CMA Part 1 · Internal Controls · Free Lesson

System controls and security measures

Free IMA CMA Part 1 (Financial Planning, Performance, and Analytics) lesson in Internal Controls. 19 min read, ~2,785 words.

A payroll clerk who can edit master file pay rates, run the payroll, and reconcile the bank account is one resignation letter away from owning the company's cash. Strong system controls remove that single point of failure. The exam tests whether you can name the control, classify it, and predict which threat it neutralizes.

Traditional SoD splits authorization, custody, recording, and reconciliation. In an IT environment the categories expand. The systems analyst designs applications. The programmer writes code. The computer operator runs production jobs. The librarian controls program and data file media. The database administrator controls schemas. The security administrator controls access rights. End users initiate transactions. No single person should hold more than one of these roles for the same system.

KEY: A programmer who can also run production jobs can move tested code into live execution with no second pair of eyes, planting fraud or sabotage that bypasses change control.

The exam expects you to name the threat from the fact pattern. Memorize the catalog:

Read the full lesson, free →
Worked examples and practice. Free with a free account, no card.

Common mistakes

Bottom line

Exam shortcut

When a question lists a threat and asks for the matching control, map threat to control category first. Input manipulation maps to input controls (edit checks, check digits). Program alteration maps to change-control and segregated environments. Data theft maps to encryption plus access controls. The mapping is the answer most of the time.

The full lesson (about 2,785 words, 19 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.

Learning objectives

Browse all free CMA Part 1 lessons or jump into free CMA Part 1 practice questions.