Chapter 3: Internal Control over Financial Reporting

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/29

flashcard set

Earn XP

Description and Tags

A complete set of vocabulary flashcards covering internal control over financial reporting, the COSO framework, control deficiency levels, and management/auditor responsibilities.

Last updated 6:49 PM on 10/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

30 Terms

1
New cards

Internal Control over Financial Reporting (ICFR)

Policies and procedures established by an organization to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements.

2
New cards

COSO Internal Control–Integrated Framework

The most widely used internal control framework, defining internal control as a process carried out by the board of directors, management, and other personnel to provide reasonable assurance regarding operations, reporting, and compliance objectives.

3
New cards

Control Environment

The component of internal control that serves as the foundation for all other components and sets the organizational tone, starting with executive leadership, the board of directors, and the audit committee.

4
New cards

Risk Assessment

The COSO internal control component that involves identifying and analyzing internal and external risks that could prevent an organization from achieving its financial reporting objectives.

5
New cards

Control Activities

Policies and procedures that help ensure management's internal control directives are carried out to mitigate identified risks.

6
New cards

Information & Communication

The component of internal control responsible for identifying, capturing, and transferring relevant information in a timely manner to help personnel fulfill their internal control responsibilities.

7
New cards

Monitoring

The component that acts as a feedback loop to evaluate whether all five COSO components of internal control are present and continue to operate effectively over time.

8
New cards

Entity - Wide Controls vs Transaction Controls

Entity-wide controls affect the organization broadly, have a pervasive effect, and can impact multiple accounts and assertions. Transaction controls affect specific transactions or processes and address specific processing risks.

<p>Entity-wide controls affect the organization broadly, have a pervasive effect, and can impact multiple accounts and assertions. Transaction controls affect specific transactions or processes and address specific processing risks.</p>
9
New cards

Transaction Controls Target Areas

The three main financial reporting areas targeted by transaction controls to ensure complete, accurate, and valid records: Business Process Transactions, Accounting Estimates, and Adjusting/Closing/Unusual Entries.

<p>The three main financial reporting areas targeted by transaction controls to ensure complete, accurate, and valid records: Business Process Transactions, Accounting Estimates, and Adjusting/Closing/Unusual Entries.</p>
10
New cards

Management's Evaluation Process for ICFR

A three-step risk-based approach where management identifies risks and controls, evaluates control operating effectiveness, and reports on overall internal control effectiveness.

<p>A three-step risk-based approach where management identifies risks and controls, evaluates control operating effectiveness, and reports on overall internal control effectiveness.</p>
11
New cards

Materiality

The threshold at which a misstatement could influence the decisions of someone relying on financial information, determined using professional judgment and considering quantitative and qualitative factors.

12
New cards

Fraud Triangle

A framework evaluated during fraud risk assessment consisting of three factors: Pressure/Incentive, Opportunity, and Rationalization.

13
New cards

Input Controls

Automated application controls designed to ensure that data entry into an IT system is authorized and complete.

14
New cards

Processing Controls

Automated controls designed to ensure that the correct program is used and that transactions accurately update the correct files.

15
New cards

Output Controls

Automated controls designed to ensure that system reports and outputs are distributed only to authorized recipients.

16
New cards

Segregation of Duties

A critical internal control activity that separates record-keeping, authorization, and physical custody to prevent a single person from committing and concealing fraud.

17
New cards

Preventive Controls

Internal controls designed to stop a misstatement before it occurs, generally considered the most cost-efficient type of control.

18
New cards

Detective Controls

Internal controls designed to discover errors or misstatements after processing has occurred.

19
New cards

General Controls Over Technology

Controls covering technology infrastructure, security management, and acquisition/development/maintenance that are required for automated application controls to function properly.

20
New cards

Policies vs Procedures

Policies outline what management expects to happen, whereas procedures are the specific operational tasks that put policies into action.

21
New cards

Whistleblower Function

A communication mechanism allowing employees to anonymously report financial or ethical violations while bypassing traditional management channels.

22
New cards

Ongoing Evaluations

Monitoring procedures integrated directly into normal, day-to-day operational activities, such as software that continuously flags statistical anomalies in transactions.

23
New cards

Separate Evaluations

Periodic internal control evaluations conducted by objective personnel, such as internal audit deep-dive audits, to provide a fresh assessment.

24
New cards

Foreign Corrupt Practices Act (FCPA)

A law prohibiting payments or bribes to foreign officials and requiring companies to maintain internal controls over payments, approvals, vendors, and payroll.

25
New cards

Sarbanes-Oxley Act - Section 302

A statutory requirement for U.S. public companies that places explicit responsibility for internal controls on signing corporate officers, typically the CEO and CFO.

26
New cards

Sarbanes-Oxley Act - Section 404

A provision requiring external auditors of large U.S. public companies to perform an integrated audit and provide an opinion on internal control effectiveness.

27
New cards

Control Deficiency

A shortcoming in internal control where reliable financial reporting may not be achieved.

28
New cards

Significant Deficiency

An internal control deficiency important enough to merit attention by management and the audit committee, but not severe enough to be a material weakness or require external reporting.

29
New cards

Material Weakness

A severe control deficiency or combination of deficiencies resulting in a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis.

30
New cards

Integrated Audit

An audit conducted for large U.S. public companies under SOX Section 404 where the auditor provides opinions on both internal control effectiveness and the financial statements.