COSO Framework, Internal Controls, and Audit Procedures for Students

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/46

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 9:33 PM on 9/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

47 Terms

1
New cards

What are the five components of the COSO framework (CRIME)?

Control Activities; Risk Assessment; Information and Communication; Monitoring; Control Environment.

2
New cards

What are control activities?

Systematic policies and procedures that help employees ensure reliable financial reporting.

3
New cards

What is an example of a control activity?

A manager reviews a journal entry before the accounting clerk records it.

4
New cards

What three responsibilities should be segregated under segregation of duties?

Custody; recording/reporting; authorization/approval.

5
New cards

What is risk assessment in the COSO framework?

Mechanisms the company uses to identify and think about risks.

6
New cards

What does information and communication include?

Tools such as software, resources such as budgets and training, and people in accounting and other departments who communicate accurate information.

7
New cards

What is the financial-reporting purpose of information and communication?

To help ensure the company's financial reporting is consistent with the five main assertions.

8
New cards

What is monitoring in the COSO framework?

Evaluating the system of internal controls to decide whether controls should be added, changed, or removed.

9
New cards

Who should be responsible for each control in ICFR?

Every control should have a designated person responsible for it.

10
New cards

What is the control environment?

The organization's culture of integrity and ethical behavior, including management's tone at the top and code of conduct.

11
New cards

How does the control environment affect COSO?

It affects all other parts of the framework and includes attracting, developing, and retaining good employees.

12
New cards

What are the eight steps of an audit in order?

1. Sign the engagement letter; 2. Understand the client and its business; 3. Plan the audit work; 4. Test operating effectiveness of controls, when applicable; 5. Perform substantive testing at interim; 6. Perform substantive testing at final; 7. Perform concluding audit procedures; 8. Issue the audit report(s).

13
New cards

What is step 1 of an audit?

Sign the engagement letter.

14
New cards

What is step 2 of an audit?

Understand the client and its business.

15
New cards

What is step 3 of an audit?

Plan the audit work.

16
New cards

What is step 4 of an audit?

Test the operating effectiveness of controls, when applicable.

17
New cards

What is step 5 of an audit?

Perform substantive testing at interim.

18
New cards

What is step 6 of an audit?

Perform substantive testing at final.

19
New cards

What is step 7 of an audit?

Perform concluding audit procedures.

20
New cards

What is step 8 of an audit?

Issue the audit report or reports.

21
New cards

When do auditors test the design and implementation of controls?

Always, whether the company is public or private.

22
New cards

When do auditors test the operating effectiveness of controls?

Always for a public company; sometimes for a private company.

23
New cards

Which organization sets auditing standards for private-company audits?

The AICPA.

24
New cards

Which organization oversees audits of public companies?

The PCAOB.

25
New cards

What additional audit is generally required for public companies?

An audit of internal control over financial reporting (ICFR), in addition to the financial-statement audit.

26
New cards

What is the audit-risk formula?

Audit Risk = Inherent Risk x Control Risk x Detection Risk.

27
New cards

What is a component auditor?

An auditor at another location who performs work on a group audit.

28
New cards

At what two levels must auditor independence be considered?

The individual auditor and the audit firm.

29
New cards

In what two ways must an auditor be independent?

Independent in fact and independent in appearance.

30
New cards

What is independence in fact?

A state of mind free from bias while performing the audit.

31
New cards

What is independence in appearance?

Avoiding circumstances that a reasonable person could view as compromising the auditor's independence.

32
New cards

What is a covered member?

A person who can influence an audit engagement or its outcome during the engagement period.

33
New cards

Which four groups are generally considered covered members?

1. Individuals on the audit engagement team; 2. individuals able to influence the audit; 3. partners or managers providing 10 or more hours of nonattest services to the audit client; 4. partners in the office where the lead audit partner practices in connection with the engagement.

34
New cards

What is the 10-hour covered-member rule?

A partner or manager who provides 10 or more hours of nonattest services to an audit client is generally a covered member.

35
New cards

Can auditors perform non-audit services for audit clients?

Yes, certain services are generally allowed, including tax services, debt-covenant compliance letters, and statutory audits.

36
New cards

What does in pari delicto mean?

A wrongdoer cannot recover damages from another party for failing to prevent the wrongdoing.

37
New cards

What four main things does the PCAOB do?

1. Registers accounting firms; 2. sets auditing and quality-control standards; 3. inspects registered firms; 4. conducts enforcement.

38
New cards

What is the main role of the PCAOB?

To establish auditing and quality-control standards for registered CPA firms that audit publicly traded companies.

39
New cards

What is the basic difference between the PCAOB and AICPA in the notes?

The PCAOB oversees public-company audits, while the AICPA governs private-company audit standards and practice.

40
New cards

How is the PCAOB board structured?

It has five members serving staggered five-year terms, with no more than two practicing CPAs.

41
New cards

Why can no more than two PCAOB board members be practicing CPAs?

To keep the board from being too closely tied to large accounting firms.

42
New cards

What three professional factors affect audit quality?

Competence, availability, and focus.

43
New cards

What five process factors affect audit quality?

Tone at the top and leadership; incentives; independence; infrastructure; monitoring and remediation.

44
New cards

What five result areas indicate audit quality?

Financial statements; internal control; going concern; auditor-audit committee communications; enforcement and litigation.

45
New cards

What does going concern evaluate?

Whether the company is expected to remain in business for the next 12 months.

46
New cards

Why can a financial-statement restatement signal an audit-quality problem?

A restatement may indicate that the auditor missed a material issue in the original financial statements.

47
New cards

What communication relationship is an audit-quality result indicator?

Communications between the auditors and the audit committee.