M1 Internal Control Frameworks Flashcards

1
Q

An independent private sector initiative that was initially established in the mid-1980s to study the factors that lead to fraudulent financial reporting

A

COSO (Committee of Sponsoring Organizations);

Sometimes referred to as the Treadway Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

to assist organizations in developing comprehensive assessments of internal control effectiveness

A

COSO - Internal Framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

a process that is designed and implemented by an organization’s management, BOD, and other employees to provide reasonable assurance that the organization will achieve its operating, reporting and compliance objectives

A

Internal Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 3 categories of objectives within the COSO framework?

A

ORC = Operating, reporting and compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

COSO objectives that relate to the effectiveness and efficiency of an entity’s operations as well as ensuring that the assets of the organization are adequately safeguarded

A

Opeartions (O in ORC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

COSO objective that pertains to the reliability timeliness and transparency of an entity’s external and internal financial and nonfinancial reporting as established by regulators

A

Reporting (R in ORC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

COSO objective that ensure the entity is adhering to all applicable laws and regulations

A

Compliance (C in ORC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the 5 components of internal control?

A

“CRIME” (Control Environment, Risk assessment, Information & Communication, Monitoring, Existing control activities)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Component of internal control that includes the processes, structures and standards that provide the foundation for an entity to establish a system of internal control “tone at the top”

A

Control environment (EBOCA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the five principles related to the control environment (C in CRIME)

A

EBOCA - Ethics and integrity, Board independence, Organizational structure, Commitment to competence, Accountability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

component of internal control that is an entity’s identification and analysis of risks to the achievement of its objectives

A

Risk assessment (R in CRIME)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the four principles related to risk assessment (R in CRIME)

A

SAFR (Specify objectives, identify and ASSESS Changes, consider potential for FRAUD, identify and analyze RISKS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Component of internal control that support the identification, capture, and exchange of information in a timely and useful manner

A

Information and Communication (I in CRIME)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the 3 principles related to information and communication (I in CRIME)

A

OIE (Obtain and use information, Internally communicate information, and communicate with External parties)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Component of internal control that is the process of assessing the quality of internal control performance over time by assessing the design and operation of controls on at timely basis and taking the necessary corrective actions

A

Monitoring Activities (M in CRIME)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the 2 principles related to monitoring activities?

A

SO D

Ongoing and Separate evaluations, communication of Deficiencies

17
Q

Component of internal control set forth by an entity’s policies and procedures to ensure that the directives initiated by management to mitigate risks are performed

A

Existing control activities (E in CRIME)

18
Q

What are the three principles related to existing control activities (E in CRIME)

A

CA T P (select and develop Control Activities; select and develop Technology controls; deployment of Policies and Procedures)

19
Q

Represents a material IC deficiency or combination of deficiencies that significantly reduces the likelihood that an organization can achieve its objectives

A

Major deficiency

20
Q

Missed MC: According to COSO, a primary purpose of monitoring IC is to verify that the IC system remains adequate to address changes in

A

Risks

21
Q

Missed MC: Considers the manner in which management monitors and authorizes changes to a variety of IT matters including software application programs

A

Change control

22
Q

Missed MC: Which of the following components of IC integrated framework addresses an entity’s financial reporting objectives?

A

Risk Assessment