Internal Controls Flashcards

1
Q

What are the five components of a comprehensive framework of internal controls (as outlined in the COSO Report) (5)?

A
  1. Control Environment
  2. Risk Monitoring and Assessment
  3. Control-related policies and procedures
  4. Information and communication
  5. Monitoring
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

An analysis of management’s fundamental responsibilities would need to address all of the following (4):

A
  1. Effectiveness
  2. Efficiency
  3. Compliance
  4. Financial Reporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The comprehensiveness of an entity’s internal control framework can be assessed on the basis of whether it does all of the following (5):

A
  1. Provides a favorable control environment
  2. Continually assesses risk
  3. Establishes and maintains effective control-related policies and procedures
  4. Effectively communicates information
  5. Monitors the effectiveness of control policies and procedures as well as the resolution of potential problems identified by controls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A favorable control environment is (3):

A
  1. management is knowledgeable about internal controls
  2. management is committed to establishing and maintaining controls
  3. management communicates its support for internal controls to staff at all levels
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Limitations of Internal Controls (3):

A
  1. cost considerations will prevent management from ever installing a “perfect” system
  2. subject to management override
  3. risk of collusion
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Managements responsibilities for internal controls can be categorized as follows:

A
  1. Design
  2. Implementation
  3. Monitoring
  4. Reporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Define “Effectiveness”

A

the extent to which management is achieving its goals and objectives (directly relates to management’s ability to communicate its directives to employees and ensure those directives are being carried out)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Define “Efficiency”

A

attaining goals and objectives with least expenditure of scarce resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Management must demonstrate “Compliance” with?

A

restrictions imposed by policy, regulation, law or contract (i.e. annual appropriated budget, grantor requirements, state oversight requirements, IRS requirements, bond covenants, and local laws/regulations)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Management must use “Financial Reporting” effectively to?

A

ensure that decision makers, both inside and outside the government, have the financial data they need to make informed decisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Who is primarily responsible for internal controls?

A

Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Who is ultimately responsible for internal controls?

A

Governing body

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The audit committee’s purpose (3):

A
  1. To ensure that the auditor of the financial statements is truly independent of management
  2. To provide an objective perspective on matters related to internal controls and the audit of the financial statements
  3. To provide a communications link between management, the independent auditor and the governing board
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which of the five elements of a comprehensive internal control framework can be viewed as the most important?

A

Control environment (because the effectiveness of the other four elements ultimately will depend on it)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the focus of risk monitoring?

A

A comprehensive internal control framework requires that management attempt on an ongoing basis to identify potential risks that could hinder it from fully realizing any of the four objectives (effectiveness, efficiency, compliance with laws and regulations, proper financial reporting).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Significant changes need to be monitored and assessed by management for potential risk. What are some of the types of changes requiring particular attention from management? (6)

A
  1. Changes in the operating environment
  2. Changes in personnel
  3. Changes in information systems and technology
  4. Rapid growth
  5. New programs and services
  6. Changes in structure
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Examples of inherent risk: (6)

A
  1. Complexity increases dangers
  2. Cash receipts
  3. Direct third-party beneficiaries (i.e. food stamps)
  4. Degree of centralization
  5. Prior problems
  6. Prior unresponsiveness to identified control weaknesses
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

A balanced assessment of risk should take these two factors into consideration:

A
  1. Significance

2. Likelihood of occurrence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

As part of control-related policies and procedures, a suitable accounting system should: (6)

A
  1. Assemble all relevant information
  2. Analyze assembled data
  3. Classify assembled data
  4. Record assembled data
  5. Furnish data needed for internal and external financial reporting on a timely basis
  6. Maintain accountability over the government’s assets
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Management’s implicit assertions when issuing financial reports: (5)

A
  1. Existence or occurrence
  2. Completeness
  3. Rights and obligations
  4. Allocation
  5. Presentation and disclosure
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

The first step toward controlling financial reporting is to ensure that

A

all transactions are properly authorized in accordance with management’s policies (require advance approval, require written documentation of approval)

