Corporate Governance Risk Management & Internal Controls 1 — Questions and Answers
Question 1: What framework is most widely used for evaluating internal controls over financial reporting?
- ISO 31000
- COSO Internal Control – Integrated Framework (Correct answer)
- COBIT 5
- Basel III
Correct answer: COSO Internal Control – Integrated Framework
The COSO Internal Control – Integrated Framework is the standard used by most US public companies to design, implement, and evaluate internal controls under SOX 404.
Question 2: What does SOX Section 404 require of management?
- An annual assessment of the effectiveness of internal controls over financial reporting (Correct answer)
- Quarterly certifications of all material accounting estimates
- A real-time audit of all financial transactions
- Annual disclosure of all related-party transactions
Correct answer: An annual assessment of the effectiveness of internal controls over financial reporting
SOX 404 requires management to assess and report on the effectiveness of internal controls over financial reporting, with external auditor attestation for large accelerated filers.
Question 3: What is 'enterprise risk management' (ERM)?
- A framework for identifying, assessing, and managing risks across the entire organization to achieve strategic objectives (Correct answer)
- An IT security system protecting company databases from breaches
- A financial model used to stress-test a company's balance sheet
- A regulatory requirement for banks to maintain capital reserves
Correct answer: A framework for identifying, assessing, and managing risks across the entire organization to achieve strategic objectives
ERM is a comprehensive, board-level process for identifying, quantifying, and managing risks that could affect an organization's ability to achieve its objectives.
Question 4: Which of the following is a 'preventive' internal control?
- Bank reconciliation
- Variance analysis
- Segregation of duties (Correct answer)
- Audit trail review
Correct answer: Segregation of duties
Segregation of duties prevents errors or fraud by ensuring no single individual controls all phases of a transaction, acting as a preventive rather than detective control.
Question 5: What is a 'material weakness' in internal controls?
- A significant deficiency that creates a reasonable possibility of a material misstatement in financial statements (Correct answer)
- A minor bookkeeping error identified during year-end close
- An audit finding that results in a restatement of prior-year earnings
- A control gap limited to a single non-critical business unit
Correct answer: A significant deficiency that creates a reasonable possibility of a material misstatement in financial statements
A material weakness is the most serious internal control deficiency — it creates a reasonable possibility that a material misstatement could occur and not be prevented or detected.
Question 6: Which board committee is primarily responsible for overseeing the company's risk management framework?
- Compensation Committee
- Nominating Committee
- Audit Committee
- Risk Committee or Audit Committee (Correct answer)
Correct answer: Risk Committee or Audit Committee
Risk oversight typically falls to either the full board, the audit committee, or a dedicated risk committee, depending on the company's governance structure.
What framework is most widely used for evaluating internal controls over financial reporting?