1/27
Vocabulary flashcards covering internal control definitions, COSO and ISO frameworks, Sarbanes-Oxley requirements, audit standard types, and risk-based auditing principles.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Internal Control
A system or process that an organization uses to achieve its operational goals, internal and external financial reporting goals, or legal and regulatory compliance goals.
Criteria of Control (CoCo) Definition
Those elements of an organization (including its resources, systems, processes, culture, structure and tasks) that, taken together, support people in the achievement of the organization's objectives.
COSO Definition of Internal Control
A process, effected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.
Institute of Internal Auditors (IIA) Definition
Any action taken by management, the board, and other parties to manage risk and increase the likelihood that established objectives and goals will be achieved.
Entity-level controls
Controls that support broad organizational objectives.
Direct controls
Controls that support objectives at the transactional level.
Control environment
The degree of importance people place on maintaining an appropriate culture and on following policies and procedures in an ethical manner.
Sarbanes-Oxley Act of 2002
A federal statutory law governing corporate directors in the areas of investor protection, internal controls, and penalties, both civil and criminal.
Sarbanes-Oxley Section 302
Requires officer certification that controls are in place to ensure the accuracy of the financial information reported.
Sarbanes-Oxley Section 404
Requires management and external auditors to report on the adequacy of the organization’s internal controls on financial reporting.
Management controls
A system of specified standards or objectives against which an organization’s management measures performance.
Preventive controls
Controls designed to prevent errors or inconsistencies.
Detective controls
Controls designed to detect errors or inconsistencies after they have occurred.
Approvals and authorizations
A preventive control where management authorizes employees to perform certain activities within defined parameters.
Reconciliations
A detective control where an employee compares different sets of data, investigates differences, and takes corrective action.
Segregation of duties
A preventive control where duties are split among employees to reduce the risk of error or inappropriate action.
Fraud Conditions
The three conditions present in every instance of fraud: motivation, rationalization, and opportunity.
COSO Cube
A depiction of the COSO framework illustrating how objectives and components are integrated across the organization by entity, division, operating unit, and function.
ISO 9000 series
International standards focusing on quality management, including assurances regarding regulatory compliance.
Audit
A systematic investigation of records, documents, systems, and operations.
ISO/IEC 27000 series
International standards focusing on information security management systems, covering areas like privacy, confidentiality, and technical security.
Attribute standard
A standard defining the attributes of organizations and individuals performing internal auditing.
Performance standard
A standard defining the nature of internal auditing and providing quality criteria against which the performance of these services can be measured.
Risk-based auditing
An approach that supports an organization’s internal control function by aligning audit resources with the areas that pose the greatest organizational risk.
Auditing Standard No. 5 (AS 5)
A PCAOB standard that applies when an auditor audits management’s assessment of the effectiveness of internal control over financial reporting, emphasizing a top-down, risk-based approach.
Risk assurance
The level of confidence in the effectiveness of the organization’s risk management culture, practices, and procedures.
Control Risk Self-Assessment (CRSA)
A process in which managers perform an annual self-audit of the risk assurance within their own area of responsibility to evaluate business process effectiveness.
Tone at the top
The environment created by senior executives through communicating expectations, leading by example, linking governance with transparency, and encouraging ethical behavior.