COSO Flashcards
ORC - Three categories of objectives on COSO Framework
O - Operations Objectives
R - Reporting Objectives
C - Compliance Objectives
CRIME - Internal Control Components
C - Control Environment R - Risk Assessment I - Information and Technology M - Monitoring Activities E - Existing Control Activities
EBOCA - Principles of Control Environment
E - Commitment to Ethical Values and Integrity B - Board independence and oversight O - Organizational structure C - Commitment to Competence A - Accountability
SAFR - Principles of Risk Assessment
S - Specify objectives
A - Identify and Assess changes
F - Consider the potential for Fraud
R - Identify and analyze Risks
OIE - Information and Communication Principles
O - Obtain and use information
I - Internally communicate information
E - Communicate with External Parties
SO D - Monitoring Activities Principles
SO - Separate and/or Ongoing Evaluations
D - Communications of Deficiencies
CA T P - Existing Control Environment Principles
CA - Select and develop Control A ctivities
T - Select and develop Technology controls
P - Deploy through Policies and P rocedures
ARTS - Help respond to risk
A - Avoid (high frequency, high severity)
R - Reduce (high frequency, low severity)
T - Transfer (low frequency, high severity) {Share}
S - Self-Insure (low frequency, low severity) {Accept}
COPS - Steps to compile and document the internal control assessment
O - Overall Assessment - supported by complement evaluations
C - Component Evaluation - supported by principal evaluations
P - Principal Evaluation - The source for isolating and defining internal control deficiencies
S - Summary of Internal Control Deficiencies (if any) - Summarized and impact the overall assessment
CPER - Develop value - make it CPER
C - Value Creation
P - Value Preservation
E - Value Erosion
R - Value Realization
CCPIS - To Manage risk and create value
C - Culture
C - Capabilities (Competitive Advantage)
P - Practices
IS - Integration With Strategy-Setting and Performance
GOPRO - Components of Enterprise Risk Management
G - Governance and Culture O - Strategy and Objective Setting P - Performance R - Review and Revision O - Information, Communication, and Reporting (Ongoing)
DOVES - Governance and Culture Principles
D - Defines Desired culture
O - Exercises board Oversight
V - Demonstrates commitment to core Value (tone at the top)
E - Attracts, developes, and retains capable individuals (Employees)
S - Establishes operating Structure
SOAR - Strategy and Objective Setting Principles
S - Evaluates alternative Strategies
O - Formulates business Objectives
A - Analyze business context
R - Defines Risk appetite
VAPIR - Performance Principles of COSO enterprise risk management
V - Develops portfolio View A - Assesses severity risk P - Prioritizes risk I - Identifies risk (events) R - Implements Risk Responses