Internal Controls & Governance Flashcards
7 cards from real CA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Internal Controls & Governance flashcards as text
IT General Controls (ITGCs) differ from IT Application Controls in that ITGCs:
Answer: Apply broadly to the IT environment supporting multiple applications, such as access management and change management
ITGCs govern the overall IT environment — including logical access, program change management, and computer operations — and their effectiveness underpins the reliability of application-level controls.
Under the Three Lines of Defense model, the internal audit function represents which line?
Answer: Third line
The third line (internal audit) provides independent assurance to the board and senior management about the effectiveness of governance, risk management, and controls established by the first and second lines.
Which of the following best describes a 'significant deficiency' in internal controls?
Answer: A control deficiency less severe than a material weakness, but important enough to merit attention by those charged with governance
A significant deficiency is a control shortcoming that, while not rising to a material weakness, still warrants the attention of the audit committee due to its potential impact on financial reporting.
Corporate governance principles generally require that a majority of board members be:
Answer: Independent directors with no material relationship to management
Independence is fundamental to effective board oversight; stock exchange listing rules and governance best practices require a majority of directors to be independent to avoid conflicts of interest.
Management override of internal controls is considered a significant inherent risk because:
Answer: Even well-designed controls can be circumvented by senior management, making fraud possible regardless of the control system
Because management has the authority and knowledge to bypass controls, auditing standards treat management override as an inherent risk that must always be addressed, regardless of the control environment.
A whistleblower policy is an example of which COSO component?
Answer: Information & Communication
Whistleblower hotlines and reporting mechanisms fall under the Information & Communication component because they facilitate the flow of relevant information — including concerns about misconduct — to appropriate parties.
Which regulatory body issues auditing standards for public company auditors in the United States regarding internal controls?
Answer: PCAOB
The Public Company Accounting Oversight Board (PCAOB) was established by SOX to issue auditing standards for registered public accounting firms, including AS 2201 on ICFR audits.