1/29
A complete set of vocabulary flashcards covering internal control over financial reporting, the COSO framework, control deficiency levels, and management/auditor responsibilities.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Internal Control over Financial Reporting (ICFR)
Policies and procedures established by an organization to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements.
COSO Internal Control–Integrated Framework
The most widely used internal control framework, defining internal control as a process carried out by the board of directors, management, and other personnel to provide reasonable assurance regarding operations, reporting, and compliance objectives.
Control Environment
The component of internal control that serves as the foundation for all other components and sets the organizational tone, starting with executive leadership, the board of directors, and the audit committee.
Risk Assessment
The COSO internal control component that involves identifying and analyzing internal and external risks that could prevent an organization from achieving its financial reporting objectives.
Control Activities
Policies and procedures that help ensure management's internal control directives are carried out to mitigate identified risks.
Information & Communication
The component of internal control responsible for identifying, capturing, and transferring relevant information in a timely manner to help personnel fulfill their internal control responsibilities.
Monitoring
The component that acts as a feedback loop to evaluate whether all five COSO components of internal control are present and continue to operate effectively over time.
Entity - Wide Controls vs Transaction Controls
Entity-wide controls affect the organization broadly, have a pervasive effect, and can impact multiple accounts and assertions. Transaction controls affect specific transactions or processes and address specific processing risks.

Transaction Controls Target Areas
The three main financial reporting areas targeted by transaction controls to ensure complete, accurate, and valid records: Business Process Transactions, Accounting Estimates, and Adjusting/Closing/Unusual Entries.

Management's Evaluation Process for ICFR
A three-step risk-based approach where management identifies risks and controls, evaluates control operating effectiveness, and reports on overall internal control effectiveness.

Materiality
The threshold at which a misstatement could influence the decisions of someone relying on financial information, determined using professional judgment and considering quantitative and qualitative factors.
Fraud Triangle
A framework evaluated during fraud risk assessment consisting of three factors: Pressure/Incentive, Opportunity, and Rationalization.
Input Controls
Automated application controls designed to ensure that data entry into an IT system is authorized and complete.
Processing Controls
Automated controls designed to ensure that the correct program is used and that transactions accurately update the correct files.
Output Controls
Automated controls designed to ensure that system reports and outputs are distributed only to authorized recipients.
Segregation of Duties
A critical internal control activity that separates record-keeping, authorization, and physical custody to prevent a single person from committing and concealing fraud.
Preventive Controls
Internal controls designed to stop a misstatement before it occurs, generally considered the most cost-efficient type of control.
Detective Controls
Internal controls designed to discover errors or misstatements after processing has occurred.
General Controls Over Technology
Controls covering technology infrastructure, security management, and acquisition/development/maintenance that are required for automated application controls to function properly.
Policies vs Procedures
Policies outline what management expects to happen, whereas procedures are the specific operational tasks that put policies into action.
Whistleblower Function
A communication mechanism allowing employees to anonymously report financial or ethical violations while bypassing traditional management channels.
Ongoing Evaluations
Monitoring procedures integrated directly into normal, day-to-day operational activities, such as software that continuously flags statistical anomalies in transactions.
Separate Evaluations
Periodic internal control evaluations conducted by objective personnel, such as internal audit deep-dive audits, to provide a fresh assessment.
Foreign Corrupt Practices Act (FCPA)
A law prohibiting payments or bribes to foreign officials and requiring companies to maintain internal controls over payments, approvals, vendors, and payroll.
Sarbanes-Oxley Act - Section 302
A statutory requirement for U.S. public companies that places explicit responsibility for internal controls on signing corporate officers, typically the CEO and CFO.
Sarbanes-Oxley Act - Section 404
A provision requiring external auditors of large U.S. public companies to perform an integrated audit and provide an opinion on internal control effectiveness.
Control Deficiency
A shortcoming in internal control where reliable financial reporting may not be achieved.
Significant Deficiency
An internal control deficiency important enough to merit attention by management and the audit committee, but not severe enough to be a material weakness or require external reporting.
Material Weakness
A severe control deficiency or combination of deficiencies resulting in a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis.
Integrated Audit
An audit conducted for large U.S. public companies under SOX Section 404 where the auditor provides opinions on both internal control effectiveness and the financial statements.