02: Foundation - Control Types Definitions Flashcards

Classification framework (preventive/detective, manual/automated) (25 cards)

1
Q

Control Type Dimensions (1/4)

Preventive

Timing (1/2)

A

Stops errors/fraud BEFORE they occur (blocks the action)

Example: SoD enforcement blocking conflicting access = preventive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Control Type Dimensions (1/4)

Detective

Timing (2/2)

A

Identifies errors/fraud AFTER they occur (finds it later)

Example: Quarterly access review finding terminated users = detective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Control Type Dimensions (2/4)

Manual

Execution (1/3)

A

Human performs entirely

(e.g., manager reviews and approves)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Control Type Dimensions (2/4)

Automated

Execution (2/3)

A

System performs without human intervention

(e.g., system rejects duplicate invoice)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Control Type Dimensions (2/4)

IT-Dependent Manual

Execution (3/3)

A

Human reviews system-generated output

(e.g., manager reviews exception report from system)

Most real-world controls are IT-dependent manual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Control Type Dimensions (3/4)

Key

Significance (1/2)

A

Directly mitigates a risk of material misstatement; if it fails, financials could be wrong.

Always tested by auditors

“If control fails, could financials be materially missated?” Y = Key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Control Type Dimensions (3/4)

Non-Key

Significance (2/2)

A

Supports key controls or mitigates lower risks; may not be tested every period

“If control fails, could financials be materially missated?” N = Non-Key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Control Type Dimensions (4/4)

Entity-Level

Level (1/3)

A

Pervasive controls affecting entire organization

E.g., tone at top, code of conduct, IT security policy, board oversight

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Control Type Dimensions (4/4)

Process-Level

Level (2/3)

A

Controls over a specific business process

E.g., revenue cycle, payroll, procure-to-pay, etc.,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Control Type Dimensions (4/4)

Application-Level

Level (3/3)

A

Controls embedded in application software

E.g.,input validation, automated calculations, system-enforced approvals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Control Classification

TIMING

The 4 Dimensions Framwork (1 of 4)

A

Question to Ask: Does it STOP or FIND?

Options (2): Preventive (blocks before) / Detective (finds after)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Control Classification

Approvals, authorizations, validations BEFORE action?

Memory Patterns: Timing (1/3)

A

Preventive

Approvals, authorizations, validations BEFORE action → Preventative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Control Classification

Human reads a system report then decides → ?

Memory Patterns: Execution (1/3)

A

IT-Dependent
Manual

Human reads a system report then decides → IT-Dependent Manual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Control Classification

System enforces automatically (no human in the loop) → ?

Memory Patterns: Execution (2/3)

A

Automated

System enforces automatically (no human in the loop) → Automated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Control Classification

Human does it entirely (no system output involved) → ?

Memory Patterns: Execution (3/3)

A

Manual

Human does it entirely (no system output involved) → Manual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Control Classification

Touches money directly (revenue, expenses, payroll, cash) → ?

Memory Patterns: Key vs. Non-Key (1 of 2)

A

Almost always Key

Touches money directly (revenue, expenses, payroll, cash) → Key

Ask: “If this fails, could the financial statements be wrong by a material amount?”

17
Q

Control Classification

Supporting/operational (logging, documentation, alerts) → ?

Memory Patterns: Key vs. Non-Key (2 of 2)

A

Usually Non-key

Supporting/operational (logging, documentation, alerts) → Non-key

Ask: “If this fails, could the financial statements be wrong by a material amount?”

18
Q

Control Classification

Org-wide governance, tone at top, policies → ?

Memory Patterns: Level (1 of 3)

A

Entity

Org-wide governance, tone at top, policies → Entity

19
Q

Control Classification

Embedded in software code/configuration → ?

Memory Patterns: Level (3 of 3)

A

Application

Embedded in software code/configuration → Application

20
Q

Control Classification

EXECUTION

The 4 Dimensions Framwork (2 of 4)

A

Question to Ask: Who/what does the work?

Options (3): Manual / Automated / IT-Dependent Manual

21
Q

Control Classification

SIGNIFICANCE

The 4 Dimensions Framwork (3 of 4)

A

Question to Ask: Could financials be materially
wrong if it fails?

Options (2): Key / Non-Key

22
Q

Control Classification

LEVEL

The 4 Dimensions Framwork (4 of 4)

A

Question to Ask: Where does it operate?

Options (3): Entity / Process / Application

23
Q

Control Classification

**Reviews, reconciliations, monitoring AFTER action ** → ?

Memory Patterns: Timing (2/3)

A

Detective

Reviews, reconciliations, monitoring AFTER action → Detective

24
Q

Control Classification

If the word ends in -“review,”, “reconciliation”, “monitoring”, it’s which TIMING option?

Memory Patterns: Timing (3/3)

A

Preventive

Approvals, authorizations, validations BEFORE action → Preventative

25
# Control Classification Specific business cycle (revenue, payroll, procurement) → ? | Memory Patterns: Level (2 of 3)
Process | Specific business cycle (revenue, payroll, procurement) → Process