Internal Control revision

0.0(0)
studied byStudied by 0 people
0.0(0)
full-widthCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/24

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

25 Terms

1
New cards

Internal Control Definition

Describes the policies, plans, and procedures implemented by management to protect assets, ensure data accuracy/completeness, and meet business objectives.

2
New cards

Who are the people involved?

Board of directors, Management, and other key personnel.

3
New cards

Reasonable Assurance Goals

Efficiency of operations , reliability of reporting , protection of assets , and compliance with laws

4
New cards

SAS No. 94

Guidance for auditors on how IT affects internal controls and adjusting audit procedures accordingly.

5
New cards

Sarbanes-Oxley (2002)

Law to protect investors by improving reporting accuracy, preventing fraud, and restoring trust

6
New cards

Internal Control Objectives

Safeguard assets , check accuracy/reliability of data , promote operational efficiency , and enforce managerial policies.

7
New cards

Governance Frameworks

COSO, CoCo, UK Corporate Governance Code, and INTOSAI

8
New cards

ERM Component 1: Internal Environment

Integrity, ethical values , employee competence , management philosophy , board attention , authority assignment , and HR policies.

9
New cards

ERM Component 2: Objective Setting

Strategic (high-level) , Operations (efficiency) , Reporting (accuracy) , and Compliance.

10
New cards

ERM Component 3: Event Identification

Identifying internal/external events ; negative impacts = Risks , positive impacts = Opportunities

11
New cards

Risk Examples

Personnel changes , new info systems , new tech , industry changes , new products , new rules/laws

12
New cards

ERM Component 4/5: Assessment & Response

Management selects actions to align with risk tolerance. Four responses: Accept, Avoid, Reduce, or Share

13
New cards

ERM Component 6: Control Activities

Establish policies/procedures. Includes: Audit trail , asset protection , performance reports , personnel policies , and separation of duties.

14
New cards

The Audit Trail

Allows following transaction data from source to financial report and back ; prevents undetected errors/irregularities.

15
New cards

Personnel Policy Examples

Hiring procedures , training , supervision , fair salary guidelines , job rotation , enforced vacations , insurance for liquid asset handlers , performance reviews

16
New cards

Segregation of Duties

Separation of: Custody of assets, Recording transactions, and Authorizing transactions

17
New cards

Internal Audit Function

Separate subsystem reporting to board/high-level management ; performs periodic operational audits to appraise info systems, controls, and compliance

18
New cards

ERM Component 7: Info & Communication

Info: identifies, assembles, and records transactions. Communication: ensuring personnel understand policies and reporting exceptions to management.

19
New cards

ERM Component 8: Monitoring

Ongoing process of assessing control quality over time and taking corrective action

20
New cards

Natural/Political Threats

Fire, floods, war, terrorism

21
New cards

Software/Equipment Threats

Hardware failures, software bugs, OS crashes, power fluctuations.

22
New cards

Human Threats

Unintentional: error/carelessness. Intentional: crimes like sabotage, fraud, embezzlement

23
New cards

Definitions (Risk/Opportunity/Control)

Risk: exposure to injury/loss. Opportunity: positive potential. Control: activity to minimize risk.

24
New cards

Why Threats are Increasing

Ubiquity of PCs/laptops , difficulty controlling LANs , and system integration with partners

25
New cards

Reasons for Lack of Protection

Underestimating problems , not understanding network implications , failing to see security as survival , and productivity pressures