ELLIOT BOOK CHAPTER 7 INTERNAL AUDIT AND CONTROL

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/27

flashcard set

Earn XP

Description and Tags

Vocabulary flashcards covering internal control definitions, COSO and ISO frameworks, Sarbanes-Oxley requirements, audit standard types, and risk-based auditing principles.

Last updated 5:29 PM on 8/12/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

28 Terms

1
New cards

Internal Control

A system or process that an organization uses to achieve its operational goals, internal and external financial reporting goals, or legal and regulatory compliance goals.

2
New cards

Criteria of Control (CoCo) Definition

Those elements of an organization (including its resources, systems, processes, culture, structure and tasks) that, taken together, support people in the achievement of the organization's objectives.

3
New cards

COSO Definition of Internal Control

A process, effected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.

4
New cards

Institute of Internal Auditors (IIA) Definition

Any action taken by management, the board, and other parties to manage risk and increase the likelihood that established objectives and goals will be achieved.

5
New cards

Entity-level controls

Controls that support broad organizational objectives.

6
New cards

Direct controls

Controls that support objectives at the transactional level.

7
New cards

Control environment

The degree of importance people place on maintaining an appropriate culture and on following policies and procedures in an ethical manner.

8
New cards

Sarbanes-Oxley Act of 2002

A federal statutory law governing corporate directors in the areas of investor protection, internal controls, and penalties, both civil and criminal.

9
New cards

Sarbanes-Oxley Section 302

Requires officer certification that controls are in place to ensure the accuracy of the financial information reported.

10
New cards

Sarbanes-Oxley Section 404

Requires management and external auditors to report on the adequacy of the organization’s internal controls on financial reporting.

11
New cards

Management controls

A system of specified standards or objectives against which an organization’s management measures performance.

12
New cards

Preventive controls

Controls designed to prevent errors or inconsistencies.

13
New cards

Detective controls

Controls designed to detect errors or inconsistencies after they have occurred.

14
New cards

Approvals and authorizations

A preventive control where management authorizes employees to perform certain activities within defined parameters.

15
New cards

Reconciliations

A detective control where an employee compares different sets of data, investigates differences, and takes corrective action.

16
New cards

Segregation of duties

A preventive control where duties are split among employees to reduce the risk of error or inappropriate action.

17
New cards

Fraud Conditions

The three conditions present in every instance of fraud: motivation, rationalization, and opportunity.

18
New cards

COSO Cube

A depiction of the COSO framework illustrating how objectives and components are integrated across the organization by entity, division, operating unit, and function.

19
New cards

ISO 9000 series

International standards focusing on quality management, including assurances regarding regulatory compliance.

20
New cards

Audit

A systematic investigation of records, documents, systems, and operations.

21
New cards

ISO/IEC 27000 series

International standards focusing on information security management systems, covering areas like privacy, confidentiality, and technical security.

22
New cards

Attribute standard

A standard defining the attributes of organizations and individuals performing internal auditing.

23
New cards

Performance standard

A standard defining the nature of internal auditing and providing quality criteria against which the performance of these services can be measured.

24
New cards

Risk-based auditing

An approach that supports an organization’s internal control function by aligning audit resources with the areas that pose the greatest organizational risk.

25
New cards

Auditing Standard No. 5 (AS 5)

A PCAOB standard that applies when an auditor audits management’s assessment of the effectiveness of internal control over financial reporting, emphasizing a top-down, risk-based approach.

26
New cards

Risk assurance

The level of confidence in the effectiveness of the organization’s risk management culture, practices, and procedures.

27
New cards

Control Risk Self-Assessment (CRSA)

A process in which managers perform an annual self-audit of the risk assurance within their own area of responsibility to evaluate business process effectiveness.

28
New cards

Tone at the top

The environment created by senior executives through communicating expectations, leading by example, linking governance with transparency, and encouraging ethical behavior.