COSO Flashcards

1
Q

Name 3 Objectives of COSO Cube

A

Compliance
Reporting
Efficient Operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

5 Components of COSO Cube

A
Control Environment
Risk Assessment
Control Activities
Information/Technology
Monitoring
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

5 Components of COSO ERM

A
Governance
Strategy/Objective Setting
Performance
Review/Revision
Info/Communication Reporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q
Board Oversight
Make Operating Structures
Define Desired Culture
Demonstrate Core Values
Attract/Retain Capable Individuals
A

Governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Analyze Business Context
Define Risk Appetite
Evaluate Alternative Strategies
Form Business Objectives

A

Strategy/Objective Setting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
Identify Risk
Assess Risk Severity
Prioritize Risks
Implement Risk Responses
Develop Portfolio View
A

Performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Assess Change
Review Risk and Performance
Pursue Improving ERM

A

Review/Revision

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Leverage Info/Tech
Communicate Risk Info
Report on Risk Culture/Performance

A

Info/communication reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
Tone at Top
BOD
Management
Competence
Accountability
A

Control Environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Objectives
Assessment
Fraud
Change Management

A

Risk Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Risk Reduction
Technology
Policies

A

Control Activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Quality
Internal
External

A

Information/Communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Ongoing and Periodic

Address Deficiencies

A

Monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

assessing aspects of risk to determine which risks are most and least important

A

Performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

systematic analysis of the political, economic, social, technological, legal, and environmental conditions
PESTLE

A

Strategy/Objective Setting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

reporting on the organization’s risk, culture, and performance (Whistle blower hotline)

A

Information/Communication/Reporting

17
Q

meetings with its investors, management, and employees to help identify its risk culture

A

Governance

18
Q

company recently issued a report on its investment philosophy and risk management culture

A

Information/Communication/Reporting

19
Q

Development of Strategy

A

Risk Appetite

20
Q

Implementation of Strategy

A

Tolerance

21
Q

They help an entity create and maintain reliable data

A

Process and Controls

22
Q

determine which data is collected and how it is stored, arranged, integrated

A

Data Management Architecture

23
Q

management’s philosophy and operating style

A

Control Environment

24
Q

process of identifying, analyzing, and managing the risks involved in achieving the organization’s objectives

A

Risk Assessment

25
Q

ongoing activities and separate evaluations

A

Monitoring

26
Q

routine controls over business processes and transactions

A

Control Activities

27
Q

policies and procedures that ensure that management’s directives are carried out

A

Control Activities

28
Q

general control rather than a transaction control activity
.Technology development policies and procedures.
.Reconciliations.
.Physical controls over assets.
.Controls over standing data.

A

Technology development policies and procedures

29
Q

the goal of proper measurement of transactions

A

Information and communication

30
Q

addresses the need to respond in an organized manner to significant changes resulting from international exposure, acquisitions, or executive transitions

A

Risk Assessment

31
Q

organizational objectives primarily relate to which fundamental component

A

Risk Assessment (help define risk)

32
Q

types of control plans is particular to a specific process or subsystem, rather than related to the timing of its occurrence

A

Application

33
Q

organization’s security awareness manual would be an example of which of the following types of controls

A

Preventive