Internal Controls & Compliance Flashcards
7 cards from real CFC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Internal Controls & Compliance flashcards as text
A controller is evaluating whether a compensating control adequately offsets a control deficiency. Which criterion is MOST important in this evaluation?
Answer: The compensating control must achieve the same control objective as the missing or deficient control
A compensating control must address the same risk and achieve the same control objective as the deficient control to be considered an effective substitute.
Under GDPR compliance requirements for U.S. companies doing business with EU customers, which role is responsible for overseeing data protection activities and serving as the point of contact with supervisory authorities?
Answer: Data Protection Officer
GDPR requires certain organizations to appoint a Data Protection Officer (DPO) who oversees data protection strategy, ensures compliance, and acts as liaison with supervisory authorities.
A company's internal controls require that all journal entries above $50,000 have supporting documentation and a second reviewer's approval. An employee posts a $49,999 entry without documentation to avoid review. This is an example of:
Answer: Control circumvention through threshold manipulation
Structuring transactions just below control thresholds to avoid triggering required reviews is a form of control circumvention that exploits rigid threshold-based controls.
Which COSO principle states that an organization should identify and analyze risks to the achievement of its objectives as a basis for determining how risks should be managed?
Answer: Principle 7 — Identifies and Analyzes Risk
COSO Principle 7 under the Risk Assessment component requires organizations to identify and analyze risks relevant to achieving objectives to determine how they should be managed.
An organization's compliance program includes a helpline that allows employees to report violations anonymously. Under SOX, which provision requires public companies to establish such procedures?
Answer: SOX Section 301
SOX Section 301 requires audit committees of public companies to establish procedures for confidential, anonymous submission of employee concerns regarding accounting or auditing matters.
A financial controller at a public company certifies quarterly financial statements under SOX. Which statement best describes their personal liability?
Answer: Knowingly certifying false statements can result in criminal penalties up to $5 million and 20 years imprisonment
SOX Section 906 imposes criminal penalties on officers who knowingly certify materially false financial reports, including fines up to $5 million and imprisonment up to 20 years.
Which of the following best describes the purpose of a 'control self-assessment' (CSA) program?
Answer: A process where business units evaluate and report on the effectiveness of their own controls
Control self-assessment (CSA) is a methodology where management and process owners assess the effectiveness of controls within their own areas of responsibility.