Exam 1 Study Guide Flashcards
COSO
Top: Operations Financial Reporting Compliance Side: Monitoring Information and Communication Control Activities Risk Assessment Control Environment
Monitoring
internal auditors
information & Communication
ERP system, policies and procedures that tell employees how to act
control activities
putting in place activities that prevent fraud
risk assessment
Entity Level Objectives - organizational view
Activity Level Objectives - activity view
Risks- make assertions, likelihood, impact
Controls - activities that prevent fraud
system
a network of parts that work together to make something
information system
converts data into information
batch processing
.requires that all similar transactions are grouped together for a specified time, and then this group of transactions is processed as a batch
Real Time/OL
the transaction is processed immediately
data levels
bit, byte, field, file/tables, relational
management information system
provides info that tells how the managers are doing
accounting information system
comprises the processes, procedures, and systems that capture accounting data from business processes; record the accounting data in the appropriate records; process the detailed accounting data by classifying, summarizing, and consolidating; and report the summarized accounting data to internal and external users
COSO
Committee of Sponsoring Organizations
COBIT
.Control Objectives for Information and related Technology
ERM
Enterprise risk management, includes methods to manage risk
AIS Flow
Source Documents Journals: special, general Ledgers: sub, GL Closing Reporting
Audit Trail
source document, involves numbering of documents and authorization
Control Environment
tone of the organization, code of ethics elements: integrity and ethical values Corp governance Management Philosophy Org Structure Assignment of Authority HR Policy and Practices
corporate governance
an elaborate system of checks and balances whereby a company’s leadership is held accountable for building shareholder value and creating confidence in the financial reporting process
Audit Commitee
structures: component of the board that is independent of the company, not paid by the organization
roles: hires external/internal auditors and oversees audit activity
Code of Ethics
SOX requires that all public companies have a code of ethics stated
Whistleblowing
Dodd Frank,
SOX 806: made a way for whistleblowers to tell on their companies
Risk Prevention what can we do
Have Stewardship(safeguarding of assets)
Provide fair and transparent and full reporting and disclosure
Design and implement internal controls
Enforce a code of Ethics
Types of fraud
misstatement
misappropriation
misstatement
manipulation of records
collusion
two people working together to commit fraud