Internal Control- COSO (Corp Gov 12-16%) Flashcards
Internal Controls
Who uses the COSO framework? What is it used for?
B1-11
- used by management/BOD
- is used to obtain an understanding of what constitutes an effective system of internal control
What are Internal Controls for?
B1-11
avoid financial reporting “CRIME”
How does COSO framework assist management?
B1-11
-Effectively applying I/C within the overall org
-Determining the requirements of an effective system of I/C
-Allowing judgment
-Identifying and analyzing risks
-Eliminating redundant, ineffective, or inefficient controls
Efficient and effective operation compliance with laws
How does COSO framework provide value to shareholders?
B1-12
Greater:
-understanding
-confidence
-
What is the definition of internal controls?
B1-12
a process that is designed and implemented by an org’s management to provide reasonable assurance that it will achieve its compliance, operating, and reporting objectives.
What are COSO’s framework objectives? (3)
“ORC” mnemonic
B1-12
Operations Objective
- -effectiveness and efficiency of ops
- -includes financial and op performance
Reporting Objective
- -“focus of COSO”
- -reliability, timeliness, and transparency
Compliance Objective
–ensure adherence to all applicable laws and regulations
What are the 5 components of COSO framework?
R2-13
C- Control Environment R- Risk Assessment I- Information and Communication M- Monitoring E- Existing Control Activities
What are the 5 principles related to the Control Environment? “C” in CRIME
R2-13
It is the Tone at the Top.
“EBOCA” Mnemonic
E- Ethics and integrity B- Board Independence and oversight O- Org structure C- Commitment to Competence A- Accountability
What are the 4 principles related to Risk Assessment? “R” in CRIME?
R2-14
“EAR” Mnemonic
E- Event ID
A- Assess Risk
R- Respond to Risk
What are the 3 principles related to Information and Communication?
“I” in CRIME?
R2-14
- obtain and use information
- internally communicate info
- communicate w/ external parties
What are the 2 principles related to Monitoring Activities? “M” in CRIME?
R2-14
- performs ongoing evaluations
- report and correct deficiencies
What are the 3 principles related to Existing Control Activities? “E” in CRIME?
R2-14
Select and develop:
- -control activities to mitigate risk
- -IT controls
- -policies and procedures