Chapter 3: INTERNAL CONTROL CONSIDERATION AND RESPONSES TO ASSESSED RISKS

CHAPTER 3

INTERNAL CONTROL CONSIDERATION AND

RESPONSES TO ASSESSED RISKS

TOPIC OVERVIEW:

This chapter discusses internal controls, assessment of control risks and how will it affect audit procedures.

LEARNING OBJECTIVES:

After studying this chapter, you should be able to:

1. Describe the objectives and inherent limitation of an internal control.

2. Identify and explain each component of internal control.

3. Describe the appropriate responses of the auditor to assessed risks.

4. Explain test of controls and substantive procedures and identify how they are affected by assessed risk.

ACCOUNTING AND INTERNAL CONTROL SYSTEMS

Accounting system is a series of tasks and records of an entity by which transactions are processed as a means of maintaining financial records. Such systems identify, assemble, analyze, calculate, classify, record, summarize and report transactions and other events.

Internal control system means all the policies and procedures (internal controls) adopted by the management of an entity to assist in achieving management’s objective of ensuring, as far as practicable:

• orderly and efficient conduct of its business, including adherence to management policies;

• safeguarding of assets;

• prevention and detection of fraud and error;

• accuracy and completeness of the accounting records; and

• timely preparation of reliable financial information.

The internal control system extends beyond those matters which relate directly to the functions of the accounting system.

INTERNAL CONTROL

Internal control is a process, effected by those charged with governance, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories:

a. Effectiveness and efficiency of operations (operational objective);

b. Reliability of financial reporting (reporting objective); and

c. Compliance with applicable laws and regulations (compliance objective).

Assurance provided by internal control

There is a direct relationship between an entity’s objectives and the controls which are implemented to provide assurance of their achievement. However, no matter how well designed and operated, internal control can only provide reasonable assurance.

Inherent Limitations of Internal Control

The internal control can only provide reasonable assurance because of inherent limitations that may affect the effectiveness of internal controls. Such limitations include: (COC CHA)

• Management usual requirement that a control be cost-effective (Cost-benefit consideration);

• The possibility that a person responsible for exercising control could abuse that responsibility (Management Overriding the control);

• The possibility of circumvention of controls through Collusion with parties outside the entity or with employees of the entity;

• The possibility that procedures may become inadequate due to Changes in condition and compliance with procedures may deteriorate;

• The potential for Human error due to carelessness, distraction, mistakes of judgment or the misunderstanding of instructions; and

• The fact that most controls tend to be directed at Anticipated types (routine) of transactions and not at unusual (non-routine) transactions.

Areas of Internal Control

Areas of internal control can be classified as either administrative control or accounting control.

1. Administrative control includes, but is not limited to, plan of organization and the procedures and records that are concerned with the decision processes leading to management’s authorization of transactions. Administrative controls promote operational efficiency and adherence to managerial policies.

2. Accounting control comprises the plan of organization and the procedures and records that are concerned with the safeguarding of assets and the reliability of financial records. It involves systems of authorization and approval controls over assets, internal audit and all other financial matters.

Controls Relevant to the Audit

The auditor’s risk assessment process relates to controls pertaining to the entity’s objective of preparing financial statements for external purposes and the management risk that may give rise to a material misstatement in those financial statements.

It is a matter of professional judgment, subject to the requirements of PSA, whether a control, individually or in combination with others, is relevant to the auditor’s consideration in assessing the risks of material misstatement and designing and performing further procedures in response to assessed risks. In exercising that judgment, the auditor considers the applicable component and factors such as the following:

a. The auditor’s judgment about materiality;

b. The size of the entity;

c. The nature of the entity’s business, including its organization and ownership characteristics;

d. The diversity and complexity of the entity’s operations;

e. Applicable legal and regulatory requirements; and

f. The nature and complexity of the systems that are part of the entity’s internal control, including the use of service organizations.

COMPONENTS OF INTERNAL CONTROL

As discussed in PSA 315 (Redrafted), an internal control has the following components: (CRIME)

a. Control Environment

b. Entity’s Risk assessment process

c. Information and communication systems

d. Control Activities

e. Monitoring of Controls

A. The control environment

The control environment includes the governance and management functions and the attitudes, awareness, and actions of those charged with governance and management concerning the entity’s internal control and its importance in the entity.

