Corporate Governance & Financial Risk Management Flashcards
What is internal control?
Process designed & implemented to provide reasonable assurance that the organization will achieve operating, reporting, & compliance objectives
ORC - internal control objectives
Operating
Reporting
Compliance
CRIME - internal control components
Control environment
Risk assessment
Control activities
Information & communication
Monitoring activities
What are operations objectives?
Relate to effectiveness & efficiency of operations, includes financial & operational performance goals & safeguarding assets
What are reporting objectives?
Pertain to reliability, timeliness, transparency of external & internal financial and nonfinancial reporting
What are compliance objectives?
To ensure entity is adhering to laws & regulations
EBOCA - control environment
Commitment to ethics & integrity
Board independence & oversight
Organizational structure
Commitment to competence
Accountability
What is the control environment?
Processes, structures, & standards providing foundation to establish internal control, tone at the top
What is risk assessment?
Entity’s identification & analysis of risk to achievement of its objectives
SAFR - risk assessment
Specify objectives
Identify & analyze risks
Consider potential for fraud
Identify & assess changes
What is information & communication?
Support identification, capture, & exchange of information in a timely manner
OIE - information & communication
Obtain & use information
Internally communicate information
Communicate with external parties
What is monitoring?
Assessing quality of internal control performance over time by assessing design & operation of controls & taking corrective actions
SOD - monitoring activities
Ongoing and/or separate evaluations
Communication of deficiencies
What are control activities?
Set forth by entity’s policies & procedures, may be detective or protective
CATP - control activities
Select & develop control activities
Select & develop technology controls
Deployment of policies & procedures
What are the two general requirements for effective internal control?
Components & principles are present & functioning
What does present mean for components & principles?
Included in design & implementation of internal controls
What does functioning mean for components & principles?
Operating as designed in internal control system
What is a major deficiency?
Material internal control deficiency or combination of deficiencies that reduces likelihood that an organization can achieve its objectives
COPS - COSO framework document
Overall assessment
Component evaluation
Principal evaluation
Summary of internal control deficiencies
What is risk?
Possibility events will occur & affect achievement of strategy & business objectives
CPER - develop value
Creation
Preservation
Erosion
Realization
CCPIS - ERM
Culture
Capabilities
Practices
Integration with strategy-setting & performance
Managing risk linked to value
What is risk inventory?
All risk that could impact an entity
What is ERM reasonable expectation?
Amount of risk having strategy & business objectives appropriate for an entity
What is business context?
Trends, events, relationships, & other factors that may influence, clarify, or change entity’s current & future strategy & business objectives
What is risk capacity?
Maximum risk entity is able to absorb in pursuit of strategy & business objectives
What is risk profile?
Composite view of risk assumed at a particular level that positions management to consider types, severity, & interdependence of risk
What is portfolio view?
Compositive view or risk entity faces which positions management to consider types, severity, & interdependence of risk
What is organizational sustainability?
Ability of an entity to withstand impact of large-scale events
What is performance management?
Measurement of efforts to achieve or exceed strategy & business objectives
GO PRO - enterprise management framework
Governance & culture
Strategy & objective-setting
Performance
Review & revision
Information, communication, & reporting (ongoing information gathering and feedback)
DOVES - governance & culture
Defines desired culture
Exercises board oversight
Demonstrates commitment to core values
Attracts, develops, & retains capable individuals (employees)
Establishes operating structure
SOAR - strategy & objective-setting
Evaluate alternative strategies
Formulates business objectives
Analyzes business context
Defines risk appetite