Internal Controls Basics
Who's
Responsible?
The COSO
Framework
Risk & Fraud
Regulations & Scandals
100

What are internal controls designed to prevent?

What are fraud, errors, and inefficiencies?

100

Who is responsible for implementing and overseeing internal controls?

Who is management?

100

What does COSO stand for?

What is the Committee of Sponsoring Organizations?

100

What process identifies potential risks that could impact business objectives?

What is risk assessment?

100

What law was passed in response to the Enron scandal?

What is the Sarbanes-Oxley Act (SOX)?

200

Internal controls ensure accuracy and reliability in what type of reports?

What are financial reports?

200

What group ensures internal controls align with the organization's goals?

What is the Board of Directors?

200

Name one of the five components of the COSO Internal Control Model.

What is control environment, risk assessment, control activities, information & communication, or monitoring?

200

What is an example of a control activity to prevent fraud?

What is requiring multiple approvals for large transactions?

200

What does SOX require companies to do?

What is strengthen internal controls and increase financial transparency?

300

Name one key benefit of having strong internal controls.

What is protecting assets, ensuring compliance, or improving efficiency?

300

Who evaluates the effectiveness of internal controls through audits?

Who are internal and external auditors?

300

Which component sets the ethical tone of the organization?

What is the control environment?

300

What type of fraud occurs when employees manipulate financial statements?

What is accounting fraud?

300

What is the role of external auditors under SOX?

What is to provide independent reviews of financial statements?

400

Which major corporate scandal in the early 2000s highlighted the need for stronger internal controls?

What is Enron?

400

What is the role of employees in internal controls?

What is following policies and reporting control issues?

400

Risk assessment evaluates two key factors. Name one.

What is likelihood or severity?

400

If a company processes online transactions, what major risk should they assess?

What is cybersecurity risk?

400

Which COSO component is directly related to ongoing audits and evaluations?

What is monitoring activities?

500

Internal controls help organizations achieve three main objectives. Name one.

What is operations, reporting, or compliance?

500

Which two groups provide oversight and assurance for internal controls?

What are the Board of Directors and auditors?

500

Which COSO component ensures employees receive clear financial and operational information?

What is information & communication?

500

Name a tool companies use to prevent online fraud.

What is two-factor authentication?

500

What are two major consequences of weak internal controls?

What are financial loss and legal penalties?

M
e
n
u