โ† All AICPA Flashcard Decks

Risk Management & Internal Control Flashcards

7 cards from real AICPA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Management & Internal Control flashcards as text
  1. Which framework is most commonly used to evaluate cybersecurity risk management programs in the United States?

    Answer: NIST Cybersecurity Framework

    The NIST Cybersecurity Framework provides guidelines for managing and reducing cybersecurity risk for critical infrastructure.

  2. A walkthrough in the context of internal control testing involves:

    Answer: Tracing one or more transactions through the entire process from initiation to recording

    A walkthrough traces a transaction end-to-end to confirm that controls are in place and operating as described.

  3. Under COSO ERM 2017, which component encompasses the day-to-day processes used to manage risk across business units?

    Answer: Performance

    The Performance component covers how risks are identified, assessed, prioritized, and responded to in daily operations.

  4. A company that decides not to enter a high-risk foreign market to avoid the associated political risks is employing which risk response?

    Answer: Risk avoidance

    Risk avoidance involves not pursuing an activity or exiting a business situation that gives rise to the risk.

  5. Which of the following best describes the purpose of a control self-assessment (CSA)?

    Answer: Management and staff evaluate the effectiveness of controls within their own area

    A CSA is a process where business unit management and staff participate in assessing the effectiveness of their own controls.

  6. The primary purpose of an entity-level control is to:

    Answer: Provide a broad control environment that permeates the entire organization

    Entity-level controls operate at an organization-wide level and set the overall control tone, affecting all transactions and processes.

  7. A company's business continuity plan (BCP) is designed to:

    Answer: Ensure critical operations can continue during and after a disruption

    A BCP provides procedures and information to keep critical functions operating during and recovering from a business disruption.