B1: Corporate Governance - Internal Control (COSO) Flashcards

1
Q

What is COSO?

A

The Committee on Sponsoring Organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Basic information of COSO?

A
  1. Private sector initiative
  2. Five major internal control components (CRIME)
  3. Used by management, directors, and external stockholders
  4. Principles-based - requires judgement
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is internal control?

A

A process that is designed and implemented by an organization’s management to provide reasonable assurance that it will achieve its compliance, operating, and reporting objectives.
* Best practice: in 1992 COSO issued Internal Control - Integrated Framework.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is COSO internal control framework objectives? (Memorize!!!) - Compare with ERM enterprise objectives

A

The “ORC”

  1. Operations objectives - effectiveness and efficiency
  2. Reporting objectives - focus of COSO, accurate and timey
  3. Compliance objectives - laws and regulations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the five components of internal control? (Memorize!!!)

A

The “CRIME”

  1. Control environment
  2. Risk assessment
  3. Information and communication systems
  4. Monitoring
  5. Existing control activities
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does the control environment refer to? (Memorize!!!)

A

Refers to “tone at the top” - “EBOCA”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is EBOCA? (Memorize!!!)

A

Internal control component - control environment (C of CRIME)
E: ethics (integrity)
B: board independence (and oversight)
O: organizational structure
C: commitment to competence - hire, develop ann retain competent employees
A: accountability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is EAR? (Memorize!!!)

A

Internal control component - risk assessment (R of CRIME)
E: event identification
A: assess risks
R: respond to risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is FACT? (Memorize!!!)

A
Internal control component - information and communication (I of CRIME)
F: fair
A: accurate
C: complete
T: timely
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What do monitoring activities refer to? (Memorize!!!)

A
  1. Ongoing and/or separate evaluation - frequency of testing is dictated by risk
  2. Communication of deficiencies
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What do (existing) control activities refer to? (Memorize!!!)

A
  1. To mitigate risk
  2. Detect or prevent
  3. Segregation of duties
  4. IT controls
  5. Put policies into action
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does the COSO Cube include?

A
  1. Columns: “ORC”
  2. Rows: “CRIME”
  3. Third dimension: Entity level - Division - Operating unit - Function
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does the effective internal control mean? - The general requirements

A
  1. framework provides reasonable assurance
  2. relevant to present: included in design
  3. relevant to functioning: operating as designed
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does the effective internal control mean? - The specific requirements

A

The “ORC”: achieve the operational, reporting and compliance objectives
* The framework requires judgement (principles-based).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does “major deficiency” mean in COSO internal control?

A

Implies ineffective internal control:

  1. reduces the likelihood that an organization can achieve the objectives
  2. may not conclude that the entity meets the requirements of effective internal control
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are internal control limitations? - No guarantee

A

e.g. Errors; Human failures; Beyond-scope events; Collusion; Management override