Internal Audit Control and Risk Management

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/32

flashcard set

Earn XP

Description and Tags

Flashcards covering fundamental concepts of risk management, internal control systems, COSO frameworks, ISO guidelines, governance structures, and auditing principles.

Last updated 3:06 AM on 9/24/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

33 Terms

1
New cards

How is risk defined and characterized in a financial context?

Risk is characterized as the possibility of an adverse event and involves uncertainty regarding the effects of an activity on something of value. In a financial context, risk measures the deviation from expected earnings and the level of uncertainty an investor is willing to accept to realize gains.

2
New cards

What is market risk, and what main sub-types does it include?

Market risk is the risk of investment value declining due to economic developments or market-wide events. It includes equity risk (price drops in shares), interest rate risk (impact on bond values), and currency risk (exchange rate movements).

3
New cards

What is liquidity risk?

Liquidity risk is the inability to sell an investment at a fair price when desired, which may require accepting a lower price or being unable to sell the investment at all.

4
New cards

How is concentration risk defined?

Concentration risk is the risk of loss resulting from having money concentrated in a single investment, industry, or geographic location.

5
New cards

What is credit risk, and how can it be evaluated?

Credit risk is the risk that a government entity or company issuing a bond will run into financial difficulties and fail to pay interest or repay principal at maturity. It can be evaluated by looking at credit ratings (e.g., AAA indicates the lowest possible credit risk).

6
New cards

What is reinvestment risk?

Reinvestment risk is the risk of loss from reinvesting principal or income at a lower interest rate than the original investment.

7
New cards

What is inflation risk?

Inflation risk is the loss in purchasing power because investment returns do not keep pace with inflation over time.

8
New cards

What is horizon risk?

Horizon risk is the risk that an investment horizon is shortened due to an unforeseen event (e.g., job loss), forcing the sale of long-term investments early during market downturns.

9
New cards

What is longevity risk?

Longevity risk is the risk of outliving one's savings, which is particularly relevant for people who are retired or nearing retirement.

10
New cards

What is foreign investment risk?

Foreign investment risk involves risks unique to investing in foreign countries, such as the risk of nationalization in emerging markets.

11
New cards

What are the five crucial components of a risk management framework?

The five crucial components are Context Understanding, Risk Identification, Risk Measurement and Assessment, Risk Mitigation, and Risk Reporting and Monitoring (supported by Risk Governance).

12
New cards

What is the distinction between core risks and non-core risks?

Core risks are essential risks taken to drive performance and long-term growth, whereas non-core risks are non-essential risks that should be minimized or eliminated.

13
New cards
<p>What tool is used in risk measurement and assessment to plot risks based on Impact and Likelihood?</p>

What tool is used in risk measurement and assessment to plot risks based on Impact and Likelihood?

A Heat Map is used to plot risks based on Impact (measured by financial effect, reputation damage, and ability to achieve objectives) and Likelihood (probability of occurrence over a predefined period).

14
New cards

What are the five key strategies for risk mitigation?

The strategies are Avoidance (ending the activity), Reduction (lowering risk level), Sharing (transferring loss potential), Retention (accepting the risk), and Exploitation (pursuing high return on investment).

15
New cards
<p>What three dimensions make up the COSO Enterprise Risk Management (ERM) framework model?</p>

What three dimensions make up the COSO Enterprise Risk Management (ERM) framework model?

The three dimensions of the COSO Cube link Objectives (Strategic, Operations, Reporting, Compliance), Organizational Levels (Entity-level, Division, Business Unit, Subsidiary), and Components (Internal Environment, Objective Setting, Event Identification, Risk Assessment, Risk Response, Control Activities, Information & Communication, Monitoring).

16
New cards
<p>What is the focus of the ISO 31000:2018 Risk Management Guidelines?</p>

What is the focus of the ISO 31000:2018 Risk Management Guidelines?

ISO 31000:2018 focuses on the design, implementation, monitoring, and continual improvement of the risk management process through a mandate of commitment from leadership.

17
New cards

What are the four elements of internal control in the CoCo framework?

Developed by CICA, the four elements are Purpose, Commitment, Capability, and Monitoring & Learning.

18
New cards

What key internal control concept was established in the UK's Turnbull Report?

