• Skip to primary navigation
  • Skip to main content
Free ACCA & CIMA online courses from OpenTuition

Free ACCA & CIMA online courses from OpenTuition

Free Notes, Lectures, Tests and Forums for ACCA and CIMA exams

  • ACCA
  • CIMA
  • FIA
  • OBU
  • Books
  • Forums
  • Ask AI
  • Search
  • Register
  • Login
    • BT
    • MA
    • FA
    • LW
    • PM
    • TX-UK
    • FR
    • AA
    • FM
    • SBL
    • AAA
    • AFM
    • APM
    • ATX
    • Dates
    • What is ACCA

Save 20% on ACCA & CIMA Books

Interactive BPP books for June 2026 exams, recommended by OpenTuition.
Get discount code >>

ACCA P3 flashcards – set 2

VIVA

See also ACCA P3 Flashcards: Set 1 | Set 2 | Set 3 | Set 4


Question
What are the eight principles of the European Data Protection Act implements Directive 95/46/EC?
Click to reveal answer
Answer
  • Data shall be processed lawfully and fairly
  • Obtained only for specified and lawful purposes
  • Not excessive
  • Accurate and up-to-date
  • Kept no longer than necessary
  • Processed in line with rights of the data subjects
  • Guard against loss and unauthorised processing
  • Not to transferred outside EEA unless similar legislation in destination.
or click card to flip back
Question
What are the four Vs of big data?
Click to reveal answer
Answer

Velocity

Volume

Variety

[Veracity]

or click card to flip back
Question
What are the three essential steps or elements of security in a virtual private network?
Click to reveal answer
Answer

(1) Access control and authentication – this ensures that unauthorized users do not access the system. Typically this will be accomplished through a log-in procedure.

(2) Confidentiality – this ensures that data cannot be intercepted and read by a third party whilst being transmitted. This is achieved using encryption.

 (3) Data integrity – this ensures that the data has not been altered or distorted whilst in transit. To ensure this, the message could have special check digits added to ensure that the data complies with a mathematical rule.

or click card to flip back
Question
What are VPNs?
Click to reveal answer
Answer

VPN = virtual private network. These allow data to be transmitted securely over the internet between any two locations.

or click card to flip back
Question
Most client-server networks comprise of three tiers or layers. What are these?
Click to reveal answer
Answer
  • Presentation tier
  • Application tier
  • Data tier
or click card to flip back
Question
What are LANs and WANs?
Click to reveal answer
Answer

LAN = local area network

WAN = wide area network

or click card to flip back
Question
What are CIMA’s five fundamental ethical principles?
Click to reveal answer
Answer
  • Integrity
  • Objectivity
  • Professional competence and due care
  • Confidentiality
  • Professional behaviour
or click card to flip back
Question
What are the elements of an anti-fraud policy which lead to fraud deterrence?
Click to reveal answer
Answer
  • Prevention
  • Detection
  • Response
or click card to flip back
Question
What are the three pre-conditions for fraud?
Click to reveal answer
Answer
  • Incentive
  • Opportunity
  • Attitude/dishonesty
or click card to flip back
Question
What are the two classes of fraud?
Click to reveal answer
Answer
  • Fraudulent financial reporting
  • Misappropriation of assets
or click card to flip back
Question
What are the four desirable requirements for an internal audit department?
Click to reveal answer
Answer
  • Staff should be qualified
  • Staff should be experienced
  • The department should be independent
  • Staff and approach should be professional
or click card to flip back
Question
What are the two techniques available in computer auditing?
Click to reveal answer
Answer
  • Audit software (examine client data)
  • Test data (examines client programs)
or click card to flip back
Question
What is the AEIOU mnemonic for ways of collecting audit evidence?
Click to reveal answer
Answer
  • Analytical procedures 
  • Enquiry and confirmation
  • Inspection: for example
  • Observation
  • RecalcUlation and reperformance. 
or click card to flip back
Question
What should go into each column and row of the table below?
Click to reveal answer
Answer
Internal auditExternal audit
Reports toManagement
– must have a clear route
to the board though
day-to-day reporting
to the audit committee.
Shareholders
Appointed byManagementShareholders
Power fromManagementStatute – allows external auditors to insist on seeing all documents and to be given full explanations.
Employed byCompany
(unless outsourced)
External firm
CoverageAll categories of risk and investigationFinancial statements: true and fair view
Responsibility
for improving the organisation
A major function of internal auditWill report to management on internal control weaknesses
or click card to flip back
Question
What are the two missing labels in the COSO framework, below?
Click to reveal answer
Answer

or click card to flip back
Question
What TARA response should go into each quadrant of the risk map, below?
Click to reveal answer
Answer

or click card to flip back
Question
If the standard deviation of a portfolio’s value from day to day is $5,000,
Click to reveal answer
Answer

