COSO Flashcards
Control Activities
Policies and Procedures that ensure that actions are taken to address the risks related to the achievement of management’s objectives
Monitoring
It is necessary to monitor and test the system and its data in order to ensure the ongoing reliability of information.
Information & Communication
The information and communication systems that enable an organization’s people to identify, process and exchange the information needed to manage and control operations.
Risk Assessment
Process of identifying, analyzing and managing the risks involved in achieving the organization’s objectives.
Control Environment
Management’s philosophy toward controls, organizational structure, system of authority and responsibility, personnel practices, policies and procedures.
3 Objectives of Internal Control
- Operations
- Reporting
- Compliance
5 Components of Internal Control
- Control Environment
- Risk Assessment
- Information &
Communication - Monitoring
- Control Activities
Control Environment Principles
- Integrity and Ethical Values
- Board of Directors
- Management
- Competence
- Accountability
Risk Assessment Principles
- Objectives
- Assessment
- Fraud
- Change Management
Control Activities Principles
- Risk Reduction
- Technology Controls
- Policies
Information & Communication Principles
- Quality
- Internal
- External
Monitoring
- Ongoing & Periodic
2. Address Deficiencies
The Control Monitoring Process
- Establish a Foundation
- Design and Execute
- Assess and Report
Control Monitoring Process Step 1: Establish a Foundation
- Tone at the Top
- Organizational Structure
- Baseline Understanding of IC
Effectiveness
Control Monitoring Process Step 2: Design and Execute
- Prioritize Risks
- Identify Controls
- Identify Persuasive
Information About Key
Controls - Implement Monitoring
Procedures