1/26
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
A control that checks a group (batch) of transactions before they are entered into the system. It makes sure that all records in a batch are complete and accurate before processing.
Batch Input Control
Example: A company enters 100 employee timecards into the payroll system. The system counts the records and verifies that all 100 timecards were entered. If only 98 are entered, the system reports an error.
A control that ensures processed information is accurate and only reaches authorized users. It protects and verifies the reports or results produced by the system.
Output Control
Example: After payroll processing, salary reports are sent only to the HR manager and not to all employees. This prevents unauthorized access to sensitive information.
A control that restricts actions based on a specific time or schedule. It allows or blocks system activities depending on the time.
Time-Based Control
Example: Employees can only log their attendance between 7:00 AM and 9:00 AM. Any attempt to clock in outside those hours is rejected.
A control that that data are accurate, complete, and protected during processing and storage. These are crucial for maintaining data quality over time. It prevents invalid or incorrect data from being stored in the system.
Integrity Control
Example: When entering a student's age, the system only accepts numbers between 5 and 100. If someone enters -10 or 200, the system displays an error.
These are used for verification purposes, not monetary validation, helping to detect inconsistencies during data processing. It is the sum of non-financial identifiers (e.g., invoice numbers)
Hash totals
It is a processing control that records the number in the batch.
Record Count
It is a processing control that gives the total dollar value of a financial field.
Batch Control Total
If an organization has no formal risk management processes, the chief audit executive should establish risk management processes based on industry norms (T/F)
False (CAE should formally discuss with the directors their obligations for risk management processes)
According to the fraud triangle, which element is most controllable by the organization?
Opportunity
It is a fraud that involves falsifying documents, like fake loan applications, to deceive and gain financially. It is often part of complex fraud schemes.
Document-based fraud
An auditor who observes the law and makes disclosures expected by the law is demonstrating
Integrity (Integrity refers to the auditorās adherence to ethical principles, such as honesty and fairness.)
According to COSO ERM, what is the purpose of reviewing entity performance during ERM review and revision?
To detect unidentified or improperly assessed risks
The degree of voluntary compliance with an organizationās adopted code of ethics is a measure of the
Cohesion and professionalism of an organization
Which ethical principle do the following actions violate?
The internal auditor assumes operational duties on a temporary basis.
The internal auditor performs an audit in a department managed by the auditorās father.
The internal auditor managed the department being audited 6 months prior to the audit.
The internal auditor receives a bonus based on the number of observations generated during an audit.
Objectivity
In the COSO Internal Control Framework, which component ensures that policies and values are emphasized and supported across all levels?
Control environment
In evaluating governance, if a Chief Audit Executive (CAE) found that safeguards across governance processes are weak, they should apply advisory services to strengthen controls and governance rather that to request an external governance consultant (T/F)
True (If governance safeguards are weak, the CAE must proactively offer advisory services to help improve them. Waiting or reassigning audits delays necessary improvements and exposes the organization to risks)
In complying with the Code of Ethics, an internal auditor should use individual judgment in the application of the principles set forth in the Code (T/F)
True (While adhering to the Code of Ethics, internal auditors are expected to use personal judgment to apply the principles in varying circumstances. This approach ensures that they maintain professional behavior and integrity, as the application of ethical principles often requires contextual decision-making. The Code offers guidance, but auditors must assess specific situations and apply the principles accordingly.)
The Chief Audit Executive (CAE) is responsible for assessing the level of IA functionās ________ independence and ________ objectivity (T/F)
collective, individual
It is an input control that checks if a value falls within an acceptable range.
Range Check
It ensures that entered numbers match those in an approved list, preventing invalid or unauthorized transactions from being entered into systems.
Validity Check
Who has the responsibility for fraud investigation when a senior manager is involved?
Audit Committee
The major reason for the internal auditorās involvement in information systems development is for the internal auditor to
Ensure that appropriate controls are built into the system from the start. (Providing recommendations is within the auditorās role and does not involve assuming management responsibilities.)
According to COBIT 2019, what distinguishes the governance system from the governance framework?
The system governs processes; the framework defines structural relationships
It shows risks at an organizational level.
Portfolio View (reflects entity-wide risks affecting performance)
It drills down into risks tied to individual objectives
Risk Profile (links risks to specific objectives)
It is the combination of portfolio view and risk profile
Risk Picture
In COSO ERM, what does āactual residual riskā refer to?
The remaining risk after management has taken actions to alter severity