Foundations of internal auditing, governance, risk, and control concepts tested on CIA Exam Part 1.
39 cards · basic cards · AI-written, checked twice. Edit anything.
- What is the primary purpose of internal auditing?
- To provide independent assurance and consulting services to help an organization accomplish its objectives.
- Define internal auditing according to the IIA Standards.
- A systematic, disciplined approach to evaluating and improving the effectiveness of risk management, control, and governance processes.
- What is governance?
- The combination of processes and structures implemented by the board to inform, direct, manage, and monitor organizational activities toward the achievement of objectives.
- Name three key responsibilities of the board in governance.
- Setting organizational strategy, ensuring accountability, and overseeing risk and control processes.
- What is risk?
- The possibility that an event will occur and negatively affect the achievement of organizational objectives.
- Define risk appetite.
- The amount and type of risk an organization is willing to accept in pursuit of its strategic objectives.
- What is risk tolerance?
- The acceptable range or level of variation in outcomes related to a specific risk or objective.
- What does Enterprise Risk Management (ERM) encompass?
- A systematic approach to identifying, evaluating, and managing risks across the entire organization at strategic and operational levels.
- Name the five components of the COSO Internal Control Framework.
- Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities.
- What is the Control Environment?
- The foundation for all other internal control components, including the organization's values, ethics, integrity, and commitment to competence.
- List the four dimensions of the COSO ERM Framework.
- Strategy and Objective-Setting, Enterprise Risk Management Design, Enterprise Risk Management Implementation, and Enterprise Risk Management Monitoring.
- Define internal control.
- A process implemented by management designed to provide reasonable assurance regarding the achievement of organizational objectives.
- What is a preventive control?
- A control activity designed to stop an error or irregularity from occurring before it affects the financial records or operations.
- What is a detective control?
- A control activity designed to identify and detect errors or irregularities that have already occurred.
- What is segregation of duties?
- The division of responsibilities among different individuals to reduce the risk of error or fraud in a business process.