Principles of Internal Control Flashcards
1
Q
Control environment — 5 principles
A
- Integrity and Ethical Values - “tone at the top”
- Board of Directors - independence from management; oversees development and monitoring of internal control
- Management - establish structures, reporting lines, and appropriate authorities and responsibilities to achieve objectives
- Competence - commitment to attract, develop, and retain competent individuals
- Accountability - hold individuals responsible for internal control responsibilities (authority, rewards, discipline)
2
Q
Risk Assessment — 4 objectives
A
- Objectives - specify objectives with sufficient clarity to enable the identification and assessment of risks that threaten the achievement of objectives
- Assessment - identify risks to the achievement of objectives across the entity and analyze risks as a basis for determining how the risk should be managed
- Fraud - consider the potential for fraud in assessing risks to the achievement of objectives
- Change Management - identify and assess changes in the external environment, business model and organizational leadership that could impact the system of internal control
3
Q
Control Activities — 3 principles
A
- Risk Reduction - organizational control activities mitigate the risks to the achievement of objectives to acceptable levels
- Technology Controls - select and implement general controls over technology which support the achievement of its objectives
- Policies - establish policies, procedures, responsibility and accountability
4
Q
Information and Communication — 3 principles
A
- Quality - relevant, high-quality information supports the internal control processes
- Internal - internal communication supports internal control processes
- External - communication with outsiders supports internal control processes
5
Q
Monitoring Activities — 2 principles
A
- Ongoing and Periodic - ongoing and separate evaluations evaluate internal control functioning
- Address Deficiencies - parties responsible for taking corrective action, including senior management and the board of directors, receive timely communication of internal control deficiencies