Internal Controls & Compliance Flashcards
7 cards from real CFC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Internal Controls & Compliance flashcards as text
An organization's internal audit function discovers that IT access controls allow users to override journal entries without a secondary approval. This is an example of which type of control gap?
Answer: Application control deficiency
Application controls are controls built directly into software applications, and the ability to override journal entries without approval is an application-level control deficiency.
Under the FCPA (Foreign Corrupt Practices Act), what is required of issuers regarding their books and records?
Answer: Books must accurately reflect transactions and assets in reasonable detail
The FCPA's books and records provision requires issuers to keep records that accurately and fairly reflect transactions and asset dispositions in reasonable detail.
A financial controller implements a monthly bank reconciliation process. Which control objective does this primarily serve?
Answer: Completeness and accuracy of cash balances
Bank reconciliations are detective controls that verify the completeness and accuracy of recorded cash transactions by comparing book balances to bank statements.
When a company relies on a third-party service organization to process payroll, management should obtain which report to understand the controls at that organization?
Answer: A SOC 1 Type II report
A SOC 1 Type II report (formerly SAS 70) evaluates the design and operating effectiveness of controls at a service organization relevant to user entities' financial reporting.
Which of the following control activities is MOST effective at preventing fraudulent disbursements?
Answer: Dual signatures required for checks above a materiality threshold
Requiring dual signatures for large disbursements is a preventive control that stops unauthorized payments before they are made.
The Committee of Sponsoring Organizations (COSO) ERM framework expands on internal controls by incorporating which additional concept?
Answer: Objective setting and risk appetite
COSO ERM adds enterprise-wide risk management concepts including objective setting, risk appetite, and portfolio view of risk, which extend beyond the internal control framework.
A significant deficiency in internal controls differs from a material weakness primarily in:
Answer: The magnitude of the potential misstatement
A significant deficiency is less severe than a material weakness — both represent control deficiencies, but a material weakness involves a higher likelihood and magnitude of potential misstatement.