Business acumen, IT, and financial management concepts tested on CIA Exam Part 3.
41 cards · basic cards · AI-written, checked twice. Edit anything.
- What is the primary purpose of an organization's strategic plan?
- To establish long-term direction, objectives, and resource allocation aligned with organizational mission.
- Define working capital in a business context.
- Current assets minus current liabilities; funds available for day-to-day operations.
- What does IT governance establish?
- Framework for IT decision-making, accountability, and alignment with business objectives.
- What is a control environment in internal auditing?
- The tone at the top; culture and values established by management regarding internal control importance.
- Define operational risk.
- Risk of loss from inadequate or failed processes, systems, people, or external events.
- What is the purpose of segregation of duties in internal controls?
- To separate authorization, execution, custody, and recording to prevent error or fraud.
- What does Return on Investment (ROI) measure?
- Profit generated on capital invested, expressed as a percentage.
- Define enterprise risk management (ERM).
- Integrated approach to identifying, assessing, and responding to risks across the entire organization.
- What is a business process?
- Series of activities or tasks performed to achieve a specific business outcome or objective.
- What is the role of the audit committee?
- Oversee internal audit, external audit, financial reporting, and risk management on behalf of the board.
- Define information security.
- Protection of information assets from unauthorized access, modification, disclosure, or destruction.
- What are the three lines of defense in internal audit?
- First: operational management controls. Second: risk management and compliance functions. Third: internal and external audit.
- What is accounts receivable?
- Amount of money customers owe an organization for goods or services delivered.
- Define cybersecurity risk.
- Threat of unauthorized digital access, data breach, or system compromise affecting business continuity.
- What is the purpose of an internal audit function?
- Provide independent, objective assurance and advisory services to improve organizational effectiveness and manage risks.