Originating by Nigel Turnbull, it emphasizes that a sound internal control system should be embedded within operations, respond to changing risks, and include procedures for reporting failings.

19
New cards
<p>What framework created by ISACA focuses specifically on IT governance and management?</p>

What framework created by ISACA focuses specifically on IT governance and management?

COBIT 2019 focuses specifically on the governance and management of Information & Technology, considering design factors such as enterprise strategy, threat landscape, and technology adoption methods.

20
New cards

What are the three main objectives of internal control systems?

The three main objectives are Operations (effectiveness, efficiency, safeguarding assets), Reporting (reliability, timeliness, transparency of financial/non-financial data), and Compliance (adherence to laws and regulations).

21
New cards

How do Preventive, Detective, Directive, and Corrective controls differ?

Preventive controls stop undesirable outcomes; Detective controls identify when an undesirable outcome has occurred; Directive controls ensure a particular outcome is achieved; Corrective controls limit loss scope and recover from damage.

22
New cards

What is the difference between compensatory and complementary secondary controls?

Compensatory (mitigative) controls reduce risk when primary controls are ineffective but are not sufficient alone, whereas complementary controls work in tandem with other controls to reduce risk to an acceptable level.

23
New cards

What is the distinction between Inherent Risk and Residual Risk?

Inherent Risk is the risk level before management takes any action to alter its likelihood or impact, whereas Residual Risk is the risk remaining after management has implemented risk responses (controls).

24
New cards

How do Risk Appetite and Risk Tolerance differ?

Risk Appetite is the broad amount of risk an entity is willing to accept in pursuit of value, while Risk Tolerance is the specific maximum risk an organization is willing to take regarding a specific risk.

25
New cards
<p>What is ISO 9001?</p>

What is ISO 9001?

ISO 9001 is a quality management standard designed to help organizations meet customer requirements and improve service and product quality.

26
New cards

How is corporate governance defined and regulated in the Philippines?

Corporate governance is defined as the system of stewardship and control used to guide organizations in fulfilling long-term economic, moral, legal, and social obligations. In the Philippines, it is regulated by the SEC through the Code of Corporate Governance for Publicly-Listed Companies (Memorandum Circular No. 19, November 22, 2016).

27
New cards

What are the key differences between Independent, Executive, and Non-Executive Directors?

Independent Directors have no interests or relationships that could interfere with judgment; Executive Directors are part of the management team; Non-Executive Directors do not have management responsibilities.

28
New cards

What are the composition requirements for an Audit Committee?

An Audit Committee must have at least three non-executive directors; the majority (including Chairman) must be independent; members must have accounting, auditing, and finance background; and the Audit Committee Chairman cannot be Chairman of the Board or any other committee.

29
New cards

What is the difference between Assurance and an Audit?

Assurance is an engagement where a practitioner expresses a conclusion designed to increase user confidence about an evaluation against criteria. An Audit is an objective examination of factual evidence intended to provide independent and reasonable assurance against established criteria.

30
New cards

Who is the Chief Audit Executive (CAE)?

The CAE is the senior position responsible for managing the internal audit activity in accordance with the internal audit charter, the Definition of Internal Auditing, the Code of Ethics, and relevant Standards.

31
New cards

How do Internal Audit and External Audit compare regarding standards and primary goals?

Internal Audit follows IIA's IPPF to provide financial, operational, and consultative assurance to improve operations. External Audit follows international or local auditing standards to attest to the fairness of financial statements for external stakeholders.

32
New cards

What are the dual reporting lines for an internal audit function?

Administrative Reporting is to the President or CEO for day-to-day operations. Functional Reporting is to the Audit Committee to ensure auditors operate independently of management.

33
New cards
<p>What are the roles of the 1st, 2nd, and 3rd lines of defense in the Three Lines of Defense Model?</p>

What are the roles of the 1st, 2nd, and 3rd lines of defense in the Three Lines of Defense Model?

1st Line (Operational Managers): Risk owners who execute day-to-day controls and corrective actions. 2nd Line (Risk Management, Compliance, Security): Ensures 1st line controls are designed and operating properly. 3rd Line (Internal Audit): Provides independent and objective risk assurance to senior management and the BOD.