Chapter 3- Acc 3300

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/47

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 3:44 PM on 8/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

48 Terms

1
New cards

What is the primary aim of internal control?

To mitigate identified risks to the company's financial information.

2
New cards

What are the three functions of internal controls?

Preventing, detecting, and correcting risks.

3
New cards

What type of controls are proactive and prevent problems from occurring?

Preventive controls.

4
New cards

What is an example of a preventive control?

Segregation of duties.

5
New cards

What are detective controls designed to do?

Alert management to issues once they have occurred.

6
New cards

What is the role of corrective controls?

To change undesirable outcomes after a risk has materialized.

7
New cards

What does management override refer to?

When internal control activities fail because management does not follow policies or procedures.

8
New cards

How does the time-based model of controls measure effectiveness?

By comparing the relationship of preventive, detective, and corrective control functions.

9
New cards

What are the three locations for controls?

Physical controls, IT general controls (ITGCs), and IT application controls.

10
New cards

What are entity-level controls?

Controls that oversee and influence the effectiveness of internal controls across the entire organization.

11
New cards

What are IT general controls (ITGCs)?

Controls that apply to the entire operation of the full system and its environment.

12
New cards

What distinguishes IT application controls?

They apply only to specific applications and the business processes linked to them.

13
New cards

What are the two methods of implementing a control?

Manual and automated.

14
New cards

Why are manual controls still significant?

They are used when human judgment or physical interaction is required.

15
New cards

What is an example of an automated control?

Using drones to scan inventory and directly import data into the system.

16
New cards

What is continuous monitoring in the context of internal controls?

A process that uses data analytics to monitor business data for risks.

17
New cards

What is the importance of frameworks in an internal control environment?

They provide structure and guidance for implementing effective controls.

18
New cards

What is the significance of segregation of duties?

It reduces the risk of error and fraud by ensuring different employees handle different parts of business activities.

19
New cards

What is the purpose of exception report reviews?

To identify problems and provide evidence of errors or irregularities.

20
New cards

What does the acronym AIS stand for?

Accounting Information Systems.

21
New cards

What is the relationship between preventive and detective controls?

Preventive controls aim to stop issues before they occur, while detective controls identify issues after they happen.

22
New cards

What are the characteristics that define a control?

Its function, location, and implementation method.

23
New cards

What is the role of internal auditors in continuous monitoring?

They use technology to create detective controls that monitor data for risks.

24
New cards

What is the risk associated with management override?

It can lead to the failure of internal controls.

25
New cards

How can collusion among employees affect internal controls?

It can circumvent controls and lead to increased risk of fraud.

26
New cards

What is the main goal of risk management in internal controls?

To ensure the reliability, completeness, and validity of financial information.

27
New cards

What do IT General Controls (ITGCs) apply to?

The entire operation of the full system and its environment.

28
New cards

What is an IT Application Control?

A control that applies only to a specific application, including all linked business processes and accounts.

29
New cards

What is a manual control?

A control that requires human judgment or physical interaction.

30
New cards

What is an automated control?

A control that uses technology to implement control activities.

31
New cards

What is continuous monitoring in internal controls?

A process using technology to create detective controls that monitor data for risks.

32
New cards

What are the three lines of defense in internal controls?

First line: Business operations, Second line: Risk Management and Compliance, Third line: Internal Audit.

33
New cards

What is the role of management in the first and second lines of defense?

Management controls business processes and mitigates risk through preventive, detective, and corrective actions.

34
New cards

What does a maturity model show?

How far along a company is on its journey to reach the ideal state compared to best practices.

35
New cards

What characterizes Phase 1 of a maturity model?

Limited: Business processes are poorly defined.

36
New cards

What characterizes Phase 2 of a maturity model?

Informal: Some processes are defined, but inconsistencies and reliance on key individuals exist.

37
New cards

What characterizes Phase 3 of a maturity model?

Defined: Policies and procedures are formally documented.

38
New cards

What characterizes Phase 4 of a maturity model?

Optimized: Considered the gold standard in business process maturity.

39
New cards

What is the role of Internal Audit?

To provide assurance, insight, and objectivity while remaining independent of the functions they audit.

40
New cards

What is the purpose of the Sarbanes-Oxley Act of 2002 (SOX)?

To protect investors from fraud by improving the reliability and accuracy of financial statements.

41
New cards

Who is required to comply with SOX?

Publicly traded companies in the U.S., their subsidiaries, foreign companies publicly traded in the U.S., and private companies planning IPOs.

42
New cards

What is the COSO Framework?

A framework used for SOX compliance that provides guidance on internal controls.

43
New cards

What are the key parts of the COSO Framework?

Control objectives and control components.

44
New cards

What are the three areas of focus for control objectives in the COSO Framework?

Operations objectives, Reporting objectives, Compliance objectives.

45
New cards

What are the five key steps to implementing effective internal controls?

Control components and their related principles.

46
New cards

What does the COSO Cube represent?

How all parts of the Internal Control - Integrated Framework are related.

47
New cards

What is the ERM Framework?

Enterprise Risk Management Framework that highlights the importance of risk in creating strategies and driving performance.

48
New cards

What is the significance of frameworks in internal control environments?

They provide a set of specifications and criteria to achieve objectives and act as a roadmap for businesses.