mga 311 ch 6&7 @@

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/59

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:01 AM on 10/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

60 Terms

1
New cards

What is internal control?

An ongoing process providing reasonable assurance that organizational objectives are achieved.

2
New cards

What are the three categories of internal-control objectives?

Effectiveness and efficiency of operations, reliable reporting, and compliance with laws and regulations.

3
New cards

Does internal control provide absolute assurance?

No. It provides reasonable assurance because people and technology can fail.

4
New cards

Who participates in developing, maintaining, and improving internal control?

The board, executive management, business process owners, internal auditors, and other employees.

5
New cards

According to your slides, who has ultimate responsibility for internal control?

The CEO.

6
New cards

How does an ongoing control process differ from its effectiveness assessment?

Internal control continues over time; effectiveness is assessed at a point in time.

7
New cards

Where should internal controls be embedded?

In the organization's culture and daily activities.

8
New cards

What happens when internal control is weak?

The risk of fraud, errors, asset losses, and unreliable reporting increases.

9
New cards

Who are stakeholders interested in internal control?

Shareholders, customers, suppliers, employees, and creditors.

10
New cards

Why do stakeholders care about internal control?

They depend on accurate financial reports for decisions and may worry auditors will not detect problems.

11
New cards

Why are legislators interested in internal control?

To protect investors and promote reliable disclosures and compliance.

12
New cards

What topics does the FCPA address in the slides?

Foreign bribery and recordkeeping/internal-control provisions.

13
New cards

What does SOX Section 302 concern in your course?

CEO/CFO certifications concerning reports and internal controls.

14
New cards

What does SOX Section 404 concern in your course?

Management assessment and applicable external-auditor responsibilities for testing/reporting on internal control.

15
New cards

What is the PCAOB's role relevant to the slides?

Oversight and auditing standards for public-company auditors.

16
New cards

Why do external auditors need to understand internal controls?

To understand financial-reporting risks and plan audit testing.

17
New cards

What happens to audit testing when controls are ineffective?

More extensive testing is generally needed.

18
New cards

What can effective controls allow auditors to do?

Place supported reliance on controls and reduce some testing.

19
New cards

What are the slide takeaways for SAS 94, SAS 104-111, and AS 2201?

SAS 94: understand control design for audit planning; SAS 104-111: understand relevant IT; AS 2201: audit key financial-reporting controls.

20
New cards

What are the three fraud triangle elements?

Pressure, opportunity, and rationalization.

21
New cards

An employee has serious personal debts. Which fraud triangle element is illustrated?

Pressure.

22
New cards

An employee can take cash without independent review. Which fraud triangle element is illustrated?

Opportunity.

23
New cards

An employee justifies theft by saying I will pay it back. Which fraud triangle element is illustrated?

Rationalization.

24
New cards

Which fraud triangle element do internal controls most directly reduce?

Opportunity.

25
New cards

When was COSO originally established, and when was it updated?

Originally in 1992; updated in 2013.

26
New cards

What did the COSO 2013 update add?

17 principles and a reporting focus extending beyond financial reporting.

27
New cards

At what organizational levels can COSO be applied?

Entity, division, operating unit, and function.

28
New cards

What are the five COSO components?

Control environment, risk assessment, control activities, information and communication, and monitoring.

29
New cards

What is control environment?

The foundation and tone of an organization that influences behavior and commitment to controls.

30
New cards

What are the five control-environment principles in the slides?

Integrity/ethics, independent oversight, structure/authority/responsibility, competent personnel, and accountability.

31
New cards

Management tolerates dishonest employee behavior. Which COSO component is weak?

Control environment.

32
New cards

What is risk assessment?

Systematic identification and analysis of risks that could undermine achievement of objectives.

33
New cards

What are the four risk-assessment principles?

Specify objectives, identify/analyze risks, consider fraud, and assess significant changes.

34
New cards

How often should risk assessment occur?

Regularly, potentially continuously, with reassessment as circumstances change.

35
New cards

What are the four risk responses?

Avoid, reduce/mitigate, share, and accept.

36
New cards

A company declines to enter a risky region. Which risk response is this?

Avoid.

37
New cards

A company keeps backups in another location. Which risk response is this?

Reduce or mitigate.

38
New cards

A company purchases insurance. Which risk response is this?

Share.

39
New cards

A control costs $500 against an expected loss of $200. Which risk response may the company choose?

Accept, based on evaluating control costs versus benefits.

40
New cards

What are control activities?

Policies and procedures that reduce risks to organizational objectives.

41
New cards

How does a policy differ from a procedure?

A policy establishes what should be done; a procedure explains how to do it.

42
New cards

What are the three control-activity principles in the slides?

Select activities mitigating risks, include general technology controls, and establish actions to implement the activities.

43
New cards

How do preventive, detective, and corrective controls differ?

Preventive controls stop problems, detective controls find problems, and corrective controls remedy detected problems.

44
New cards

Required approval before payment is what type of control?

Preventive.

45
New cards

A bank reconciliation is generally what type of control?

Detective.

46
New cards

Correcting an entry after discovering an error is what type of control?

Corrective.

47
New cards

What are the four control-activity classifications?

Performance reviews, physical controls, segregation of duties, and information-processing controls.

48
New cards

What are examples of performance reviews and physical controls?

Performance review: budget-to-actual comparison. Physical control: locked storage or swipe-card access.

49
New cards

Which duties should be segregated?

Authorization, custody of assets, and recordkeeping/modification of related data and program files.

50
New cards

Why segregate duties?

To prevent one individual from both committing and concealing fraud or an error.

51
New cards

Katie receives customer payments, deposits them, and reconciles the bank. What is the weakness and fix?

Cash custody conflicts with independent reconciliation; someone independent of cash handling should reconcile.

52
New cards

An employee holds inventory and changes inventory records. What is the weakness and fix?

Custody and recordkeeping are combined; assign record changes to someone independent of inventory handling.

53
New cards

An employee approves payments and releases funds. Which duties conflict?

Authorization and custody.

54
New cards

What are collusion and management override?

Collusion: two or more people cooperate to perpetrate fraud. Management override: management uses authority to bypass a control.

55
New cards

What six underlying control concepts appear in the slides?

Isolation, redundancy, comparison, assistance, oversight, and accountability.

56
New cards

What do the six underlying control concepts mean?

Isolation protects/separates resources; redundancy provides backups; comparison checks data; assistance helps staff comply; oversight provides supervision/verification; accountability holds staff responsible.

57
New cards

How do general IT controls differ from application controls?

General controls support the overall IT environment; application controls govern specific input, processing, output, or master-file maintenance.

58
New cards

What are examples of general IT controls?

Access security, network/data-center operations, and software acquisition, development, implementation, and maintenance controls.

59
New cards

What are the four application-control categories and their purposes?

Input: authorize/verify entered data; processing: ensure accuracy/completeness; output: appropriate recipients/use; master maintenance: control additions, changes, and deletions.

60
New cards

How do information and communication differ from monitoring, and how should you structure a case answer?

Information/communication supplies and shares relevant control information; monitoring evaluates controls and follows up on deficiencies. Structure a case answer as weakness, specific risk, and specific recommended control.