Challenging Topics - CIA Part 1

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/50

flashcard set

Earn XP

Description and Tags

Topics that I need extra study time for

Last updated 8:33 PM on 8/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

51 Terms

1
New cards

Process owner, internal auditor, user

The participants of an assurance service

2
New cards

Scope of assurance services

Determined by the internal auditor.

  • Operational efficiency

  • Reliability of reporting

  • Compliance

  • Safeguarding assets

  • Ethical culture


3
New cards

Control Self Assessment (CSA)

Evaluation of organization’s risk management and control systems

  • facilitated by internal auditors

  • participation by employees of all levels

  • results in: sense of ownership, awareness of risks, improved effectiveness of controls


4
New cards

Workshop-Facilitation; Survey (questionnaire); Self-certification

The three primary approaches of CSA programs:

5
New cards

Workshop Facilitation Approach

CSA that is structured, documented, and repetitive.

  • Objective-based format: best way to accomplish business objective? identifies controls.

  • Risk-based format: risks to achieving adjective? identifies risks.

  • Control-based format: how well controls in place are working? risks & controls preidentified. gap analysis.

  • Process-based format: activities in chain of processes. evaluate & better entire process.


6
New cards

Self-Certification Approach

CSA through management produced analysis of selected business processes, risk management activities, and control procedures.

Assumes managers and members of work team understand risk and control concepts and use them in communications.

7
New cards

Survey Approach

CSA though question based format - mostly “yes or no”, “have or have not”.

Preferred if the culture in the organization limits open, candid discussions in workshop settings or there is a need to minimize time spent & costs of information gathering.

8
New cards

External Business Relationships

Service providers, supply-side partners, demand-side partners, strategic alliances & Joint Ventures, Intellectual property partners

Benefits of: lower costs, operational efficiency, special expertise, new tech, known brand, and/or economies of scale

Mgmt ensures that benefits > costs; IA assists in validating those efforts

9
New cards

Lump Sum Contracts

Used when requirements are well-defined, uncertainties can be identified and costs estimated, and competition is adequate

Consider:

  • Progress payments

  • Incentives

  • Escalator clause

  • Adjustments for labor costs

  • Change orders



10
New cards

Cost-Plus Contracts

Contract which copes with uncertainties about costs by setting a price equal to project expenditures in addition to a determined amount.

Balance in getting contractor to have incentive for economy and efficiency

Look for:

  • maximum cost provisions

  • incentives for early completion


11
New cards

Unit Price Contracts

Contracts used when convenient measure of work is available [i.e. person-hours logged, acres of land cleared, cubic yards of earth moved, etc.]

key issue of accurate measurement of work performed

12
New cards

Total Quality Management

Focuses on the customer. Continuous pursuit of quality throughout the organization.

  • do it right the first time

  • empower employees

  • promote teamwork

  • continuous improvement

  • satisfy the customer (internal and external)


13
New cards

Balanced Scorecard

Tool relating Critical Success Factors determined by a strategic analysis with financial and non-financial measures. Prioritize both long- and short-term considerations.

Perspectives:

  • Financial (sales, fair value of stock, profits, liquidity)

  • Customer (retention rate, relationships, marketing, delivery, response time, quality, market share)

  • Internal (quality, productivity, adaptability, lead-time, safety)

  • Learning, Growth, and Innovation (R&D, HR development, morale, competence)


14
New cards

Process (functional) Engagements

Engagement following process-crossing organizational lines, service units, and geographical locations.

Emphasis on operations and effectiveness and efficiency of the cooperation of the area under review.

i.e. Purchasing and receiving; Safety; Marketing; Scrap handling and disposal; etc.

15
New cards

Program-Results Engagement

Obtain information about the costs, outputs, benefits, and effects of a program

[Program - funded activity not part of the continuing operations of the organization i.e. new information system implementation]

16
New cards

Productivity Ratio

[Program-Results Eng: assessing tool]

Output / Input

17
New cards

Productivity Index

[Program-Results Eng: assessing tool]

Production potential - (Output / Input) tracked overtime

18
New cards

Resource Usage Rate

[Program-Results Eng: assessing tool]

Resource use / Available Resources

19
New cards

Operating Ratio

[Program-Results Eng: assessing tool]

Operating Costs (C.O.G.S + OpEx) / Revenue

20
New cards

(COGS + OpEx) / Revenue

Operating Ratio

21
New cards

Integrity

Adherence to ethical principles; honesty and professional courage; tell the truth and do the right things.

The foundation of trust and other principles within the code of ethics.

  • Disclose all material facts that could affect org’s ability to make informed decision

  • Observe all applicable laws and make all disclosures expected by the profession


22
New cards

Objectivity

Unbiased mental attitude that allows auditors to make professional judgments, fulfill responsibilities, and achieve objectives without compromise.

  • Avoid conflict of interests - either in fact or appearance [must be disclosed]

  • Avoid bias - self-review bias; familiarity bias; prejudice/unconscious bias


23
New cards

Competency

Must use their knowledge, skills, and abilities to effectively perform their duties.

Only provide services for which required skills are possessed or will soon be developed.

24
New cards

Due Professional Care

Auditors should take great care when planning and performing IA services.

