Chapter 6 - Internal Controls in Financial Statement Audits Flashcards
Management has the responsibility to design and maintain controls that provide reasonable assurance that:
- The entity’s assets and records are properly safeguarded.
- The information system generates reliable information for decision making
The auditor has the responsibility to:
Obtain an understanding of the entity’s internal control
Assess control risk
(ESSAY QUESTION) What is Coso’s Internal Control - Integrated Framework?
A system of internal control is designed and carried out by an entity’s board of directors, management, and other personnel to provide reasonable assurance about the objectives in three categories.
(ESSAY QUESTION) What are the 3 Objectives of Coso’s Internal Control?
- Reliability, timeliness, and transparency of internal and external Financial and Nonfinancial Reporting
- Effectiveness and efficiency of operations, including safeguarding of assets
- Compliance with applicable laws and regulations
Which Controls are Relevant to the Audit?
Generally, internal controls that contribute to the Reliability, Timeliness, and Transparency of external financial reporting are the most relevant.
ESSAY QUESTION - What are the Components of Internal Control (5)
Control Environment
Entity’s Risk Assessment Process
Control Activities
Information and Communication
Monitoring Activities
!! Components of Internal Control: Describe the Control Environment !!
The set of standards, processes, and structures that provide the basis for carrying out internal controls across the organization.
!! Components of Internal Control: Risk Assessment Process !!
A dynamic and iterative process for identifying and analyzing risks to achieving the entity’s objectives, thereby forming a basis for determining how risks should be managed.
!! Components of Internal Control: Control Activities !!
The actions established by policies and procedures to help ensure management directives to mitigate risks to the achievement of objectives are carried out.
!! Components of Internal Control: Information and Communication !!
Info is necessary to carry out internal control responsibilities. Communication occurs both internally and externally and provides the organization with the info needed.
!! Components of Internal Control: Monitoring of Controls !!
Evaluations, whether ongoing or separate, to ascertain whether the five components of internal control, including controls within each component, are present and functioning.
! What are the Five Principles of Control Environment? !
- The org demonstrates a commitment to integrity and ethical values.
- The board demonstrates independence from management and exercises oversight of internal control
- Management establishes structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.
- Org demonstrates a commitment to attract, develop, and retain competent individuals.
- Org holds individuals accountable for their internal control responsibilities.
! What are the Four Principles of the Risk Assessment Process? !
- Org specifies objectives with sufficient clarity to enable the identification and assessment of risks.
- Org identifies and analyzes risks to internal control and determines how the risks should be managed.
- Org considers the potential for fraud
- Org identifies and assesses changes that could impact the internal control system
! What are the Three Principles of Control Activities? !
- Org selects and develops control activities that mitigate risk. (Performance reviews, physical controls, separation of duties, info processing controls)
- Org selects and develops general control activities over technology.
- Org deploys control activities through policies that establish what is expected and procedures that put policies into action.
! What are the Three Principles of Information and Communication for Internal Control? !
- Org obtains or generates and uses relevant, quality info to support internal control.
- Org internally communicates info necessary to support the functioning of internal control.
- Org communicates with external parties regarding matters that affect internal control.