NEW
Font size
WorksheetsControl Frameworks Quiz
Total questions: 56
Worksheet time: 28mins
What is the purpose of internal controls according to the text?
Enhancing operations and achieving better results
Reducing the value for stakeholders
Creating complexities in modern business environments
Increasing risks for stakeholders
Which organization developed the ISO 17799 standard?
The Information Technology Infrastructure Library
Capability Maturity Model Integration
The Committee of Sponsoring Organizations
The International Organization for Standardization
What is the purpose of the COSO Framework according to the text?
Encouraging e-commerce activities
Promoting fraud and risk management
Enhancing global trade and cultural diversity
Improving financial reporting and focusing on governance, ethics, and internal controls
Which component of the COSO Framework focuses on identifying, quantifying, and managing organizational risks?
Control Activities
Information and Communication
Control Environment
Risk Assessment
What is the purpose of the ITIL framework?
Enhancing customer satisfaction and reducing fraud
Improving financial performance and reducing operational risks
Aligning IT activities with business goals and managing IT-related risks
Defining organizational structure and standard management procedures for IT operations
Which organization administers the CMMI process improvement appraisal program?
The Committee of Sponsoring Organizations
The Institute of Internal Auditors
The International Organization for Standardization
Carnegie Mellon University
What is the focus of the COBIT framework?
Aligning IT activities with business goals and managing IT-related risks
Defining organizational structure and skill requirements for IT operations
Improving financial reporting and governance
Enhancing internal controls and fraud prevention
What is the purpose of the Global Technology Audit Guides (GTAGs)?
Enhancing project management and performance improvement
Developing voluntary standards for innovation
Facilitating communication between stakeholders
Providing essential IT management, control, and security information
Which risk category typically arises from intentional and opportunistic actions by service providers?
Financial Risks
Operational Risks
Composite Risks
Strategic Risks
What is the purpose of monitoring activities in internal control?
Determining whether each component of internal control is present and functioning
Identifying and testing control activities
Assessing organizational risks
Improving communication within the organization
These frameworks help organize and prioritize internal controls, which are practices that add value and reduce risks for stakeholders.
internal control framework
external control framework
cobit
iso
are voluntarily adopted by businesses to enhance their operations and achieve better results. They provide structure and guidance for managing the complexities of modern business environments.
Introduction
control frameworks
internal control framework
external control framework
cobit
what year that coso widespread financial fraud led to the creation of a commission chaired by James C. Treadway.
1990
1890
1980
1985
what year the COSO initiative was formed, backed by five professional associations and industry representatives
1980
1890
1990
1985
aimed to improve financial reporting by focusing on governance, ethics, and internal controls, with an emphasis on risk management and fraud prevention
Control Objectives for Information and Related Technology
The Information Technology Infrastructure Library
The International Organization for Standardization 17799
Committee of Sponsoring Organizations
statement 1: ICF was released in 1992, revised in 2013. it also contains 17 principles for effective internal control
statement 2: provides a structured approach for organizations to design, implement, and assess internal controls, which are processes, policies, and procedures aimed at achieving business objectives, managing risks, and ensuring compliance with laws and regulations
both statement are true
both statement are false
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
which of the following is not included in the five key components
CONTROL ENVIRONMENT
RISK MANAGEMENT
CONTROL ACTIVITIES
INFORMATION AND COMMUNICATION
MONITORING ACTIVITIES
It identify, assess, and manage risks across an organization and
provides a comprehensive strategy for organizations to understand and mitigate risks that could impact their ability to achieve their objectives.
Enterprise Risk Management (ERM) Framework
COSO FRAMEWORK
CONTROL FRAMEWORK
NONE FO THE ABOVE
also known as the workplace environment
Control Environment
Risk assessment
Control activities
Monitoring activities
the following is an examples of unethical behavior IN CONTROL ENVIRONMENT which is NOT?
prioritizing profits over customer satisfaction
using high-pressure sales tactics
engaging in kickbacks or bribery
Violations of ethical standards
statement 1: Violations of ethical standards can lead to significant financial penalties and damage to a company's reputation.
statement 2: Auditors must remain vigilant for signs of ethical behavior and ensure compliance with laws and regulations
both statements are true
both statements are false
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
This refers to management practices that may appear to fulfill necessary tasks on the surface, but lack true execution.
form over substance
control environment
ethical behavior
substance over form
are used to determine if an organization’s values, systems, policies, and processes would enable or dissuade fraud and encourage proper conduct
Entity level controls
organization level control
low level control
high level control
external auditors are encouraged to remember that a person’s behavior is determined by the person and his or her environment. There are a number of different and competing forces that combine to result in the situation the individual encounters
true
false
The second component of the COSO framework relates to the identification, quantification, analysis, and management of organizational risks
risk management
risk assessment
monitoring activity
control activity
This is the risk that the organization’s processes are not effectively obtaining, managing, and disposing their assets, that the organization is not performing effectively and efficiently in meeting customer needs, is not creating value or is diluting value by suffering the degradation of financial, physical, and information assets
business
process risk
both
none of the above
is a process improvement appraisal program administered and marketed by Carnegie Mellon University.
