Internal Control Frameworks Flashcards
Control Activities
Control activities encompass policies and procedures that ensure that management’s directives are carried out.
Control Activities
Control activities, policies and procedures are designed to assure that management’s directives are followed.
Control Envirnoment Component of Internal Control
- Commitment to competence.
- Organizational structure.
- Integrity and ethical values
Information and communication is a separate component of internal control
Asset Safeguarding in not one of the objects of internal control as defined by COSO
COSO Definition of Internal Control
A process designed to provide reasonable assurance regarding the achievement of objectives in the following categories:
- (1) reliability of financial reporting
- (2) effectiveness and efficiency of operations
- (3) compliance with applicable laws and regulations
COSO Management Override
Management overide is a limitation for all control systems no matter how effectively designed and implemented.
Enterprise Risk Management System
- Risk relates to the future that is uncertain.
- Collusion among two or more individuals can result in enterprise risk management failure.
- Enterprise risk management is subject to management override
Companies cannot avoid risk this fact results in the need to have enterprsie risk management
Five Elements of Control Environment
- integrity and ethical values
- board of directors
- management
- competence
- accountability
Goverance and Culture
Governance is the identification and allocation of roles, authorities, and responsibilities among stakeholders, including identifying the organization’s risk culture.
monitoring-for-change continuum
- Establish a control baseline
- Identify Changes
- Manage Changes
- REvalidate control baseline
Seven Control Environment Factors
- (1) integrity and ethical values
- (2) commitment to competence
- (3) human resource policies and practices
- (4) assignment of authority and responsibility
- (5) management’s philosophy and operating style
- (6) board of directors or audit committee participation
- (7) organizational structure.
Internal Control Defined
COSO defines internal control as a process—effected by an entity’s board of directors, management, and other personnel—designed to provide reasonable assurance regarding the achievement of objectives in the following categories:
- (1) reliability of financial reporting
- (2) effectiveness and efficiency of operations
- (3) compliance with applicable laws and regulations.