Achievable logoAchievable logo
CMA Part 1
Sign in
Sign up
Purchase
Textbook
Practice exams
Support
How it works
Exam catalog
Mountain with a flag at the peak
Textbook
1. External financial reporting decisions
2. Planning, budgeting, and forecasting
3. Performance management
4. Cost management
5. Internal control
5.1 Governance, risk and compliance
5.1.1 Internal control objectives and the COSO Framework
5.1.2 Responsibility for internal control and segregation of duties
5.1.3 Internal control limitations, risks, and deficiencies
5.1.4 Corporate governance structure and responsibilities
5.1.5 Corporate governance roles and responsibilities
5.1.6 External audit
5.1.7 The Sarbanes-oxley Act
5.1.8 Other regulatory bodies
5.2 System controls and security measures
6. Technology and analytics
Achievable logoAchievable logo
5.1.8 Other regulatory bodies
Achievable CMA Part 1
5. Internal control
5.1. Governance, risk and compliance
Our CMA Part 1 course is currently in development and is a work-in-progress.

Other regulatory bodies

4 min read
Font
Discuss
Share
Feedback

Learning outcome statements

The learning outcome statements relevant for this section are:

  1. identify the role of the Public Company Accounting Oversight Board (PCAOB) in providing guidance on the auditing of internal controls
  2. differentiate between a top-down (risk-based) approach and a bottom-up approach to auditing internal controls
  3. identify the PCAOB preferred approach to auditing internal controls
  4. identify and describe the major internal control provisions of the Foreign Corrupt Practices Act

Public Company Accounting Oversight Board (PCAOB)

The Public Company Accounting Oversight Board (PCAOB) was established under Title I of the Sarbanes-Oxley Act (SOX) of 2002 in response to major corporate accounting scandals. Its primary mission is to oversee the audits of public companies and broker-dealers in order to protect investors and promote accurate, transparent, and independent financial reporting.

The PCAOB conducts inspections of registered public accounting firms on a regular basis: (1) annually for firms that audit more than 100 issuers; and (2) at least once every three years for other registered firms. Registered public accounting firms include all audit firms that prepare or issue audit reports for publicly traded companies or broker-dealers registered with the SEC. These firms must register with the PCAOB before performing such audits. to assess their compliance with auditing standards and the quality of their audit work.

It also has the authority to conduct investigations and disciplinary proceedings in cases of misconduct or violation of standards. The PCAOB’s jurisdiction covers auditors of publicly traded companies and broker-dealers that file reports with the U.S. Securities and Exchange Commission (SEC). The PCAOB provides standards and guidance for auditors, particularly in the area of internal control over financial reporting (ICFR). A key element of its role is issuing auditing standards that define how audits should be planned, performed, and documented.

Top-down (risk-based) vs. bottom-up approach:

  • The top-down approach, preferred by the PCAOB, begins with identifying and assessing entity-level controls and major risks, then moves down to significant accounts, disclosures, and relevant assertions. This helps auditors focus on areas of greatest risk.
  • The bottom-up approach involves detailed testing of individual controls at the transaction or process level without necessarily aligning to overall risk assessment. It can be less efficient and less effective at identifying systemic weaknesses.

Through its oversight, standard-setting, and inspection activities, the PCAOB plays a critical role in enhancing audit quality and ensuring investor confidence in capital markets.

Foreign Corrupt Practices Act (FCPA)

The Foreign Corrupt Practices Act (FCPA) is a U.S. federal law that addresses both anti-bribery and accounting transparency requirements for companies. While it is widely known for prohibiting bribery of foreign officials, the FCPA also imposes significant internal control and recordkeeping obligations on companies to prevent and detect corruption. Key internal control provisions of the FCPA include:

Books and records requirement

Companies must maintain books, records, and accounts that accurately and fairly reflect the company’s transactions and disposition of assets. This requirement applies even if the company is unaware of the corruption.

Internal controls requirement

Companies must design and maintain a system of internal accounting controls sufficient to provide reasonable assurance that:

  1. Transactions are executed with management’s authorization.
  2. Transactions are recorded accurately to permit preparation of financial statements and to maintain accountability of assets.
  3. Access to assets is permitted only with proper authorization.
  4. Recorded assets are compared with existing assets at reasonable intervals and appropriate action is taken regarding any discrepancies.

These provisions apply to issuers of securities registered with the U.S. Securities and Exchange Commission (SEC), including U.S. public companies and certain foreign issuers. Even without evidence of bribery, failure to comply with these internal control provisions can lead to enforcement actions.

The FCPA emphasizes the importance of strong internal controls not only for accurate financial reporting but also as a deterrent against corrupt practices across global operations.

Public Company Accounting Oversight Board (PCAOB)

  • Oversees audits of public companies and broker-dealers
  • Sets auditing standards, especially for internal control over financial reporting (ICFR)
  • Conducts inspections, investigations, and disciplinary actions for registered public accounting firms

Top-down (risk-based) vs. bottom-up approach

  • Top-down approach:
    • Starts with entity-level controls and major risks
    • Focuses on significant accounts, disclosures, and assertions
    • PCAOB preferred method
  • Bottom-up approach:
    • Focuses on detailed testing at transaction/process level
    • Less efficient at identifying systemic risks

Foreign Corrupt Practices Act (FCPA)

  • Requires accurate books, records, and accounts for all transactions
  • Mandates internal accounting controls to ensure:
    • Management authorization of transactions
    • Accurate recording and asset accountability
    • Proper authorization for asset access
    • Regular asset verification and discrepancy resolution
  • Applies to SEC-registered issuers, including U.S. public and certain foreign companies

Sign up for free to take 5 quiz questions on this topic

Previous
Next  | 5.2.1 General accounting system controls
All rights reserved ©2016 - 2026 Achievable, Inc.

