B1 - Corporate Governance & Financial Risk Management Flashcards
How many objectives are in the COSO Framework?
3
What are the 3 objects in the COSO Framework?
ORC
How many components are in the COSO Framework?
5
What are the components in the COSO Framework?
CRIME
“O” in ORC
Operations
“R” in ORC
Reporting
“C” in ORC
Compliance
“C” in CRIME
Control environment
“R” in CRIME
Risk Management
“I” in CRIME
Info and communication systems
“M” in CRIME
Monitoring
“E” in CRIME
Existing controls
Who is responsible for the following:
-effectively applying IC
-Determining requirements for IC
Management & Board
Which of the components of ORC does this apply to:
Effectiveness and efficiency of the company’s operations and ensuring safeguards of the assets
Operations
Which of the components of ORC does this apply to:
Reliability, timeliness, and transparency of an entity’s external and internal financial/nonfinancial reporting
Reporting
Which of the components of ORC does this apply to:
Entity is adhering to applicable laws and regulations
Compliance
Control Environment Principle
EBOCA
“E” in EBOCA
Ethics
“B” in EBOCA
Board independence
“O” in EBOCA
Organizational structure
“C” in EBOCA
Commitment to competence
“A” in EBOCA
Accountability
Risk Assessment principle
SAFR
“S” in SAFR
Specify objectives
“A” in SAFR
Assess change
“F” in SAFR
Fraud risk
“R” in SAFR
Risk analysis
Information and communication principle
OIE
O in OIE
Obtain and use info
I in OIE
Internally communicate
E in OIE
Externally communicate
Who should be internally communicated to?
Internal auditors & committee
Who should be externally communicated to?
Management, CPA firm, consultants
Monitoring Activities principle
SOD
S in SOD
Separate evaluations of IC
O in SOD
Ongoing evaluations of IC
D in SOD
Deficiencies are communicated
Existing Control Activities principles
CAT P
CA in CAT P
Control activities are developed
T in CAT P
Tech controls
P in CAT P
Policies and procedures
Major deficiency
Material IC deficiency
What is the objective of applying the COSO framework?
Reduce assessed risk to acceptable levels
COSO Framework documentation pnuemonic
COPS
C in COPS
Component evaluation
O in COPS
Overall assessment
P in COPS
Principal evaluations
S in COPS
Summary of IC deficiencies
What is the objective of ERM
Strategy to balance risk and return
Risk
Possibility events will occur and affect the achievement of strategy and business objectives
Value creation
Benefits exceed the cost of resources used