Chapter 01 - Internal Control FW Flashcards
What is IC - 3 objective
designed and implemented by an organization BOD and other employees to provide reasonable assurance that the organization will achieve
1. Operation
2. Reporting
3. Compliance
Five Internal Control Componets
C - Control Environment
R- Risk Assessment
I - Information and Communication
M - Monitoring Activities
E - Control Activities
Control Environment
Processes, structures, standards, foundations. tone at the top
1. Commitment to Ethics and integrity
2. Board Independence and oversight
3. Organizational structure
4. Commitment to Competence
5. Accountability
Risk Assessment
- Specify Objectives - identify and asses risk
- Identify and Analyze Risk - how the risks should be managed
- Consider Potential for Fraud - pressures - opportunities, attitude, realization
- Identify an assess changes: assessing changes in external environment, business model and leadership
Information and Communication
Obtain and use information
Internally Communicate Information - the organization communicates information necessary to support IC objectives and responsibilities.
External Communication
Monitoring Activites
Ongoing and Or separate evaluation - whether the components of internal control are present and functioning
Communicate defiencies.
Control ( Existing) Activities
Entities policy and procedures, to mitigate risk
1. Develop Control Activities - mitigation of risk
2. Technology Control - technology to support achievement and objective
3.Policy and Procedures - put policy into action
Internal Control Limitations
does not prevent bad decision or eliminate all external events that may prevent the achievement of the entitys operational goal.
human failure
faulty or biased judgement
external events
collusion
management over ride
ERM
Governance and Culture
Strategy and Objective
Performance
Review and Revision
Information and Communication and Rerporting
Governance and Culture
D - Desire Culture
O - Board Oversight
V - Value - tone at top
E - Employee - attracts develops retains
S - Establishes operating structure
Strategy and Objective
S - Alternative strategy - more equity less debt
O - Business Objective - why do we exist - business mission
A - Analyze Business Context -
R - Define Risk Appetite - Goal based how critical - ranges
Performance
V - Portfolio view
A- Assessment of severity of risk
P- Prioritize Risk
I - Identify risk events.
R - Implement risk response
Review revision
S- Substantial change
I - Improvement in ERM
R - Review risk and performance
Information and Communication and Reporting
T - Leverage information and technology
I - Communicate risk information
P - Report on risk, culture and performance
Risk Assessment - Inherent - VAPIR
in the absence of any direct or focused action by management to alter severity