1/26
Vocabulary flashcards covering internal controls, the COSO framework, transaction controls, SOX 404 compliance, walkthroughs, and control deficiencies.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
COSO
The Committee of Sponsoring Organizations, which published the widely used Internal Control, Integrated Framework used to assess internal control effectiveness.
Internal Control
A process effected by an entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.
Internal Control Over Financial Reporting (ICFR)
Controls designed to provide reasonable assurance that a company's financial statements are reliable and prepared in accordance with GAAP.
Control Environment
The set of standards, processes, and structures that provides the basis for carrying out internal control across an organization, establishing the tone at the top regarding internal control and expected standards of conduct.
Risk Assessment
The process for identifying and assessing internal and external risks that may affect an organization's ability to achieve its objectives.
Control Activities
The specific actions established through policies and procedures designed to mitigate financial reporting risk and ensure management's directives are carried out.
Information and Communication
The component of internal control involving the gathering of information from internal and external sources, and the process of providing, sharing, and obtaining necessary information.
Monitoring Activities
The process of providing feedback on the effectiveness of each of the five components of internal control using ongoing evaluations, separate evaluations, or a combination of both.
Entity-Wide Controls
Controls that operate across an entire entity and affect multiple processes, transactions, accounts, and assertions, such as controls over management override and period-end reporting.
Transaction Controls
Control activities implemented to mitigate transaction processing risk that affect specific processes, transactions, accounts, and assertions.
Input Controls
Controls designed to ensure that authorized transactions are correct and complete, and that only authorized transactions can be input into the system.
Processing Controls
Controls designed to ensure that the correct program is used for processing, all transactions are processed, and transactions update appropriate files.
Output Controls
Controls designed to ensure that all data are completely processed and output is distributed only to authorized recipients.
Segregation of Duties
A control activity requiring a minimum of two employees to be involved so that no single individual has both transaction authority/ability and custodial responsibilities, protecting against fraud concealment.
Physical Controls over Assets
Control activities designed to protect and safeguard physical assets from accidental or intentional destruction and theft.
Preventive Controls
Controls designed to prevent the occurrence of a misstatement (e.g., limiting IT access); noted as being the most cost efficient.
Detective Controls
Controls designed to discover errors or misstatements that occur during processing (e.g., bank reconciliations).
Transaction Trail
Records that allow auditors to trace transactions from origination through final disposition, or vice versa.
Walkthrough
A process where management or auditors follow a transaction from origination through an organization's processes until it is reflected in financial records, combining inquiry, observation, inspection, and reperformance.
SOX Section 404(a)
A provision of the Sarbanes-Oxley Act of 2002 requiring public company management to annually report on the design and operating effectiveness of ICFR.
SOX Section 404(b)
A requirement under AS 5 (PCAOB) for an independent auditor attestation and audit of a company's internal control over financial reporting.
SOX 404(b) Exemption Criteria
Criteria exempting non-accelerated filers and SRCs with less than $100 million revenue and less than $700 million public float, or less than $75 million public float, from requiring auditor attestation.
Control Deficiency
A shortcoming in internal controls such that the objective of reliable financial reporting may not be achieved, divided into design and operation deficiencies.
Design Deficiency
A control deficiency that occurs when a control necessary to meet a control objective is missing, or an existing control is not properly designed.
Operation Deficiency
A control deficiency that occurs when a properly designed control does not operate as designed, or the person performing it lacks necessary authority or competence.
Material Weakness
A deficiency, or combination of deficiencies, in ICFR such that there is a reasonable possibility that a material misstatement of annual or interim financial statements will not be prevented or detected on a timely basis.
Significant Deficiency
A deficiency, or combination of deficiencies, in ICFR that is less severe than a material weakness, yet important enough to merit attention by those responsible for oversight of financial reporting.