COSO Flashcards

1
Q

ORC - Three categories of objectives on COSO Framework

A

O - Operations Objectives
R - Reporting Objectives
C - Compliance Objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

CRIME - Internal Control Components

A
C - Control Environment
R - Risk Assessment
I - Information and Technology
M - Monitoring Activities
E - Existing Control Activities
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

EBOCA - Principles of Control Environment

A
E - Commitment to Ethical Values and Integrity
B - Board independence and oversight
O - Organizational structure
C - Commitment to Competence
A - Accountability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

SAFR - Principles of Risk Assessment

A

S - Specify objectives
A - Identify and Assess changes
F - Consider the potential for Fraud
R - Identify and analyze Risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

OIE - Information and Communication Principles

A

O - Obtain and use information
I - Internally communicate information
E - Communicate with External Parties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SO D - Monitoring Activities Principles

A

SO - Separate and/or Ongoing Evaluations

D - Communications of Deficiencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

CA T P - Existing Control Environment Principles

A

CA - Select and develop Control A ctivities
T - Select and develop Technology controls
P - Deploy through Policies and P rocedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

ARTS - Help respond to risk

A

A - Avoid (high frequency, high severity)
R - Reduce (high frequency, low severity)
T - Transfer (low frequency, high severity) {Share}
S - Self-Insure (low frequency, low severity) {Accept}

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

COPS - Steps to compile and document the internal control assessment

A

O - Overall Assessment - supported by complement evaluations
C - Component Evaluation - supported by principal evaluations
P - Principal Evaluation - The source for isolating and defining internal control deficiencies
S - Summary of Internal Control Deficiencies (if any) - Summarized and impact the overall assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

CPER - Develop value - make it CPER

A

C - Value Creation
P - Value Preservation
E - Value Erosion
R - Value Realization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

CCPIS - To Manage risk and create value

A

C - Culture
C - Capabilities (Competitive Advantage)
P - Practices
IS - Integration With Strategy-Setting and Performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

GOPRO - Components of Enterprise Risk Management

A
G - Governance and Culture
O - Strategy and Objective Setting
P - Performance
R - Review and Revision
O - Information, Communication, and Reporting (Ongoing)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

DOVES - Governance and Culture Principles

A

D - Defines Desired culture
O - Exercises board Oversight
V - Demonstrates commitment to core Value (tone at the top)
E - Attracts, developes, and retains capable individuals (Employees)
S - Establishes operating Structure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SOAR - Strategy and Objective Setting Principles

A

S - Evaluates alternative Strategies
O - Formulates business Objectives
A - Analyze business context
R - Defines Risk appetite

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

VAPIR - Performance Principles of COSO enterprise risk management

A
V - Develops portfolio View
A - Assesses severity risk
P - Prioritizes risk
I - Identifies risk (events)
R - Implements Risk Responses
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SIR - Review and Revision Principles

A

S - Assesses Substantial change
I - Pursues Improvement in Enterprise Risk Management
R - Reviews risk and performance

17
Q

TIP - Information, Communication and Reporting (Ongoing) Principles

A

T - Leverages information and Technology
I - Communicates risk Information
P - Reports on risk, culture, and performance