![]() |
I. Policy
Financial management decisions affect every aspect of the University, but such decisions can only be as good as the data on which they are based. Consequently, each unit must establish and implement a system to ensure data integrity. This system must provide reasonable assurance that transactions are in accordance with management's authorization and are recorded in the University records in an accurate and timely manner.
Each unit head shall be responsible for developing a system to ensure data integrity that adheres to the following principles and responsibilities.
II. Principles
Principle 1: An adequate data control system including independent checks and balances must exist within and between operating units.
Principle 2: All employees engaged in financial management activities are responsible for ensuring that adequate data controls are being employed. If they are not, all employees must take an active role in developing and implementing appropriate corrective actions.
Principle 3: Each unit must ensure that recorded assets match actual existing assets. A mechanism must be in place to spot discrepancies and to ensure that corrective actions are taken.
Principle 4: Each unit must ensure that all financial transactions are recorded correctly. Correct transactions must:
- reflect the actual values involved,
- contain sufficient detail for proper identification and classification,
- be posted on a timely basis in the proper accounting period,
- be stored securely,
- be readily retrievable for inquiry or reporting, and
- be safeguarded against improper alteration.
Principle 5: All systems that affect or are used to report financial data must be secure, reliable, responsive and accessible. These systems must be designed, documented, and maintained according to accepted development and implementation standards. They should be built upon sound data models and employ technology that allows data to be shared appropriately.
Principle 6: All financial systems should meet the users' needs. In addition, all interfaces affecting any financial system must contain controls to ensure the data is synchronized and reconciled.
Principle 7: All technical networks, including electronic mail, through which departmental users access University financial data must be reliable, stable and secure.
III. Responsibilities
A system of data integrity includes:
- recording transactions into the Financial System directly or through an interfacing system,
- authorizing transactions through preapproval or post audit review,
- receiving or disbursing funds,
- reconciling financial system transactions, and
- recording corrections or adjustments.
If insufficient personnel within the unit requires that one person perform all of these functions, the unit must assign a second person to review the work for accuracy, timeliness and honesty.
- All transactions must be verified for:
- amount,
- account classification (FAU),
- description, and
- proper accounting period.
- All reconciliations must be performed in a timely manner.
- Employees are adequately trained in preparing and processing financial transactions,
- Transactions and balances that exceed control thresholds or counter policies, regulations or laws are questioned and thoroughly analyzed, with corrections or adjustments fully documented and processed in a timely manner,
- Locally generated reports do not distort or misrepresent the source data used to prepare them. In particular,
- one must be able to reconcile reports back to the original data, as it appears in the Financial System, and
- any adjustments made in preparing a local report must be documented and recorded immediately, where appropriate in the Financial System,
- All unit assets are properly described and accounted for in the Financial System or other "official books of record", and
- Actual physical assets are compared to recorded assets in the Financial System and discrepancies are resolved in a timely manner.
For further information, contact Internal Audit
A reliable financial computing environment includes the following components:
- Project Initiation.
This includes:
- gaining appropriate administrative approval,
- defining the nature, scope, benefits, risks, priorities, timing and most likely development and implementation method for the project,
- identifying areas and individuals affected by the project,
- anticipating staffing, equipment and other requirements,
- determining funding requirements and funding sources for the project life cycle and ongoing maintenance, and
- naming a project coordinator, if the complexity of the project warrants it.
- Analysis and Design.
This includes:
- identifying the functional, informational and technical requirements of the proposed system, and
- using data models or similar tools to ensure that the systems will be developed separate from the data, data redundancy will be minimized, and overall referential integrity will be satisfied.
- Acquiring Hardware and Software.
This involves a written proposal when significant hardware and software purchases are being requested. Such proposals should always cross reference specific projects defined in the long-term administrative computing plan.
- Implementation.
This includes:
- developing a detailed project plan that identifies all tasks that need to be completed, who will do them and when they will be done,
- ensuring that all aspects of the project will adhere to central data administrative standards, and
- testing to ensure that the new system interfaces smoothly with other systems, and that audits, controls and checkpoints function properly.
- Post Audit.
Once operational, the unit responsible for the new system must ensure that the agreed to level of service provided to the users is being satisfied and that proper maintenance, backup and recovery systems are in place.
- Availability. The system must be available when the users need it,
- Data Access. The system must provide access to data in ways that are timely, compliment work flow processes, and are retained as specified in University Records Disposition Schedules Manual,
- Performance. The system must meet users' performance needs,
- Support. Users must receive training and documentation and have individuals to contact to help resolve problems,
- Maintenance. The system must provide reliable service, and should be upgraded as technology or user needs change, and
- Security. Access to the system must be protected at a minimum by user IDs and passwords. The system must also be protected from theft and vandalism.
These include:
- Connectivity.
If several campus units use the new system, it should operate through the campus backbone network. It should also support TCP/IP, the primary communication protocol for UCLA and UC computing.
- Hardware.
Hardware purchases should be evaluated with several criteria in mind, including:
- connectivity,
- performance,
- reliability,
- ease of maintenance,
- efficiency,
- availability of software,
- vendor support,
- cost.
- Software.
Software purchases should also be evaluated with several criteria in mind:
- The choice of operating system should consider such issues as connectivity,
consistency of user interfaces, vendor support, and ease of application interfaces.
- UCLA administrative applications should be based on relational databases, with SQL the standard database access and manipulation language.
The selection of a programming language should depend upon code availability, performance, staff skills, development time, interoperability, long-term vendor support, and how well the programs will work with existing programs.
- User Interface.
Administrative applications should provide a standard, consistent and friendly user interface incorporating screen appearance, navigation procedures, menu selections, function keys, colors, messages, on-line help and terminology.
For further information, contact Administrative Information Services