Elements of control environment: (IM CPA HO)

1. Communication and enforcement of integrity and ethical values;

2. Management’s philosophy and operating style;

3. Commitment to competence;

4. Participation by those charged with governance;

5. Assignment of authority and responsibility;

6. Human resources policies and procedures; and

7. Organizational structure.

B. The entity’s risk assessment process

An entity’s risk assessment process is the process of identifying and responding to business risks and the results thereof.

For financial reporting purposes, the entity’s risk assessment process includes how management identifies risks relevant to the preparation of financial statements that are presented fairly, in all material respects in accordance with the entity’s applicable financial reporting framework, estimates their significance, assesses the likelihood of their occurrence, and decides upon actions to manage them.

Risks can arise or change due to circumstances such as the following:

a. Changes in operating environment

b. New personnel

c. New or revamped information systems

d. Rapid growth

e. New technology

f. New business models, products, or activities

g. Corporate restructurings

h. Expanded foreign operations

i. New accounting pronouncements

The auditor shall obtain an understanding of whether the entity has a process for: (IAM)

• Identifying business risks relevant to financial reporting objectives

• Assessing the significance of risks and the likelihood of their occurrence

• Deciding how to manage those risks

C. The information system, including the related business processes relevant to financial reporting, and communication

An information system consists of

a. Infrastructure (physical and hardware components);

b. Software

c. Processes and procedures;

d. People; and

e. Input or data.

NOTE: Infrastructure and software will be absent, or have less significance in systems that are exclusively or primarily manual.

The information system relevant to financial reporting objectives, such as the financial reporting system, consists of the procedures and records established to initiate, record, process, and report entity transactions (as well as events and conditions) and to maintain accountability for the related assets, liabilities, and equity.

Communication of financial reporting roles and responsibilities and significant matters relating to financial reporting includes:

a. Communications between management and those charged with governance and

b. External communications, such as those with regulatory authorities

D. Control activities

Control activities are the policies and procedures to help ensure that management directives are carried out.

Examples of control activities include those relating to the following: (APIPS)

1. Authorization

◦ Specific authorization - for unusual, material, or infrequent transactions

◦ General authorization - for regular transactions

2. Performance reviews - examples include actual performance versus budget, forecasts, and prior period performance

3. Information processing - includes controls from initiation up to the eventual inclusion of transaction in financial reports

4. Physical controls (for both assets and documents)

5. Segregation of duties

Segregation of incompatible function or duties is intended to reduce the opportunities to allow any person to be in a position to both perpetrate and conceal errors or fraud in the normal course of the person’s duties.

To achieve optimum segregation of responsibilities, the following responsibilities should be separated: (I CARE)

◦ Independent checks

◦ Custody of assets

◦ Authorization of transactions

◦ Recording of transactions

◦ Execution of transactions

E. Monitoring of controls.

Monitoring is the process of assessing the quality of internal control performance over time. It involves assessing the design and operations of controls on a timely basis and taking necessary corrective actions. Monitoring is done to ensure that controls continue to operate effectively.

Monitoring can be accomplished through

a. Ongoing monitoring activities (performed by persons within the same line function)

b. Separate evaluations (performed by internal auditors, audit committee, and/or external auditors

c. Combination of the two.

INTERNAL CONTROL CONSIDERATION

The auditor should obtain an understanding of the accounting and internal control systems sufficient to plan the audit and develop an effective audit approach. It involves the following steps:

1. Obtain an understanding of the internal control.

2. Preliminary assessment of control risk

3. Determine the overall response to assessed risks

4. Perform test of controls

5. Reassess control risk

6. Final assessment of control risk

7. Determine the nature, timing, and extent of substantive tests necessary to restrict detection risk to an acceptable level.

Obtain an Understanding of the Internal Control

The auditor shall obtain an understanding of policies and procedures within the accounting and internal control systems that are relevant to the financial statement assertions. The understanding of relevant aspects of the accounting and internal control systems, together with the inherent and control risk assessments and other considerations, will enable the auditor to:

a) Identify the types of potential material misstatements that could occur in the financial statements;

b) Consider factors that affect the risk of material misstatements; and

c) Design appropriate audit procedures.

