Internal Controls & Risk Management Flashcards
7 cards from real CAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Internal Controls & Risk Management flashcards as text
What is the primary purpose of internal controls within an organization?
Answer: To safeguard assets, ensure financial accuracy, and promote operational efficiency
Internal controls are designed to safeguard assets, ensure the accuracy and reliability of financial reporting, and promote operational efficiency and compliance.
Which component of the COSO Internal Control Framework establishes the organization's tone, values, and operating style?
Answer: Control Environment
The Control Environment is the foundation of COSO and sets the tone of the organization by reflecting management's philosophy and operating style.
A bank reconciliation performed monthly by an accounting clerk is best classified as which type of internal control?
Answer: Detective control
A bank reconciliation detects discrepancies that have already occurred between book and bank balances, making it a detective control.
What is the primary objective of segregation of duties as an internal control?
Answer: To ensure no single employee can commit and conceal an error or fraud
Segregation of duties divides key tasks among different employees so that no single person can both perpetrate and conceal a fraudulent act or error.
Which of the following is the best example of a preventive internal control?
Answer: Requiring dual authorization before releasing large payments
Requiring dual authorization before releasing payments prevents unauthorized transactions from occurring in the first place, making it a preventive control.
Which of the following frameworks is most widely used by U.S. public companies to evaluate the effectiveness of internal controls over financial reporting?
Answer: COSO Internal Control — Integrated Framework
The COSO Internal Control — Integrated Framework is the most widely accepted standard for evaluating internal controls, particularly as required under Sarbanes-Oxley Section 404.
What does a risk assessment in the context of internal controls primarily help management determine?
Answer: How risks that could prevent the organization from achieving its objectives should be managed
Risk assessment identifies and analyzes relevant risks to achieving organizational objectives, forming the basis for determining how those risks should be managed.