133k views
3 votes
Which of the following is not a component of internal control as defined by coso?

O monitoring.
O inherent risk.
O control environment.
O control activities.

1 Answer

4 votes

Final answer:

Inherent risk is not a component of internal control per the COSO framework, while control environment, control activities, and monitoring are. COSO includes risk within the 'Risk Assessment' component.

Step-by-step explanation:

The COSO internal control framework identifies five components of internal control. These are:

  1. Control Environment
  2. Risk Assessment
  3. Control Activities
  4. Information and Communication
  5. Monitoring

Inherent risk is not a component of internal control as defined by COSO. Inherent risk refers to the exposure to loss that exists within the organization before considering the effectiveness of any controls. Instead, COSO incorporates the concept of risk in the 'Risk Assessment' component, which is about identifying and analyzing risks as a basis for defining effective controls.

User Driscoll
by
8.3k points