0% found this document useful (0 votes)
3 views12 pages

sec e

The document outlines the importance of internal controls, IT controls, and regulatory frameworks such as SOX and FCPA in ensuring reliable financial reporting and compliance. Key concepts include the need for segregation of duties, the independence of audit committees, and the flexibility of internal control systems under FCPA. It also emphasizes the significance of IT governance, cybersecurity measures, and disaster recovery planning in maintaining effective internal controls.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views12 pages

sec e

The document outlines the importance of internal controls, IT controls, and regulatory frameworks such as SOX and FCPA in ensuring reliable financial reporting and compliance. Key concepts include the need for segregation of duties, the independence of audit committees, and the flexibility of internal control systems under FCPA. It also emphasizes the significance of IT governance, cybersecurity measures, and disaster recovery planning in maintaining effective internal controls.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

OVERALL BIG PICTURE

INTERNAL CONTROLS + IT CONTROLS + REGULATORY FRAMEWORKS (SOX & FCPA)

These are mainly tested in:

• Section C: Performance Management

• Internal Control & Risk Management

ORGANIZED SUMMARY BY TOPIC

INTERNAL CONTROL BASICS (CORE FOUNDATION)

Key Ideas:

• Internal controls provide reasonable assurance, NOT absolute assurance

• Must balance cost vs benefit

Exam meaning:

• Controls cannot eliminate all risk

• Too much control = too expensive

Financial Reporting Objective: In Financial reporting, Internal Control


Ensure Reliable FS.
• Ensure reliable financial statements

Segregation of Duties (VERY TESTED):

Examples from your notes:

• Cashier handling cash + preparing deposit slip → violation

• Computer operator running programs + holding files → violation

Rule: NEVER combine: (HIGHLY IMPORTANT)

• Custody

• Recording

• Authorization
SOX (GOVERNANCE + AUDIT COMMITTEE)

Sarbanes-Oxley Act of 2002

Key Takeaways:

• Audit committee must be independent

• Can hire outside lawyers/consultants

Meaning:

• Not dependent on management

• Strong oversight = better controls

FCPA (ETHICS + INTERNAL CONTROL FLEXIBILITY)

Foreign Corrupt Practices Act

Key Points:

• Requires internal controls + accurate records

• BUT does NOT require a specific framework like COSO

Companies can design:

• Any system (as long as it works)

IT CONTROLS (VERY HIGH YIELD)

A. TYPES OF IT CONTROLS

Input Controls:
• Check digit
• Validity check
Prevent wrong data entry Preventive Controls

Processing Controls:
• Transaction logs
Track system processing Detective Controls

Output Controls:
• Spooling
Manage output delivery Corrective Controls
B. ACCESS & SECURITY CONTROLS

• Unique user ID → authentication

• Compatibility check → verifies access rights

• Single sign-on → convenient but risky (single failure point)

C. CYBERSECURITY

Trojan horse malware

• Installed voluntarily

• Hidden malicious function

Computer virus

• Spreads automatically

D. DATA SECURITY

• Encryption → protects data (cannot read without key)

• Firewall → blocks unauthorized access

IT GOVERNANCE & SEGREGATION (ADVANCED)

Proper IT role separation:

• Data control group → reprocess errors

• Manager → review only

• Programmer → access programs only

Rule:
No one should process + control + review

DATA & PROCESS TOOLS

• Flowchart → visual representation of processes

• Key verification → protects critical data fields


DISASTER RECOVERY & BUSINESS CONTINUITY

Cold Site:

• Empty facility ready for emergency use

• Needs hardware setup after disaster

Recovery Priority:

• Operating system restored FIRST

Business Continuity Planning:

• Keeps operations running during/after disruption

HOW CMA CONNECTS ALL THIS FINAL MENTOR SUMMARY


They DON’T test definitions. If I compress EVERYTHING into one line:
They test: Internal control = balance risk, assign roles properly,
“What control failed?” protect data, and ensure reliable reporting
“What risk exists?”
“Who has too much power?”

