Internal Controls & Governance Flashcards
7 cards from real CA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Internal Controls & Governance flashcards as text
The COSO Enterprise Risk Management (ERM) framework added which element that distinguished it from the original COSO internal control framework?
Answer: A broader focus on strategy-setting and the pursuit of organizational objectives across the full risk spectrum
COSO ERM expanded beyond financial reporting controls to encompass strategic, operational, reporting, and compliance risks, integrating risk appetite and tolerance into organizational strategy.
In evaluating the severity of a control deficiency, which factor is most relevant?
Answer: The magnitude of the potential misstatement and the likelihood it would occur
Severity is assessed by considering both the likelihood that the deficiency would result in a misstatement and the magnitude (quantitative and qualitative) of that potential misstatement.
Which of the following is an example of an entity-level control?
Answer: The annual code of conduct certification signed by all employees
Entity-level controls such as a code of conduct, management's risk assessment process, and the control environment operate at the company-wide level and influence all other controls.
Independence of the internal audit function is best maintained by having the Chief Audit Executive (CAE) report functionally to:
Answer: The Audit Committee of the Board
Functional reporting to the Audit Committee (rather than management) preserves the internal audit function's objectivity and independence, as the committee can act on audit findings without management influence.
Which of the following anti-fraud controls is considered most effective at deterring fraudulent financial reporting by senior management?
Answer: A strong, independent Audit Committee with oversight of financial reporting and the external auditor
An independent, active Audit Committee that directly oversees the external auditor and financial reporting process is consistently identified as the most effective deterrent to senior management fraud.
Control testing that evaluates whether a control operated effectively throughout the period (not just at a point in time) is called:
Answer: Test of operating effectiveness
A test of operating effectiveness assesses whether a control actually functioned as designed over the audit period, as opposed to a design assessment which only considers whether the control is suitably designed.
The Dodd-Frank Act enhanced whistleblower protections in the United States by:
Answer: Offering financial awards to individuals who report securities law violations resulting in SEC enforcement actions over $1 million
Dodd-Frank established an SEC whistleblower program that pays eligible individuals 10–30% of sanctions collected in successful enforcement actions exceeding $1 million, significantly incentivizing reporting.