Other regulatory bodies

Learning outcome statements

The learning outcome statements relevant for this section are:

  1. identify the role of the Public Company Accounting Oversight Board (PCAOB) in providing guidance on the auditing of internal controls
  2. differentiate between a top-down (risk-based) approach and a bottom-up approach to auditing internal controls
  3. identify the PCAOB preferred approach to auditing internal controls
  4. identify and describe the major internal control provisions of the Foreign Corrupt Practices Act

Public Company Accounting Oversight Board (PCAOB)

The Public Company Accounting Oversight Board (PCAOB) was established under Title I of the Sarbanes-Oxley Act (SOX) of 2002 in response to major corporate accounting scandals. Its primary mission is to oversee the audits of public companies and broker-dealers in order to protect investors and promote accurate, transparent, and independent financial reporting.

The PCAOB conducts inspections of registered public accounting firms on a regular basis: (1) annually for firms that audit more than 100 issuers; and (2) at least once every three years for other registered firms. Registered public accounting firms include all audit firms that prepare or issue audit reports for publicly traded companies or broker-dealers registered with the SEC. These firms must register with the PCAOB before performing such audits. to assess their compliance with auditing standards and the quality of their audit work.

It also has the authority to conduct investigations and disciplinary proceedings in cases of misconduct or violation of standards. The PCAOB’s jurisdiction covers auditors of publicly traded companies and broker-dealers that file reports with the U.S. Securities and Exchange Commission (SEC). The PCAOB provides standards and guidance for auditors, particularly in the area of internal control over financial reporting (ICFR). A key element of its role is issuing auditing standards that define how audits should be planned, performed, and documented.

Top-down (risk-based) vs. bottom-up approach:

  • The top-down approach, preferred by the PCAOB, begins with identifying and assessing entity-level controls and major risks, then moves down to significant accounts, disclosures, and relevant assertions. This helps auditors focus on areas of greatest risk.
  • The bottom-up approach involves detailed testing of individual controls at the transaction or process level without necessarily aligning to overall risk assessment. It can be less efficient and less effective at identifying systemic weaknesses.

Through its oversight, standard-setting, and inspection activities, the PCAOB plays a critical role in enhancing audit quality and ensuring investor confidence in capital markets.

Foreign Corrupt Practices Act (FCPA)

The Foreign Corrupt Practices Act (FCPA) is a U.S. federal law that addresses both anti-bribery and accounting transparency requirements for companies. While it is widely known for prohibiting bribery of foreign officials, the FCPA also imposes significant internal control and recordkeeping obligations on companies to prevent and detect corruption. Key internal control provisions of the FCPA include:

Books and records requirement

Companies must maintain books, records, and accounts that accurately and fairly reflect the company’s transactions and disposition of assets. This requirement applies even if the company is unaware of the corruption.

Internal controls requirement

Companies must design and maintain a system of internal accounting controls sufficient to provide reasonable assurance that:

  1. Transactions are executed with management’s authorization.
  2. Transactions are recorded accurately to permit preparation of financial statements and to maintain accountability of assets.
  3. Access to assets is permitted only with proper authorization.
  4. Recorded assets are compared with existing assets at reasonable intervals and appropriate action is taken regarding any discrepancies.

These provisions apply to issuers of securities registered with the U.S. Securities and Exchange Commission (SEC), including U.S. public companies and certain foreign issuers. Even without evidence of bribery, failure to comply with these internal control provisions can lead to enforcement actions.

The FCPA emphasizes the importance of strong internal controls not only for accurate financial reporting but also as a deterrent against corrupt practices across global operations.

Key points

Public Company Accounting Oversight Board (PCAOB)

  • Oversees audits of public companies and broker-dealers
  • Sets auditing standards, especially for internal control over financial reporting (ICFR)
  • Conducts inspections, investigations, and disciplinary actions for registered public accounting firms

Top-down (risk-based) vs. bottom-up approach

  • Top-down approach:
    • Starts with entity-level controls and major risks
    • Focuses on significant accounts, disclosures, and assertions
    • PCAOB preferred method
  • Bottom-up approach:
    • Focuses on detailed testing at transaction/process level
    • Less efficient at identifying systemic risks

Foreign Corrupt Practices Act (FCPA)

  • Requires accurate books, records, and accounts for all transactions
  • Mandates internal accounting controls to ensure:
    • Management authorization of transactions
    • Accurate recording and asset accountability
    • Proper authorization for asset access
    • Regular asset verification and discrepancy resolution
  • Applies to SEC-registered issuers, including U.S. public and certain foreign companies

More from Governance, risk and compliance

  • Internal control objectives and the COSO Framework
  • Responsibility for internal control and segregation of duties
  • Internal control limitations, risks, and deficiencies
  • Corporate governance structure and responsibilities
  • Corporate governance roles and responsibilities