1/52
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Is obtaining an understanding of a client's internal control required in every financial statement audit?
Yes, obtaining an understanding of the client's system of internal control is required in every financial statement audit.
What component of internal control does the 'C' represent in the CRIME framework?
Control Environment.
What component of internal control does the 'R' represent in the CRIME framework?
Risk Assessment.
What component of internal control does the 'I' represent in the CRIME framework?
Information and Communication.
What component of internal control does the 'M' represent in the CRIME framework?
Monitoring.
What component of internal control does the 'E' represent in the CRIME framework?
Existing Control Activities.
To what organizational levels does a system of internal control apply?
It applies to the entire entity as well as to individual operating units and business functions.
Which of the five CRIME components are optional for an auditor to evaluate during a financial statement audit?
None; all five components of the CRIME framework apply to every financial statement audit.
Is management required to use the COSO framework to establish internal control?
No, management may choose COSO or another internal control framework.
What is the auditor's primary focus regarding a client's internal controls?
Controls that prevent, detect, and correct material misstatements in the financial statements.
Are financial statement auditors primarily concerned with internal controls over operational efficiency?
No, auditors focus on controls that prevent or detect material financial misstatements rather than operational efficiency.
What two aspects of internal controls must auditors test during the planning phase?
The design and the implementation of controls that address the risk of material misstatement.
Is testing the operating effectiveness of controls required when obtaining an initial understanding of internal controls?
No, testing operating effectiveness is not required at the initial planning stage.
Name two specific control areas auditors focus on when evaluating design and implementation.
Controls addressing significant risks (such as revenue recognition) and controls over journal entries and adjustments.
Why do auditors evaluate design and implementation for controls they plan to rely on?
To support assessing control risk below maximum, which allows a reduction in substantive testing assurance.
How are preventive controls defined in an internal control system?
Controls applied before processing occurs to ensure only valid transactions are recognized, approved, and submitted.
How are detective controls defined in an internal control system?
Controls performed after processing to provide reasonable assurance that errors or irregularities are discovered and corrected timely.
Is performing a bank reconciliation classified as a preventive control or a detective control?
It is a detective control because it occurs after processing to identify errors in cash balances.
Is segregation of duties categorized as a preventive or detective control?
Segregation of duties is a preventive control.
How does mandatory employee GAAP training serve as a preventive control?
It prevents misstatements before processing by ensuring accounting staff correctly understand and record transactions.
How can technology enhance the 'Risk Assessment' component of internal control?
By providing timely information that helps management identify and assess organizational risks.
How does management's failure to address IT risks impact the CRIME framework?
It negatively impacts the entity's control environment.
For what types of transactions are manual controls most appropriate?
Large, unusual, or non-recurring transactions, or situations where templates are difficult to define.
What is a major vulnerability of manual controls compared to automated controls?
Manual controls are less consistent, prone to human error or bias, and easily bypassed or overwritten.
Under what operational conditions are automated controls most effectively used?
High-volume, recurring transactions in predictable situations that can be clearly programmed.
What is the primary definition of General IT Controls (GITCs)?
Policies and procedures that support the effective functioning of information processing across multiple applications.
What is the auditor's first step when evaluating General IT Controls?
To understand the specific risks the entity faces through its reliance on technology.
How does requiring a VPN for remote access function as a general IT control?
It mitigates network security risks by enforcing authentication and encrypted access.
What IT control practice prevents unauthorized changes to operating system settings?
Restricting administrative access privileges exclusively to authorized personnel.
Why should program developers be separated from personnel who migrate code to production?
To enforce segregation of duties over change management and prevent unauthorized changes.
What type of IT operations control protects company data during a disaster or cyber attack?
Backup and recovery controls.
Restricting user access strictly to applications necessary for their specific job role demonstrates what control principle?
The principle of authorization (or least privilege).
Give two examples of information processing controls that ensure data integrity.
Edit checks and manual follow-ups for exception reports.
What audit procedure traces a transaction step-by-step from inception through reporting in the financial statements?
A walkthrough.
What four audit techniques are typically combined during a walkthrough to evaluate controls?
Inquiry, observation, inspection of documents, and reperformance.
Is inquiry alone sufficient evidence to establish that an internal control has been implemented?
No, inquiry alone is not sufficient to confirm implementation.
When is an internal control considered to be 'implemented'?
When the control exists and is actively being used in entity operations.
What question does an auditor evaluate when assessing the 'design' of an internal control?
Whether the control individually or with others can prevent, detect, and correct material misstatements.
What is the ultimate objective of evaluating internal control design and implementation during audit planning?
To identify where potential financial statement misstatements could occur.
What documentation regarding internal controls is explicitly required by GAAS?
Documentation showing the auditor's understanding of the design and implementation of internal controls.
In the FIND documentation mnemonic, what does 'F' represent?
Flowchart.
In the FIND documentation mnemonic, what does 'I' represent?
Internal Control Questionnaire (or checklist).
In the FIND documentation mnemonic, what does 'N' represent?
Narrative.
In the FIND documentation mnemonic, what does 'D' represent?
Documentation from the client (e.g., policy manuals and organizational charts).
In a standard internal control flowchart, what does a diamond symbol represent?
A decision point in the process.
In a standard internal control flowchart, what does a keyboard symbol represent?
Key entry or manual data entry.
What does a negative ('no') response on an internal control questionnaire typically signify?
A potential weakness in internal control that warrants further written explanation.
Why are flowcharts preferred over narratives for complex internal control structures?
Flowcharts clearly depict sequential flows of authority, processes, and documentation using visual symbols.
What is a major limitation of using written narratives to document internal controls?
Their length and wordiness make it difficult to identify control weaknesses.
Why can even well-designed internal controls only provide reasonable assurance rather than absolute assurance?
Because internal controls possess inherent limitations that cannot be completely eliminated.
How does management override weaken internal controls?
Management can bypass established controls to record unauthorized entries or manipulate reporting.
How does collusion between employees bypass internal control design?
Two or more individuals combine efforts to circumvent segregation of duties.
List three inherent limitations of internal control.
Management override, human error/bias, and employee collusion.