1/121
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
accounting information system (AIS)
An information system that performs data collection, transformation, and reporting that is specific to financial data. It captures accounting data created by business events (or activities) that involve an exchange of economic resources.
information system
A system that consists of interrelated components including physical hardware like monitors and laptops, the software that users interact with, databases used for storage, networks that send data and information throughout the system, and the people who use and maintain it.
input
In an information system, raw and unorganized data captured by the system.
output
In information systems, information that comes from a system in a format that is useful to users.
business event
A single business activity in a business process that takes place during the normal operation of a business. Examples of __s include “Sell goods to customer” and “Purchase equipment from vendor.” These give rise to accounting transactions if they involve an exchange of economic resources that impacts the accounting equation. Also called a business activity.
business model
A company’s plan for operations. It identifies the customer base, products, operation plans, and sources of revenue and financing.
franchise business model
A business model in which individuals purchase and run a franchise, such as a franchise of a popular fast food chain (for example, McDonald’s).
subscription business model
A business model that involves charging a monthly subscription fee for unlimited access to a service or product (for example, Netflix).
freemium business model
A business model that involves offering free services but charging a fee to access upgraded features (for example, Dropbox).
fundamental characteristics
The two characteristics that are required to make information useful for decision making, according to the Financial Accounting Standards Board (FASB)
information event
A business event that involves an exchange of information and never involves an exchange of economic resources.
information quality
The suitability of information for a particular purpose in a specific task.
information system
A system that consists of interrelated components including physical hardware like monitors and laptops, the software that users interact with, databases used for storage, networks that send data and information throughout the system, and the people who use and maintain it.
investing event
A business event that provides long-term value to a company by purchasing long-term assets that will deliver value in the future.
key performance indicator (KPI)
A quantifiable metric used to measure and evaluate the success of a company based on its objectives.
operating event
A business event that occurs during the normal operations of a company and directly relates to the company’s creation and provision of a good or service to its customers.
peer-to-peer business model
A business model that connects individuals with one another (for example, Airbnb).
process-based information system
An information system that captures all the data of interest generated in a business process, including informational events.
purpose of a business
The goal of making a profit and generating enough cash flow to continue operating. Without the profit motive, a business would not be a business (at least not for very long).
reporting
The process of aggregating data into information on the activities and performance in a company. ___ provides a strictly descriptive view of what happened and does not seek insights into the context or reasons.
retailer business model
A business model in which a manufacturer sells goods to a retailer to sell to consumers on its behalf.
subscription business model
A business model that involves charging a monthly subscription fee for unlimited access to a service or product (for example, Netflix).
transaction-based AIS
A traditional information system that captures only accounting business events and ignores nonfinancial data and the relationships between business events and business processes.
actual residual risk
The risk that actually remains after a risk is addressed.
business function
A high-level business area or department that performs business processes to achieve company goals. More than one __ may be necessary to complete a single business process.
compliance risk
Risk that occurs when a company fails to follow regulation and legislation and is subjected to legal penalties, including fines.
cyber risk
A unique type of technology risk that occurs when an external party accesses a company’s technology assets and performs unauthorized actions that are malicious. For example, cyberattacks can cause data breaches or lock down a company’s systems and hold them for ransom. Attackers may simply mean to prove that they have the skill needed to perform attacks successfully.
enterprise risk management (ERM)
The comprehensive process of identifying, categorizing, prioritizing, and responding to a company’s risks. It involves creating a formal risk assessment and plans for addressing the risks.
external risk
A risk that is not related to business operations and comes from outside a company. __ are not related to business operations. While _ are often unpredictable, companies still prepare for them to the best of their abilities.
financial risk
A risk specifically related to money going into and out of a company and the potential loss of a substantial sum. This type of risk is associated with various types of financial transactions, including investments, sales, purchases, and loans.
heat map
A type of risk matrix that uses different colors to represent values of data in a map or diagram format. The different colors in the risk matrix heat map typically represent the priority of a risk based on the risk score; for example, green may indicate a lower priority and red a higher priority.
impact
The estimation of damage that could be caused if a risk occurs. It is equivalent to the outcome in a risk statement.
inherent risk
The natural level of risk in a business process or activity if there are no risk responses in place. It is the risk before implementing a risk response. __ consists of two parts
internal risk
A risk that occurs throughout a company’s operations and arises during normal operations. Most __s are preventable through careful risk identification and management. Note that an internal risk may relate to an external party, such as the company’s reputation with customers.
