Please enable JavaScript.
Coggle requires JavaScript to display documents.
CHAPTER 8: INTERNAL CONTROL SYSTEM - Coggle Diagram
CHAPTER 8: INTERNAL CONTROL SYSTEM
COSO cube (internal focus)
https://www.accaglobal.com/gb/en/student/exam-support-resources/professional-exams-study-resources/strategic-business-leader/technical-articles/coso-enterprise-risk-management-framework.html
ERM (Enterprise Risk Management)
System used to apply the COSO approach
Control environment
-sets the tone of the org and addresses risk management philoshophy andrisk appetite, integrity and ethical values.
Risk assessment
-COSO: combination of qualitative and quantitative risk assessment methodologies.
-assess residual risks left after risk management actions have been taken
Control activities
COSO: mix controls (prevention/detection manual/automated)
Information and communication
COSO: relevant and appropriate quality
Monitoring activities
COSO: regular review (ongoing monitoring) and periodic review (separate evaluation)
:feedback and action
Discretionary controls - subject to human discretion Non-discretionary controls - automatic; cannot be bypassed, ignored or overridden
General controls - passwords, backup systems, anti-virus
Application controls - inputs, processes and outputs
Control procedures (APIPS)
Authorisation, Performance reviews, Information processing, Physical controls, Segregation of duties
2. Monitoring
(external focus)
Levels of information
Strategic information, Tactical info, Operational info
Qualities of good information
ACCURATE (accurate, complete, cost beneficial, user-targeted, relevant, authoritative, timely, easy to use)
Sources for good information
Directors, NEDs, auditors, exception reports, employees (whistleblowers), customer feedback
Reviewing internal controls
assess ongoing need for internal audit
Company size, complexity, unexpected risks events, problems in internal control, cost v benefit analysis