?period = ?day ?n

So, the appropriate standard deviation would be $5,000 x ?25 = $25,000.

or click card to flip back
Question
What is ‘value at risk’?
Click to reveal answer
Answer

Generally it uses normal distribution tables to work out, for example, the minimum value of a portfolio of shares at the end of a period to a 95% probability (or conversely the maximum amount of fall in value to a 95% probability).

or click card to flip back
Question
What is the expected value of the following project?
Click to reveal answer
Answer
State of the worldP of that state occurringNPV of project $000P x NPV $000
I0.710,0007,000
II0.37,0002,100
Expected value9,100
or click card to flip back
Question
What is risk consolidation?
Click to reveal answer
Answer

This the process of aggregating divisional/subsidiary risks at the corporate level. Some risks can be handled together and be subject to a common approach, or they might even substantially cancel.

or click card to flip back
Question
What is assurance mapping?
Click to reveal answer
Answer

The aim of an assurance map is to identify where the safeguards against risks are to be found.

Assurance maps usually identify that an organisation has various lines of defences against risk. 

Typically these are:

  • Management-based assurance
  • Internal procedures
  • Independent assurance
or click card to flip back
Question
What is a risk register?
Click to reveal answer
Answer

It notes identified risks, their probability of occurrence, impact, responses to them and the date by which they should be addressed. The person in charge of dealing with the risk needs to be identified and it needs to be signed off when the risk has been mitigated (if needs be).

or click card to flip back
Question
What is the difference between gross and net risks?
Click to reveal answer
Answer
  • Gross risk = the risk before any mitigation (reduction) procedures. Gross risk is sometimes referred to as inherent risk. 
  • Net risk = the residual risk after reduction and mitigation.
or click card to flip back
Question
What is meant by ‘stress testing’ a strategy?
Click to reveal answer
Answer

A stress test is an assessment of how a system or strategy is likely to function if severe adverse events occur.

or click card to flip back
Question
What is scenario planning?
Click to reveal answer
Answer

Scenario planning looks at all the things that could happen (and there can be many permutations of future events) and from those builds viable scenarios: a number of believable, internally consistent futures. 

or click card to flip back
Question
What is a risk report?
Click to reveal answer
Answer

UK quoted companies are now required to include risk reports as part of their annual reports. This informs shareholders and others about the organisation’s main risks and what the company is doing about them.

or click card to flip back
Question
What is the project sensitivity to selling price?
Click to reveal answer
Answer

NPV = 20,000. For this to become Zero, NPV from sales must fall by $20,000.

Therefore, the percentage sensitivity = 20,000/120,000 = 0.17 or 17%

or click card to flip back
Question
What does a coefficient of correlation, r, of 0.5 indicate?
Click to reveal answer
Answer

r is Positive, so as one variable increases so does the other.

r2 = coefficient of determination = 0.25. This means that 25% of the variation in one variable can be explained by variation in the other. 75% of the change seems to be for other reasons.

or click card to flip back
Question
What is ‘corporate governance’?
Click to reveal answer
Answer

Corporate governance is a system by which companies are directed and controlled.

or click card to flip back
Question
What are the five OECD principles of corporate governance?
Click to reveal answer
Answer

Corporate governance frameworks should:

  • Protect shareholders’ rights
  • Recognise the rights of all shareholders
  • Ensure disclosure and transparency
  • Ensure timely and accurate information is available
  • The board should determine and be accountable for the strategy of the company
or click card to flip back
Question
What are the fie headings of the UK Corporate Governance CODE?
Click to reveal answer
Answer
  • Leadership 
  • Effectiveness 
  • Accountability 
  • Remuneration 
  • Relations with shareholders
or click card to flip back
Question
Which of the UK Corporate Governance Code and the USA’s Sarbanes Oxley has the force of law?
Click to reveal answer
Answer

UKCGC = not in statute. Enforced for listed companies by the stock exchange: comply or explain

SA Act = US law.

