1. Which of the following are included in the control environment described in the COSO internal control framework?
A. Organizational structure, management philosophy, and planning.
B. Integrity and ethical values, assignment of authority, and human resource policies.
C. Competence of personnel, backup facilities, laws, and regulations.
D. Risk assessment, assignment of responsibility, and human resource practices.
Answer (B) is correct.
REQUIRED: The elements of the control environment.
DISCUSSION: The control environment is a set of standards, processes, and structures that includes
• Integrity and ethical values
• Commitment to competence
• Board of directors or audit committee
• Management's philosophy and operating style
• Organizational structure
• Assignment of authority and responsibility
• Human resource policies and practices
Answer (A) is incorrect. Planning is not an element of the control environment.
Answer (C) is incorrect. Backup facilities, laws, and regulations are not elements of the control environment.
Answer (D) is incorrect. Risk assessment is part of planning the internal audit activity and specific engagements.