Study Unit 4 - Control Frameworks & Fraud Flashcards
1
Q
COSO’s 3 Control Objectives
A
- Effectiveness & Eficiency of Operations
- Reliability of Financial Reporting
- Compliance w/ laws & regs.
(Everything Really Counts)
2
Q
COSO 5 Internal Control (IC) Components
A
- Control Activities (policies & procedures)
- Risk Assmt (basis of risk management)
- Info & Communication (timing is key)
- Monitoring (assess performance of IC)
- Control Environment (Tone from the top)
(CRIME)
3
Q
CoCo 4 Components
A
- Purpose
- Commitment
- Capability
- Monitoring & Learning
(Police Can Catch Many Lawbreakers)
4
Q
COBIT 5 Key Principles
A
- Meeting Stakeholder Needs
- Covering the Enterprise End-to-End
- Applying a Single, Integrated Framework
- Enabling a Holistic Aproach
- Separating Governance from Mgmt.
5
Q
eSAC model processes for inputs & outputs
A
- Inputs:
- Mission
- Values
- Strategies
- Objectives
- Outputs:
- Results
- Reputation
- Learning
6
Q
eSAC 4 control objectives
A
- Efectiveness & Eficiency of Ops
- Reporting of Financial & Management info.
- Compliance w/ laws & regs
- Safeguarding of Assets
(Similar to COSO, ERCs)
7
Q
eSAC Business Assurance objectives
A
- Avaliability (of info)
- Capability (bring to completion)
- Functionality (to achieve objectives)
- Protectability (safeguarding of assets)
- Accountability (principles)
(A Court Finds People Accountable)
8
Q
COSO Enterprise Risk Mmanagement (ERM) Framework 8 Components
A
- Control Environment
- Obj. Setting (align with mission, risk aptte)
- Event identification (Opportunity & Risk)
- Risk assessment (Likelihood & Impact)
- Risk Response (consistent w/ appetite)
- Control Activities (Policies & Procedures)
- Information & Communication
- Monitoring (evaluating performance)
9
Q
5 Risk Response Strategies
A
- Avoidance
- Retention (Acceptance)
- Reduction (Mitigation)
- Sharing (transfer of loss to another party)
- Exploitation (Risk for reward)
10
Q
Terminology of Fraud Indicators (Symptoms)
A
- Document Symptom (tampering with info)
- Pressure (Personal or Organizational)
- Opportunity
- Lifestyle Symptom
- Rationalization (justfication for actions)
- Behavioral Symptom
11
Q
10 Fraud Indicators
A
- No employee rotation
- No SoD
- No definitions of responsibility
- Unrealistic goals
- No vacation taken
- Not following controls
- High profits in downturn
- High turnover of supervisors
- Unjustified use of sole-source suppliers
- Sales out of proportion from COGS