ACTG 313 UPDATED ACTUAL FINAL EXAM QUESTIONS
AND SOLUTIONS GUARANTEE A+
✔✔ERP Disadvantages - ✔✔cost, time-consuming to implement, changes to an
organization's existing business processes can be disruptive, complex, resistance to
change.
✔✔why is control needed - ✔✔- Any potential adverse occurrence or unwanted event
that could be injurious to either the accounting information system or the organization is
referred to as a threat or an event.
- The potential dollar loss should a particular threat become a reality is referred to as the
exposure or impact of the threat.
- The probability that the threat will happen is the likelihood associated with the threat
✔✔primary objective of an AIS - ✔✔to control the organization so the organization can
achieve its objectives
✔✔management expects accountants to - ✔✔1. Take a proactive approach to
eliminating system threats.
2. Detect, correct, and recover from threats when they occur.
✔✔foreign corrupt practices act (FCPA) - ✔✔1977
prevents companies from bribing foreign officials to obtain business
requires all publicly owned corporations to maintain a system of internal accounting
controls
✔✔sarbanes oxley act (SOX) - ✔✔law passed in 2002 that applies to publicly held
companies and their auditors to report on the effectiveness of internal controls
✔✔major control frameworks - ✔✔Cobit
COCO
COSO-ERM
✔✔COSO Framework 5 componets - ✔✔1. Control Environment
2. Risk Assessment
3. Control Activities
4. Information and Communication
5. Monitoring
committee of sponsoring organizations
control based approach
CRIME
, ✔✔17 principals control environment - ✔✔1. demonstrates commitment to integrity and
ethics
2. oversight responsibility
3. establishes structure, authority, and responsibility
4. demonstrates commitment to competence
5. enforces accountability
✔✔17 principals risk assessment - ✔✔6. specifies suitable objectives
7. identifies and analyzes risk
8. assesses fraud risk
9. identifies and analyzes significant change
✔✔17 principals control activities - ✔✔10. selects and develops control activities
11. selects and develops control over technology
12. deploys through policy and procedures
✔✔17 principals monitoring - ✔✔16. conducts ongoing and separate evaluations
17. evaluates and communicates deficiencies
✔✔coso vs coso ERM - ✔✔COSO ERM
adds
internal environment
event identification
risk response---- cost benefit
and strategic
coso erm is a strategic risk based approach
✔✔inherent risk - ✔✔Risk that exists before plans are made to control it
✔✔residual risk - ✔✔the risk that remains after management implements internal
controls or some other response to risk
✔✔cobit framework - ✔✔Control Objectives for Information and Related Technology
focused on IT
based on 5 principals
1. meeting the stakeholder neeeds
2. covering the enterprise end to end
3. applying a single integrated framework
4. holistic approach
5. separating governance from management
✔✔basic revenue cycle activities - ✔✔sales order entry
shipping
billing
cash collections
AND SOLUTIONS GUARANTEE A+
✔✔ERP Disadvantages - ✔✔cost, time-consuming to implement, changes to an
organization's existing business processes can be disruptive, complex, resistance to
change.
✔✔why is control needed - ✔✔- Any potential adverse occurrence or unwanted event
that could be injurious to either the accounting information system or the organization is
referred to as a threat or an event.
- The potential dollar loss should a particular threat become a reality is referred to as the
exposure or impact of the threat.
- The probability that the threat will happen is the likelihood associated with the threat
✔✔primary objective of an AIS - ✔✔to control the organization so the organization can
achieve its objectives
✔✔management expects accountants to - ✔✔1. Take a proactive approach to
eliminating system threats.
2. Detect, correct, and recover from threats when they occur.
✔✔foreign corrupt practices act (FCPA) - ✔✔1977
prevents companies from bribing foreign officials to obtain business
requires all publicly owned corporations to maintain a system of internal accounting
controls
✔✔sarbanes oxley act (SOX) - ✔✔law passed in 2002 that applies to publicly held
companies and their auditors to report on the effectiveness of internal controls
✔✔major control frameworks - ✔✔Cobit
COCO
COSO-ERM
✔✔COSO Framework 5 componets - ✔✔1. Control Environment
2. Risk Assessment
3. Control Activities
4. Information and Communication
5. Monitoring
committee of sponsoring organizations
control based approach
CRIME
, ✔✔17 principals control environment - ✔✔1. demonstrates commitment to integrity and
ethics
2. oversight responsibility
3. establishes structure, authority, and responsibility
4. demonstrates commitment to competence
5. enforces accountability
✔✔17 principals risk assessment - ✔✔6. specifies suitable objectives
7. identifies and analyzes risk
8. assesses fraud risk
9. identifies and analyzes significant change
✔✔17 principals control activities - ✔✔10. selects and develops control activities
11. selects and develops control over technology
12. deploys through policy and procedures
✔✔17 principals monitoring - ✔✔16. conducts ongoing and separate evaluations
17. evaluates and communicates deficiencies
✔✔coso vs coso ERM - ✔✔COSO ERM
adds
internal environment
event identification
risk response---- cost benefit
and strategic
coso erm is a strategic risk based approach
✔✔inherent risk - ✔✔Risk that exists before plans are made to control it
✔✔residual risk - ✔✔the risk that remains after management implements internal
controls or some other response to risk
✔✔cobit framework - ✔✔Control Objectives for Information and Related Technology
focused on IT
based on 5 principals
1. meeting the stakeholder neeeds
2. covering the enterprise end to end
3. applying a single integrated framework
4. holistic approach
5. separating governance from management
✔✔basic revenue cycle activities - ✔✔sales order entry
shipping
billing
cash collections