Obtaining an understanding of internal control consists of:

a) Evaluating the design of relevant controls – involves determining whether those controls, individually or in combination with other controls, is capable of effectively preventing or detecting and correcting material misstatements

b) Determining whether the controls have been implemented – involves determining whether the control is placed in operation; implementation of a control means that the control exists and is being used by the entity

c) Documenting the system’s internal controls and identifying transaction cycles

d) Performing “walk-through” test to determine whether controls are implemented

e) Identifying controls that are potentially reliable

The following procedures are used in obtaining understanding of an entity’s internal control:

a) Inquiring of entity personnel.

b) Observing the application of specific controls.

c) Inspecting documents and reports.

d) Tracing transactions through the information system relevant to financial reporting (i.e., walkthrough)

Documentation of auditor’s understanding of internal control

To document the understanding of internal controls, auditors commonly use the following:

• Narrative memorandum is a written description of a particular phase or phases of an accounting system.

• Flowchart or data flow diagram consists of interrelated symbols that diagram the flow of transactions and events through a system. Flowcharts capture the complexity of the systems, allowing the auditors to focus sharply on key controls within the system.

• Internal control questionnaire (ICQ) consists of a series of questions designed to detect control deficiencies.

• Checklist

Preliminary Assessment of Control Risk

After obtaining an understanding of the accounting and internal control systems, the auditor should make a preliminary assessment of control risk, at the assertion level, for each material account balance or class of transactions.

The preliminary assessment of control risk is the process of evaluating the effectiveness of an entity’s accounting and internal control systems in preventing or detecting and correcting material misstatements. There will always be some control risk because of the inherent limitations of any accounting and internal control system.

Assessment of control risk

1. Maximum or high level

✓ The entity’s accounting and internal control systems are not effective;

✓ Evaluating the effectiveness of the entity’s accounting and internal control systems would not be efficient

2. Below maximum or less than high

✓ The auditor is able to identify internal controls relevant to the assertion which are likely to prevent or detect and correct a material misstatement and plans to perform tests of control to support the assessment

✓ Auditor’s judgment is that substantive procedures alone do not provide sufficient appropriate audit evidence

Determine the Overall Response to Assessed Risks

In order to reduce audit risk to an acceptably low level, the auditor should determine overall responses to assessed risks at the financial statement level, should design and perform further audit procedures to respond to assessed risk at the assertion level. Such responses include:

1. If preliminary control risk assessment is HIGH, the auditor relies primarily on substantive tests.

2. If preliminary control risk assessment is LESS THAN HIGH, the auditor performs tests of controls.

Perform Test of Controls

The auditor shall design and perform tests of controls to obtain sufficient appropriate audit evidence as to the operating effectiveness of relevant controls. Tests of control are concerned with the:

1. Design of the accounting and internal control systems

2. Implementation of the accounting and internal control systems

3. Operating effectiveness of the accounting and internal control systems

Test of control procedures includes the following:

1. Inspection

2. Inquiry

3. Observation

4. Reperformance

5. Walk-through

6. Recalculation

Reassess Control Risk

Based on the results of the tests of control, the auditor should evaluate whether the internal controls are designed and operating as contemplated in the preliminary assessment of control risk. The evaluation of deviations may result in the auditor concluding that the assessed level of control risk needs to be revised. In such cases, the auditor would modify the nature, timing and extent of planned substantive procedures.

Effect of the reassessment of control risk on the audit approach

Effect of the reassessment of control risk on the audit approach

When reassessment of control risk remains at less than high:

• Audit approach is reliance or systems approach

• Effect on substantive procedures includes less effective procedures, interim testing may be appropriate, and smaller sample size

When reassessment of control risk is changed to high:

• Audit approach is switch to no reliance approach

• Effect on substantive procedures includes more effective procedures, tests nearer or at year-end, and larger sample size

Final Assessment of Control Risk

Before the conclusion of the audit, based on the results of the substantive procedures and other audit evidence obtained by the auditor, the auditor should consider whether the assessment of control risk is confirmed.

Determine the nature, timing, and extent of substantive tests necessary to restrict detection risk to an acceptable level

Irrespective of the assessed risk of material misstatement, the auditor should design and perform substantive procedures for each material class of transactions, account balance and disclosures.

RESPONSES TO ASSESSED RISKS

The auditor shall design and implement overall responses to address the assessed risks of material misstatement at the financial statement level.

Moreover, the auditor shall design and perform further audit procedures whose nature, timing, and extent are based on and are responsive to the assessed risks of material misstatement at the assertion level.

