ALL RIGHTS RESERVED.
Chapter 5: COSO Components to the
Internal Control Framework Questions And
Answers
According to COSO, there are 5 components to the Internal Control framework: - Answers✔Control
Environment - "tone at the top"
Risk Assessment
Control Activities
Information and Communication
Monitoring
Control Environment - "tone at the top" (9) - Answers✔a. Management integrity and ethical values
b. Board of directors
c. Management's philosophy and operating style
d. Organizational structure and clear lines of authority
e. Financial reporting competencies
, ©SIRJOEL EXAM SOLUTIONS 2024/2025
ALL RIGHTS RESERVED.
f. Authority and responsibility
g. Human resources, proper hiring and background checks
h. The control environment is the most important element.
i. Publicly-traded companies must have audit committees
The audit committee (5) - Answers✔acts as liaison between the internal auditors and management, and
the external auditors and management. The audit committee resolves audit conflicts
hires/fires the external auditors and negotiates the audit fee
resolves conflicts brought to the audit committee by both the internal and external auditors (auditors
should take problems and disagreements to the audit committee, not to management)
approves any non-audit services provided by the external auditor
oversees the confidential fraud hotline used by client employees to report fraud
Risk Assessment (3) - Answers✔-the extent to which a client manages its own business risk using the
COSO's ERM system
-the client's ability to conduct its own risk assessment
-the client's ability to apply the iceberg principle.
Control Activities are - Answers✔actions taken by management to prevent/detect errors, safeguard
assets, etc.
The 5 kinds of Control Activities are - Answers✔-Separation of duties - custody, authorization, record-
keeping, reconciliations