  • Conformance with IPPF standards

  • Consideration of nature, circumstances, and requirements of work to be performed

  • Application of professional skepticism


25
New cards

Professional Skepticism

  • Maintaining an attitude of inquisitiveness;

  • Critically assessing reliability of information;

  • Straightforwardness and honesty in questioning;

  • Seeking additional evidence to make judgments of information


26
New cards

Confidentiality

Internal Auditors use and protect information appropriately.

  • Following policies, procedures, laws, and regulations when using information.

    • Not to be used for personal gain


27
New cards

Internal Governance Mechanisms

Corporate charters & bylaws, boards of directors, internal audit functions.

28
New cards

External Governance Mechanisms

Laws, regulations, and government regulators (enforcement)

29
New cards

Strategic Direction

Governance component which determines the:

  • Business Model

  • Overall Objectives

  • Approach to risk taking (including risk appetite)

  • Limits of organizational conduct


30
New cards

Oversight

Governance component which include the following elements:

  • Risk management activities performed by Senior Management & Risk Owners

  • Internal & External assurance activities

This component is which internal audit is most concerned; where risk management & control processes are most likely to be applied.


31
New cards

Risk Owners

Determined by Senior Management. They are Managers responsible for specific day-to-day risks.

Responsible for:

  • Evaluating adequacy of RM activities

  • Determining if activities are operating as designed

  • Establishing monitoring activities

  • Ensuring accurate, timely, and available information is to be reported


32
New cards

Identification of context; Risk identification; Risk assessment and prioritization; Risk response; Risk monitoring

The steps of the Risk Management Process

33
New cards

Controls

Actions by management to manage risk and ensure risk responses are carried out

34
New cards

Control Risk

Risk that controls fail to effectively manage controllable risks

35
New cards

Enterprise Risk Management

The culture, capabilities, and practices, integrated with strategy-setting and performance, that organizations rely on to manage risk in creating, preserving, and realizing value.

36
New cards

Risk Profile

Composite view of the types, severity, and independence of risks related to a specific strategy or business objective and their effect on performance.

  • Any level (entity, division, operating unit, or function) or aspect (product, service) of the org


37
New cards

Portfolio View

Composite view of risks related to entity-wide strategy and business objectives and their effects on entity performance.

38
New cards

Acceptance (Retention)

Risk response where no action is taken to alter severity of the risk. “Self-Insurance”.

Appropriate when risk is within the risk appetite.

39
New cards

Avoidance

Risk Response where action is taken to remove the risk.

Suggests that no response would reduce the risk to an appropriate level.

Ex. risk of pipeline sabotage is mitigated by selling the pipeline.

40
New cards

Pursuit (exploitation)

Risk response where action is taken to accept increased risk to improve performance without exceeding acceptable tolerance.

41
New cards

Reduction (mitigation)

Risk response where action is taken to reduce the severity of the risk so that it becomes within the target residual risk profile and risk appetite.

Ex. risk of system penetration is mitigated by maintaining an effective cybersecurity team

42
New cards

Sharing (transfer)

Risk response where action is taken to reduce the severity of risk by transferring a portion of the risk to another party.

Ex. Insurance, hedging, joint ventures, outsourcing, and contracts

43
New cards

COSO ERM

ERM Framework. Prescriptive.

5 Components

  • Governance and Culture

  • Strategy and Objective Setting

  • Performance

  • Review and Revision

  • Information, Communication, and Reporting

20 Sub Principles across the components.

Reasonably expected to manage risks effectively and to help create, preserve, and realize value when the components, principles, and controls are present and functioning.

44
New cards

ISO 31000

ERM framework. Flexible, integrated.

8 Principles

6 Framework components

6 RM Process Elements

3 RM Assurance Approaches

  • P.P.M. - Principles, Process, Maturity


45
New cards

ISO 31000 Principles

Each inducive to Value Creation & Protection:

  • Integrated

  • Structured and Comprehensive

  • Customized

  • Inclusive

  • Dynamic

  • Best Available Information

  • Human and Cultural Factors

  • Continual Improvement


46
New cards

Risk Treatment

Element of ISO 31000 RM process.

Repetitive process of:

  • 1) selecting a risk response (accept, avoid, reduce, share, pursue),

  • 2) implementing it

  • 3) assessing effectiveness & determining acceptability of residual risk

  • 4) repeat if attempt was unacceptable



47
New cards

Authorization, Recordkeeping, Custody

Segregation of Duties: for any given transactions the following functions should be performed by separate individuals in different parts of the organization

48
New cards

COSO Internal Control Framework

3 Objectives to achieve

  • O.R.C - Operations, Reporting, Compliance

4 Entities affect it

5 Components

  • C.R.I.M.E. - Control activities, Risk assessment, Information & communication, Monitoring, control Environment


49
New cards

COBIT 2019

IT Control & Governance Framework.

6 Governance System Principles

3 Governance Framework Principle

50
New cards

Pressure, Opportunity, Rationalization

The fraud triangle

51
New cards

Independence

Freedom from conditions that may impair the ability of the internal audit function to carry out internal audit responsibilities in an unbiased manner.

“Am I free from influence?”

Organizational position & relationships