OVERALL BIG PICTURE
INTERNAL CONTROLS + IT CONTROLS + REGULATORY FRAMEWORKS (SOX & FCPA)
These are mainly tested in:
• Section C: Performance Management
• Internal Control & Risk Management
ORGANIZED SUMMARY BY TOPIC
INTERNAL CONTROL BASICS (CORE FOUNDATION)
Key Ideas:
• Internal controls provide reasonable assurance, NOT absolute assurance
• Must balance cost vs benefit
Exam meaning:
• Controls cannot eliminate all risk
• Too much control = too expensive
Financial Reporting Objective: In Financial reporting, Internal Control
Ensure Reliable FS.
• Ensure reliable financial statements
Segregation of Duties (VERY TESTED):
Examples from your notes:
• Cashier handling cash + preparing deposit slip → violation
• Computer operator running programs + holding files → violation
Rule: NEVER combine: (HIGHLY IMPORTANT)
• Custody
• Recording
• Authorization
SOX (GOVERNANCE + AUDIT COMMITTEE)
Sarbanes-Oxley Act of 2002
Key Takeaways:
• Audit committee must be independent
• Can hire outside lawyers/consultants
Meaning:
• Not dependent on management
• Strong oversight = better controls
FCPA (ETHICS + INTERNAL CONTROL FLEXIBILITY)
Foreign Corrupt Practices Act
Key Points:
• Requires internal controls + accurate records
• BUT does NOT require a specific framework like COSO
Companies can design:
• Any system (as long as it works)
IT CONTROLS (VERY HIGH YIELD)
A. TYPES OF IT CONTROLS
Input Controls:
• Check digit
• Validity check
Prevent wrong data entry Preventive Controls
Processing Controls:
• Transaction logs
Track system processing Detective Controls
Output Controls:
• Spooling
Manage output delivery Corrective Controls
B. ACCESS & SECURITY CONTROLS
• Unique user ID → authentication
• Compatibility check → verifies access rights
• Single sign-on → convenient but risky (single failure point)
C. CYBERSECURITY
Trojan horse malware
• Installed voluntarily
• Hidden malicious function
Computer virus
• Spreads automatically
D. DATA SECURITY
• Encryption → protects data (cannot read without key)
• Firewall → blocks unauthorized access
IT GOVERNANCE & SEGREGATION (ADVANCED)
Proper IT role separation:
• Data control group → reprocess errors
• Manager → review only
• Programmer → access programs only
Rule:
No one should process + control + review
DATA & PROCESS TOOLS
• Flowchart → visual representation of processes
• Key verification → protects critical data fields
DISASTER RECOVERY & BUSINESS CONTINUITY
Cold Site:
• Empty facility ready for emergency use
• Needs hardware setup after disaster
Recovery Priority:
• Operating system restored FIRST
Business Continuity Planning:
• Keeps operations running during/after disruption
HOW CMA CONNECTS ALL THIS FINAL MENTOR SUMMARY
They DON’T test definitions. If I compress EVERYTHING into one line:
They test: Internal control = balance risk, assign roles properly,
“What control failed?” protect data, and ensure reliable reporting
“What risk exists?”
“Who has too much power?”
ULTRA-FAST MEMORY MAP
• Internal Control → Reasonable assurance
• SOX → Governance + audit oversight
• FCPA → No bribery + flexible controls
• IT Controls → Input / Process / Output
• Security → Encryption + Firewall
• Risk → Segregation failures
• Continuity → Disaster recovery
CMA PART 1 — INTERNAL CONTROLS / SOX / FCPA / IT (CRAM SHEET)
1. INTERNAL CONTROL CORE
Objective:
Reliable financial reporting
Efficient operations
Compliance
KEY RULE:
Reasonable assurance ONLY (not absolute)
Cost of control ≤ Benefit
SEGREGATION OF DUTIES (ALWAYS TESTED)
NEVER combine:
• Authorization
• Recording
• Custody
Example traps:
• Cashier handles cash + records → WRONG
• IT operator runs + controls files → WRONG
2. COSO FRAMEWORK
Committee of Sponsoring Organizations of the Treadway Commission
5 Components (MEMORIZE):
CRIME
• Control Environment
• Risk Assessment
• Information & Communication
• Monitoring
• Execution (Control Activities)
3. SOX (GOVERNANCE)
Sarbanes-Oxley Act of 2002
MUST KNOW:
• 302 → CEO/CFO certify FS
• 404 → Internal controls
o Management → evaluates
o Auditor → attests
Audit Committee:
• Independent
• Hires auditors
• Can use external consultants
KEY RULE:
Auditor = independent (NO system design!)
