What does control environment mean on the CPA exam?
Control environment. The governance and management functions and the attitudes, awareness, and actions of those charged with governance and management concerning the entity's system of internal control. One of its five components. A strong one supports the others but prevents no misstatement by itself.
Defined against AU-C 315.12, appendix A.
Which CPA exam sections use control environment?
Control environment appears in the AUD section of the CPA exam.
Other terms defined against AU-C 315
- application controls: Controls built into one business process or system, such as a validity check on an input field or a three-way match.
- assessed risk: The auditor's judgment about the risk of material misstatement at the assertion level, combining inherent and control risk.
- general controls: Controls over the IT environment as a whole -- access, change management, operations -- that everything else depends on.
- general IT control: A control over the entity's IT processes that supports the continued effective functioning of information-processing controls and the integrity of information.
- information and communication: One of the five components of internal control: how an entity obtains the information it needs and gets it to the people who have to act on it.
- information-processing control: A control over processing in an IT application or a manual information process that directly addresses a risk to the integrity of information.
- rights and obligations: The assertion that the entity genuinely owns the assets it reports and genuinely owes the liabilities.
- risk assessment procedures: The audit procedures designed and performed to identify and assess the risks of material misstatement at the financial statement and assertion levels.
Related terms
- senior management: The people who direct and control the entity day to day, as distinct from those charged with governance, whose job is to oversee them.
- service organization: A third party whose processing affects a user entity's financial reporting, such as a payroll bureau or a claims processor.
- COSO Internal Control - Integrated Framework: The reference model for internal control: five components and seventeen principles, all of which must be present and functioning for control to be effective.
- significant deficiency: A deficiency, or combination of deficiencies, less severe than a material weakness but important enough to merit attention by those charged with governance.
- those charged with governance: The people responsible for overseeing the entity's strategic direction and its accountability, including the financial reporting process.
- internal control over financial reporting: A process designed to provide reasonable assurance regarding the preparation of reliable financial statements.