Auditing and Internal Controls Flashcards
6 cards from real ACFE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Auditing and Internal Controls flashcards as text
Which component of the COSO Internal Control Framework addresses the tone set by leadership regarding ethics and control?
Answer: Control Environment
The Control Environment is the foundation of the COSO framework and encompasses the ethical values, governance structure, and management philosophy that set the tone for internal control.
Which type of internal control is designed to detect fraud after it has occurred?
Answer: Detective control
Detective controls are designed to identify and surface fraud or errors that have already occurred, such as account reconciliations or exception reports.
Segregation of duties is most effective at preventing fraud when it separates which three functions?
Answer: Authorization, custody, and recordkeeping
Effective segregation of duties requires that no single individual can authorize a transaction, maintain physical custody of the related asset, and record the transaction.
An internal auditor discovers that the same employee approves purchase orders and signs vendor checks. This is an example of:
Answer: A segregation of duties weakness
When one employee controls both the authorization of a purchase and the disbursement of funds, a critical segregation of duties weakness exists that enables fraud.
Which COSO framework component involves identifying and analyzing risks that could prevent an organization from achieving its objectives?
Answer: Risk Assessment
The Risk Assessment component requires management to identify internal and external risks and analyze their likelihood and impact on achieving organizational objectives.
A fraud examiner is reviewing an organization's internal controls. Which condition most increases the risk that internal controls will fail to prevent fraud?
Answer: Management override of established controls
Management override is a significant fraud risk because those with authority can circumvent even well-designed controls, which is why it is identified in both COSO and ISA 240.