4. FCPA (ETHICS + CONTROLS)
Foreign Corrupt Practices Act
CORE IDEA:
NO BRIBES + CLEAN BOOKS
Key Points: Foreign Corrupt Practices Act (FCPA)
• Applies to foreign dealings
• Covers third parties
• Requires accurate records + controls
• DOES NOT require COSO specifically
5. IT CONTROLS (HIGH YIELD)
TYPES OF CONTROLS
Input:
• Validity check
• Check digit
Processing:
• Transaction logs
Output:
• Spooling
ACCESS CONTROLS
• User ID + password → authentication
• Compatibility check → access rights
• Single sign-on → risk (single failure point)
6. CYBER & DATA SECURITY
Trojan horse malware
• Looks safe, acts malicious
Computer virus
• Self-spreading
Protection:
• Encryption → unreadable without key
• Firewall → blocks unauthorized access
7. IT SEGREGATION (ADVANCED TRAP)
• Data control → fix errors
• Manager → review only
• Programmer → code only
NO overlap of duties
8. PROCESS TOOLS
• Flowchart → visual process
• Key verification → protects key fields
9. DISASTER RECOVERY
Cold Site:
• Empty backup location
Priority:
Restore Operating System FIRST
Business Continuity:
Keep operations running during disruption
FINAL EXAM TRIGGERS (READ THIS BEFORE TEST)
If you see:
• One person doing too much → Segregation issue
ULTIMATE MEMORY LINE
• CEO/CFO → Section 302
“Right people, right roles,
• Internal control assessment → Section 404 clean records, controlled
• Foreign payment → FCPA risk systems.”
• System access issue → IT control weakness
• “Looks okay but feels wrong” → TRUST THAT
CMA PART 1 — BRAIN DUMP SHEET
INTERNAL CONTROL
Goal:
✔ Reliable reporting
✔ Efficiency
✔ Compliance
Rule:
Reasonable ≠ Absolute
Cost ≤ Benefit
SEGREGATION OF DUTIES
NEVER combine:
• A = Authorization
• R = Recording
• C = Custody
ARC violation = FRAUD RISK
COSO
Committee of Sponsoring Organizations of the Treadway Commission
CRIME
• C = Control Environment
• R = Risk Assessment
• I = Info & Communication
• M = Monitoring
• E = Execution (Control Activities)
SOX
Sarbanes-Oxley Act of 2002
302 = SIGN
• CEO/CFO certify FS
404 = CONTROL
• Mgmt → assess
• Auditor → attest
Audit Committee:
• Independent
• Hires auditors
Auditor cannot design system
FCPA
Foreign Corrupt Practices Act
NO BRIBE + CLEAN BOOKS
• Covers foreign officials
• Includes 3rd parties
• Accurate records REQUIRED
• No specific framework required
IT CONTROLS
Input → validity, check digit
Process → logs
Output → spooling
ACCESS CONTROL
• User ID + password
• Compatibility check
• Single sign-on = risk
SECURITY
• Encryption = unreadable data
• Firewall = blocks access
MALWARE
• Trojan = disguised
• Virus = self-spread
IT SEGREGATION
• Data control = fix errors
• Manager = review only
• Programmer = code only
No overlap
TOOLS
• Flowchart = visualize
• Key verification = protect key fields
DISASTER
• Cold site = empty backup
• Restore OS FIRST
• Business continuity = keep running
FINAL TRIGGERS
1 person doing too much → SOD issue
CEO/CFO → 302
Internal control → 404
Foreign payment → FCPA
System weakness → IT control issue
FINAL LINE (WRITE THIS BIG)
“RIGHT PEOPLE. RIGHT ROLES. CLEAN RECORDS. CONTROLLED SYSTEMS.”