Internal Control Monitoring and Change Control Processes Flashcards

1
Q

What are some control monitoring process methods?

A

1) Reviewing process
2) Benchmarking assessments
3) Questionnaires
4) Focus groups and interviews

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Define reviewing process?

A

Include reviews of flowcharts, and, risk and control documentation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is benchmarking assessments?

A

Comparing to other companies or other components within the organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the three stages in the COSO Model of the control monitoring process?

A

1) Establish foundation (tone at the tope, organizational structure, and baseline understanding of internal control effectiveness)
2) Design and execute- (prioritize risks, identify controls, identify persuasive information about controls, implement monitoring procedures)
3) Assess and report- (prioritize findings, report results to the appropriate level, and follow-up on corrective action)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the foundation for monitoring?

A

Generate a “baseline” of known effective IC to guide future monitoring and evaluation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do you design and execute monitoring procedures?

A

Generate persuasive information about key controls and meaningful risks

Prioritize risks (which are critical?)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How do you assess and report results?

A

Prioritize findings?
- Determine severity of identified deficiencies

Report results
- Follow up with corrective action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do you assess changes in IC effectiveness? (Four stage process called “monitoring-for-change continuum”

A

1) Establish a control baseline (begin with area where controls are well understood. Provides baseline for enhanced monitoring)
2) Change Identification (Identify changes in control operations, design, or, related risks)
3) Control revalidation (periodically revalidate that controls remain effective, thus maintaining continuous control baseline)
4) Change management (when changes occur, verify that controls remain effective. Establish a new control baseline for modified controls)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Effective change controls processes must…:

A

1) anticipate and promptly react to changes

2) Control change management must consider costs vs benefits
- If they are minor, don’t assign much money to fix it

3) Must have well-structured documentation
4) Appropriate procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Change management is part of risk assessment including consideration of what….?

A
  • Changes in operations
  • Personnel change
  • Changing technologies and information systems
  • Rapid, unexpected growth
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Identify three activities that comprise assessing and reporting on control monitoring?

A

1) Prioritize finds
2) Report results as appropriate
3) Follow-up to implement corrective actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the three elements for establishing a foundation for control?

A

1) Tone at the top
2) Organization structure
3) baseline understanding of control effectiveness

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Define ongoing monitoring

A

Actives the effectiveness of IC in the ordinary course of business

How well did you know this?
1
Not at all
2
3
4
5
Perfectly