Internal Controls

Purpose

The purpose of this policy is to establish strong internal controls that help protect Maryland Global Initiatives Corporation (MGIC) assets from fraud, loss, and errors.

Background

MGIC policies and procedures are designed to maintain strong internal controls. These include effective segregation of duties, bank account and confidential data access controls, preference to electronic forms of payment through international finance systems, signatory and execution authorities, and custodial care of physical assets.

UMB personnel and affiliates (including MGIC Personnel and constituent institutions of the University System of Maryland, referred to in these policies as Affiliate Entities) must comply with internal controls and stewardship expectations that protect resources managed by MGIC, as part of the Ethics and Conduct Policy. Violations shall be subject to disciplinary action, up to and including termination of employment.

The International Operations (IO) division of UMB’s Administration & Finance Department administers MGIC and executes MGIC activity on behalf of the MGIC Board of Directors.

Policy Statement

Fundamental Standards of Internal Control

  1. MGIC Financial Policies and Procedures must adhere to these fundamental standards of internal control:
    • Authorization and approval levels:
      • Responsibility for authorizing and recording transactions are clearly delegated.
    • Segregation of duties:
      • Access to monetary and identified physical assets is limited to select personnel.
      • The person who has access to MGIC monetary and identified physical assets does not also conduct inventory or financial spot-check audits.
      • Each transaction is divided into component tasks and completed by different personnel.
      • The person who initiates a purchase requisition does not approve it.
      • The person who prepares payments does not approve purchases.
      • The person sourcing, approving, or disbursing funds does not validate their own actions.
  2. Any procurement or payment of goods or services, and other legally binding commitment made through MGIC on behalf of a Requesting Unit of UMB or a UMB Affiliate Entity, must be approved and executed by UMB personnel vested with the appropriate level of authority, as defined in MGIC’s Corporate Governance policy and any prevailing Delegation of Signatory Approval and Execution Authority, in accordance with the MGIC Table of Authorities. See MGIC policy on Signature Authorities for additional policy details.
  3. MGIC must maintain strong internal controls for banking, including:
    • Two approvals for every transaction from an MGIC bank account, and at least one designated approver from a money transfer service account unless the money transfer service offers dual-approval functionality.
    • Assign access and permission levels to online banking and vendor payment portals only as needed.
    • Audit the list of authorized users on a regular basis.
    • Ensure each person who is assigned access has a separate user profile – with unique login and password – to help enforce segregation of duties.
    • Restrict access to the MGIC Vendor Files to IO personnel responsible for procurement and finance functions.
    • Monitor adherence to the signature limits specified in the Table of Authorities.
    • Segregate the duties of preparing payments from the duty of releasing those payments.
    • Segregate the duty of reconciling the bank accounts from the duties of authorizing disbursements.
    • Reconcile all bank accounts on a monthly basis and submit the signed reconciliation statements and bank statements with the MGIC monthly financial report. (See MGIC Financial Reporting Policy)
    • Submit bank account statements to UMB on a semi-annual basis.
  4. The IO division must carefully control paper checks issued by the MGIC bank:
    • Use sequentially numbered checks for all disbursements.
    • Keep unused, blank checks in a locked location accessible only by personnel who are authorized to prepare checks but do not themselves have signature authority.
    • Prohibit access to the check stock by bank account signatories.
    • Prohibit pre-signing of blank checks.
  5. Only the MGIC Board of Directors has the authority to approve a line of credit for MGIC. See Corporate Governance policy.
  6. The IO division must carefully control the use of any debit or credit cards associated with the MGIC bank:
    • Physical bank cards must be reasonably secured and accessible only to the IO employee assigned to use the cards.
    • Card numbers and security codes must be retained and used exclusively by the IO‑assigned staff and are not stored in a shared drive or Teams site.
    • The assigned card user shall not approve any payment transactions for MGIC bank cards.
    • The assigned card user may process a payment only after receiving the complete payment package approved by the Assistant Vice President (AVP) – IO.
    • All debit and credit card transactions will be reviewed by the IO Finance Manager for verification, ensuring validity and documentation compliance.
    • Credit card statements shall be reviewed and reconciled monthly, with each transaction matched against MGIC payment records, and documented through the system reconciliation process in QuickBooks as part of internal control requirements.
  7. MGIC financial activity currently does not require the use of cash. No personnel should transact MGIC business in cash unless approved as an exception by the MGIC President.

Scope

This policy applies to all UMB personnel and affiliates who administer or use finance and procurement operations through MGIC.

Responsibilities

  1. International Operations Finance staff: Implement Internal Control policy and all required elements. Develop and promote associated procedures and processes for all personnel involved in MGIC financial activity. Maintain strong safeguards for their assigned levels of access to MGIC online banking and tax filing platforms, accounting system, financial records, and physical assets. Monitor policy compliance by all involved personnel, and alert AVP-IO to any discrepancies or need for a policy exception for a specific instance.
  2. International Operations designated personnel: Serve as secondary online approver of MGIC bank account, and primary approver of MGIC money transfer account, as delegated in the MGIC Table of Authorities. Safeguard and utilize MGIC bank cards, bank checks, and financial institution account access if assigned these roles. Comply fully with this policy and related MGIC policies and procedures.
  3. Assistant Vice President (AVP) - IO (in their capacity as MGIC VP – Policy & Administration): Serve as MGIC signatory and approval authority, subject to the MGIC Table of Authorities and as delegated by the MGIC President. Serve as Primary Administrator and Online Approver of MGIC bank account. Serve as Primary Administrator of MGIC money transfer account. Oversee IO division compliance with MGIC policies and procedures. (See MGIC Policy on Signature Authorities)
  4. MGIC President: Approve or deny policy exceptions requested under this policy (see MGIC Policy on Policy Exceptions). Serve as MGIC signatory and approval authority and ensure delegations of authority are documented and time-bound.

Procedures

See MGIC Standard Operating Procedures.

Documentation Requirements

  • MGIC monthly financial reports
  • MGIC Vendor Files
  • Banking and other external platform authorized user permissions
  • MGIC Policy Exception Request Form

References

  • MGIC Policy on Corporate Governance
  • MGIC Policy on Ethics and Conduct
  • MGIC Policy on Financial Reporting
  • MGIC Policy on Policy Exceptions
  • MGIC Policy on Signature Authorities
  • MGIC Table of Authorities