Corporate Governance and Financial Risk Mgmt Flashcards
What was the initial purpose of the COSO framework?
It was established in the mid 1980s to study the factors that lead to fraudulent financial reporting
Who are the 5 main sponsor of COSO?
AICPA IMA IIA AAA FEI (Financial exec Institute)
Who primarily uses the framework?
Mainly used by company management and its Board of directors.
Name the 3 categories of objectives within the framework? (ORC)
- Operations objective - related to effectiveness and efficiency of an entity’s operations
- Reporting objective - pertain to reliability of entity’s reports
- Compliance objective - adherence to all applicable laws and regulations
What are the 5 components of internal control? (CRIME)
- Control environment
- Risk assessment
- Information processing and communication
- Monitoring
- Existing control activities
Name 5 principal related to the control environment? (EBOCA)
- Commitment to ethics and integrity
- Board independence and oversight
- Organization structure
- Commitment to competence
- Accountability
Name 4 principal related to the risk assessment? (SAFR)
- Specify objectives - identify and assess risks
- Identify and Assess changes
- Fraud potential
- Identify and analyze Risk
Name 3 principal related to the information and communication? “OIE”
- Obtain and use information
- Internally communicate information
- Communicate with External parties
Name 2 principal related to the monitoring component? (SO D)
- Separate and ongoing evaluations of IC (are they present and functioning)
- Communication of deficiencies
Name 3 principal related to the (existing) control activities component? CA T P)
- Select and develop control activities
- Select and develop tech controls
- Deployment of policies and procedures
What is considered a ‘major deficiency’ by the COSO framework?
A major deficiency represents a material internal control deficiency, or combination of deficiencies, that significantly reduces the likelihood that an organization can achieve its objectives
What are the 3 risk preferences?
Risk-indifferent
Risk-averse
Risk-seeking
What type of risk preference describes most managers and why?
Risk-averse. An increase in the level of risk results in an increase in managements required rate of return. Greater the risk = more return is needed.
Describe interest rate risk (yield risk)?
Represents the exposure of the owner of an instrument to fluctuations in the value of the instrument in response to changes in interest rate.
Describe Market/Systematic/Nondiversifiable risk
Market risk is the exposure of a security or firm to fluctuations in value as a result of operating within an economy. Nondiversifiable risks can be attributed to things like war, inflation. international affairs, and political events.