• What is the definition of internal controls (based on the COSO Internal
Control- Integrated Framework)?
o Internal control is a process, effected by an entity’s board of
directors, manage- ment, and other personnel, designed to provide
reasonable assurance regarding the achievement of objectives
relating to operations, reporting, and compliance.
• What are the 5 components of the COSO oInternal Control- Integrated
Framework?
o Control Environment
o Risk Assessment
o Control Activities
o Information and Communication
o Monitoring Activities
• According to this COSO framework, what are the requirements for an
effective system of internal control?
o Each of the five components and relevant principles is present and
functioning. “Present” refers to the determination that the
components and relevant principles exist in the design and
implementation of the system of internal control to achieve specified
objectives. “Functioning” refers to the determination that the
components and relevant principles continue to exist in the
operations and conduct of the system of internal control to achieve
specified objectives.
o The five components operate together in an integrated manner.
“Operating together” refers to the determination that all five
components collectively reduce, to an acceptable level, the risk of
not achieving an objective. Components should not be considered
discretely; instead, they operate together as an integrated system.
Components are interdependent with a multitude of
interrelationships and linkages among them, particularly the manner
in which principles interact within and across components
• Select one principle for each of the 5 components of the COSO-Internal
Control Framework and give one example for each.
o One principle for Control Environment components is the
"Commitment to Integrity and Ethical Values." A good example of this
principle in practice is when a corporation creates a code of
conduct outlining appropriate behaviors and values for employees
to follow, fostering integrity and ethical decision-making within the
organization.
o One principle for Risk Assessment components is the "Identification
and Analysis of Risks." An example for this is when a corporation does
a thorough risk assessment to detect potential operational threats
and weaknesses, such as fluctuations in the market, changes in
regulation, or cybersecurity issues. This evaluation helps the
organization understand the possibility and potential impact of these
risks, allowing it to devise effective risk mitigation or management
measures.
o One principle for Control Activities components is the "Segregation
of Duties." An example for this is when a corporation guarantees that
the individual held accountable for authorizing a transaction is not
the same as the individual accountable for recording it in the
accounting records. This division helps to prevent errors and fraud by
ensuring that no single individual has entire control of a transaction
from start to finish without monitoring.
o One principle for Information and Communication components is the
"Communication of Internal Control Deficiencies." An example for this
principle is when an organization sets a procedure for employees to
report any discovered weaknesses or shortcomings in the internal
control system to management. This interaction enables
management to identify and resolve concerns quickly, ensuring that
internal controls are successful in protecting assets and attaining
organizational goals.
o One principle for Monitoring Activities components is the "Ongoing
and/or Separate Evaluations." An example of this principle is when a
company undertakes frequent internal audits or evaluations to
evaluate the performance of its internal control system. This constant
examination ensures that controls are functioning properly and
reveals any shortcomings or opportunities for improvement, allowing
management to take remedial action quickly.