Anagrams Flashcards

1
Q

COSO Objectives (ORC)

A

O-operating objectives (effectiveness and efficiency)
R-reporting objectives (reliability, timeliness, transparency)
C-compliance objectives (adhering to laws and regulations)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

COSO Components

A
  1. Control Environment
  2. Risk Assessment
  3. Control Activities
  4. Information and Communication
  5. Monitoring
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Control Environment (EBOCA)

A

Ethics
Board independence and oversight
Org. structure
Commitment to competence
Accountability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Risk Assesment (SAFR)

A

Specify objectives
Assess and identify changes
Fraud potential
Risk (analyzed)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Information and Communication (OIE)

A

Obtain and use information
Internally communicate information
External parties communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Monitoring (So D)

A

Separate/ongoing evaluations
Deficiencies communicated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Existing Control Activities (CA T P)

A

Control Activities
Technology controls
Policies and procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

5 Components of ERM (GO PRO)

A

G-governance and culture
O-objective setting/strategy
P-performance
R-review and revision
O-ongoing information, communication, and reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Governance & Culture (“DOVES”)

A

D-desired culture
O-oversight from board
V-values commitment
E-employees (capable)
S-structure established

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Objective setting/strategy (SOAR)

A

S-strategies (alternative)
O-objectives (business)
A-analyzes business context
R-defines risk appetite

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Performance (VAPIR)

A

V-view (portfolio)
A-assesses severity of risk
P-prioritizes risk
I-identifies risks (events)
R-responses to risk implemented

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Review and revision (SIR)

A

S-substantial change
I-improvement in ERM
R-reviews risk and performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Ongoing information, communication, reporting (TIP)

A

T-technology and information leveraged
I-information risk communicated
P-performance and risk culture reports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly