Overview of AIS
Risk & Risk Assessments
Risk Management and Internal Controls
Purchasing & Payment Processes
Marketing, Sales, & Collections Processes
100

A system that performs data collection, transformation, and reporting.

What is an information system?

100

The comprehensive process of identifying, categorizing, prioritizing, and responding to a company's risks.

What is Enterprise Risk Management?

100

A term that describes the attitude of management toward integrity and ethical behavior.

What is the control environment?

100

A request to obtain goods from an authorized source created by the inventory control department.

What is a purchase requisition?

100

A source document that is used to bill a B2B customer who purchases on a line of credit.

What is a sales invoice?

200

It performs the same functions as an information system, but is specific to accounting and financial data.

What is an AIS?

200

A type of risk matrix that uses different colors to represent values of data in a map or diagram format

What is a heat map?

200

The scenario where two or more employees work together to evade an internal control.

What is collusion?

200

An accounting journal that contains a record of a company's payments in chronological order.

What is a cash disbursements journal?

200
A document that provides details of a shipment and proof of delivery.

What is a shipping notice?

300

A group of related business events designed to accomplish strategic objectives.

What is a business process?

300

A matrix that includes both likelihood and impact of various risks.

What is a risk matrix?

300

A controls-based approach to risk management that is widely accepted as the authoritative guidance on internal controls and SOX compliance.

What is the COSO Integrated Control - Integrated Framework?

300

A document used to request a supplier to sell and deliver the products in the quantities and for the prices specified.

What is a purchase order?

300

A document sent by the buyer along with payment that indicates which invoices are being paid.

What is a remittance advice?

400

A process of using technology to transform raw data into useful information.

What is data analytics?

400

A statement that identifies an issue and a possible outcome.

What is a risk statement?

400

Data analytics technology that creates detective controls that automatically identify red flags for risks.

What is continuous monitoring?

400

A document that shows descriptions and quantities of goods received from vendors.

What is a receiving report?

400

A recommended practice that allocates responsibilities for receiving payments, depositing payments, and recording payments to different personnel.

What is separation of duties?

500

Quantifiable metrics used to measure and evaluate the success of an organization based on its objectives.

What are key performance indicators (KPIs)?

500

The remaining risk posed by a process or activity once a plan to respond to the risk is in place.

What is residual risk?

500

An example of this type of control would be a firewall that prevents unauthorized access to the organization's computer network.

What is a preventative control?

500

A type of fraud in which employees intentionally separate a single purchase into two or more purchase orders to stay within a single authorization limit.

What is a split purchase order?

500

A type of fraud that occurs when revenues and profits are intentionally inflated by recognizing revenue from unnecessary sales in the current period.

What is channel stuffing?

M
e
n
u