In designing the further audit procedures to be performed, the auditor shall:

1. Consider the reasons for the assessment given to the risk of material misstatement at the assertion level for each class of transactions, account balance, and disclosure, including:

a. The likelihood of material misstatement due to the particular characteristics of the relevant class of transactions, account balance, or disclosure (i.e., the inherent risk); and

b. Whether the risk assessment takes account of relevant controls (i.e., the control risk), thereby requiring the auditor to obtain audit evidence to determine whether the controls are operating effectively (i.e., the auditor intends to rely on the operating effectiveness of controls in determining the nature, timing and extent of substantive procedures); and

2. Obtain more persuasive audit evidence, the higher the auditor’s assessment of risk.

Documentation requirements

For control risk assessment at high level:

• Understanding of internal control: Yes

• Control risk assessment: Yes

• Basis for the control risk assessment: No

For control risk assessment at less than high level:

• Understanding of internal control: Yes

• Control risk assessment: Yes

• Basis for the control risk assessment: Yes


CHAPTER 3: REVIEW QUESTIONS - THEORETICAL

1. It is the process designed and effected by those charged with governance, management, and other personnel to provide reasonable assurance about the achievement of the entity's objectives.

a. Internal auditing

b. Business strategy

c. Internal control

d. Accounting process

2. Internal controls are not designed to provide reasonable assurance that

a. The recorded accountability for assets is compared with the existing assets at reasonable intervals

b. Access to assets is permitted only in accordance with management's authorization

c. Transactions are executed in accordance with management's authorization

d. Irregularities will be eliminated

3. This is a basic concept of internal control which recognizes that the cost of internal control should not exceed the benefits expected to be derived from it:

a. Management by exception

b. Limited liability

c. Management responsibility

d. Reasonable assurance

4. An internal control system that is working effectively

a. Eliminates risk and potential loss of to the entity

b. Cannot be circumvented by management

c. Reduces the need for management the review exception reports on a day-to-day basis

d. Is unaffected by changing circumstances and conditions encountered by the entity

5. Which of the following is an example of an inherent limitation in a client's internal control system?

a. The effectiveness of procedures depends on the segregation of employee duties.

b. Procedures are designed to assure the execution and recording of transactions in accordance with management's authorization.

c. In the performance of most control procedures, there are possibilities of errors arising from mistakes in judgment.

d. Procedures for handling large numbers of transactions are processed by information technology (IT) equipment.

6. Which of the following statements best describes "control environment"?

a. Policies and procedures that help ensure that management directives are carried out.

b. The system for transferring information from transaction processing systems to the general ledger or the financial reporting system.

c. The entity's process for identifying business risks relevant to financial reporting objectives and deciding about actions to address those risks, and the results thereof.

d. This includes the governance and management functions and the attitudes, awareness, and actions of those charged with governance and management concerning the entity's internal control and its importance to the entity.

7. Which of the following considered control environment elements?

a. Commitment to Competence: Yes; Detection Risk: No; Organizational Structure: Yes

b. Commitment to Competence: Yes; Detection Risk: Yes; Organizational Structure: Yes

c. Commitment to Competence: No; Detection Risk: No; Organizational Structure: No

d. Commitment to Competence: No; Detection Risk: No; Organizational Structure: Yes

8. An entity's risk assessment process includes how management:

• Identifies risk:

A: Yes

B: Yes

C: No

D: Yes

• Assess significance and likelihood of occurrence of these identified risks:

A: Yes

B: Yes

C: Yes

D: No

• Decides upon actions to manage these risks:

A: Yes

B: No

C: Yes

D: No

9. Risks can arise or change due to circumstances such as the following, except:

a. There is a change in the regulatory or operating environment (i.e. a new law has been passed which prohibits the use of a chemical which is a main ingredient of the company's major product).

b. New employees have been hired by the company.

c. The company switched from manual information systems to a computerized system.

d. The accounting and financial reporting framework has remained stable for the past five years, and no new pronouncements have been made.

10. As part of a periodic planning exercise, Cedric Naranjo Company discovers that a political dispute may interfere with the company's supply sources. This is an example of:

a. Control environment

b. Risk assessment

c. Control activities

d. Monitoring of controls

11. Control activities constitute one of the five components of internal control. Which of the following is not included in this internal control component?

a. Segregation of duties

b. Performance reviews

c. An internal audit function

d. Authorization

12. Control activities are the policies and procedures that help ensure that management directives are carried out. These include activities relating authorization, performance reviews, information processing, physical controls and segregation of duties. There is proper segregation of duties when an individual who

a. Authorizes a transaction records it.

b. Maintains custody of an asset has access to the accounting records for the asset.

c. Authorizes transaction maintains custody of the asset that resulted from the transaction.

d. Records a transaction do not compare the accounting record of the asset with the asset itself.

