Auditor Assessment of Client Systems and Internal Control Environment

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/52

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:48 PM on 10/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

53 Terms

1
New cards

Is obtaining an understanding of a client's internal control required in every financial statement audit?

Yes, obtaining an understanding of the client's system of internal control is required in every financial statement audit.

2
New cards

What component of internal control does the 'C' represent in the CRIME framework?

Control Environment.

3
New cards

What component of internal control does the 'R' represent in the CRIME framework?

Risk Assessment.

4
New cards

What component of internal control does the 'I' represent in the CRIME framework?

Information and Communication.

5
New cards

What component of internal control does the 'M' represent in the CRIME framework?

Monitoring.

6
New cards

What component of internal control does the 'E' represent in the CRIME framework?

Existing Control Activities.

7
New cards

To what organizational levels does a system of internal control apply?

It applies to the entire entity as well as to individual operating units and business functions.

8
New cards

Which of the five CRIME components are optional for an auditor to evaluate during a financial statement audit?

None; all five components of the CRIME framework apply to every financial statement audit.

9
New cards

Is management required to use the COSO framework to establish internal control?

No, management may choose COSO or another internal control framework.

10
New cards

What is the auditor's primary focus regarding a client's internal controls?

Controls that prevent, detect, and correct material misstatements in the financial statements.

11
New cards

Are financial statement auditors primarily concerned with internal controls over operational efficiency?

No, auditors focus on controls that prevent or detect material financial misstatements rather than operational efficiency.

12
New cards

What two aspects of internal controls must auditors test during the planning phase?

The design and the implementation of controls that address the risk of material misstatement.

13
New cards

Is testing the operating effectiveness of controls required when obtaining an initial understanding of internal controls?

No, testing operating effectiveness is not required at the initial planning stage.

14
New cards

Name two specific control areas auditors focus on when evaluating design and implementation.

Controls addressing significant risks (such as revenue recognition) and controls over journal entries and adjustments.

15
New cards

Why do auditors evaluate design and implementation for controls they plan to rely on?

To support assessing control risk below maximum, which allows a reduction in substantive testing assurance.

16
New cards

How are preventive controls defined in an internal control system?

Controls applied before processing occurs to ensure only valid transactions are recognized, approved, and submitted.

17
New cards

How are detective controls defined in an internal control system?

Controls performed after processing to provide reasonable assurance that errors or irregularities are discovered and corrected timely.

18
New cards

Is performing a bank reconciliation classified as a preventive control or a detective control?

It is a detective control because it occurs after processing to identify errors in cash balances.

19
New cards

Is segregation of duties categorized as a preventive or detective control?

Segregation of duties is a preventive control.

20
New cards

How does mandatory employee GAAP training serve as a preventive control?

It prevents misstatements before processing by ensuring accounting staff correctly understand and record transactions.

21
New cards

How can technology enhance the 'Risk Assessment' component of internal control?

By providing timely information that helps management identify and assess organizational risks.

22
New cards

How does management's failure to address IT risks impact the CRIME framework?

It negatively impacts the entity's control environment.

23
New cards

For what types of transactions are manual controls most appropriate?

Large, unusual, or non-recurring transactions, or situations where templates are difficult to define.

24
New cards

What is a major vulnerability of manual controls compared to automated controls?

Manual controls are less consistent, prone to human error or bias, and easily bypassed or overwritten.

25
New cards

Under what operational conditions are automated controls most effectively used?

High-volume, recurring transactions in predictable situations that can be clearly programmed.

26
New cards

What is the primary definition of General IT Controls (GITCs)?

Policies and procedures that support the effective functioning of information processing across multiple applications.

27
New cards

What is the auditor's first step when evaluating General IT Controls?

To understand the specific risks the entity faces through its reliance on technology.

28
New cards

How does requiring a VPN for remote access function as a general IT control?

It mitigates network security risks by enforcing authentication and encrypted access.

29
New cards

What IT control practice prevents unauthorized changes to operating system settings?

Restricting administrative access privileges exclusively to authorized personnel.

30
New cards

Why should program developers be separated from personnel who migrate code to production?

To enforce segregation of duties over change management and prevent unauthorized changes.

31
New cards

What type of IT operations control protects company data during a disaster or cyber attack?

Backup and recovery controls.

32
New cards

Restricting user access strictly to applications necessary for their specific job role demonstrates what control principle?

The principle of authorization (or least privilege).

33
New cards

Give two examples of information processing controls that ensure data integrity.

Edit checks and manual follow-ups for exception reports.

34
New cards

What audit procedure traces a transaction step-by-step from inception through reporting in the financial statements?

A walkthrough.

35
New cards

What four audit techniques are typically combined during a walkthrough to evaluate controls?

Inquiry, observation, inspection of documents, and reperformance.

36
New cards

Is inquiry alone sufficient evidence to establish that an internal control has been implemented?

No, inquiry alone is not sufficient to confirm implementation.

37
New cards

When is an internal control considered to be 'implemented'?

When the control exists and is actively being used in entity operations.

38
New cards

What question does an auditor evaluate when assessing the 'design' of an internal control?

Whether the control individually or with others can prevent, detect, and correct material misstatements.

39
New cards

What is the ultimate objective of evaluating internal control design and implementation during audit planning?

To identify where potential financial statement misstatements could occur.

40
New cards

What documentation regarding internal controls is explicitly required by GAAS?

Documentation showing the auditor's understanding of the design and implementation of internal controls.

41
New cards

In the FIND documentation mnemonic, what does 'F' represent?

Flowchart.

42
New cards

In the FIND documentation mnemonic, what does 'I' represent?

Internal Control Questionnaire (or checklist).

43
New cards

In the FIND documentation mnemonic, what does 'N' represent?

Narrative.

44
New cards

In the FIND documentation mnemonic, what does 'D' represent?

Documentation from the client (e.g., policy manuals and organizational charts).

45
New cards

In a standard internal control flowchart, what does a diamond symbol represent?

A decision point in the process.

46
New cards

In a standard internal control flowchart, what does a keyboard symbol represent?

Key entry or manual data entry.

47
New cards

What does a negative ('no') response on an internal control questionnaire typically signify?

A potential weakness in internal control that warrants further written explanation.

48
New cards

Why are flowcharts preferred over narratives for complex internal control structures?

Flowcharts clearly depict sequential flows of authority, processes, and documentation using visual symbols.

49
New cards

What is a major limitation of using written narratives to document internal controls?

Their length and wordiness make it difficult to identify control weaknesses.

50
New cards

Why can even well-designed internal controls only provide reasonable assurance rather than absolute assurance?

Because internal controls possess inherent limitations that cannot be completely eliminated.

51
New cards

How does management override weaken internal controls?

Management can bypass established controls to record unauthorized entries or manipulate reporting.

52
New cards

How does collusion between employees bypass internal control design?

Two or more individuals combine efforts to circumvent segregation of duties.

53
New cards

List three inherent limitations of internal control.

Management override, human error/bias, and employee collusion.