COSO PAPER Questions and Answers
Verified Solutions Latest Update
Question:
Auditor's Assurance.
Answer:
The auditor needs assurance about the reliability of the data generated by the
information system.
Question:
What procedures does the auditor use for risk assessment?.
Answer:
The auditor uses procedures to obtain an understanding of the entity's internal control,
identify key controls, recognize types of potential misstatements, assess control risk
(risk of material misstatement), and design tests of controls and substantive
procedures.
Question:
Why is the auditor's understanding of internal control important?.
Answer:
It is a major factor in determining the overall audit strategy.
Question:
What type of controls are most relevant to an audit?.
Answer:
Internal controls that contribute to the reliability, timeliness, and transparency of
external financial reporting.
,Question:
When may controls relating to operations and compliance objectives be relevant in an
audit?.
Answer:
When they relate to data the auditor uses to apply auditing procedures.
Question:
COSO's Internal Control-Integrated Framework.
Answer:
A system designed and carried out by an entity's board of directors, management, and
other personnel to provide reasonable assurance about the achievement of the entity's
objectives.
Question:
Objectives of COSO's Internal Control-Integrated Framework.
Answer:
Reliability, timeliness, and transparency of internal and external Financial and
Nonfinancial Reporting. One of the categories of objectives that internal control aims to
achieve. Adherence to Laws and Regulations as part of the internal control objectives.
Question:
COSO-Components of Internal Control.
Answer:
Control Environment.
Question:
Entity's Risk Assessment Process.
Question:
Control Activities.
Question:
Information and Communication.
,Question:
Monitoring Activities.
Question:
Control Environment.
Answer:
Set of standards, processes, and structures that provides the basis for carrying out
internal control across the organization.
Question:
Tone at the Top.
Answer:
The board of directors and senior management establish the tone at the top regarding
the importance of internal control and expected standards of conduct.
Question:
Principle 1 of Control Environment.
Answer:
The organization demonstrates a commitment to integrity and ethical values.
Question:
Principle 2 of Control Environment.
Answer:
The board of directors demonstrates independence from management and exercises
oversight of the development and performance of internal control.
Question:
Principle 3 of Control Environment.
Answer:
Management establishes, with board oversight, structures, reporting lines, and
appropriate authorities and responsibilities in the pursuit of objectives.
, Question:
Principle 4 of Control Environment.
Answer:
The organization demonstrates a commitment to attract, develop, and retain
competent individuals in alignment with objectives.
Question:
Principle 5 of Control Environment.
Answer:
The organization holds individuals accountable for their internal control responsibilities
in the pursuit of objectives.
Question:
What is the primary purpose of the Entity's Risk Assessment Process?.
Answer:
To identify and respond to business risks in relation to achieving business objectives.
Question:
What types of events should the risk assessment process consider?.
Answer:
Both external and internal events and circumstances.
Question:
How can adverse events affect an entity according to the risk assessment process?.
Answer:
They may adversely affect the entity's ability to initiate, record, process, and report
financial data.
Verified Solutions Latest Update
Question:
Auditor's Assurance.
Answer:
The auditor needs assurance about the reliability of the data generated by the
information system.
Question:
What procedures does the auditor use for risk assessment?.
Answer:
The auditor uses procedures to obtain an understanding of the entity's internal control,
identify key controls, recognize types of potential misstatements, assess control risk
(risk of material misstatement), and design tests of controls and substantive
procedures.
Question:
Why is the auditor's understanding of internal control important?.
Answer:
It is a major factor in determining the overall audit strategy.
Question:
What type of controls are most relevant to an audit?.
Answer:
Internal controls that contribute to the reliability, timeliness, and transparency of
external financial reporting.
,Question:
When may controls relating to operations and compliance objectives be relevant in an
audit?.
Answer:
When they relate to data the auditor uses to apply auditing procedures.
Question:
COSO's Internal Control-Integrated Framework.
Answer:
A system designed and carried out by an entity's board of directors, management, and
other personnel to provide reasonable assurance about the achievement of the entity's
objectives.
Question:
Objectives of COSO's Internal Control-Integrated Framework.
Answer:
Reliability, timeliness, and transparency of internal and external Financial and
Nonfinancial Reporting. One of the categories of objectives that internal control aims to
achieve. Adherence to Laws and Regulations as part of the internal control objectives.
Question:
COSO-Components of Internal Control.
Answer:
Control Environment.
Question:
Entity's Risk Assessment Process.
Question:
Control Activities.
Question:
Information and Communication.
,Question:
Monitoring Activities.
Question:
Control Environment.
Answer:
Set of standards, processes, and structures that provides the basis for carrying out
internal control across the organization.
Question:
Tone at the Top.
Answer:
The board of directors and senior management establish the tone at the top regarding
the importance of internal control and expected standards of conduct.
Question:
Principle 1 of Control Environment.
Answer:
The organization demonstrates a commitment to integrity and ethical values.
Question:
Principle 2 of Control Environment.
Answer:
The board of directors demonstrates independence from management and exercises
oversight of the development and performance of internal control.
Question:
Principle 3 of Control Environment.
Answer:
Management establishes, with board oversight, structures, reporting lines, and
appropriate authorities and responsibilities in the pursuit of objectives.
, Question:
Principle 4 of Control Environment.
Answer:
The organization demonstrates a commitment to attract, develop, and retain
competent individuals in alignment with objectives.
Question:
Principle 5 of Control Environment.
Answer:
The organization holds individuals accountable for their internal control responsibilities
in the pursuit of objectives.
Question:
What is the primary purpose of the Entity's Risk Assessment Process?.
Answer:
To identify and respond to business risks in relation to achieving business objectives.
Question:
What types of events should the risk assessment process consider?.
Answer:
Both external and internal events and circumstances.
Question:
How can adverse events affect an entity according to the risk assessment process?.
Answer:
They may adversely affect the entity's ability to initiate, record, process, and report
financial data.