13. Under PSA 315, monitoring of controls is an internal control component that involves a process of assessing the quality of internal control performance over time. It involves assessing the design and operation of controls on a timely basis and taking necessary corrective actions. Monitoring of controls is accomplished through ongoing monitoring activities, separate evaluations, or a combination of the two. An entity's ongoing monitoring activities often include

a. Periodic reporting by the entity's internal auditors about the functioning of internal control

b. The audit of the annual financial statements

c. Periodic audits by the audit committee

d. Reviewing the purchasing account

14. The primary purpose of the auditor's consideration of internal control is to provide a basis for

a. Determining whether procedures and records that are concerned with the safeguarding of assets are reliable.

b. Constructive suggestions to clients concerning deficiencies in internal control.

c. Determining the nature, timing and extent of audit tests to be applied.

d. The expression of an opinion.

15. Which of the following statements concerning the relevance of various types of controls to a financial statement audit is correct?

a. All controls are ordinarily relevant to a financial statement audit.

b. Controls over the reliability of assets and liabilities are of primary importance, while controls over the reliability of financial reporting may also be relevant.

c. Controls over the reliability of financial reporting are ordinarily most directly relevant to a financial statement audit, but other controls may also be relevant.

d. An auditor may ordinarily ignore a consideration of controls when a substantive audit approach is taken.

16. PSA 315 Redrafted requires the auditor to obtain an understanding of the client's internal controls

a. For every audit

b. For first-time audits

c. Whenever it would be appropriate

d. Sufficient to find any frauds which may exist

17. When obtaining knowledge about an entity's internal control, it is important for the auditor to consider the competence of its employees, because their competence bears directly and importantly upon the

a. Cost-benefit relationship of internal control

b. Comparison of recorded accountability with assets

c. Achievement of the objectives of internal control

d. Timing of substantive tests to be performed

18. Obtaining an understanding of internal control involves:

• Evaluating the design of a control:

• Determining whether the control has been implemented:

• Testing the effectiveness of a control:

A: Yes, Yes, Yes

B: Yes, Yes, No

C: Yes, No, Yes

D: No, Yes, Yes

19. The primary objective of procedures performed to obtain an understanding of internal control is to provide an auditor with

a. Information necessary to prepare flowcharts.

b. Evidence to use in reducing detection risk.

c. Knowledge necessary to plan the audit.

d. A basis for modifying test of controls.

20. To obtain an understanding of the relevant policies and procedures of internal control, the auditor performs all of the following except:

a. Make inquiries

b. Make observations

c. Design substantive tests

d. Inspect documents and records

21. After obtaining an understanding of an entity's internal control, an auditor may assess control risk at the maximum level for some assertions because the auditor

a. Believes the internal control policies and procedures are unlikely to be effective.

b. Determines that the pertinent internal control components are not well documented.

c. Performs tests of controls to restrict detection risk to an acceptable level.

d. Identifies internal control policies and procedures that are likely to prevent material misstatements.

22. After obtaining an understanding of internal control and assessing control risk, an auditor decided to perform tests of controls. The auditor most likely decided that

a. Additional evidence to support a further reduction in control risk is not available.

b. It would be efficient to perform tests of controls that would result in a reduction in planned substantive tests.

c. An increase in the assessed level of control risk is justified for certain financial statement assertions.

d. There were many internal control weaknesses that could allow errors to enter the accounting system.

23. Information about segregation of duties ordinarily is best obtained by

a. Performing test of transactions that corroborate management's financial statements assertions.

b. Developing audit objectives that reduce control risk.

c. Observing employees as they apply specific controls.

d. Obtaining a flowchart of activities performed by entity personnel.

24. In conducting an audit in accordance with PSAs, the auditor is required to identify and assess the risks of material misstatement at the financial statements level, and at the assertion level for classes of transactions, account balances, and disclosure. Some of these risks, in the auditor's judgment, require special audit consideration, such as those that involve fraud or complex transactions. Such risks are called

a. Business risks

b. Significant risks

c. Audit risks

d. Material risks

25. The auditor's primary objective in obtaining an understanding of the client's control over the purchasing function is to

a. Investigate the recording of unusual transactions regarding raw materials.

b. Determine the reliability of financial reporting by the purchasing function.

c. Observe the annual physical count.

d. Ascertain that raw material paid for are on hand.