ULTRA-FAST MEMORY MAP

• Internal Control → Reasonable assurance

• SOX → Governance + audit oversight

• FCPA → No bribery + flexible controls

• IT Controls → Input / Process / Output

• Security → Encryption + Firewall

• Risk → Segregation failures

• Continuity → Disaster recovery


CMA PART 1 — INTERNAL CONTROLS / SOX / FCPA / IT (CRAM SHEET)

1. INTERNAL CONTROL CORE

Objective:

Reliable financial reporting


Efficient operations
Compliance

KEY RULE:

Reasonable assurance ONLY (not absolute)


Cost of control ≤ Benefit

SEGREGATION OF DUTIES (ALWAYS TESTED)

NEVER combine:

• Authorization

• Recording

• Custody

Example traps:

• Cashier handles cash + records → WRONG

• IT operator runs + controls files → WRONG

2. COSO FRAMEWORK

Committee of Sponsoring Organizations of the Treadway Commission

5 Components (MEMORIZE):

CRIME

• Control Environment

• Risk Assessment

• Information & Communication

• Monitoring

• Execution (Control Activities)


3. SOX (GOVERNANCE)

Sarbanes-Oxley Act of 2002

MUST KNOW:

• 302 → CEO/CFO certify FS

• 404 → Internal controls

o Management → evaluates

o Auditor → attests

Audit Committee:

• Independent

• Hires auditors

• Can use external consultants

KEY RULE:

Auditor = independent (NO system design!)

4. FCPA (ETHICS + CONTROLS)

Foreign Corrupt Practices Act

CORE IDEA:

NO BRIBES + CLEAN BOOKS

Key Points: Foreign Corrupt Practices Act (FCPA)

• Applies to foreign dealings

• Covers third parties

• Requires accurate records + controls

• DOES NOT require COSO specifically


5. IT CONTROLS (HIGH YIELD)

TYPES OF CONTROLS

Input:

• Validity check

• Check digit

Processing:

• Transaction logs

Output:

• Spooling

ACCESS CONTROLS

• User ID + password → authentication

• Compatibility check → access rights

• Single sign-on → risk (single failure point)

6. CYBER & DATA SECURITY

Trojan horse malware

• Looks safe, acts malicious

Computer virus

• Self-spreading

Protection:

• Encryption → unreadable without key

• Firewall → blocks unauthorized access


7. IT SEGREGATION (ADVANCED TRAP)

• Data control → fix errors

• Manager → review only

• Programmer → code only

NO overlap of duties

8. PROCESS TOOLS

• Flowchart → visual process

• Key verification → protects key fields

9. DISASTER RECOVERY

Cold Site:

• Empty backup location

Priority:

Restore Operating System FIRST

Business Continuity:

Keep operations running during disruption

FINAL EXAM TRIGGERS (READ THIS BEFORE TEST)

If you see:

• One person doing too much → Segregation issue


ULTIMATE MEMORY LINE
• CEO/CFO → Section 302
“Right people, right roles,
• Internal control assessment → Section 404 clean records, controlled
• Foreign payment → FCPA risk systems.”

• System access issue → IT control weakness

• “Looks okay but feels wrong” → TRUST THAT


CMA PART 1 — BRAIN DUMP SHEET

INTERNAL CONTROL

Goal:
✔ Reliable reporting
✔ Efficiency
✔ Compliance

Rule:
Reasonable ≠ Absolute
Cost ≤ Benefit

SEGREGATION OF DUTIES

NEVER combine:

• A = Authorization

• R = Recording

• C = Custody

ARC violation = FRAUD RISK

COSO

Committee of Sponsoring Organizations of the Treadway Commission

CRIME

• C = Control Environment

• R = Risk Assessment

• I = Info & Communication

• M = Monitoring

• E = Execution (Control Activities)


SOX

Sarbanes-Oxley Act of 2002

302 = SIGN

• CEO/CFO certify FS

404 = CONTROL

• Mgmt → assess

• Auditor → attest

Audit Committee:

• Independent

• Hires auditors

Auditor cannot design system

FCPA

Foreign Corrupt Practices Act

NO BRIBE + CLEAN BOOKS

• Covers foreign officials

• Includes 3rd parties

• Accurate records REQUIRED

• No specific framework required

IT CONTROLS

Input → validity, check digit


Process → logs
Output → spooling
ACCESS CONTROL

• User ID + password

• Compatibility check

• Single sign-on = risk

SECURITY

• Encryption = unreadable data

• Firewall = blocks access

MALWARE

• Trojan = disguised

• Virus = self-spread

IT SEGREGATION

• Data control = fix errors

• Manager = review only

• Programmer = code only

No overlap

TOOLS

• Flowchart = visualize

• Key verification = protect key fields

DISASTER

• Cold site = empty backup

• Restore OS FIRST

• Business continuity = keep running


FINAL TRIGGERS

1 person doing too much → SOD issue


CEO/CFO → 302
Internal control → 404
Foreign payment → FCPA
System weakness → IT control issue

FINAL LINE (WRITE THIS BIG)

“RIGHT PEOPLE. RIGHT ROLES. CLEAN RECORDS. CONTROLLED SYSTEMS.”

You might also like