ALL RIGHTS RESERVED.
COSO Exam Questions And Answers
What are the five elements of internal control according to COSO)? - Answers✔Monitoring, control
activities, risk assessment, control environment (foundation)
Control Environment - Answers✔Managements philosophy toward controls, organizational structure,
system of authority and responsibility, personal practices, policies, etc. This component is the
foundation of any system of internal control.
Risk Assessment - Answers✔Process of identifying, analyzing, and managing risks involved in achieving
the organization's objectives.
Control Activities - Answers✔Policies and procedures that ensure that actions are taken to address the
risks related to the achievement of management's objectives.
Five Principles of Control Environment - Answers✔1. Integrity and ethical values; 2. Board of directors
independent of management; 3. Management establishes oversight over achieving objectives; 4.
Competence; Management attracts, develops and retains good employees; 5. Accountability of
individuals.
Five Principles of Control Environment; Integrity and Ethical Values - Answers✔"Tone at the Top"
Five Principles of Control Environment; Board of Directors - Answers✔Independent of management,
oversees development and monitoring of internal control including 1. clear board of directors overnight
responsibilities and independence. 2. Evidence and application of relevant expertise.
Five Principles of Control Environment; Management - Answers✔Strive to achieve objectives
Five Principles of Control Environment; Competence - Answers✔Commitment to attract, develop and
retain competent individuals
Five Principles of Control Environment; Accountability - Answers✔Individuals held accountable for
internal control responsibilities
Risk Assessment; Four Principles; Objectives - Answers✔Objectives, Assessment, Fraud, Change
Management
Risk Assessment; Four Principles; Objectives; - Answers✔Organizational objectives should consider risk
tolerance, materiality in relation to risk assessment, risks related to the organization's ability to comply
, ©SIRJOEL EXAM SOLUTIONS 2024/2025
ALL RIGHTS RESERVED.
with standards, frameworks, laws and regulations, risks related to operational and financial
performance goals and risks in committing resources
Risk Assessment; Four Principles; Assessment - Answers✔Managing risk involves including management
in risk assessment, consider entity levels, analyze internal and external factors, estimate risk importance,
and develop appropriate risk responses.
Risk Assessment; Four Principles; Change Management - Answers✔Organization identifies and assesses
and changes in the external environment, business model and organizational leadership that could
impact the system of internal control.
Control Activities; Three Principles - Answers✔Risk Reduction, technology controls,policies
Control Activities; Three Principles; Risk Reduction - Answers✔Control activities reduce the risks to the
achievement of objectives to acceptable levels. Examples include evaluating mix of control activity tpes
like manual and automated, preventive and detective. Or segregatexion of duties.
Information & Communication; Three Principles - Answers✔Quality of information of supporting
controls, internal and external communications
Monitoring; Two Principles - Answers✔Ongoing and periodic evaluations, address control deficiencies
What types of buyers takes precedence over perfected secured interests? - Answers✔Buyers in the
ordinary course of business.
Risk assessment materiality - Answers✔The determination of how large of a risk poses a threat to
objectives
Organizational policies - Answers✔The organization's control activities that establish stakeholder
expectations regarding conduct and operations.
Risk Assessment Precision - Answers✔Whether, and the extent to which, risk can be quantified.
COSO ERM - Answers✔A process effected by an entity's board, management and other personnel,
applied in strategy setting and across enterprise, designed to identify events that may affect the entity,
and manage risks to be within its risk appetite, to provide reasonable assurance regarding achieving
objectives.
COSO ERM Objectives - Answers✔Strategic objectives, operations objectives, reporting objectives, and
compliance objectives
COSO Cube - Answers✔Four objectives by four organizational levels by eight control components
COSO ERM Components - Answers✔Control environment, risk assessment, information and
communication, monitoring, control activities, objectives setting, event identification, and risk response.
Risk Response - Answers✔Management's response to risk. Depends on managements risk appetite. May
include avoidance, reduction, sharing or acceptance.