Risk Management & Internal Control Flashcards
7 cards from real AICPA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Management & Internal Control flashcards as text
Which framework is most commonly used to evaluate cybersecurity risk management programs in the United States?
Answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework provides guidelines for managing and reducing cybersecurity risk for critical infrastructure.
A walkthrough in the context of internal control testing involves:
Answer: Tracing one or more transactions through the entire process from initiation to recording
A walkthrough traces a transaction end-to-end to confirm that controls are in place and operating as described.
Under COSO ERM 2017, which component encompasses the day-to-day processes used to manage risk across business units?
Answer: Performance
The Performance component covers how risks are identified, assessed, prioritized, and responded to in daily operations.
A company that decides not to enter a high-risk foreign market to avoid the associated political risks is employing which risk response?
Answer: Risk avoidance
Risk avoidance involves not pursuing an activity or exiting a business situation that gives rise to the risk.
Which of the following best describes the purpose of a control self-assessment (CSA)?
Answer: Management and staff evaluate the effectiveness of controls within their own area
A CSA is a process where business unit management and staff participate in assessing the effectiveness of their own controls.
The primary purpose of an entity-level control is to:
Answer: Provide a broad control environment that permeates the entire organization
Entity-level controls operate at an organization-wide level and set the overall control tone, affecting all transactions and processes.
A company's business continuity plan (BCP) is designed to:
Answer: Ensure critical operations can continue during and after a disruption
A BCP provides procedures and information to keep critical functions operating during and recovering from a business disruption.