watching tarzan on vhs

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/121

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 9:01 PM on 9/20/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

122 Terms

1
New cards

accounting information system (AIS)

An information system that performs data collection, transformation, and reporting that is specific to financial data. It captures accounting data created by business events (or activities) that involve an exchange of economic resources.

2
New cards

information system

A system that consists of interrelated components including physical hardware like monitors and laptops, the software that users interact with, databases used for storage, networks that send data and information throughout the system, and the people who use and maintain it.

3
New cards

input

In an information system, raw and unorganized data captured by the system.

4
New cards

output

In information systems, information that comes from a system in a format that is useful to users.

5
New cards

business event

A single business activity in a business process that takes place during the normal operation of a business. Examples of __s include “Sell goods to customer” and “Purchase equipment from vendor.” These give rise to accounting transactions if they involve an exchange of economic resources that impacts the accounting equation. Also called a business activity.

6
New cards

business model

A company’s plan for operations. It identifies the customer base, products, operation plans, and sources of revenue and financing.

7
New cards

franchise business model

A business model in which individuals purchase and run a franchise, such as a franchise of a popular fast food chain (for example, McDonald’s).

8
New cards

subscription business model

A business model that involves charging a monthly subscription fee for unlimited access to a service or product (for example, Netflix).

9
New cards

freemium business model

A business model that involves offering free services but charging a fee to access upgraded features (for example, Dropbox).

10
New cards

fundamental characteristics

The two characteristics that are required to make information useful for decision making, according to the Financial Accounting Standards Board (FASB)

11
New cards

information event

A business event that involves an exchange of information and never involves an exchange of economic resources.

12
New cards

information quality

The suitability of information for a particular purpose in a specific task.

13
New cards

information system

A system that consists of interrelated components including physical hardware like monitors and laptops, the software that users interact with, databases used for storage, networks that send data and information throughout the system, and the people who use and maintain it.

14
New cards

investing event

A business event that provides long-term value to a company by purchasing long-term assets that will deliver value in the future.

15
New cards

key performance indicator (KPI)

A quantifiable metric used to measure and evaluate the success of a company based on its objectives.

16
New cards

operating event

A business event that occurs during the normal operations of a company and directly relates to the company’s creation and provision of a good or service to its customers.

17
New cards

peer-to-peer business model

A business model that connects individuals with one another (for example, Airbnb).

18
New cards

process-based information system

An information system that captures all the data of interest generated in a business process, including informational events.

19
New cards

purpose of a business

The goal of making a profit and generating enough cash flow to continue operating. Without the profit motive, a business would not be a business (at least not for very long).

20
New cards

reporting

The process of aggregating data into information on the activities and performance in a company. ___ provides a strictly descriptive view of what happened and does not seek insights into the context or reasons.

21
New cards

retailer business model

A business model in which a manufacturer sells goods to a retailer to sell to consumers on its behalf.

22
New cards

subscription business model

A business model that involves charging a monthly subscription fee for unlimited access to a service or product (for example, Netflix).

23
New cards

transaction-based AIS

A traditional information system that captures only accounting business events and ignores nonfinancial data and the relationships between business events and business processes.

24
New cards

actual residual risk

The risk that actually remains after a risk is addressed.

25
New cards

business function

A high-level business area or department that performs business processes to achieve company goals. More than one __ may be necessary to complete a single business process.

26
New cards

compliance risk

Risk that occurs when a company fails to follow regulation and legislation and is subjected to legal penalties, including fines.

27
New cards

cyber risk

A unique type of technology risk that occurs when an external party accesses a company’s technology assets and performs unauthorized actions that are malicious. For example, cyberattacks can cause data breaches or lock down a company’s systems and hold them for ransom. Attackers may simply mean to prove that they have the skill needed to perform attacks successfully.

28
New cards

enterprise risk management (ERM)

The comprehensive process of identifying, categorizing, prioritizing, and responding to a company’s risks. It involves creating a formal risk assessment and plans for addressing the risks.

29
New cards

external risk

A risk that is not related to business operations and comes from outside a company. __ are not related to business operations. While _ are often unpredictable, companies still prepare for them to the best of their abilities.

30
New cards

financial risk

A risk specifically related to money going into and out of a company and the potential loss of a substantial sum. This type of risk is associated with various types of financial transactions, including investments, sales, purchases, and loans.

31
New cards

heat map

A type of risk matrix that uses different colors to represent values of data in a map or diagram format. The different colors in the risk matrix heat map typically represent the priority of a risk based on the risk score; for example, green may indicate a lower priority and red a higher priority.

32
New cards

impact

The estimation of damage that could be caused if a risk occurs. It is equivalent to the outcome in a risk statement.

