Risk Management and Internal Controls Flashcards
7 cards from real RCC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management and Internal Controls flashcards as text
Which element is NOT one of the five components of the COSO Internal Control – Integrated Framework?
Answer: Risk Appetite
The five COSO components are Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring Activities; Risk Appetite is a concept from COSO ERM, not the IC framework.
An organization's 'risk tolerance' differs from 'risk appetite' in that risk tolerance refers to:
Answer: The acceptable variation around risk appetite objectives
Risk tolerance defines the acceptable deviation from risk appetite, providing operational boundaries around the broader strategic risk appetite statement.
Under SOX Section 302, which executives must personally certify the effectiveness of disclosure controls and procedures?
Answer: Chief Executive Officer and Chief Financial Officer
SOX Section 302 requires the CEO and CFO to personally certify the adequacy of disclosure controls and that financial statements fairly present the company's financial condition.
A 'walkthrough' in the context of internal control testing involves:
Answer: Selecting a sample of transactions and tracing each through the entire control process
A walkthrough traces one or more transactions through each step of a process to confirm controls are designed and operating as described.
Which of the following risks is BEST managed through establishing clear third-party vendor due diligence policies?
Answer: Operational risk from outsourcing
Vendor due diligence policies directly address the operational risk that third-party partners may introduce through inadequate controls, data breaches, or compliance failures.
Which internal control is MOST effective at detecting unauthorized changes to financial records?
Answer: Automated system access logs and audit trails
Automated audit trails capture every system change with timestamps and user IDs, providing a detective control to identify unauthorized modifications to financial records.
What does a 'material weakness' in internal controls mean under PCAOB standards?
Answer: A deficiency or combination of deficiencies with a reasonable possibility of material financial statement misstatement
A material weakness is a deficiency—or combination of deficiencies—in internal control that presents a reasonable possibility of a material misstatement not being prevented or detected on a timely basis.