1 - Internal Control Frameworks Flashcards
(120 cards)
COSO issued the “internal Control - Integrated Framework” to assist organizations do what?
develop comprehensive assessments of IC effectiveness
This framework is also often referred to as “the framework”
How does the principles-based approach support an effective system o internal control under the COSO framework?
An EFFECTIVE system of IC requires the use of judgment in determining the sufficiency of controls, applying the proper controls, and assessing the effectiveness of the system of controls.
The principles-based approach of the COSO framework emphasizes the importance of MGT JUDGMENT
MS: One framework for controls does not fit all companies because every company is different (i.e. in size, its business, process, etc), and as such mgt must use judgment
Define “internal control”
a process that is designed and implemented by an organization’s management, board of directors, and other employees to provide REASONABLE ASSURANCE that the organization will achieve its OPERATING, REPORTING, and COMPLIANCE objectives
What are the objectives of internal controls
- financial Reporting
- effective & efficient Operations
- Compliance with laws & regulations
What is comprised in the “COSO Cube”
ORC - 3 main objectives
CRIME - 5 I/C components
Organizational structure
Describe the Operations objective
relates to the effectiveness and efficiency of an entity’s operations.
Want to ensure the assets of the org. are adequately safeguarded against potential losses
Describe the Reporting objective
pertains to the RELIABILITY, TIMELINESS, and TRANSPARENCY of an entity’s external & internal financial AND nonfinancial reporting as established by regulators
Describe the Compliance objective
established to ensure the entity is adhering to all applicable laws and regulations
What are the five components of internal control
Control environment Risk assessment Information & communication Monitoring Controls Existing Control activities
“CRIME”
What things are needed in order to achieve the 3 objectives of I/C?
ALL 5 components (CRIME) and the 17 principles that are relevant to be both PRESENT & FUNCTIONING
Describe Control Environment
Tone at the top - ethics
includes the processes, structures, and standards that provide the foundation for an entity to establish a system of I/C.
What are the principles related to Control Environment?
“EBOCA”
- Commitment to ETHICS & Integrity — establish standards/code of conduct
- Board Independence & Oversight — independent and knowledgeable
- Organizational Structure — reporting lines, the authority and responsibilities are all appropriate
- Commitment to Confidence — there is a commitment to hire, develop, and retain competent employees
- Accountability — establish performance measures, incentives, and rewards without excessive pressure
Describe Risk Assessment
an entity’s identification and analysis of risk to the achievement of its objectives
What principles are related to Risk Assessment
Make an entity “SAFR”
- Specify objectives — identify and assess risks related to those (not achieving ) objectives
- Identify and ASSESS Changes — the org identifies and assesses changes that could significantly affect I/C such as change in external environment, business model, and leadership
- Consider potential for FRAUD — assess fraud triangle
- Identify and analyze RISKS — determine how risks should me managed (Enterprise Risk Management)
Describe the Information & Communication component
these systems support the identification, capture, and exchange of information (b/t internal and external parties) in a timely and useful manner.
List the principles included in Information and Communication
“OIE”
- Obtain and use information — obtains or generates and uses RELEVANT, HIGH QUALITY information to support functioning of IC
- Internally communicate information – information necessary to support functioning of I/C is communicated in a flow of information up, down, and across the organization
- Communicate with external parties — two way external communication channels using a variety of methods and channels (i.e. CPA firm or consultants)
Describe Monitoring Activities
process of assessing the quality of I/C performance over time by assessing the design and operation of controls on a timely basis and taking the necessary corrective actions
What principles relate to Monitoring Activities
“SOD”
- SO = Ongoing and/or Separate Evaluations — on whether the comoponent’s of I/C are present and functioning (the frequency of testing is dictated by RISK)
- Communication of deficiencies —report deficiencies in a timely manner and make sure corrective action is taken
Describe Existing Control Activities
the controls set forth by an entity’s policies and procedures to ensure that the directives initiated by mgt to mitigate risks are performed
Control activities may be detective or preventive
Segregation of duties is usually a big one
What principles relate to Existing Control Activities
“CAT PP”
- Select and develop CONTROL ACTIVITIES
- Select and develop TECHNOLOGY controls
- Deployment of POLICIES & PROCEDURES
Define present and functioning
present - included in the design and implementation of the I/C
functioning - operating as designed in the I/C system
What specific requirements must I/C have in order to be considered and EFFECTIVE SYSTEM?
Senior mgt and the board must have reasonable assurance that the entity:
- achieves effective and efficient operations
- complies with all applicable rules, regulations, laws, etc.
- prepares reports that are in conformity with the entitiy’s reporting objectives and standards.
What results when there is an ineffective I/C
= greater risk that ORC is not achieved
GAAS uses the terms “material weakness” and “Significant deficiency”
COSO uses the term “major deficiency”
Describe a “major deficiency” and what results if one exists
represents a material I/C deficiency that significantly reduces the likelihood that an organization can achieve its objectives
if identified, the entity may NOT conclude that it has met the requirements for an effective I/C system under the COSO framework