Risk Management & Internal Control Flashcards
7 cards from real AICPA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Management & Internal Control flashcards as text
Under COSO ERM, which component addresses the organization's philosophy about managing risk and its risk appetite?
Answer: Internal Environment
The Internal Environment component sets the foundation for how risk is viewed and addressed, including risk philosophy and appetite.
A company implements a policy requiring two signatures on checks exceeding $10,000. This is an example of which type of control?
Answer: Preventive control
Requiring dual signatures before a check is issued prevents unauthorized transactions from occurring, making it a preventive control.
Which risk response strategy involves transferring risk to a third party through insurance or outsourcing?
Answer: Risk sharing
Risk sharing (also called risk transfer) moves some or all of the risk to another party, such as through insurance contracts.
The Sarbanes-Oxley Act Section 404 requires management to assess the effectiveness of internal controls over:
Answer: Financial reporting
SOX Section 404 mandates that management assess and report on the effectiveness of internal controls over financial reporting.
When auditors test the same control at different points during the year, this is best described as:
Answer: Interim testing with update procedures
Interim testing with update procedures allows auditors to test controls mid-year and then perform limited procedures at year-end.
Which element of the fraud triangle describes a person's ability to rationalize fraudulent behavior as acceptable?
Answer: Rationalization
Rationalization is when a fraudster justifies their actions as acceptable, such as believing they are simply 'borrowing' funds.
An organization's risk appetite is best defined as:
Answer: The amount of risk an entity is willing to accept in pursuit of value
Risk appetite is the broad amount of risk an entity is willing to accept while pursuing its strategy and objectives.