Internal Controls and Audit Flashcards
6 cards from real CCO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Internal Controls and Audit flashcards as text
What is a control self-assessment (CSA)?
Answer: A process where business units assess their own controls against defined criteria, often facilitated by internal audit or compliance
CSAs engage business management and employees in evaluating the effectiveness of their own controls, building ownership and providing an early warning of control gaps.
What is the difference between preventive and detective controls?
Answer: Preventive controls stop violations before they occur; detective controls identify violations after they have occurred
Preventive controls (e.g., approval requirements) block violations before they happen, while detective controls (e.g., reconciliations) identify them after the fact.
What is an internal audit charter?
Answer: A formal document that defines the internal audit function's purpose, authority, responsibility, and independence within the organization
The internal audit charter establishes the function's organizational authority, independence, scope, and accountability structure, typically approved by the Audit Committee.
What does 'reasonable assurance' mean in the context of internal controls?
Answer: That controls provide a high but not absolute level of assurance that objectives will be met, given inherent limitations of any control system
Reasonable assurance acknowledges that no control system is perfect and that there are inherent limitations — cost/benefit tradeoffs and human fallibility mean absolute assurance is unachievable.
What is a management response to an audit finding?
Answer: A formal response from management agreeing with or disputing the finding and committing to specific corrective actions with timelines
Management responses commit the business to remediation actions, owners, and deadlines for each audit finding, creating accountability for resolving control deficiencies.
What is an audit risk model?
Answer: A framework combining inherent risk, control risk, and detection risk to determine the audit procedures needed to achieve acceptable assurance levels
The audit risk model helps auditors calibrate the nature, timing, and extent of procedures based on the combination of inherent, control, and detection risks in each area.