Internal Controls and COSO Framework Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/26

flashcard set

Earn XP

Description and Tags

Vocabulary flashcards covering internal controls, the COSO framework, transaction controls, SOX 404 compliance, walkthroughs, and control deficiencies.

Last updated 3:38 AM on 9/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

27 Terms

1
New cards

COSO

The Committee of Sponsoring Organizations, which published the widely used Internal Control, Integrated Framework used to assess internal control effectiveness.

2
New cards

Internal Control

A process effected by an entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.

3
New cards

Internal Control Over Financial Reporting (ICFR)

Controls designed to provide reasonable assurance that a company's financial statements are reliable and prepared in accordance with GAAP.

4
New cards

Control Environment

The set of standards, processes, and structures that provides the basis for carrying out internal control across an organization, establishing the tone at the top regarding internal control and expected standards of conduct.

5
New cards

Risk Assessment

The process for identifying and assessing internal and external risks that may affect an organization's ability to achieve its objectives.

6
New cards

Control Activities

The specific actions established through policies and procedures designed to mitigate financial reporting risk and ensure management's directives are carried out.

7
New cards

Information and Communication

The component of internal control involving the gathering of information from internal and external sources, and the process of providing, sharing, and obtaining necessary information.

8
New cards

Monitoring Activities

The process of providing feedback on the effectiveness of each of the five components of internal control using ongoing evaluations, separate evaluations, or a combination of both.

9
New cards

Entity-Wide Controls

Controls that operate across an entire entity and affect multiple processes, transactions, accounts, and assertions, such as controls over management override and period-end reporting.

10
New cards

Transaction Controls

Control activities implemented to mitigate transaction processing risk that affect specific processes, transactions, accounts, and assertions.

11
New cards

Input Controls

Controls designed to ensure that authorized transactions are correct and complete, and that only authorized transactions can be input into the system.

12
New cards

Processing Controls

Controls designed to ensure that the correct program is used for processing, all transactions are processed, and transactions update appropriate files.

13
New cards

Output Controls

Controls designed to ensure that all data are completely processed and output is distributed only to authorized recipients.

14
New cards

Segregation of Duties

A control activity requiring a minimum of two employees to be involved so that no single individual has both transaction authority/ability and custodial responsibilities, protecting against fraud concealment.

15
New cards

Physical Controls over Assets

Control activities designed to protect and safeguard physical assets from accidental or intentional destruction and theft.

16
New cards

Preventive Controls

Controls designed to prevent the occurrence of a misstatement (e.g., limiting IT access); noted as being the most cost efficient.

17
New cards

Detective Controls

Controls designed to discover errors or misstatements that occur during processing (e.g., bank reconciliations).

18
New cards

Transaction Trail

Records that allow auditors to trace transactions from origination through final disposition, or vice versa.

19
New cards

Walkthrough

A process where management or auditors follow a transaction from origination through an organization's processes until it is reflected in financial records, combining inquiry, observation, inspection, and reperformance.

20
New cards

SOX Section 404(a)

A provision of the Sarbanes-Oxley Act of 2002 requiring public company management to annually report on the design and operating effectiveness of ICFR.

21
New cards

SOX Section 404(b)

A requirement under AS 5 (PCAOB) for an independent auditor attestation and audit of a company's internal control over financial reporting.

22
New cards

SOX 404(b) Exemption Criteria

Criteria exempting non-accelerated filers and SRCs with less than $100 million\$100\text{ million} revenue and less than $700 million\$700\text{ million} public float, or less than $75 million\$75\text{ million} public float, from requiring auditor attestation.

23
New cards

Control Deficiency

A shortcoming in internal controls such that the objective of reliable financial reporting may not be achieved, divided into design and operation deficiencies.

24
New cards

Design Deficiency

A control deficiency that occurs when a control necessary to meet a control objective is missing, or an existing control is not properly designed.

25
New cards

Operation Deficiency

A control deficiency that occurs when a properly designed control does not operate as designed, or the person performing it lacks necessary authority or competence.

26
New cards

Material Weakness

A deficiency, or combination of deficiencies, in ICFR such that there is a reasonable possibility that a material misstatement of annual or interim financial statements will not be prevented or detected on a timely basis.

27
New cards

Significant Deficiency

A deficiency, or combination of deficiencies, in ICFR that is less severe than a material weakness, yet important enough to merit attention by those responsible for oversight of financial reporting.