ACC 416 Exam 2: Internal Controls, COBIT & Sales Processes Flashcards | Quizlet

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/296

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:58 PM on 10/10/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

297 Terms

1
New cards
Risk
A possible event or condition that negatively affects achievement of an organization's objectives; risk must be considered when choosing strategies and designing controls.
2
New cards
Opportunity
A possible event or condition that positively affects achievement of objectives; an organization may pursue it while controlling associated risks.
3
New cards
Risk and opportunity in the same decision
One decision can produce both benefits and threats. The slide's Walmart return-policy example can attract customers and build loyalty, but can also create return fraud, extra processing costs, and inventory losses.
4
New cards
Reasons to control risk
Protect resources, support reliable information, comply with obligations, and improve the likelihood of meeting objectives. Evaluate risk before decisions and continue monitoring as conditions change.
5
New cards
Enterprise risk management (ERM)
A process carried out by the board, management, and other personnel, applied in strategy setting and across the enterprise, to identify potential events, manage risk within risk appetite, and provide reasonable assurance of achieving objectives.
6
New cards
Risk appetite
The amount and type of risk an organization is willing to accept in pursuing its objectives; ERM seeks to keep risk within this level.
7
New cards
Reasonable assurance
A high but imperfect level of confidence that objectives will be achieved; human mistakes, collusion, management override, and cost constraints prevent absolute assurance.
8
New cards
Eight ERM components
Internal environment; objective setting; event identification; risk assessment; risk response; control activities; information and communication; monitoring.
9
New cards
ERM internal environment
The organizational context for managing risk, including ethical values, risk philosophy, risk appetite, responsibilities, and management's attitude toward control.
10
New cards
ERM objective setting
Establishing objectives consistent with strategy and risk appetite before identifying and assessing events that could affect those objectives.
11
New cards
ERM event identification
Identifying internal and external events that may affect objectives and distinguishing adverse risks from favorable opportunities.
12
New cards
Risk assessment
Identifying and analyzing relevant risks; a supplemental way to assess them is to consider likelihood and impact and prioritize risks requiring attention.
13
New cards
ERM risk response
Choosing how to address a risk, such as avoiding an activity, reducing risk through controls, sharing risk through insurance or contracts, or accepting it within risk appetite.
14
New cards
Control activities
Policies and procedures that help ensure management directives and risk responses are carried out; examples include approvals, reconciliations, and access restrictions.
15
New cards
Information and communication
Identifying, capturing, and exchanging relevant information so people can perform their responsibilities; information must reach the people who need it.
16
New cards
Monitoring activities
Assessing the quality and operation of internal control over time and communicating weaknesses so they can be corrected.
17
New cards
Internal control
A process carried out by the board, management, and other personnel to provide reasonable assurance regarding achievement of organizational objectives; controls implement risk responses and may themselves be risk responses.
18
New cards
Internal control objective categories
Effectiveness and efficiency of operations; reliability of reporting; compliance with applicable laws and regulations.
19
New cards
ERM versus internal control
ERM addresses enterprise-wide risks, strategy, objectives, events, and responses; internal control provides policies and procedures supporting objectives and implementing responses.
20
New cards
Organizational governance
The arrangements through which the board and management direct the organization, oversee risk and performance, assign accountability, and protect stakeholder interests.
21
New cards
COSO
Committee of Sponsoring Organizations of the Treadway Commission; a joint initiative of five private-sector organizations that develops frameworks and guidance for ERM, internal control, and fraud deterrence.
22
New cards
COSO sponsoring organizations
American Accounting Association (AAA); American Institute of Certified Public Accountants (AICPA); Financial Executives International (FEI); Institute of Internal Auditors (IIA); Institute of Management Accountants (IMA).
23
New cards
Five COSO internal control components
Control environment; risk assessment; control activities; information and communication; monitoring activities.
24
New cards
Control environment
The organization's tone, awareness of control, and commitment to control; integrity and ethical values are central and influence whether rules are obeyed, bent, or ignored.
25
New cards
Corporate culture and controls
Shared organizational values and practices shape what actually happens; written controls are weakened when management tolerates unethical conduct or routinely ignores procedures.
26
New cards
Tone at the top
Management's ethical example and commitment to controls; strong fraud prevention requires ethical leadership and zero tolerance for fraud regardless of who commits it.
27
New cards
Sarbanes-Oxley Act of 2002 (SOX)
The slides describe SOX as creating the PCAOB, strengthening auditor independence, increasing officer and director accountability, requiring management responsibility for internal control, improving financial reporting, and increasing white-collar crime penalties.
28
New cards
PCAOB
Public Company Accounting Oversight Board; the accounting oversight board created by SOX to oversee public-company auditing.
29
New cards
SOX Section 201
Restricts nonaudit services provided by an audit firm to its audit clients; the slides emphasize prohibiting consulting engagements involving design and implementation of financial information systems to protect independence.
30
New cards
SOX Section 404
Requires an annual internal control report; the slides emphasize management assessment of control effectiveness and independent auditor testing and reporting.
