Internal Controls
Risk Management & Risk Types
Internal Control Frameworks & Components
IT Governance & System Controls
Audit, Fraud & Information Systems
100

This type of control deters problems before they arise.

What is preventive controls?

100

Measures such as vacations, rotation of duties, and fidelity bond insurance are used to prevent this.

What is fraud?

100

Controls that prevent problems before they occur.

What are preventive controls?


100

This occurs when two or more people cooperate to override internal controls.

What is collusion?

100

Analytical reviews and reconciliations are part of this type of control.

What are independent checks on performance?

200

Internal controls aim to provide this type of information to support decision-making and reporting.


What are accurate and reliable information?

200

The type of risk that exists before any controls are implemented.

What is inherent risk?

200

These control activities include policies, procedures, and rules designed to meet objectives.  

What are control activities?

200

The separation of authority and responsibility within the information system function.

What is segregation of systems duties?

200

A path that allows transactions to be traced from origin to output.

What is an audit trail?

300

This framework allows management to benchmark IT security, assures users that controls exist, and helps auditors advise on IT matters.

What is COBIT?

300

The risk that remains after management implements controls.

What is residual risk?

300

Three types of controls that should be included in a good internal control system 

What are preventive, detective, and corrective controls?


300

This committee oversees systems development and acquisition. 

What is a steering committee?
300

This technology is tamper-resistant and ensures transaction integrity by storing duplicate copies across a network.

What is blockchain?

400

The COBIT process “EDM” stands for these three words.

What is Evaluate, Direct, and Monitor?

400

The term for a company taking no action because the risk is within tolerance levels.

What is accepting risk?

400

The control activity that ensures employees have proper authority to perform tasks.

What is authorization?

400

The control process that ensures modifications to systems do not introduce errors or facilitate fraud. 

What is change management?

400

This system gathers, records, processes, stores, summarizes, and communicates information about an organization.  

What is an Accounting Information System (AIS)?

500

A weak or deficient control environment often results in breakdowns in this.

What is risk management and control?

500

One of the four ways management can respond to risk that involves transferring it to another party.

What is sharing risk?


500

A type of authorization for routine transactions that does not require special approval.

What is general authorization?


500

Employees who enter transactions and create new accounts are part of this function.

What is data entry?
500

Software that identifies suspicious patterns and unusual behavior to detect fraud is called this.

What is fraud detection software?

M
e
n
u