The COSO Internal Control Framework Flashcards
(25 cards)
What is internal auditing?
Independant, objective assurance and consulting activity designed to add value/improve on organization’s operations.
Who do internal auditors report to ?
Board & senior managament within organization governance structure
What is the objective of internal audit?
Brings a systematic, disciplined approach to evaluate/improve effectiveness of risk management, control, and governance processes. Bring assurance to help board fulfill their duties to org
What does internal audit cover?
All categories of risk, their management and reporting on them
What are the responsibilities for improvement ?
Fundamental to purpose of internal auditor. Done by advising, coaching, facilitating in order to not undermine responsibility of management
What are 3 examples of internal audit activities?
1)Evaluating controls/advising managers at all lvls
2)Evaluating risks
3)Analysing operations
What is COSO?
Committee of sponsoring organizations of the Treadway Commission: joint initiative of the 5 private sector professional accounting, auditing and finance organization and is dedicated to providing thought leadership through the development of frameworks and guidance on enterprise risk managament, internal control and fraud deterrence
What is internal control?
process effected by BofD, managament, and other personnel, designed to provide reasonable assurance of objective
In what does internal control provide assurance in? (3)
1)Effectiveness/efficiency of operations
2)Reliability of financial reporting
3)COmpliance with applicable laws/regulations
What are the 3 levels of organization of the COSO?
1)Business entity-level controls
2)Division and function controls
3)Business unit activities
What is the Control environment?
set of standards, processes, stuctures that provide basis/stucture for carrying out effective IC activities across enterprise
What are the control environment elements to consider? (6)
1) Tone at the top
2)Actions of BofD and senior management
3)Ethical values
4)Does management take business risk to achive objective ? (achieve at all cost attitude or encourage risk?)
5Does management attempt to manipulate performance measures so they appear more favorable?
6)Is management open and honest with employees about performance and results?
What COSO internal control component is prevasive ?
The control environment
What is the risk assessment component?
Process for determining how all lvls of risks will be managed, and a precondition to risk assessment is the establishment of risk related onjectives, linked at different lvls of enterprise operations
What are the risk assessment elements to consider ? (4)
1) Specify objective with sufficient clarity to enable ientification/assessment of risks relating to those obj
2)Identify risk to achievement of its obj, across the entity and should analyze if risks as a basis for determining how those risks should be managed
3)Consider potential for fraud in assessing risks
4)Identify/assess changes that could impact its system of IC
What are Internal control activities ?
Actions established through enterprise policies/procedures that help ensure that management’s directives to mitigate risks to achieve objectives are carried out
What are the 6 types of internal control activities?
1)Verifications
2)Reconciliations
3)Authorizations/approvals
4)Physical controls
5)Controls over standing data
6)Supervisory controls
What are the 2 types of information and communication?
1)internal communication
2)External communication
What is internal communication?
The mean by which info is disseminated throughout enterprise, flowing up/down and across entity
What is the purpose of internal communication ?
Enables personnel to receive clear messages from senior management that control responsibilities must be taken seriously
What is external communication?
Enables inbound communication of relevant external info & provide info to external parties in response to requirements/expectations (goes/comes from outside)
What is the overall concept of Information and communication ?
Enterprise needs to develop and deliver many forms/types of competent information, from and to management
What are monitoring activities?
Assess whether each of the other objective or components of COSO IC are present and functioning
What do internal auditor do?
Monitor activities