Keeping the Train on the Tracks
Blame Management
COSO: Sounds Italian, Actually Accounting
Risky Business
How Not to Run a Dumpster Fire
100

An organized process designed to provide reasonable assurance that an entity’s objectives (operations, reporting, compliance) will be achieved.

What is internal control?

100

According to the GAO, the group responsible for designing, implementing and evaluating internal controls at all levels.

Who is management?

100

The five interrelated components of the COSO internal control framework.

What are the control environment, risk assessment, control activities, information & communication, and monitoring?

100

The possibility that an event will occur and adversely affect achievement of objectives.

What is risk?

100

Duty that requires management to define the mission, strategic plan and objectives before designing controls.

What is setting clear objectives?

200

The three broad categories of objectives that internal controls help achieve.

What are operations, reporting and compliance?

200

The concept that the commitment to internal controls and ethical values starts with leadership.

What is “tone at the top”?

200

This component sets the tone for the organization and provides discipline and structure.

What is the control environment?

200

Why management needs to perform risk assessments both periodically and in real time.

What is to adapt to changes and identify emerging risks?

200

Reason policies and procedures must be documented and updated.

What is to ensure control activities are understood, carried out and effective?

300

This term describes the collection of plans, methods, policies and procedures used to fulfill an organization’s mission and goals.

What is an internal control system?

300

In Indiana University’s “three lines of defense,” this group is the first line responsible for establishing and monitoring internal controls.

What is department or operational management?

300

Component that involves identifying and analyzing risks to achieving objectives.

What is risk assessment?

300

Factors management should consider when analyzing risks, such as program complexity, staffing, IT limitations and external changes.

What are internal and external risk factors?

300

Maintaining ethical values and a positive control consciousness is part of this duty.

What is maintaining a strong control environment (tone at the top)?

400

The level of assurance internal controls provide—never absolute.

What is reasonable assurance?

400

The independent group that acts as the third line of defense by evaluating whether controls are operating as intended.

What is internal audit?

400

Policies and procedures designed to mitigate risks—examples include approvals, authorizations, and reconciliations.

What are control activities?

400

The term for risk that remains after management’s response is applied.

What is residual risk?

400

This duty ensures that communication flows in all directions and that deficiencies are reported upstream.

What is communicating and reporting?

500

Rather than a single event, internal control is described as this kind of ongoing series of actions throughout an organization.

What is a continuous process?

500

Phrase used to describe that everyone in an organization, not just management, has a part in internal control.

What is “internal control is everyone’s responsibility”?

500

Ensures that quality information is identified, captured, and communicated up, down and across the organization.

What is information and communication?

500

A question recommended by the Ohio auditor to highlight the purpose of risk assessment: “How do I avoid reading this headline while drinking my morning coffee?”.

What is “What could go wrong (and how can we avoid it)?”

500

Ongoing evaluations of control effectiveness and corrective actions taken as needed.

What are monitoring and continuous improvement?