Capability Maturity Model Intergration
Information Technology Infrastructure Library
International Organization for Standardization
Control Objectives for Information and Related Technologies
defines the organizational structure and skill requirements of an IT organization and standard management procedures and practices to manage an IToperation
Capability Maturity Model Intergration
Information Technology Infrastructure Library
International Organization for Standardization
Control Objectives for Information and Related Technologies
provides a comprehensive set of controls and guidelines that help organizations align their IT activities with business goals
Capability Maturity Model Intergration
Information Technology Infrastructure Library
International Organization for Standardization
Control Objectives for Information and Related Technologies
is an independent, nongovernmental organization. Through its 162 national standards groups, it brings together experts to share knowledge and develop voluntary standards that support innovation and provide solutions to global and business challenges
Capability Maturity Model Intergration
Information Technology Infrastructure Library
International Organization for Standardization
Control Objectives for Information and Related Technologies
the following are included in the Critical managerial and accounting/financial activities which is NOT?
Establishing IT direction
Project management
Purchases
Training end users
software development
are a collection of guides published by the Institute of Internal Auditors (IIA) that provide essential IT management, control, and security information.
Global Technology Audit Guides
World Technology Audit Guide
Organizational Technology Guide
none of the above
consist of ongoing, separate or a combination of evaluations used to determine whether each of the five components of internal control is present and functioning.
monitoring activities
control activities
risk assessment
information and communication
arise when a client loses its ability to implement a process due to longterm outsourcing, potentially resulting in a lack of back-office operational capabilities, both material and intellectual
Composite risks
Strategic Risks
Operational Risks
risk of outsourcing
occur when work processes break down or are repeated incorrectly, often due to misunderstandings or insufficient capabilities, leading to delays, increased costs, and reduced quality.
composite risk
strategic risk
Operational Risks
outsourcing risk
risks typically arise from intentional and opportunistic actions undertaken by service providers or their staff
composite risk
operational risk
strategic risk
outsourcing risk
occurs between individuals
Interpersonal or face-to-face communication
Group-level communications
Organizational level communications
external communication
occur within and among teams, units, and interest groups.
Interpersonal or face-to-face communication
Group-level communications
Organizational-level communication
external communication
focus on company vision and mission, policies, and new initiatives
Organizational-level communication
external communication
Group-level communication
Interpersonal or face to face communication
which communication disseminates messages throughout the organization, facilitating clear directives from senior management
internal
external
Group-level
Organizationallevel
which communication involves receiving external information and providing responses to external parties' requirements and expectations
inetrnal
external
Group-level
Organizational-level
component of the COSO IC/IF model focuses on information flow within an organization, aiming for clear, consistent, timely, and purposeful directives from top management to measure performance.
risk assessment
information and communication
control activity
monitoring activity
which control activities that act before the error or omission can occur
Preventive
Directive
Compensating
Detective
which control activities that identify error after occurence
Preventive
Directive
Detective
Compensating
which control activity that temporary controls to redirect actions
Preventive
Directive
Detective
Compensating
which one of the control activity that put in place when a control is not where it is expected
Preventive
Directive
Detective
Compensating
actions established through policies and procedures that mitigate the likelihood and/or impact of risks
monitoring
control
regulation
rules
rewards received should be commensurate with the effort exerted and the outcome achieved
Rewarding
Evaluated
Time-bound
none of the above
Excitable, ethical, engaging, ecological, and enjoyable
Rewarding
Evaluated
Time-bound
none of the above
Timed, timely, time-specific, trackable, and tangible
rewarding
evaluated
Time-bound
none of the above
Realistic and resourced
rewarding
evaluated
time-bound
relevant
Appropriate, assignable, ambitious, aspirational, attainable, agreed, actionable, and aligned.
achievable
relevant
rewarding
time- bound
Meaningful, motivational, and manageable.
measurable
relevant
rewarding
achievable
Significant, simple, stretching, and sufficiently detailed.
specific
measurable
relevant
achievable
which of the following is not included in political
Regulations and legislation risk
Public policy risk
Instability risk
Data integrity
which of the following is not part of social risk
Demographics risk
Privacy risk
CSR
Mobility
Instability risk