likelihood
The estimated probability of risk occurrence. Companies use different methods to calculate _, but is always ranked on a spectrum. In different industries, _ is described as “frequency” or “probability”; these terms are synonymous.
purpose of a business
The goal of making a profit and generating enough cash flow to continue operating. Without the profit motive, a business would not be a business (at least not for very long).
operational risk
The most important type of risk for an AIS, which occurs during day-to-day business operations and causes breakdowns in business activities. These risks are a priority for an AIS because they result from inadequate or failed procedures within the company.
physical risk
A threat such as adverse weather, crime, or physical damage. __ is the easiest type of risk to understand, and it is one of the most important types of risk to identify because the impact is usually high. The losses from physical risks range from financial loss to legal actions and reputational loss due to mismanagement of assets.
portfolio view
A view of risk that examines risk at the entity level.
profile view
A view of risk that considers risk at the granular level of a business function, process, or event.
reputational risk
Risk that occurs when the reputation—or good name—of a company is damaged. With reputational risk comes financial loss through a loss of customers and revenue. __ can be both internal and external in nature. The exact financial loss tied to a __ is hard to quantify, but reputation is so important to a company that in accounting it is considered an intangible asset.
residual risk
The remaining risk posed by a process or an activity once a plan to respond to the risk is in place. It is the risk after implementing a risk response.
risk
The likelihood of an unfavorable event occurring. __s differ by business type, size, industry, and location.
risk acceptance
A risk response in which an inherent risk is present but the organization chooses not to act. The company chooses to live with the risk.
risk appetite
The amount of risk a company is willing to take on at a particular time.
risk assessment
An assessment that identifies, categorizes, and prioritizes individual risks in a company. After assessing risk, management decides how to manage it.
risk avoidance
A risk response that involves eliminating the risk by completely avoiding the events causing the risk. Rather than accept or reduce risk, companies avoid risk when it is both significant and highly likely to occur.
risk inventory
A listing of all a business’s known risks. A __ is an essential part of approaching risk at the entity level and creating a portfolio view.
risk matrix
A diagram that helps paint a clearer picture of risk by helping users visualize variations in risk scores. Using a __ allows management to plot risk and move prioritization around; it is especially helpful for risks that are scored the same numerically.
risk mitigation
The most commonly used risk response. It involves reducing risk based on careful consideration and calculation. __ enables a company to take on risks in order to create a competitive advantage.
risk severity
The likelihood of risks occurring and their potential impact on a company.
risk statement
A statement that summarizes a potential problem that needs to be addressed. It contains two parts: the issue and the possible outcome. The outcome of a risk varies greatly, from delaying the launch of an information system to preventing the success of an entire company.
risk transfer
A risk response that involves shifting a risk to a third party. In other words, a third party assumes the liabilities for the risk. Most often, this is done through a contract, such as an insurance policy.
strategic risk
The inevitable risk that results when a strategy becomes less effective. Companies constantly update their strategies—and change their risks—to stay ahead of the competition. Adopting new technology, overhauling a product design, and changing vendors to avoid high costs of materials are all examples of companies taking proactive measures to avoid strategic risk.
target residual risk
The goal level of residual risk after implementing a risk response.
technology risk
A specific subset of operational risk that exists when technology failures have the potential to disrupt business. Technology failures include threats, vulnerabilities, and exposures of information.
application
A type of software that allows end users to perform specific functions. _ software may be designed for general use or a specific function. It may also be custom developed for a specific function.
A control that only applies to a specific application, including all the business processes and accounts that are linked to it. __s in an AIS can be called transaction controls because they relate specifically to accounting transaction processing.
audit committee
A committee of a company’s board of directors that includes outside committee members with special qualifications in finance or accounting. The ___ provides objective oversight of a company’s financial reporting, internal controls, and regulatory compliance, and the company’s internal audit department should have a direct line of communication to this committee.
automated control
A control that uses technology to implement control activities and requires no human intervention. __s are often more reliable and consistent than manual controls because they are not susceptible to human error, judgment, or override. __s include embedded IT controls and controls that use other automation technologies, such as robotics, to perform what have traditionally been manual tasks.
collusion
A secretive agreement to deceive others when two or more people work together to circumvent controls. For example, if a control requires one employee to input invoices into the accounts payable system and a different employee to approve payments for the invoices, these two employees could work together to commit fraud by inputting a fictitious invoice and authorizing the payment to go to a bank account they control.
