COSO Flashcards

(33 cards)

1
Q

Name 3 Objectives of COSO Cube

A

Compliance
Reporting
Efficient Operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

5 Components of COSO Cube

A
Control Environment
Risk Assessment
Control Activities
Information/Technology
Monitoring
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

5 Components of COSO ERM

A
Governance
Strategy/Objective Setting
Performance
Review/Revision
Info/Communication Reporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q
Board Oversight
Make Operating Structures
Define Desired Culture
Demonstrate Core Values
Attract/Retain Capable Individuals
A

Governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Analyze Business Context
Define Risk Appetite
Evaluate Alternative Strategies
Form Business Objectives

A

Strategy/Objective Setting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
Identify Risk
Assess Risk Severity
Prioritize Risks
Implement Risk Responses
Develop Portfolio View
A

Performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Assess Change
Review Risk and Performance
Pursue Improving ERM

A

Review/Revision

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Leverage Info/Tech
Communicate Risk Info
Report on Risk Culture/Performance

A

Info/communication reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
Tone at Top
BOD
Management
Competence
Accountability
A

Control Environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Objectives
Assessment
Fraud
Change Management

A

Risk Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Risk Reduction
Technology
Policies

A

Control Activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Quality
Internal
External

A

Information/Communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Ongoing and Periodic

Address Deficiencies

A

Monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

assessing aspects of risk to determine which risks are most and least important

A

Performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

systematic analysis of the political, economic, social, technological, legal, and environmental conditions
PESTLE

A

Strategy/Objective Setting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

reporting on the organization’s risk, culture, and performance (Whistle blower hotline)

A

Information/Communication/Reporting

17
Q

meetings with its investors, management, and employees to help identify its risk culture

18
Q

company recently issued a report on its investment philosophy and risk management culture

A

Information/Communication/Reporting

19
Q

Development of Strategy

A

Risk Appetite

20
Q

Implementation of Strategy

21
Q

They help an entity create and maintain reliable data

A

Process and Controls

22
Q

determine which data is collected and how it is stored, arranged, integrated

A

Data Management Architecture

23
Q

management’s philosophy and operating style

A

Control Environment

24
Q

process of identifying, analyzing, and managing the risks involved in achieving the organization’s objectives

A

Risk Assessment

25
ongoing activities and separate evaluations
Monitoring
26
routine controls over business processes and transactions
Control Activities
27
policies and procedures that ensure that management’s directives are carried out
Control Activities
28
general control rather than a transaction control activity .Technology development policies and procedures. .Reconciliations. .Physical controls over assets. .Controls over standing data.
Technology development policies and procedures
29
the goal of proper measurement of transactions
Information and communication
30
addresses the need to respond in an organized manner to significant changes resulting from international exposure, acquisitions, or executive transitions
Risk Assessment
31
organizational objectives primarily relate to which fundamental component
Risk Assessment (help define risk)
32
types of control plans is particular to a specific process or subsystem, rather than related to the timing of its occurrence
Application
33
organization’s security awareness manual would be an example of which of the following types of controls
Preventive