Under Control
Who Me?
Me COSO
Taking Risks
Duty to Control
100

These people are NOT responsible for internal controls.

Who is an auditor?

100

This component is comprised of the organizational structure, assignment of responsibilities, policy and procedures monitored by Board of Directors and Audit Committee.

What is the control environment

100

This process during risk assessment is done to determine how the risks should be managed.

What is identify and analyzing risks?

100

The process of protecting the company's information and assets.

What is safeguarding?

200

This is a back up procedure designed to catch items or events

What is Detective Controls?

200

This person checks validates amount in her cash drawer matches receipts.

Who is the front line employee?

200

This component is identifying and analyzing, managing change as a company wide objective.

What is risk assessment?

200

Making sure the information is complete and accurate.

What is ensuring reliability and integrity of financial information?

300

This is an ongoing process of identifying business continuity, security, policy and procedures that may involve outsourcing for additional support.

What is control activities?

300

This step is done by management before the auditors evaluate for risk assessment.

What is identifying the probability of risk and impact?

300

This is when we follow the federal, state and local laws regarding a business.

What is being in compliance?

400

This activity is used to deter errors or fraud. 

What is preventative control?

400

This person monitors others by running deposit reports and compare to receipts.

Who is the department manager?

400

This component requires quality and effectiveness of what is being said and done.  

What is information and communication?

400

This is done to monitor and show achievement of goals and objectives.

Why are there policies and procedures?

500

A company's plan to safeguard its assets, checking for accuracy and validating financial statements through monitoring processes. 

What is an internal control?

500

This employee validate bank statements with financial statements.

Who is the controller?

500

The component is essential to success with internal control by ongoing and separate evaluations and reporting any deficiencies.

What is monitoring?

500
Discussions held during risk assessment process about the most important risks is the purpose of this. 

What is control factor of a risk assessment?

500

This is done on a scheduled bases to validate is records and monitoring are correct.

What is periodic assessment?

M
e
n
u