Def: internal control
policies + procedures instituted and maintained by the management to provide reasonable assurance that management’s objectives are met
who’s responsibility is internal controls
management’s
primary objectives of effective internal controls (4)
management must ___+____ . the entity’s internal controls
establish + maintain
if the company is public, management is required to
publicly report on operating effectiveness of internal controls in financial reports
auditors are responsible for
understanding entity internal control relevant to the audit
why must auditors understand
to identify the risks of material misstatement at the financial statement and assertion level
when must auditor obtain understanding of controls
ALL the time even if he does not intend on placing reliance on internal controls
when assessing control risk, auditors are concerned with (2)
2. transaction controls
Def: entity level controls
pervasive in nature and not address particular transaction cycles
entity level controls may prevent or detect and correct
misstatements in several cycles
def: transaction controls
implemented for specific transaction risks
transaction controls specifically prevent or detect and correct
misstatements in classes of transactions, account balances or disclosures and their related assertions
before the auditor can conclude that the total for any given class of transactions is fairly stated
five audit objectives must be met
what are the 5 audit objectives (transaction)
occurrence, completeness, accuracy, cut-off and classification
5 components of COSO internal control framework
principles associated with control environment (5)
principles with risk assessment (4)
principles with control activities (3)
principles with info and communication (3)
principles with monitoring (2)
def: control activities
actions established by policies and procedures to help ensure that management directives to mitigate risks are carried out
Def: transaction controls
control activities to mitigate transaction processing risk for specific business processes
control activities should be a combination of
preventive and detective controls