Chapter 5: Risk Assessment: Internal Control Evaluation Flashcards
(39 cards)
COSO internal control categories include _____ and _____ of operations.
effectiveness; efficiency
What are the 3 main objectives of the COSO Framework?
- reliability of financial reporting
- effectiveness and efficiency of operations
- compliance with applicable laws and regulations
What does Section 302 of SOX do?
stipulates criminal penalties for CEOs and CFOs if they issue materially misleading financial statements
Section 302 of SOX requires….
- managers to be responsible for establishing a control environment
- management to assess the risks it wishes to control
- management to be responsible for monitoring and maintaining control activities
The assessment of risk of material misstatement at the assertion level is completed to give the audit team a basis for planning the audit and determining the ____, ____, and ____ of further audit procedures to be conducted for the financial statement audit.
nature, timing, extent
When would the audit team likely use substantive tests of detail designed to obtain evidence (nature), at or near entity’s fiscal year-end (timing), with large sample sizes (extent)? When the control risk is high or low?
When control risk is assessed as high
When would the audit team likely use substantive analytical procedures to obtain evidence (nature), at an interim date before the entity’s fiscal year-end (timing), with much smaller sample sizes (extent)?
When control risk is assessed as low
The audit team must adjust the substantive procedures accordingly in order to obtain enough evidence to mitigate the risk of material misstatements to a low level for the relevant assertions being tested if the assessment of control risk is ______.
moderate
What are the 5 components of the COSO framework?
- control environment
- risk assessment
- control activities
- monitoring
- information and communication
They work in an integrated manner
The COSO definition states that internal control is designed to provide _____ _____ regarding the achievement of objectives in three categories.
reasonable assurance
Integrity, ethical values and competence of the entity’s people are all ______ ______ factors.
control environment
Each member of the audit committee must be financially ____ and one member must be a financial _____.
literate, expert
All entities recognize the need for a formalized process to identify, assess and manage factors, events and conditions, known as _____ _____, that can prevent the organization from achieving its objectives.
business risk
The foundation for all other components of internal control is the _____ _____.
control environment
The risk assessment element of the COSO framework is ____ responsibility.
management’s
In a well-functioning internal control system, once the risks to management’s objectives have been identified, ____ are established to eliminate, mitigate, or compensate for the risks.
internal control activities
In some sense, all controls can be thought of as ____ controls.
preventative
The possibility of being caught by a detective control might prevent someone from committing an error or fraud.
Duties that should be separated are the _____ to execute transactions, _____ transactions, ____ of assets involved in the transactions and periodic ____ of existing assets to recorded amounts.
- authorization
- recording
- custody
- reconciliation
COSO developed a(n) ____ framework to facilitate the assessment and mitigation of business risks a company faces.
enterprise risk management
The professional standards require the auditor to gain an understanding of the client’s risk assessment process related to ______.
- financial reporting risks
- fraud risk
But all busines risks are still important
Specific actions a client’s management and employees take to help ensure management’s directives are carried out are called?
control activities
Professional standards recognize that to make effective decisions, managers must have access to _______, ______, and _____ information.
- timely
- reliable
- relevant
T/F: When gaining an understanding of internal controls, assertions should always be considered whether or not they are relevant
False
T/F: When gaining an understanding of internal controls, assertions should only be considered whether or not they are relevant
True