33
New cards

inherent risk

The natural level of risk in a business process or activity if there are no risk responses in place. It is the risk before implementing a risk response. __ consists of two parts

34
New cards

internal risk

A risk that occurs throughout a company’s operations and arises during normal operations. Most __s are preventable through careful risk identification and management. Note that an internal risk may relate to an external party, such as the company’s reputation with customers.

35
New cards

likelihood

The estimated probability of risk occurrence. Companies use different methods to calculate _, but is always ranked on a spectrum. In different industries, _ is described as “frequency” or “probability”; these terms are synonymous.

36
New cards

purpose of a business

The goal of making a profit and generating enough cash flow to continue operating. Without the profit motive, a business would not be a business (at least not for very long).

37
New cards

operational risk

The most important type of risk for an AIS, which occurs during day-to-day business operations and causes breakdowns in business activities. These risks are a priority for an AIS because they result from inadequate or failed procedures within the company.

38
New cards

physical risk

A threat such as adverse weather, crime, or physical damage. __ is the easiest type of risk to understand, and it is one of the most important types of risk to identify because the impact is usually high. The losses from physical risks range from financial loss to legal actions and reputational loss due to mismanagement of assets.

39
New cards

portfolio view

A view of risk that examines risk at the entity level.

40
New cards

profile view

A view of risk that considers risk at the granular level of a business function, process, or event.

41
New cards

reputational risk

Risk that occurs when the reputation—or good name—of a company is damaged. With reputational risk comes financial loss through a loss of customers and revenue. __ can be both internal and external in nature. The exact financial loss tied to a __ is hard to quantify, but reputation is so important to a company that in accounting it is considered an intangible asset.

42
New cards

residual risk

The remaining risk posed by a process or an activity once a plan to respond to the risk is in place. It is the risk after implementing a risk response.

43
New cards

risk

The likelihood of an unfavorable event occurring. __s differ by business type, size, industry, and location.

44
New cards

risk acceptance

A risk response in which an inherent risk is present but the organization chooses not to act. The company chooses to live with the risk.

45
New cards

risk appetite

The amount of risk a company is willing to take on at a particular time.

46
New cards

risk assessment

An assessment that identifies, categorizes, and prioritizes individual risks in a company. After assessing risk, management decides how to manage it.

47
New cards

risk avoidance

A risk response that involves eliminating the risk by completely avoiding the events causing the risk. Rather than accept or reduce risk, companies avoid risk when it is both significant and highly likely to occur.

48
New cards

risk inventory

A listing of all a business’s known risks. A __ is an essential part of approaching risk at the entity level and creating a portfolio view.

49
New cards

risk matrix

A diagram that helps paint a clearer picture of risk by helping users visualize variations in risk scores. Using a __ allows management to plot risk and move prioritization around; it is especially helpful for risks that are scored the same numerically.

50
New cards

risk mitigation

The most commonly used risk response. It involves reducing risk based on careful consideration and calculation. __ enables a company to take on risks in order to create a competitive advantage.

51
New cards

risk severity

The likelihood of risks occurring and their potential impact on a company.

52
New cards

risk statement

A statement that summarizes a potential problem that needs to be addressed. It contains two parts: the issue and the possible outcome. The outcome of a risk varies greatly, from delaying the launch of an information system to preventing the success of an entire company.

53
New cards

risk transfer

A risk response that involves shifting a risk to a third party. In other words, a third party assumes the liabilities for the risk. Most often, this is done through a contract, such as an insurance policy.

54
New cards

strategic risk

The inevitable risk that results when a strategy becomes less effective. Companies constantly update their strategies—and change their risks—to stay ahead of the competition. Adopting new technology, overhauling a product design, and changing vendors to avoid high costs of materials are all examples of companies taking proactive measures to avoid strategic risk.

55
New cards

target residual risk

The goal level of residual risk after implementing a risk response.

56
New cards

technology risk

A specific subset of operational risk that exists when technology failures have the potential to disrupt business. Technology failures include threats, vulnerabilities, and exposures of information.

57
New cards

application

A type of software that allows end users to perform specific functions. _ software may be designed for general use or a specific function. It may also be custom developed for a specific function.

58
New cards
application control

A control that only applies to a specific application, including all the business processes and accounts that are linked to it. __s in an AIS can be called transaction controls because they relate specifically to accounting transaction processing.

59
New cards

audit committee

A committee of a company’s board of directors that includes outside committee members with special qualifications in finance or accounting. The ___ provides objective oversight of a company’s financial reporting, internal controls, and regulatory compliance, and the company’s internal audit department should have a direct line of communication to this committee.

