Internal Controls & Compliance Flashcards
7 cards from real CFC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Internal Controls & Compliance flashcards as text
Which concept ensures that IT systems' data inputs, processing, and outputs are complete, accurate, and authorized?
Answer: Application controls
Application controls are embedded within specific software applications to ensure the completeness, accuracy, and authorization of data processed by those systems.
Under Dodd-Frank, the SEC's whistleblower program provides financial incentives to individuals who report securities law violations. What is the minimum percentage of sanctions that a whistleblower may receive?
Answer: 10%
Under Dodd-Frank's SEC whistleblower program, eligible whistleblowers may receive between 10% and 30% of sanctions collected when the total exceeds $1 million.
A controller discovers that the company's revenue recognition policy allows premature recognition of sales before delivery. Which COSO component has most clearly failed?
Answer: Control Environment
The Control Environment includes the ethical tone, policies, and management's commitment to integrity; a policy that allows improper revenue recognition reflects a failed Control Environment.
An organization uses a 'three lines of defense' model. Which line is represented by the internal audit function?
Answer: Third line
In the three lines of defense model, the third line is internal audit, which provides independent assurance; the first line is operational management, and the second line is risk and compliance functions.
A company's external auditors issue an adverse opinion on internal controls over financial reporting. What does this mean for investors?
Answer: There is a material weakness that could result in a material misstatement
An adverse ICFR opinion means the auditor has identified one or more material weaknesses, indicating the controls may not prevent or detect material misstatements.
Which regulation requires financial institutions to implement programs to detect and prevent money laundering, including filing Suspicious Activity Reports (SARs)?
Answer: Bank Secrecy Act (BSA)
The Bank Secrecy Act (BSA) requires financial institutions to assist government agencies in detecting and preventing money laundering, including SAR filing requirements.
When assessing the risk of fraud in a financial reporting context, which of the following factors would MOST increase the risk of management override of controls?
Answer: Management compensation tied heavily to short-term earnings targets
When management compensation is heavily tied to short-term financial results, there is a strong incentive to manipulate reported earnings, increasing the risk of management override.