Corporate Governance & Financial Risk Management Flashcards
What is internal control?
Process designed & implemented to provide reasonable assurance that the organization will achieve operating, reporting, & compliance objectives
ORC - internal control objectives
Operating
Reporting
Compliance
CRIME - internal control components
Control environment
Risk assessment
Control activities
Information & communication
Monitoring activities
What are operations objectives?
Relate to effectiveness & efficiency of operations, includes financial & operational performance goals & safeguarding assets
What are reporting objectives?
Pertain to reliability, timeliness, transparency of external & internal financial and nonfinancial reporting
What are compliance objectives?
To ensure entity is adhering to laws & regulations
EBOCA - control environment
Commitment to ethics & integrity
Board independence & oversight
Organizational structure
Commitment to competence
Accountability
What is the control environment?
Processes, structures, & standards providing foundation to establish internal control, tone at the top
What is risk assessment?
Entity’s identification & analysis of risk to achievement of its objectives
SAFR - risk assessment
Specify objectives
Identify & analyze risks
Consider potential for fraud
Identify & assess changes
What is information & communication?
Support identification, capture, & exchange of information in a timely manner
OIE - information & communication
Obtain & use information
Internally communicate information
Communicate with external parties
What is monitoring?
Assessing quality of internal control performance over time by assessing design & operation of controls & taking corrective actions
SOD - monitoring activities
Ongoing and/or separate evaluations
Communication of deficiencies
What are control activities?
Set forth by entity’s policies & procedures, may be detective or protective
CATP - control activities
Select & develop control activities
Select & develop technology controls
Deployment of policies & procedures
What are the two general requirements for effective internal control?
Components & principles are present & functioning
What does present mean for components & principles?
Included in design & implementation of internal controls
What does functioning mean for components & principles?
Operating as designed in internal control system
What is a major deficiency?
Material internal control deficiency or combination of deficiencies that reduces likelihood that an organization can achieve its objectives
COPS - COSO framework document
Overall assessment
Component evaluation
Principal evaluation
Summary of internal control deficiencies
What is risk?
Possibility events will occur & affect achievement of strategy & business objectives
CPER - develop value
Creation
Preservation
Erosion
Realization
CCPIS - ERM
Culture
Capabilities
Practices
Integration with strategy-setting & performance
Managing risk linked to value