31
New cards
Management's internal control assessment
Evaluate whether controls address the risk of a material financial-statement misstatement not being prevented or detected promptly; gather and evaluate evidence of control operation; present a written assessment of effectiveness.
32
New cards
Independent auditor's internal control role
Test and report on internal control effectiveness rather than simply relying on management's assertion.
33
New cards
Fraud
A deliberate act or untruth intended to obtain unfair or unlawful gain; can involve manipulating information for criminal purposes.
34
New cards
Fraud versus error
Fraud is intentional; error is unintentional. A deliberately altered invoice is fraud, while an accidental typing mistake is an error.
35
New cards
SAS No. 99
Brainstorm fraud risks, increase professional skepticism, use unpredictable audit tests, and detect management override of controls.
36
New cards
Professional skepticism
A questioning attitude and critical evaluation of evidence; do not assume information is reliable simply because management provides it.
37
New cards
Management override
Management bypassing established controls, such as directing an unauthorized journal entry; can undermine otherwise sound control procedures.
38
New cards
Computer fraud
Computer-related crime in which the computer is either the tool used to commit an illegal act or the target of the criminal, including information stored in the computer.
39
New cards
Computer as a fraud tool
The computer helps commit the illegal act; for example, using a system to create fictitious payments or manipulate accounting records.
40
New cards
Computer as a fraud target
The computer or its stored information is attacked; for example, stealing data or deliberately destroying stored records.
41
New cards
Control goal
A business-process objective that the internal control system is designed to achieve; the desired result rather than the procedure used to achieve it.
42
New cards
Control plan
An information-processing policy or procedure that helps accomplish a control goal; for example, requiring approval before a transaction is processed.
43
New cards
Control matrix
A tool that matches control goals with relevant control plans to evaluate potential effectiveness of control design in a business process.
44
New cards
Operations process control goals
Ensure effectiveness of operations, efficient employment of resources, and security of resources.
45
New cards
Effectiveness of operations
Achieving the process's intended results; goals are specific to the organization.
46
New cards
Efficient employment of resources
Using people, computers, and other resources productively with minimal unnecessary effort, time, and cost; reducing duplicate data entry is an example.
47
New cards
Security of resources
Protecting resources from loss, destruction, disclosure, copying, sale, or other misuse; covers physical assets and information such as inventory and customer master data.
48
New cards
Information process control goals
Ensure input validity (IV), input completeness (IC), input accuracy (IA), update completeness (UC), and update accuracy (UA).
49
New cards
Input validity (IV)
Only genuine, authorized, appropriate business events enter the system. A fictitious sale or an unauthorized order threatens IV.
50
New cards
Input completeness (IC)
All events that should enter the system are captured and entered without omission; an unentered customer order threatens IC.
51
New cards
Input accuracy (IA)
Entered data correctly describe the event, including amounts, quantities, dates, and identities; entering 15 instead of 51 threatens IA.
52
New cards
Update completeness (UC)
All accepted transactions that should update master data actually do so; an accepted shipment that never reduces inventory threatens UC.
53
New cards
Update accuracy (UA)
Master data are updated with correct amounts in the correct records; reducing the wrong inventory item or updating the wrong customer balance threatens UA.
54
New cards
Input versus update control goals
Input goals concern data entering the system; update goals concern accepted data changing stored records.
55
New cards
Validity versus completeness versus accuracy
Validity asks whether the event should be included; completeness asks whether all required events are included; accuracy asks whether the recorded facts are correct.
56
New cards
Pervasive control plans
Broad controls that address multiple goals and apply across many business processes, such as personnel policies, segregation of duties, and IT general controls.
57
New cards
IT general controls
A major subset of pervasive controls covering the overall IT environment, including development/change procedures, security, operations, backup, and recovery.
58
New cards
Business process control plans
Controls relating to a specific AIS process or the technology used to perform it, such as checking customer credit during order entry.
59
New cards
Application controls
A major subset of business-process controls embedded in particular applications, such as edit checks and programmed comparisons of input with master data.
60
New cards
Preventive controls
Controls designed to stop problems before they occur; examples include approval requirements, restricted access, and programmed checks that reject invalid input.
61
New cards
Detective controls
Controls designed to identify problems that have occurred; examples include reconciliations, exception reports, and reviewing missing document numbers.
62
New cards
Corrective controls
Controls designed to resolve detected problems and restore appropriate operations; examples include correcting and resubmitting rejected data or restoring damaged data from backup.
63
New cards
Control hierarchy
First level: the control environment supports overall protection. Second level: pervasive controls, including IT general controls. Third level: business-process controls, including application controls.
64
New cards
Interaction of control hierarchy levels
A strong control environment enhances pervasive and application control effectiveness; specific application checks can be undermined by weak access controls or management's disregard for procedures.
65
New cards
Suprina order-entry effectiveness goals
The Chapter 7 example identifies A: provide timely acknowledgment of customer orders; B: provide assurance of customer creditworthiness.
