B1 - Corporate Governance and Financial Risk Management Flashcards
(168 cards)
What are the five major financial professional associations in the US that are part of the private sponsoring organizations?
- The American Accounting Association (AAA)
- The American Institute of Certified Public Accountants (AICPA)
- The Financial Executive Institute (FEI)
- The Institute of Internal Auditors (IIA)
- The Institute of Management Accountants (IMA)
Is the Committe on Sponsoring Organization (COSO) an independent private initiative?
Yes, COSO is an independent private initiative established in 1980’s to study the factors that can lead to fraudulent financial reporting.
How is COSO also referred to?
COSO is sometimes referred to as the Tradeway Commission after the Original Chairman, James Tradeway, Jr., an executive in the private sector.
What is the nature of the board of directors’ relationship to the company?
The board of director has a fiduciary responsability to act on the best interest of the organization.
What does the existance of published code of ethics and periodic acknowledgment that ethical values are understood represents?
A published code of ethics and periodic acknowledgement that ethical values are understood is evidence of sound integrity, ethical values are developed and understood and set the standard of conducting for financial reporting.
What are the three main objectives of COSO - Internal Control Framework?
- Operations
- Reporting
- Compliance
What does the operational objective intends to achieve?
Efficient and effective operations that meet profit goals (financial and operations performance goals) and properly safeguard assets.
What does the reporting objective intends to achieve?
Reporting objectives pertain to the reliability, timeliness, and transparency of an entity’s external and internal financial and non-financial reporting.
What does the compliance objective intends to achieve?
Compliance with laws and regulations
What are the principles that support the Risk Assessment component of the COSO Internal Control Framework?
S - Setting objectives
I - Identify and analyze risk
C - Consider potential for fraud
I - Identify and assesses changes (change mgmt.)
What are the 3 types of risk that support the assessment of risk principle?
- Operational Risk
- Reporting Risk
- Compliance Risk
What does the ongoing and/or separate evaluation principle from the monitoring component refers to?
O - ongoing and/or separate evaluation
C
The organization selects, develops, and performs ongoing and/or separate evaluation to ascertain whether the components of internal control are present and functioning.
- One point of focus is to consider establishing baseline understandings.
What does monitoring activities refer to?
It involves ongoing or separate evaluations to determine whether the components of internal control are present and functioning properly (effectively) as well as reporting and correcting deficiencies.
is the act of approving high-dollar transactions by supervisors a monitoring activity?
No, the act of approving high-dollar transactions is an internal control, not a monitoring activity under the COSO framework.
What are the two monitoring principles?
O - ongoing/periodic and/or separate evaluation
C - Communication of deficiencies
What are the 3 principles of the Information and Communication component of the COSO internal control framework?
O - Obtain and use information (Quality)
C - Communicate with external parties (external)
I - Internally Communicate Information (internal)
What does communication of deficiencies from the monitoring component relates to?
O
C - communicates deficiencies
The organization evaluates and communicates internal control deficiencies in a timely manner to parties responsible for taking corrective action. Examples:
- Reporting to the audit committee represents reporting of deficiencies
What is change control?
Change control considers the manner in which management monitors an authorizes changes to a variety of information technology matters including software application programs.
- Only authorized individuals should be allowed to move changes into production and the function of making the changes should be segregated from the function of putting the change into production.
What are the 3 principles of the control activities component of the COSO internal control framework?
- Risk Reduction - selection and development of control activities
- Technology controls - development of technology controls
- Policies and Procedures - implementation of policies and procedures.
What are inherent limitations of internal controls (framework)?
- Human failure (errors)
- Bad decisions based on faulty judgement or biased judgement
- External events beyond the entity’s control
- Collusion-two or more plot to rip off the company
- Management over-ride of controls
What are not inherent limitations?
- Cost benefit consideration - constraints: prevent management from investing more in internal control than the perceived benefit
- Incompatible functions: collusion due to lack of segregation of duties.
What is value creation?
Value is created when benefits of value exceed the cost of resources used.
What does uncertainty means in Enterprise Risk Management (ERM)?
Uncertainty is a state of not knowing how or whether events may occur and the impact they may not have on an organization if they occur.
What is inherent risk and how is this used?
- Inherent risk is used to assess the severity of risk
- Inherent risk is the risk to an entity in the absence of any direct or focused actions by management to alter its severity (“in the absence of any actions management might take”).
- Managing risk such that it aligns with risk appetite is an appropriate component of the framework.