1/59
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is internal control?
An ongoing process providing reasonable assurance that organizational objectives are achieved.
What are the three categories of internal-control objectives?
Effectiveness and efficiency of operations, reliable reporting, and compliance with laws and regulations.
Does internal control provide absolute assurance?
No. It provides reasonable assurance because people and technology can fail.
Who participates in developing, maintaining, and improving internal control?
The board, executive management, business process owners, internal auditors, and other employees.
According to your slides, who has ultimate responsibility for internal control?
The CEO.
How does an ongoing control process differ from its effectiveness assessment?
Internal control continues over time; effectiveness is assessed at a point in time.
Where should internal controls be embedded?
In the organization's culture and daily activities.
What happens when internal control is weak?
The risk of fraud, errors, asset losses, and unreliable reporting increases.
Who are stakeholders interested in internal control?
Shareholders, customers, suppliers, employees, and creditors.
Why do stakeholders care about internal control?
They depend on accurate financial reports for decisions and may worry auditors will not detect problems.
Why are legislators interested in internal control?
To protect investors and promote reliable disclosures and compliance.
What topics does the FCPA address in the slides?
Foreign bribery and recordkeeping/internal-control provisions.
What does SOX Section 302 concern in your course?
CEO/CFO certifications concerning reports and internal controls.
What does SOX Section 404 concern in your course?
Management assessment and applicable external-auditor responsibilities for testing/reporting on internal control.
What is the PCAOB's role relevant to the slides?
Oversight and auditing standards for public-company auditors.
Why do external auditors need to understand internal controls?
To understand financial-reporting risks and plan audit testing.
What happens to audit testing when controls are ineffective?
More extensive testing is generally needed.
What can effective controls allow auditors to do?
Place supported reliance on controls and reduce some testing.
What are the slide takeaways for SAS 94, SAS 104-111, and AS 2201?
SAS 94: understand control design for audit planning; SAS 104-111: understand relevant IT; AS 2201: audit key financial-reporting controls.
What are the three fraud triangle elements?
Pressure, opportunity, and rationalization.
An employee has serious personal debts. Which fraud triangle element is illustrated?
Pressure.
An employee can take cash without independent review. Which fraud triangle element is illustrated?
Opportunity.
An employee justifies theft by saying I will pay it back. Which fraud triangle element is illustrated?
Rationalization.
Which fraud triangle element do internal controls most directly reduce?
Opportunity.
When was COSO originally established, and when was it updated?
Originally in 1992; updated in 2013.
What did the COSO 2013 update add?
17 principles and a reporting focus extending beyond financial reporting.
At what organizational levels can COSO be applied?
Entity, division, operating unit, and function.
What are the five COSO components?
Control environment, risk assessment, control activities, information and communication, and monitoring.
What is control environment?
The foundation and tone of an organization that influences behavior and commitment to controls.
What are the five control-environment principles in the slides?
Integrity/ethics, independent oversight, structure/authority/responsibility, competent personnel, and accountability.
Management tolerates dishonest employee behavior. Which COSO component is weak?
Control environment.
What is risk assessment?
Systematic identification and analysis of risks that could undermine achievement of objectives.
What are the four risk-assessment principles?
Specify objectives, identify/analyze risks, consider fraud, and assess significant changes.
How often should risk assessment occur?
Regularly, potentially continuously, with reassessment as circumstances change.
What are the four risk responses?
Avoid, reduce/mitigate, share, and accept.
A company declines to enter a risky region. Which risk response is this?
Avoid.
A company keeps backups in another location. Which risk response is this?
Reduce or mitigate.
A company purchases insurance. Which risk response is this?
Share.
A control costs $500 against an expected loss of $200. Which risk response may the company choose?
Accept, based on evaluating control costs versus benefits.
What are control activities?
Policies and procedures that reduce risks to organizational objectives.
How does a policy differ from a procedure?
A policy establishes what should be done; a procedure explains how to do it.
What are the three control-activity principles in the slides?
Select activities mitigating risks, include general technology controls, and establish actions to implement the activities.
How do preventive, detective, and corrective controls differ?
Preventive controls stop problems, detective controls find problems, and corrective controls remedy detected problems.
Required approval before payment is what type of control?
Preventive.
A bank reconciliation is generally what type of control?
Detective.
Correcting an entry after discovering an error is what type of control?
Corrective.
What are the four control-activity classifications?
Performance reviews, physical controls, segregation of duties, and information-processing controls.
What are examples of performance reviews and physical controls?
Performance review: budget-to-actual comparison. Physical control: locked storage or swipe-card access.
Which duties should be segregated?
Authorization, custody of assets, and recordkeeping/modification of related data and program files.
Why segregate duties?
To prevent one individual from both committing and concealing fraud or an error.
Katie receives customer payments, deposits them, and reconciles the bank. What is the weakness and fix?
Cash custody conflicts with independent reconciliation; someone independent of cash handling should reconcile.
An employee holds inventory and changes inventory records. What is the weakness and fix?
Custody and recordkeeping are combined; assign record changes to someone independent of inventory handling.
An employee approves payments and releases funds. Which duties conflict?
Authorization and custody.
What are collusion and management override?
Collusion: two or more people cooperate to perpetrate fraud. Management override: management uses authority to bypass a control.
What six underlying control concepts appear in the slides?
Isolation, redundancy, comparison, assistance, oversight, and accountability.
What do the six underlying control concepts mean?
Isolation protects/separates resources; redundancy provides backups; comparison checks data; assistance helps staff comply; oversight provides supervision/verification; accountability holds staff responsible.
How do general IT controls differ from application controls?
General controls support the overall IT environment; application controls govern specific input, processing, output, or master-file maintenance.
What are examples of general IT controls?
Access security, network/data-center operations, and software acquisition, development, implementation, and maintenance controls.
What are the four application-control categories and their purposes?
Input: authorize/verify entered data; processing: ensure accuracy/completeness; output: appropriate recipients/use; master maintenance: control additions, changes, and deletions.
How do information and communication differ from monitoring, and how should you structure a case answer?
Information/communication supplies and shares relevant control information; monitoring evaluates controls and follows up on deficiencies. Structure a case answer as weakness, specific risk, and specific recommended control.