SimplyCPA
CPA/AUD/Understanding the Entity & Internal Control

Understanding the Entity & Internal Control

The five COSO components, documenting internal control, and evaluating control deficiencies.

Medium 1 hrArea II: Assessing Risk and Developing a Planned Response

The five COSO components — "CRIME"

ComponentWhat it means
Control environmentTone at the top: integrity, ethical values, board oversight, competence, accountability
Risk assessmentHow the entity identifies and responds to business risks affecting financial reporting
Information and communicationThe accounting system and how information flows internally and externally
MonitoringOngoing and separate evaluations of whether controls keep working
Existing control activitiesAuthorizations, reconciliations, segregation of duties, physical controls, performance reviews

What the auditor must do

In every audit the auditor must obtain an understanding of internal control relevant to the audit, sufficient to identify and assess risks of material misstatement and design further procedures. Obtaining that understanding is mandatory — testing controls for operating effectiveness is not, unless the auditor intends to rely on them or substantive procedures alone are insufficient.

IMPORTANT: Understanding a control means evaluating its design and determining whether it has been implemented (placed in operation). That is different from testing operating effectiveness, which is only required if you plan to rely on the control.

Severity of deficiencies

LevelDefinitionCommunicate to
Control deficiencyDesign or operation doesn't allow timely prevention/detectionManagement (optional at auditor's discretion)
Significant deficiencyLess severe than a material weakness but important enough to merit attention by those charged with governanceThose charged with governance, in writing
Material weaknessReasonable possibility that a material misstatement would not be prevented or detected on a timely basisThose charged with governance and management, in writing

EXAM TIP: Segregation of duties means separating Authorization, Record keeping, and Custody of assets ("ARC"). If one person does two or more of these, that's a classic deficiency scenario.