or click card to flip back
Question
The UK Corporate Governance Code mentions three board sub-committees
Click to reveal answer
Answer
  • Nomination committee appointment of new directors)
  • Audit committee (liaison with internal and external auditors)
  • Remuneration committee (directors’ remuneration)
or click card to flip back
Question
What are the five elements of an internal control system?
Click to reveal answer
Answer
  • The control environment
  • The risk assessment process
  • The information system
  • The control activities
  • Monitoring
or click card to flip back
Question
What is an internal control system?
Click to reveal answer
Answer

‘The management system of controls, financial and otherwise, established in order to provide reasonable assurance of:

(a) effective and efficient operation

(b) internal financial control

(c) compliance with laws and regulations’

 

(CIMA Official Terminology, 2005).

or click card to flip back
Question
Who is responsible for establishing procedures to manage risk
Click to reveal answer
Answer

The Board

or click card to flip back
Question
What is external audit?
Click to reveal answer
Answer

‘A periodic examination of the books of account and records of an entity carried out by an independent third party (the auditor), to ensure that they have been properly maintained, are accurate and comply with established concepts, principles, accounting standards, legal requirements and give a true and fair view of the financial state of the entity.’ (CIMA’s Management Accounting Official Terminology)

or click card to flip back
Question
What is internal audit?
Click to reveal answer
Answer

‘An independent appraisal activity established within an organisation as a service to it. It is a control which functions by examining and evaluating the adequacy and effectiveness of other controls; a management tool which analyses the effectiveness of all parts of an entity’s operations and management.’ (CIMA’s Management Accounting Official Terminology)

or click card to flip back
Question
In auditing, what is meant by ‘inherent risk’?
Click to reveal answer
Answer

Inherent risk: this is the risk that an error is made in the first place before the application of any controls of checks.

or click card to flip back
Question
What two labels are missing in the diagram below?
Click to reveal answer
Answer

 

or click card to flip back
Question
What are the two components of risk appetite?
Click to reveal answer
Answer

Risk appetite is determined by two factors: 

  • Stakeholder’s attitude to risk
  • Risk capacity, which is the amount of risk that the organisation can bear.
or click card to flip back
Question
What is an organisation’s risk appetite?
Click to reveal answer
Answer

‘Risk appetite’ is the term given to describe the amount of risk an organisation is willing to accept in pursuit of value.

or click card to flip back
Question
What is the difference between strategic risks and operational risks?
Click to reveal answer
Answer

Strategic risks: arise from long term effects such as those relating to the nature and type of business, changes in competitive and legal environments, poor long-term decisions being made.

Operational risks: short-term, day-to-day problems.

or click card to flip back
Question
What is malware?
Click to reveal answer
Answer

Malware is a term that covers all software intentionally designed to cause damage to a client computer, a server, the network or data.

or click card to flip back
Question
What is cloud computing?
Click to reveal answer
Answer

Data, programs and processing are (mostly) not held locally, but are held remotely on servers (the cloud). Software updates are easy and heavy processing can be carried out on powerful cloud computers rather than each user having to have a powerful machine.

or click card to flip back
Question
What is a DOS attack?
Click to reveal answer
Answer

Denial of service (DOS) attacks. Typically, the overwhelming of internet sites with demands for responses so that legitimate users are denied service.

or click card to flip back
Question
What is a bot?
Click to reveal answer
Answer

Bots: derived from ‘robot, this is a piece of software that carries out automated processes. For example, emails or posts on social media can be generated to give the appearance of support for particular causes.

or click card to flip back
Question
"In cyber-security
Click to reveal answer
Answer

Penetration testing (‘a pen test’) is an authorised simulated cyberattack on a computer system. It is a controlled form of hacking where the hackers act on behalf of the client to probe the system for vulnerabilities.

or click card to flip back
Question
"In cyber-security, what is meant by ‘malware analysis’?"
Click to reveal answer
Answer

what is meant by ‘malware analysis’?”

This aims process aims to understand what a piece of malware does and how it does it. The analysis might discover ways in which the malware can be countered.

or click card to flip back
Question
In cyber-security, what is meant by ‘forensic analysis’?
Click to reveal answer
Answer

‘Forensic’ implies that findings will be presented in a court of law or possibly some legal argument or negotiation. Computer forensics techniques discover, preserve and analyse information on computer systems.

or click card to flip back
Question
What are the labels for the two blank quadrants in the diagram below?
Click to reveal answer
Answer

or click card to flip back
Question
What is the relationship between ‘conformance’ and ‘performance’?
Click to reveal answer
Answer

Conformance (compliance with rules) is necessary to avoid failure, but it does not produce success. Performance implies taking some risks.

or click card to flip back
Question
What is meant by the term ’speculative risk’?
Click to reveal answer
Answer