66
New cards
Four categories of pervasive controls
Organizational design with emphasis on segregation of duties; corporate policies with emphasis on personnel policies; monitoring controls; IT general controls.
67
New cards
Organizational design
Creating roles, processes, and formal reporting relationships; includes departmental relationships, degree of centralization, chain of command, and approval levels.
68
New cards
Centralization
Concentrating decision authority at higher organizational levels; organizational design determines how much authority is centralized or delegated.
69
New cards
Chain of command
Formal reporting relationships specifying who reports to whom and who has authority to direct or approve work.
70
New cards
Segregation of duties
Separating authorization, execution, recording, and safeguarding of resources so one person cannot control an entire event and readily conceal errors or fraud.
71
New cards
Authorizing events
Approving phases of event processing; examples include approving customer credit, inventory picking or shipment, accounting entries, and IT activities or budgets.
72
New cards
Executing events
Performing the event, physically moving resources, and completing source documents; sales examples include picking inventory, moving it to shipping, shipping it, and preparing source documents.
73
New cards
Recording events
Recording transactions in books of original entry and posting event summaries to the general ledger; recording should be separated from custody of the resources.
74
New cards
Safeguarding resources
Physically protecting assets and maintaining accountability, such as protecting inventory in storage and transit and independently counting it against recorded totals.
75
New cards
Credit-sale accounting
Record debit Accounts Receivable and credit Sales; record debit Cost of Goods Sold and credit Inventory; then post applicable summaries to the general ledger.
76
New cards
Risk from incompatible duties
A person with both custody and recording responsibilities can take assets and alter records to conceal the theft; authorization plus execution can enable unauthorized transactions.
77
New cards
Inventory custody
Concerns possession and protection of inventory.
78
New cards
Inventory accountability
Concerns independently checking quantities and comparing physical resources with recorded amounts.
79
New cards
Personnel-related business risks
Dishonest employees, incompetent employees, unmotivated or disgruntled employees, dissatisfied employees, excessive turnover, and inadequate staffing can undermine operations and controls.
80
New cards
Five personnel-policy control groups
Selection and hiring; retention; personnel development; personnel management; personnel termination.
81
New cards
Selection and hiring controls
Assess ability and integrity before hiring through aptitude assessment, references, college transcripts, aptitude testing, personal interviews, recommendation letters, and background checks.
82
New cards
Retention controls
Reduce avoidable turnover through creative and challenging work opportunities, viable career paths, and competitive reward structures.
83
New cards
Personnel development controls
Training and education plus performance evaluations help employees develop skills and identify weaknesses needing improvement.
84
New cards
Personnel management controls
Personnel planning, job descriptions, supervision, and personnel security help provide adequate staffing, clear responsibilities, oversight, and protection against employee misconduct.
85
New cards
Personnel planning
Project labor needs, forecast turnover, maintain skills information, and plan for staffing shortages so insufficient staffing does not compromise controls.
86
New cards
Job descriptions
Written responsibilities and authority for each position, helping employees understand duties and preventing incompatible responsibilities from being assigned together.
87
New cards
Supervision
Oversight of employee work to promote appropriate performance, compliance with procedures, and timely detection of mistakes.
88
New cards
Rotation of duties
Periodically changing assigned responsibilities, helping expose irregularities that could remain hidden if one employee always handles the same function.
89
New cards
Forced vacations
Requiring employees to take leave while others perform their work, which may reveal fraud or errors that depend on the employee's continuous presence.
90
New cards
Fidelity bonding
Insurance protecting the organization from certain losses caused by employee dishonesty; a personnel-security measure that transfers some financial risk.
91
New cards
Personnel termination controls
Collect keys, badges, and similar access items, cancel passwords and access, and conduct exit interviews when employees leave voluntarily or involuntarily.
92
New cards
Monitoring control plans
Management assessments that verify whether normal control plans function appropriately; establish a baseline, periodically test controls, identify changes, and communicate weaknesses.
93
New cards
Monitoring baseline
A documented understanding of an effectively operating control used to evaluate later changes or deterioration.
94
New cards
Communicating control weaknesses
Ensure identified deficiencies reach responsible personnel and appropriate management so corrective action can be taken.
95
New cards
IT department organization
The diagram separates implementation, security, and operations under the CIO, with an IT steering committee helping guide the overall IT organization.
96
New cards
IT steering committee
Guides IT in establishing and meeting user information requirements and ensuring effective and efficient use of resources.
97
New cards
Chief information officer (CIO)
The senior executive responsible for IT supporting organizational goals; designs the IT department and monitors IT services and controls.
98
New cards
IT authorization responsibilities
The steering committee and CIO approve IT activities and budgets; these duties should be separated from developing programs and operating them.
99
New cards
IT execution responsibilities
Implementation personnel create or update programs; the table includes the implementation supervisor, business analyst, systems analyst, and testing/quality assurance analyst.
100
New cards
IT recording responsibilities
Operations personnel process data received from user departments; the table associates these duties with the operations supervisor and infrastructure/network manager.