17 Principles of Internal Control Flashcards
What is the most important principle to internal control??
Control Environment- The organization demonstrates a commitment to INTEGRITY AND ETHICAL VALUES.
Set and demonstrates (through actions) an ethical “tone at the top”
What is the Board of Directors responsibility with control environment?
They are concerned with big risk and big issues. They should have oversight. There should be independence between them and management. They should have expertise in various areas of the business.
What role does competence play in control environment?
the organization should demonstrate a commitment to attract, develop, and retain competent individuals including:
Assessing competencies, creating development plans to achieve needed skills, and addressing deficiencies through training, hiring, or outsourcing.
Planning and preparing for turnover and succession
What role does accountability play in control environment?
The organization holds individuals accountable for their internal control responsibilities including:
- Establishing and evaluating performance measures, incentives, rewards and disciplinary actions for individuals.
- NOTE: Excessive performance pressures that result in unethical things is not good
What role does objectives play in risk assessment?
Organization have sufficient clarity to enable the identification of risks that threaten achievement of objectives including:
- Precision of risk tolerance levels, can we quantify the risk and can we add a range? (What is the likely that we will go bankrupt if we don’t apply a certain technology?)
What role does assessment play in the risk assessment?
The organization identifies risks to achievement of objectives and analyzes risk to guide risk management strategy including
- Engage appropriate management in risk assessment
- Consider and include entity, subsidiary, division, operating unit, and functional levels
- Analyze internal and external factors
- Develop risk responses
What role does fraud play in risk assessment?
Organization considers potential fraud in assessing risks to achieving objectives including:
- Consider fraud risk factors and threats
- Assess potential fraud influence of incentive and pressures
- Assess fraud opportunities
- Assess attitudes and potential rationalizations that might justify fraud
What role does change management play in risk assessment?
The organization identifies and assesses changes in external environment
What role does risk reduction play in control activities?
Control activities reduce the risks to the achievement of objectives to an acceptable level including:
- Integrate control with risk assessment
- Risk reduction analyzes determine business processes to target control
- Consider influence of environment, complexity, and nature and scope of operations, on risk reduction and control
What role does technology control play in control activities?
Management has to understanding the technology.
Has to understand dependencies of business processes, automated controls, and technology general controls
What role does policies play in control activities?
The organization control activities inform policies that establish stakeholder expectations. Establish procedures to insure implementation.
What role does quality play in information and communication?
Relevant, high-quality information supports internal control processes including organization processes that:
- Identify information required to support internal control processes
- Capture internal and external sources of data
- Transform data
What role does internal communication play in information and communication?
Organizational processes communicate required information to enable all personnel to understand and execute their internal control responsibilities.
What role does external communication play in information and communication?
- Board of directors receive relevant information
- External communication methods are sensitive to the timing, audience, and nature of the communication and to legal, regulatory and fiduciary requirements.
What role both ongoing and periodic monitoring play in internal control?
- Benchmarking and providing feedback
- Consideration of environmental and business changes, knowledge of evaluation personnel and risk assessments