This is where there can be both good and bad outcomes. It might occasionally be called ‘two-way risk’.

or click card to flip back
Question
What is meant by the term ‘pure risk’?
Click to reveal answer
Answer

This is where there is a chance of loss but no gain. There is downside risk only.

or click card to flip back
Question
It the following statement true or false? Risk covers the occurrence of both good and bad outcomes.
Click to reveal answer
Answer

True

or click card to flip back
Question
What is the difference between risk and uncertainty?
Click to reveal answer
Answer

Risk is when both the probability that a particular outcome occurs and its impact are known. If the probabilities of different outcomes occurring are not known then we are working under conditions of uncertainty, not risk.

or click card to flip back
1 / 56 (0 done)

Restart deck (bring all cards back)

🎉

Deck complete!

You worked through every card. Restart to revise the deck again.


Reader Interactions

Comments

  1. AvatarMilena says

    December 6, 2017 at 2:50 pm

    Thanks for the very helpful tool!

    Log in to Reply
  2. Avatarmks2016 says

    November 13, 2017 at 1:15 pm

    This is very helpful thank you 🙂

    Log in to Reply
  3. Avatarshahz20 says

    March 6, 2017 at 7:03 pm

    subarahshiiiii desuu

    Log in to Reply
  4. Avatarnasirsadat says

    November 19, 2013 at 12:39 pm

    Its very useful resource to remind concepts.

    Log in to Reply
  5. Avatarraheelnaseer says

    November 5, 2013 at 7:37 am

    Thanks, THIS IS GREAT…. very useful in revision

    Log in to Reply
  6. Avatarcakunalpatel says

    October 26, 2013 at 10:51 am

    Well..very nice work..can I get the pdf of the same so that I can take the print outs.. 🙂

    Log in to Reply
  7. Avatarrameez13031988 says

    September 1, 2013 at 7:01 pm

    They are moving so fast i cant read them

    Log in to Reply
  8. Avatarirenan says

    March 29, 2013 at 9:06 am

    I can not read them. I press on the read field that says press for the question and it does not give me anything

    Log in to Reply
    • Avataradmin says

      March 29, 2013 at 9:47 am

      Enable javascript (try another browser, like google chrome)

      Log in to Reply
  9. AvatarFortunate says

    March 14, 2013 at 3:37 pm

    Thank you open tuition…This is just wonderful …

    Log in to Reply
  10. Avataracca0393 says

    January 31, 2013 at 10:25 am

    Thumbs up Open tuition. You keep looking ahead and innovative for the benefit of ACCA students. Thank you and keep it up. It is amazing the way we are made to revise with confidence.

    Log in to Reply
  11. Avatarimran09 says

    December 5, 2012 at 4:18 pm

    Axes of ansoff matrix are wrongly stated.

    they are either existing and new, or
    current or new.

    not existing and current…

    Log in to Reply
  12. Avatarpaul says

    November 21, 2012 at 4:23 pm

    I like to ask that is there any plan for p1

    Log in to Reply
  13. Avatarshamaan says

    November 20, 2012 at 10:47 am

    It is amazing introduction of flash card.I like to ask that is there any plan for p1

    Log in to Reply
  14. Avatarbrgilbert2002 says

    November 1, 2012 at 3:55 pm

    This is great, many thanks OT,
    Can we get them down loadable?

    Log in to Reply
    • Avataradmin says

      November 1, 2012 at 4:06 pm

      NO, you can download the course notes,

      Log in to Reply
  15. Avatarmassline says

    October 31, 2012 at 11:27 am

    It keeps getting better. Thank you.

    Log in to Reply
  16. Avatarsatyajit says

    October 31, 2012 at 11:02 am

    Thank you for a nice initiatives.

    Log in to Reply
  17. Avatarbupechibamba says

    October 30, 2012 at 5:15 pm

    Wow pass cards are certainly hand when revising and their have boosted my confidence in p3, thumbs up open tuition.

    Log in to Reply
  18. Avatarsolochi says

    October 25, 2012 at 2:35 pm

    Thanks to open tuition for the wonderful job you are doing. with this flash in my hands , Iam sure of passing p3 first attempt.God bless you

    Log in to Reply
  19. Avatarwilliam241 says

    October 24, 2012 at 7:26 pm

    this is just wonderful.Thanks Guys!

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Copyright © 2026 · Contact · Advertising · OpenLicense · About · Sitemap · Privacy Policy · Cookie settings · Comments · Log in