BEC - COSO & Corp Governance Flashcards
(91 cards)
Control Environment - Integrity and Ethical Values
Most important principle - the organization demonstrates a commitment to INTEGRITY AND ETHICAL VALUES. “Tone at the top”.
Control Environment - Board of Directors
The BoD demonstrates independence of management, and oversees development and monitoring of internal control.
Control environment - Competence
The organization demonstrates commitment to attract, develops, and retain competent (high quality) individuals.
Control environment - Accountability
The organization holds individuals accountable for their internal control responsibilities.
– do not want to put too much pressure on individuals or else it will work against the organization.
Risk Assessment - Objectives
Organization objectives have sufficient clarity to enable the identification and assessment of risks that threaten achievement of objectives including consideration of:
- Precision of risk tolerance levels (quantify risk? Range?)
- Materiality in relation to risk assessment.
Risk Assessment - Assessment
The organization identifies risks to achievement of objectives and analyzes risks to guide risk management strategy
Risk Assessment - Fraud
The organization considers potential fraud in assessing risks to achieve objectives.
Risk Assessment - Change Management
The organize identifies and assesses changes in external environment, business model and organizational leadership that could impact system of internal control.
Control Activities - Risk Reduction
Control activities reduce the risks to the achievement of objectives to acceptable levels.
Control Activities - Technology Controls
The organization selects and implements general controls over technology which support the achievement of its objectives.
Control Activities - Policies
The organization’s control activities inform policies that establish stakeholder expectations. Established procedures ensure that implementation of these policies.
Information and Communication - Quality
Relevant, high-quality information supports internal control processes including organizational processes that identify information required to support internal control processes, capture internal and external sources of data & transform data into information.
Information and Communication - Internal
Internal Communication supports internal control processes.
Can either support or hinder internal controls.
Information and Communication - External
Communication with outsiders supports internal control processes.
Monitoring - Both ongoing and Periodic
Monitoring evaluates internal control including benchmarking and providing feedback.
Monitoring - Address Deficiencies
Parties charged with taking corrective action, including senior management and the BoDs, receive timely communication of internal control deficiencies.
Control Environment - Management
Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities to achieve objectives.
Internal control is the responsibility of
Management (not the auditors)
What is internal control?
a PROCESS designed to provide REASONABLE (cost-effective) assurance. (Not absolute assurance)
Who is responsible for Internal Control?
Management, the BoD and other personnel
What are the goals (the why) of internal control?
Regarding achievement of objectives related to:
- Effectiveness and efficiency of operations
- Reliable financial reporting
- Compliance with laws and regulations
Control deficiency
Least serious of the three types. Shortcomings that reduces likelihood of entity achieving its objectives. Management must assess the severity of deficiency
Significant deficiency
More serious than a control deficiency but less severe than a material weakness.
Material weakness
Creates a reasonable possibility of a material misstatement of the entity’s financial statements.