, and are included in this annex in the year they are reported.

Assessment elements
Assessment engagements Document framework Design effectiveness testing and remediation Operational effectiveness testing and remediation
T2 corporation income tax Completed 2007-2008
(Footnote 1)
Completed 2008-2009 (CRA)
(Footnote 1)
Completed 2011-2013 (CRA)
(Footnote 1)
Completed 2009-2010 (OAG)
(Footnote 1)
2013-2014 (OAG)
(Footnote 2)
T1 individual income tax Completed 2009-2010
(Footnote 1)

Completed 2010-2011 (CRA)
(Footnote 1)

Completed 2011-2012 (OAG)
(Footnote 1)

2014-2016 (CRA)
(Footnote 3)

2016-2017 (OAG)
(Footnote 3)

T1 unapplied taxes/source deductions Completed 2012-2013
(Footnote 1)
2013-2014 (CRA)
(Footnote 2)
Will be included in the T1 operating effectiveness assessment
(Footnote 3)
2014-2015 (OAG)
(Footnote 3)
T3 trust income tax 2012-2013 to 2013-2014 (CRA)
(Footnote 2)

2014-2015 (CRA)
(Footnote 3)

2015-2016 (OAG)
(Footnote 3)

2016-2017 (CRA)
(Footnote 3)

2017-2018 (OAG)
(Footnote 3)

(Footnote 1) : Assessment completed as scheduled

(Footnote 2) : Assessment progressing as scheduled

(Footnote 3) : Assessment scheduled

(Footnote 4) : Assessment dates to be determined

Page details

Date modified: