Internal Controls & Auditing Flashcards
7 cards from real CSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Internal Controls & Auditing flashcards as text
Which control framework specifically addresses internal controls over financial reporting for publicly traded companies?
Answer: COSO 2013 Framework
The COSO 2013 Internal Control – Integrated Framework is the primary standard used for evaluating internal controls over financial reporting under SOX Section 404.
A 'detective control' in a securities firm is best exemplified by which of the following?
Answer: Monthly reconciliation of broker statements to internal records
Monthly reconciliation is a detective control because it identifies errors or irregularities after transactions have already occurred.
Under SOX Section 404(b), which party is required to attest to the effectiveness of a public company's internal control over financial reporting?
Answer: The company's external auditor
SOX Section 404(b) requires the registered public accounting firm (external auditor) to attest to and report on management's assessment of internal controls.
What is the primary purpose of a 'walkthrough' in an internal audit of a securities firm?
Answer: To trace a transaction from initiation through completion to verify controls operate as described
A walkthrough traces a single transaction end-to-end to confirm that documented controls exist and function as described in process narratives.
A broker-dealer's internal audit function discovers that a trader has been executing trades just below the reporting threshold to avoid detection. This activity is known as:
Answer: Structuring
Structuring involves breaking transactions into smaller amounts specifically to evade reporting thresholds, which is illegal under the Bank Secrecy Act.
Which of the following best describes the 'three lines of defense' model used in securities firm risk management?
Answer: Business lines, compliance/risk functions, and internal audit
The three lines of defense model designates business lines as the first line (own/manage risk), compliance/risk as the second line (oversee), and internal audit as the third line (independent assurance).
When an internal auditor issues an 'adverse' opinion on internal controls, it means:
Answer: A material weakness exists and internal controls are not effective
An adverse opinion on internal controls means the auditor has concluded that internal control over financial reporting is not effective due to the presence of a material weakness.