Committee of Sponsoring Organizations of the Treadway Commission (COSO)
An organization that is committed to fighting corporate fraud. It is composed of five private organizations that focus on providing guidance to executives and government entities on fraud prevention and response. __ helps publicly traded companies comply with SOX and the SEC requirement of using an internal control framework.
control component
One of the five key steps of the COSO Internal Control Framework involved in implementing an effective system of internal control. The _s flow from the top to the bottom of a business, starting with the control environment and ending with monitoring. _s and their related principles help framework users understand what an effective control is and how to judge whether a control is effectively designed and implemented.
Data analytics technology that internal auditors use to create detective controls that use rules-based programming to monitor a business’s data for red flags of risks. __ is often programmed to keep tabs on key performance indicators (KPIs) or to look for red flags indicating possible fraud.
corrective control
A control that changes undesirable outcomes and occurs after the potential outcome of a risk has become a reality. __s are used when it is not cost-effective to implement preventive or detective controls to mitigate a specific risk. They are also used as a backup plan in the event of a failure of preventive or detective controls.
A control that alerts management to an issue once it has occurred. __s monitor business processes to identify problems like fraud, quality control, or legal compliance issues.
ERM Framework
Enterprise Risk Management—Integrating with Strategy and Performance, a set of five interrelated components that highlight the importance of risk in creating strategies and driving a company’s performance. The __ aims to improve the risk management process by addressing more than just internal control.
framework
A published set of specifications and criteria that defines a strategy to achieve certain objectives. Accounting __s are specific to the information appearing in a company’s financial statements, and risk management __s focus on how a company defines its strategy for eliminating or minimizing the impact of risks.
internal audit
An independent function in a company that tests internal controls to provide assurance of their effectiveness to executive management and the board of directors. __ adds value to a business by providing assurance, insight, and objectivity to the company.
internal control
A process that specifically mitigates risks to the company’s financial information. ___, as it relates to accounting information, focuses on providing quality information to internal decision makers and external stakeholders.
IT general control (ITGC)
A control that applies to the entire operation of a system and its environment. All corporate applications, like email, web browsers, time-keeping software, benefits management systems, and more, are subject to __s.
management override
A control weakness that occurs when internal control activities are ineffective because management is not following policy or procedure—as when managers tell employees who report directly to them to ignore specific controls. The American Institute of Certified Public Accountants (AICPA) describes ___ as the Achilles heel of fraud prevention.
manual control
A control that is executed by people or physical interaction. __s are used when human judgment or physical interaction is required. __ are subject to human error or intentional manipulation and override, which means there is an increased risk that a manual control might fail. For this reason, auditors—both internal and external—frequently focus on manual controls during their assessments.
maturity model
A model that shows how far along a company is on its journey to reach the ideal state by comparing the current state to a predetermined set of best practices. Companies use __s to judge their current performance and create a roadmap, or plan, for continuous improvement.
A control that prevents problems from happening. Examples of _s include firewalls to prevent unauthorized access to an organization’s computer network and policy and procedure documentation that specifies how employees should execute procedures and clarifies company policies to reduce the organization’s risk of error and misconduct.
Sarbanes-Oxley Act of 2002 (SOX)
A U.S. federal law that protects investors from fraud and other risks by improving the reliability and accuracy of financial statements. ___ primarily focuses on the internal control structure of a company. It changed the way companies operate by mandating audit trails and shifting the responsibility for financial reporting misstatements. Responsibility for control failures moved directly to management, and violation of internal control requirements now comes with serious criminal penalties—with fines up to $5 million and/or imprisonment for up to 20 years.
batch processing
In a transaction processing system, a type of processing in which data is collected as it is generated and then is processed later, at a scheduled time. Because transactions are processed together in a batch—whether at the end of a day, week, or month—___ is most suitable for transactions that are not time sensitive.
cloud computing
A type of computing that provides access to shared resources over the internet, such as computer processing, software applications, data storage, and other services. In the business context, ___ allows companies to minimize computer resources kept on hand, which can be expensive to both purchase and securely store. The costs are absorbed by the cloud provider, which maintains the physical equipment at its facility and provides access to customers via the cloud network.
An information system that, rather than having a single location, utilizes multiple locations that each maintain a copy of the data needed for connected systems. In a decentralized network, there are multiple access points for users, but not all users are connected to all access points. __s may be used when there are regional offices that process data, then summarize it and communicate the data back to headquarters.
distributed system
An information system in which all the users and systems are directly connected to one another across the network. In a __, the processing and databases are distributed among several business locations. All users have access to all data, depending on their user access privileges, and all users are connected throughout the business.
enterprise resource planning (ERP)
A solution that offers a single system with aggregated parts that meet the needs of each business function. An __ system integrates multiple systems into a single, cohesive communication system.