60
New cards

automated control

A control that uses technology to implement control activities and requires no human intervention. __s are often more reliable and consistent than manual controls because they are not susceptible to human error, judgment, or override. __s include embedded IT controls and controls that use other automation technologies, such as robotics, to perform what have traditionally been manual tasks.

61
New cards

collusion

A secretive agreement to deceive others when two or more people work together to circumvent controls. For example, if a control requires one employee to input invoices into the accounts payable system and a different employee to approve payments for the invoices, these two employees could work together to commit fraud by inputting a fictitious invoice and authorizing the payment to go to a bank account they control.

62
New cards

Committee of Sponsoring Organizations of the Treadway Commission (COSO)

An organization that is committed to fighting corporate fraud. It is composed of five private organizations that focus on providing guidance to executives and government entities on fraud prevention and response. __ helps publicly traded companies comply with SOX and the SEC requirement of using an internal control framework.

63
New cards
control
A mechanism that is part of the internal control process—such as a rule, policy, or procedure—and that is put in place to mitigate risks by providing reasonable assurance that risk is at an acceptable level. Also known as a control activity.
64
New cards

control component

One of the five key steps of the COSO Internal Control Framework involved in implementing an effective system of internal control. The _s flow from the top to the bottom of a business, starting with the control environment and ending with monitoring. _s and their related principles help framework users understand what an effective control is and how to judge whether a control is effectively designed and implemented.

65
New cards
control environment
The first of the COSO Internal Control Framework control components. It is the foundation for other components and includes the attitude of management concerning integrity and ethical behavior. It is the most important component because it sets the overall tone for integrity and ethics for the organization.
66
New cards
control objective
One of the three areas on which the COSO Internal Control Framework focuses to achieve results: operations objectives, reporting objectives, and compliance objectives.
67
New cards
continuous monitoring

Data analytics technology that internal auditors use to create detective controls that use rules-based programming to monitor a business’s data for red flags of risks. __ is often programmed to keep tabs on key performance indicators (KPIs) or to look for red flags indicating possible fraud.

68
New cards

corrective control

A control that changes undesirable outcomes and occurs after the potential outcome of a risk has become a reality. __s are used when it is not cost-effective to implement preventive or detective controls to mitigate a specific risk. They are also used as a backup plan in the event of a failure of preventive or detective controls.

69
New cards
detective control

A control that alerts management to an issue once it has occurred. __s monitor business processes to identify problems like fraud, quality control, or legal compliance issues.

70
New cards

ERM Framework

Enterprise Risk Management—Integrating with Strategy and Performance, a set of five interrelated components that highlight the importance of risk in creating strategies and driving a company’s performance. The __ aims to improve the risk management process by addressing more than just internal control.

71
New cards
first line of defense
The business operations portion of the Institute of Internal Auditors’ three lines of defense model. In this line of defense, management has the ownership and the responsibility of enforcing mitigating measures to prevent identified risk from occurring. This line of defense reports only to executive management.
72
New cards

framework

A published set of specifications and criteria that defines a strategy to achieve certain objectives. Accounting __s are specific to the information appearing in a company’s financial statements, and risk management __s focus on how a company defines its strategy for eliminating or minimizing the impact of risks.

73
New cards
independence
A condition in which an auditor is removed from a business process and has no stake in or influence over the outcome of the business processes that they are auditing. It is important for an auditor to remain independent in order to audit the business objectively.
74
New cards

internal audit

An independent function in a company that tests internal controls to provide assurance of their effectiveness to executive management and the board of directors. __ adds value to a business by providing assurance, insight, and objectivity to the company.

75
New cards

internal control

A process that specifically mitigates risks to the company’s financial information. ___, as it relates to accounting information, focuses on providing quality information to internal decision makers and external stakeholders.

76
New cards
Internal Control—Integrated Framework
A controls-based approach to risk management that is widely accepted as the authoritative guidance on internal controls and SOX compliance. It defines internal control and gives the criteria for developing, implementing, and monitoring an effective internal control system.
77
New cards

IT general control (ITGC)

A control that applies to the entire operation of a system and its environment. All corporate applications, like email, web browsers, time-keeping software, benefits management systems, and more, are subject to __s.

78
New cards

management override

A control weakness that occurs when internal control activities are ineffective because management is not following policy or procedure—as when managers tell employees who report directly to them to ignore specific controls. The American Institute of Certified Public Accountants (AICPA) describes ___ as the Achilles heel of fraud prevention.

79
New cards

manual control

A control that is executed by people or physical interaction. __s are used when human judgment or physical interaction is required. __ are subject to human error or intentional manipulation and override, which means there is an increased risk that a manual control might fail. For this reason, auditors—both internal and external—frequently focus on manual controls during their assessments.

