Module 4: Control Frameworks Flashcards
(58 cards)
T or F: The past business environment has resulted in a proliferation of vulnerabilities, risks, stakeholders, and activities much more complex than ever before
False. The current business environment
Internal Control Frameworks are structures that ___, ____, and sometimes ___ an organization’s internal controls
organize, categorize, prioritize
What are the main objectives internal controls?
- Create value for stakeholders
- Minimize risk
What is the widely known internal controls framework?
COSO’s Internal Control Integrated Framework
What are the IT Control Frameworks?
- Control Objectives for Information and Related Technology (COBIT)
- International Organization for Standardization 17799 (ISO)
- Information Technology Infrastructure Library
What internal control framework is used for project management, process assessment and performance improvement?
Capability Maturity Model Integration (CMMI)
What are the 3 control objectives in the COSO Framework?
- Operations
- Reporting
- Compliance
What are the five components of internal control?
- Control Environment
- Risk Assessment
- Control Activities
- Information and Communication
- Monitoring Activities
What are the 4 depths of the COSO framework?
- Entity
- Divisions
- Operating Unit
- Function
What are the five principles of the Control Environment?
- Commitment to integrity and ethical values
- BOD exercises oversight responsibility
- Establish structure, authority, and responsibility
- Commitment to competence
- Enforce accountability
Control Environment: the workplace environment, characterized by the way the organization is structured, the manner of leadership, the degree of ____, management’s ___ ___ having and practicing the tenets of its ___ __ ____ and
statement of values.
openness, operating style, code of ethics
Control Environment: What should happen to the tone at the top?
Congruence
Control Environment: Organizational culture of?
Collection of Learned Beliefs
Control Environment: What is the result of a healthy culture and ethical environment?
advancement of employee morale
Control Environment: T or F: The Control environment includes the development of personnel
T
Control Environment: Management should also establish what in terms of risk?
- Risk Management Philosophy
- Risk Appetite
Control Environment: According to Trompenaars, organizational culture includes three key elements:
- The general relationship between employees and their organizations
- The vertical or hierarchical system of authority defining superiors and subordinates
- The general views of employees about the organization’s destiny, purpose, and goals, and their place in it
Control Environment: What unethical behavior should not be done?
- Undue emphasis on bottom-line performance
- High-pressure sales tactics
- Kickbacks or bribes
Control Environment: New employees should do what?
Sign documents such as code of ethics, conduct, conflict of interest to indicate that they agree to comply with them
Control Environment: State an example of what organization can do to enforce ethical behavior
- Company Newsletter
Control Environment: Consists of management practices where on the surface it appears like an essential activity has been performed when it hasn’t
Form over substance
Control Environment: ___ ___ controls are used to determine if an organization’s values, systems, policies, and processes would?
Entity Level, enable or dissuad fraud and encourage proper conduct
Control Environment: Entity level controls refer to?
the Entity’s Management Style
Control Environment: What do we audit for entity level controls?
- Tangibles like policies and procedures
- Intangibles observation of management culture