1/33
Vocabulary practice flashcards covering internal control concepts, COSO framework components, auditing standards (AS 2201/SOX 404), risk assessment, control testing, and service organization reports.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
COSO
The Committee of Sponsoring Organizations of the Treadway Commission, formed by FEI, AAA, IIA, IMA, and AICPA to provide guidance on internal control, enterprise risk management, and fraud deterrence.
Internal Control
A process effected by an entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the reliability of financial reporting, effectiveness and efficiency of operations, and compliance with applicable laws and regulations.
Control Environment
The foundational COSO component setting the ethical tone of an organization, encompassing commitment to integrity, board independence and oversight, organizational structure, employee competence, and accountability.
Audit Committee
A subcommittee of the board of directors composed of 3 to 6 independent outside members responsible for overseeing financial reporting, internal controls, internal audit, and the independent auditor.
Risk Assessment
The COSO component involving management's identification and analysis of relevant operational, compliance, and financial reporting risks—including fraud risks—that could impede entity objectives.
Control Activities
The policies and procedures established by management to ensure directives are carried out, including performance reviews, separation of duties, physical controls, and information processing controls.
Preventive Controls
Internal control activities designed to deter or prevent misstatements or errors from occurring, such as segregation of duties and restricted access to assets.
Detective Controls
Internal control activities designed to discover and correct potential misstatements after they have occurred, such as bank reconciliations and periodic counts of inventory.
Separation of Duties
A fundamental control activity dividing authorization, custody of assets, record keeping, and reconciliation among different individuals to prevent one person from committing and concealing fraud.
Information and Communication
The COSO component focused on identifying, capturing, and exchanging operational and financial information in a timely form and manner that enables personnel to perform their duties.
Audit Trail
A sequential record of accounting activities produced by an information system that allows an auditor to trace transactions from initial data identification to final financial statement items.
Monitoring
The COSO component that evaluates the quality of internal control performance over time through ongoing management supervisory activities and separate internal audit evaluations.
Section 922 of the Dodd-Frank Act
A statutory provision requiring the SEC to pay monetary awards of 10% to 30% of collected sanctions to whistleblowers who voluntarily provide original information leading to successful enforcement exceeding \text{\\$1 million}.
Reasonable Assurance
The principle that an internal control system cannot guarantee absolute compliance or complete error prevention, as the costs of internal control should not exceed its expected benefits.
Entity-Level Controls
Internal controls that pervasive across the entire entity and impact overall financial statement reliability, such as tone at the top, management override controls, and general IT security controls.
Transaction-Level Controls
Internal controls that pertain to specific classes of transactions, account balances, or disclosures, such as cash receipt processing, inventory authorization, and accounts payable approvals.

Internal Control Evaluation Process
The structured three-phase auditing process comprising Phase 1: Understanding and documenting internal control, Phase 2: Preliminary assessment of control risk, and Phase 3: Testing of controls.
Vouching
An audit procedure performed by moving backwards from recorded journal entries or ledgers to underlying source documentation to test the assertion of occurrence.
Tracing
An audit procedure performed by moving forward from initial source documents to general ledger entries to test the assertion of completeness.
PCAOB Auditing Standard No. 2201 (AS 2201)
The standard establishing requirements for integrated audits of internal control over financial reporting and financial statements for public companies with public float exceeding \text{\\$75 million}.
Top-Down Risk-Based Approach
An integrated audit methodology where the auditor begins at the financial statement level, focuses on entity-level controls, and identifies critical controls for testing rather than comprehensively testing all controls.
Design Effectiveness
The evaluation of whether an internal control procedure, if operating as designed, would effectively prevent or detect material misstatements in financial statement assertions.
Operating Effectiveness
The evaluation of whether an internal control procedure is being applied as designed and whether the person performing the control possesses the necessary authority and competence.
Service Auditor
An auditor who examines and issues a formal report on the internal controls implemented at a third-party service organization, such as a payroll processing provider.
User Auditor
An auditor who conducts the financial statement audit of a client entity that utilizes a third-party service organization to process financial transactions.

SOC 1 Type 1 vs Type 2 Reports
A SOC 1 Type 1 report evaluates description and design suitability of internal controls at a point in time, whereas a SOC 1 Type 2 report additionally evaluates operating effectiveness over a specified period.
Internal Control Deficiency
A condition occurring when the design or operation of a control does not allow management or employees to prevent or detect financial misstatements on a timely basis.
Design Deficiency
A control flaw that exists when a necessary control is missing or an existing control is so inadequately designed that it fails to achieve its intended objective.
Operating Deficiency
A control flaw that occurs when a properly designed control is ignored, improperly applied, or executed by personnel lacking sufficient training or authority.
Material Weakness
A deficiency, or combination of deficiencies, in internal control over financial reporting such that there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis.
Significant Deficiency
An internal control deficiency or combination of deficiencies that is less severe than a material weakness yet important enough to merit attention by those charged with governance.
Unqualified Opinion on ICFR
The audit report issued when the auditor concludes that the client maintained effective internal control over financial reporting in all material respects as of fiscal year-end.
Adverse Opinion on ICFR
The audit report issued when the auditor identifies one or more material weaknesses in internal control over financial reporting as of fiscal year-end.
Disclaimer of Opinion on ICFR
The audit report issued when the audit scope is limited and the audit team cannot perform all procedures deemed necessary to evaluate internal controls.