What's changed: Initial version
4.2The six components of internal control and COSO
Covers the six basic components of internal control (control environment, risk assessment and response, control activities, information and communication, monitoring, and response to IT) and their relationship to the COSO framework (which has five components—it does not include response to IT), building the judgment to diagnose which component's absence a control deficiency stems from.
When a systems auditor points out a control deficiency, merely saying "there is a weak spot" does not lead to improvement. Only by identifying which component of internal control's absence the deficiency stems from can the auditor make an effective recommendation to management. Japan's internal control reporting system (J-SOX) frames internal control in terms of six basic components, but its source, the U.S. COSO framework, has five components, with the important difference that only "response to IT" was added by Japan's implementation standards. Grounded in the role of each of the six components and their relationship to COSO, this section builds the viewpoint from which an auditor diagnoses where a deficiency lies.
4.2.1The six basic components of internal control
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