22
Q

The second step toward achieving management’s financial reporting objectives is

A

to ensure that accounting records are properly designed (sequential numbering of documents, automatic duplicates, gathering info for multiple purposes, avoiding unnecessary information)

23
Q

Ways to secure assets and records include: (4)

A
  1. Controlled access
  2. Physical security
  3. Backup for computer records
  4. Disaster recovery
24
Q

An incompatible duty is

A

one that would put a single individual in the position of being able to both commit an irregularity and then conceal it

25
Q

The information component of the internal control framework may be considered to be functioning properly when

A

current, accurate and appropriate information is made available on a timely basis to those who need it

26
Q

To be truly effective, communication must be

A

multidirectional

27
Q

Why is it essential that management monitor control-related policies and procedures on an ongoing basis?

A

to ensure that they are continuing to function properly

28
Q

In order to evaluate controls over accounting and financial reporting, management should begin by

A

breaking down what a government does into manageable groupings of similar or related activities, commonly known as control cycles

29
Q

Once control-related policies and procedures have been identified, the next step is to

A

determine whether there are appropriate compensating controls in place to counteract or contain each identified risk

30
Q

Two key factors to be considered in assessing vulnerability are:

A

inherent risk

the quality of the control environment

31
Q

In order to initiate the process of testing controls, management should:

A

document how transactions and events are supposed to be handled in the particular department, activity or control cycle selected for evaluation (flow chart, walk through)

32
Q

These situations may predispose a given individual to consider committing fraud: (4)

A
  1. Financial stress
  2. Addiction
  3. Disaffection (feel they have been mistreated)
  4. Pathologies
33
Q

The most important cause of fraud is:

A

Opportunity (which not only permits fraud to occur, but actually promotes it)

34
Q

Costs of fraud: (4)

A
  1. Diversion of public resources from their intended purpose
  2. Loss of confidence in the government
  3. Loss to the reputation of innocent third parties (guilt by association)
  4. Cost to the perpetrator
35
Q

Kiting

A

borrowing funds from a government then concealing their absence

36
Q

Lapping

A

borrowing funds by failing to credit a payment made to an account, then later reimbursing the account with payment intended for another account (and on and on)

37
Q

Bid rigging

A

circumventing the competitive bid process

38
Q

Payroll fraud

A

paying salaries that have not been earned

39
Q

Healthcare beneficiary fraud

A

cheating on health insurance coverage by listing as beneficiaries individuals who do not qualify (or no longer qualify) as family members

40
Q

False claims

A

billing for goods/services not received (substituting an inferior good)

41
Q

Double payments

A

billing twice for same goods or services

42
Q

Charge-off fraund

A

making an unexpected collection on a delinquent account, then writing it off as uncollectible

43
Q

Disposal fraud

A

profiting personally from the disposal of surplus items

44
Q

Travel-claim fraud

A

cheating on travel claims by claiming expenses they did not actually incur

45
Q

Pilfering

A

petty theft of supplies and similar items of small monetary value

46
Q

Misuse of assets and services

A

small-scale misuse of assets and services (such as phone, copier, fax)

47
Q

Petty cash fraud

A

“borrowing” from the petty cash fund and concealing the missing cash by producing a false register tape

48
Q

Internal controls that can stop fraud before it happens include: (5)

A
  1. Properly designed records (i.e. original documentation)
  2. Segregation of incompatible duties
  3. Periodic reconciliations
  4. Periodic verifications
  5. Analytical review
49
Q

The following guidelines can significantly increase the likelihood of detecting fraud when it does occur: (5)

A
  1. Remember that anyone can commit fraud
  2. Do not dismiss tips, even when obtained from hostile sources
  3. Use analytical review to identify potential problems
  4. Carefully examine unusual transactions
  5. Carefully examine supporting documentation
50
Q

Steps to investigate fraud: (8)

A
  1. Obtain professional legal help
  2. Maintain objectivity
  3. Seek out the “best evidence”
  4. Obtain documents only from official custodians
  5. Maintain a “chain of custody” over potential evidence
  6. Exercise care in conducting interviews
  7. Retain all written records
  8. Discuss the investigation only with competent authorities