Internal Controls & Risk Management Flashcards
7 cards from real CAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Internal Controls & Risk Management flashcards as text
What is inherent risk in the context of audit and internal control?
Answer: The risk of a material misstatement before considering any related controls
Inherent risk is the susceptibility of an assertion to a material misstatement assuming no related internal controls exist.
What is control risk as defined in auditing standards?
Answer: The risk that a material misstatement will not be prevented or detected by internal controls
Control risk is the risk that a material misstatement will occur and not be prevented or detected on a timely basis by the entity's internal controls.
Under Sarbanes-Oxley Act Section 404, what are public company management teams required to do?
Answer: Assess and report on the effectiveness of internal controls over financial reporting
SOX Section 404 requires management to assess and report on the effectiveness of internal controls over financial reporting, and external auditors must attest to that assessment.
How is a 'material weakness' in internal controls defined under PCAOB standards?
Answer: A deficiency where there is a reasonable possibility that a material misstatement will not be prevented or detected
A material weakness is a deficiency, or combination of deficiencies, in internal control such that there is a reasonable possibility that a material misstatement will not be prevented or detected and corrected on a timely basis.
Which of the following best describes a detective control?
Answer: A control that identifies errors or fraud after they have occurred
Detective controls are designed to identify and expose undesirable events that have already occurred, such as reconciliations, audits, and exception reports.
What is Enterprise Risk Management (ERM)?
Answer: A comprehensive approach to identifying, assessing, and managing risks across an entire organization
ERM is a holistic, organization-wide process for identifying, assessing, managing, and monitoring risks that could affect the achievement of the organization's objectives.
Which of the following is the key distinction between internal auditors and external auditors?
Answer: Internal auditors are employees of the organization; external auditors are independent third parties
Internal auditors are employed by the organization and focus on operational efficiency and risk management, while external auditors are independent third parties who attest to the fairness of financial statements.