Chapter 12 - Internal Control Reporting

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:55 PM on 10/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards
What is SOX Section 404(a) and who does it apply to?
Requires management of public companies to establish, maintain, and assess the effectiveness of Internal Control Over Financial Reporting (ICFR) annually in Form 10-K.
2
New cards
What is SOX Section 404(b) and who does it apply to?
Requires the independent auditor to express an opinion on the operating effectiveness of ICFR for large public companies (accelerated filers). Non-accelerated filers and nonpublic companies are exempt.
3
New cards
What two key aspects of ICFR must management evaluate under SOX Section 404(a)?
1. Design of ICFR (whether controls prevent/detect material misstatements across assertions) ; 2. Operating effectiveness of controls (testing that controls operate as designed).
4
New cards
What is SOX Section 302 certification?
Quarterly certification signed by the CEO and CFO confirming they evaluated ICFR effectiveness and disclosed all significant deficiencies and material weaknesses to auditors and the audit committee.
5
New cards
What is an Integrated Audit under PCAOB AS 2201?
An audit combining both the financial statement audit and an audit of internal control over financial reporting (ICFR), required for large public companies.
6
New cards
What is a Control Deficiency in internal control?
A condition where the design or operation of a control does not allow management or employees to prevent, or detect and correct, misstatements on a timely basis. Example: Skipped review of bank reconciliations.
7
New cards
What is a Significant Deficiency in internal control?
An internal control deficiency, or combination of deficiencies, that is less severe than a material weakness yet important enough to merit attention by those charged with governance. Example: Inconsistent review of sales contracts.
8
New cards
What is a Material Weakness in internal control?
An internal control deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement will not be prevented, or detected and corrected, on a timely basis. Example: CFO approves unrestricted journal entries with no independent review.
9
New cards
What ICFR audit opinion is required if even ONE Material Weakness exists at year-end?
Management and auditors MUST issue an Adverse Opinion on the company's internal control over financial reporting (ICFR).
10
New cards
How is the severity of an internal control deficiency evaluated?
Evaluated based on the potential magnitude and reasonable possibility of a material misstatement occurring, NOT solely on the actual dollar amount of identified errors.
11
New cards
What are the auditor's required written communications regarding internal control deficiencies?
All significant deficiencies and material weaknesses identified during the audit must be communicated in writing to management and the audit committee (or board of directors).
12
New cards
What are IT General Controls (ITGCs) and what are their 3 main categories?
System-wide controls applying to all IT functions. 1. Access Management (passwords, firewalls) ; 2. System Change Management (approvals, user testing) ; 3. IT Operations Management (backups, disaster recovery).
13
New cards
What are IT Application Controls and what are their 3 main categories?
Controls operating at the business process level for specific applications. 1. Input Controls (preformatted screens, validity tests) ; 2. Processing Controls (reasonableness checks) ; 3. Output Controls (exception report reviews).
14
New cards
Why must auditors evaluate IT General Controls before Application Controls?
If general controls are ineffective, auditors cannot rely on automated application controls because unauthorized program changes or system crashes could compromise processing.
15
New cards
What is the difference between Pilot Testing and Parallel Testing for IT software implementation?
Pilot testing implements a new system in one part of the organization while others use the old system. Parallel testing operates old and new systems simultaneously in all locations (costliest method).
16
New cards
How should key duties be segregated within an IT department?
Separate Systems Analysts & Programmers (development) from Computer Operators (live production execution) and Data Control Clerks.
17
New cards
What is the difference between Physical Access Controls and Online Access Controls in IT?
Physical controls: Keypads, badge entry, cameras, retinal scans restricting hardware access. Online controls: Passwords, user IDs, two-factor authentication, firewalls, and encryption.
18
New cards
[Case Study: Ledger Legends] What is management's flawed argument regarding control exceptions?
Management argued a control failure was not a material weakness because actual identified errors were below overall materiality. Rule: Severity is judged by potential misstatement risk, not just identified error dollars.
19
New cards
[Case Study: The Fraud Squad] What COSO breakdowns allowed founder fraud?
Control Environment failure (founder dominance, non-independent internal audit reporting to founder) and Control Activity breakdowns (shared credentials, no dollar approval thresholds, override capability).
20
New cards