80
New cards

maturity model

A model that shows how far along a company is on its journey to reach the ideal state by comparing the current state to a predetermined set of best practices. Companies use __s to judge their current performance and create a roadmap, or plan, for continuous improvement.

81
New cards
preventive control

A control that prevents problems from happening. Examples of _s include firewalls to prevent unauthorized access to an organization’s computer network and policy and procedure documentation that specifies how employees should execute procedures and clarifies company policies to reduce the organization’s risk of error and misconduct.

82
New cards

Sarbanes-Oxley Act of 2002 (SOX)

A U.S. federal law that protects investors from fraud and other risks by improving the reliability and accuracy of financial statements. ___ primarily focuses on the internal control structure of a company. It changed the way companies operate by mandating audit trails and shifting the responsibility for financial reporting misstatements. Responsibility for control failures moved directly to management, and violation of internal control requirements now comes with serious criminal penalties—with fines up to $5 million and/or imprisonment for up to 20 years.

83
New cards
second line of defense
The risk management and compliance portion of the Institute of Internal Auditors’ three lines of defense model. In this line of defense, the ERM team identifies and assesses organizational risks. This line of defense aids the first line of defense in ensuring that controls are designed to adequately address risk and monitors the controls to ensure that the first line of defense is complying with internal control requirements. This line of defense reports only to executive management.
84
New cards
segregation of duties
A type of preventive control that reduces the risk of error and fraud by ensuring that different employees are responsible for the separate parts of a business activity: authorizing, recording, and custody. The work of one employee acts as a check on the work of another employee. Also called separation of duties.
85
New cards
third line of defense
The internal audit portion of the Institute of Internal Auditors’ three lines of defense model. The primary objective of internal audit is to test internal controls to provide assurance of their effectiveness to executive management and the board of directors. Internal audit is an independent function of the company that reports both to executive management and to the board of directors.
86
New cards
time-based model of controls
A model that measures the residual risk for technology attacks by comparing the relationship of preventive (P), detective (D), and corrective (C) control functions. If P > (D + C), then the controls are effective. Otherwise, the security measures are inadequate to protect the company’s systems from intruders.
87
New cards
acquisition
One company’s purchase of all or the majority of another company’s shares to gain control over that company.
88
New cards
acquisition-based growth
Growth in a company that occurs as the company purchases and integrates other companies into its infrastructure.
89
New cards

batch processing

In a transaction processing system, a type of processing in which data is collected as it is generated and then is processed later, at a scheduled time. Because transactions are processed together in a batch—whether at the end of a day, week, or month—___ is most suitable for transactions that are not time sensitive.

90
New cards
centralized system
An information system that connects all users to one central location that is built around a server or cluster of servers that all authorized users can access. All the network’s main business processing occurs at, and business information is stored in, that one place.
91
New cards

cloud computing

A type of computing that provides access to shared resources over the internet, such as computer processing, software applications, data storage, and other services. In the business context, ___ allows companies to minimize computer resources kept on hand, which can be expensive to both purchase and securely store. The costs are absorbed by the cloud provider, which maintains the physical equipment at its facility and provides access to customers via the cloud network.

92
New cards
compensating control
A control that can be used to reduce risk when more expensive or more complex controls are not available.
93
New cards
configurable ERP system
An enterprise resource planning (ERP) system that has some add-ins and features that can be customized for customers’ needs.
94
New cards
Customer Relationship Management (CRM) module
An enterprise resource planning (ERP) system module that captures and stores all customer information. It captures communication with customers like emails and phone calls and can generate leads of prospective customers for sales team members to contact.
95
New cards
customizable ERP system
An enterprise resource planning (ERP) system in which the features are customized for an individual customer’s needs.
96
New cards
decentralized system

An information system that, rather than having a single location, utilizes multiple locations that each maintain a copy of the data needed for connected systems. In a decentralized network, there are multiple access points for users, but not all users are connected to all access points. __s may be used when there are regional offices that process data, then summarize it and communicate the data back to headquarters.

97
New cards
decision support system (DSS)
An information system that assists in nonroutine problem solving and unstructured decision making.
98
New cards

distributed system

An information system in which all the users and systems are directly connected to one another across the network. In a __, the processing and databases are distributed among several business locations. All users have access to all data, depending on their user access privileges, and all users are connected throughout the business.

99
New cards

enterprise resource planning (ERP)

A solution that offers a single system with aggregated parts that meet the needs of each business function. An __ system integrates multiple systems into a single, cohesive communication system.

100
New cards
ERP feature
A specific capability for a business process within an enterprise resource planning (ERP) system module. Each feature is specifically designed to support the unique requirements of its business processes. Accounts Receivable is an example of a feature within the Financial module of an ERP system.