BEC 1 Flashcards
What is COSO?
Committee of Sponsoring Organizations. An independent “private sector” initiative initially established in the 1980s to study factors that lead to fraud.
Why did COSO release “Internal Control” - Integrated Framework?
To assist organizations in developiong comprehensive assessments of internal control effectiveness.
How many objectives, components and principles are in the COSO internal controls framework?
3 objectives, 5 components, 17 principles.
Who uses the framework?
Company management and the Board create the framework to obtain an initial understanding of what constitutes an effective system of internal control and to provide insight as to when internal controls are being properly applied within an organization. The framework also provides confidence to external stakeholders that an organization has a system of internal control in place that is conducive to achieving its objectives.
What does an effective system of internal control require of management?
More than the adherence to policies and procedures by managment, the board, and internal auditors. It requires the use of judgement. Not black and white, thus not rules-based.
Define Internal Control
Process that is designed and implemented by an organization’s management, board, and other employees to provide reasonable assurance that the organization will achieve its operating, reporting, and compliance objectives.
What areas does the framework assist an entity’s management and board of directors (internal takeholders)?
- Effectively applying internal controls
- Determining requirements of an effective system of internal controls.
- Allowing judgement and flexibility in its designe and implementation within all operation and functional ares.
- Identifying and analyzing risks, developing responses.
- Eliminating redundant, ineffective, or inefficient controls.
- Extending internal control application beyond organization’s financial reporting.
How does the framework provide value to external stakeholders?
- Understanding of effective internal controls.
- Confidence in management’s management of controls.
- Confidence in Board Oversight.
- Confidence orgnization will achieve objectives and will be capable of identifying, analyzing, and responding to risks.
Name the categories of objectives.
ORC:
- Operating
- Reporting
- Compliance
Name the internal control components.
CRIME:
- Control environment.
- Risk Assessment
- Information and Communication
- Monitoring Activities
- (Existing) Control Activities
Name the basic levels of organizational structure.
Entity level, division, operating unit, and function.
Operational Objectives relate to what? And ensure what?
Relate to effectiveness and efficiency of an entity’s’ operations. Includes financial and operation performance goals as well as ensuring that the assets of the organization are adequately safeguarded againast potential losses.
Reporting Objectives pertain to what?
Pertain to reliability, timeliness, and transparency of an entity’s external and internal financial and nonfinancial reporting as established by regulators, accounting standard setters, or firm’s internal policies.
Compliance Objectives ensure what?
Ensure the entity is adhering to all apllicable laws and regulations (in all countries and states).
What is needed to achieve the three objectives of internal control (ORC)?
CRIME. The five components of internal control.
Name and describe the five compenents of internal control (CRIME).
Control Environment - Tone @ top, ethics.
Risk Assessement - Financial statements misstated, not efficient, breaking law.
Information and Communication - Fair, accurate, complete, timely (FACT).
Monitoring Activities - Effectiveness of controls or report deficiencies.
(Existing) Control Activities - Policies/Procedures to mitigate risks.
What are the principles related to the control environment?
EBOCA (5)
- Committment to ethics and integrity.
- Board Independence and Oversight
- Organizational Structure.
- Committment to competence.
- Accountability
What are the principles related to risk assessment?
SAFR (4)
- Specify objectives
- Identify and analyze risks.
- Consider the potential for fraud.
- Identify and Assess changes.
What are the principles related to information and communcation?
OIE (3)
- Obtain useful information.
- Internally communication information.
- Communicate with external parties.
What are the principles related to monitoring activies?
SOD (2)
- Ongoing and Separate Evaluations.
- Communication of deficiencies.
What are the principles related to (existing) control activities?
CA T P (3)
- Select and develop control activities.
- Select and develop technology control.
- Deployment of policies and procedures.
What are the general requirements of effective internal control?
Effective system of internal control provides “reasonable” assurance that the entity’s objecttives will be achieved.
What does an organization want all five compenents and 17 principles that are relevant to be?
Present and functioning. Also, that all five components operate together as an integrated system in order to reduce risk that an entity will not ahieve its objectvies.
Define present (design).
Compenents and relevant principles are included in teh design and implementation of the internal control system.