26. When obtaining an understanding of an entity's internal control, an auditor should concentrate on the substance of controls rather than their form because:

a. The controls may be operating effectively but may not be documented.

b. Management may establish appropriate controls but not act on them.

c. The controls may be so inappropriate that no reliance is contemplated by the auditor.

d. Management may implement controls with costs in excess of benefits.

27. When obtaining an understanding of the accounting and internal control system the auditor may trace a few transactions through the accounting system. This technique is:

a. Reperformance

b. Control test

c. Walk-through

d. Validity test

28. Control risk assessment procedures include all of the following, except

a. Inspection of documents

b. Confirmation of bank balances

c. Observation of procedures

d. Inquiry of client personnel

29. Evidence of the performance of control risk assessment procedures includes all of the following, except

a. Flowcharts

b. Questionnaires

c. Lead schedule

d. Memoranda

30. Which of the following statements regarding auditor documentation of the client's internal control structure is correct?

a. Documentation must include flowcharts.

b. Documentation must include procedural write-ups.

c. No documentation is necessary although it is desirable.

d. No one particular form of documentation is necessary, and the extent of documentation may vary.

31. The ultimate purpose of assessing control risk is to contribute to the auditor's evaluation of the risk that:

a. Specified controls requiring segregation of duties may be circumvented by collusion.

b. Tests of controls may fail to identify controls relevant to assertions.

c. Material misstatements may exist in the financial statements.

d. Entity policies may be circumvented by senior management.

32. An auditor may decide to assess control risk at the maximum level for certain assertions because the auditor believes

a. Evaluating the effectiveness of policies and procedures is inefficient.

b. Sufficient evidence matter to support the assertions is likely to be available.

c. More emphasis on tests of controls than substantive tests is warranted.

d. Considering the relationship of assertions to specific account balances is more efficient.

33. An auditor's flowchart of a client's accounting system is a diagrammatic representation that depicts the auditor's

a. Assessment of control environment's effectiveness

b. Identification of weaknesses in the system

c. Understanding of the system

d. Assessment of control risk

34. Which of the following statements is true?

a. Tests of controls are necessary if the auditor plans to use the primarily substantive approach.

b. Tests of controls are necessary if the auditor plans to assess the level of control risk at maximum.

c. The auditor can simultaneously obtain an understanding of internal control and perform tests of controls.

d. After performing tests of controls, the auditor will always assess control risk at maximum.

35. After documenting internal control in an audit engagement, the auditor may perform tests on:

a. Those controls that were reviewed (selected on a random basis).

b. Those controls that the auditor plans to rely on.

c. Those controls in which deficiencies or weaknesses were identified.

d. Those controls that have a material effect on the balances in the financial statements.

36. In a financial statement audit, the auditor is required to perform test of controls when:

I. The auditor's risk assessment includes expectation of the operating effectiveness of controls.

II. When substantive procedures alone do not provide sufficient appropriate audit evidence at the assertion level.

a. I only

b. Either I or II

c. II only

d. Neither I nor II

37. Tests of controls are used to test whether controls are:

a. Properly incorporated in the financial statements

b. Placed in operation or implemented

c. Properly documented by the client

d. Operating at the effectiveness

38. Tests of controls may include the following, except:

a. Reperformance of internal control procedures

b. Inquiries about, and observation of, internal controls which leave no audit trail

c. Inspection of documentary support to transactions evidencing authorization

d. Analytical procedures involving comparison of operating expenses with budget amount

39. An auditor intends to perform test of controls on a client's control procedures that leaves no audit trail of documentary evidence. The auditor most likely will use the procedure by

a. Inquiry and inspection

b. Inquiry and observation

c. Confirmation and reperformance

d. Analytical procedures and confirmation

40. Which of the following is the auditor's purpose of further testing internal control procedures?

a. Provide a basis for reducing the assessed level of control risk below that which resulted from the auditor's initial understanding of internal control.

b. Reduce the risk that errors or fraud which are not prevented or detected by internal control are not detected by the independent audit.

c. Provide assurance that transactions are executed in accordance with management's authorization and access to assets is limited by a proper segregation of functions.

d. Provide assurance that transactions are recorded as necessary to permit the preparation of the financial statements in accordance with PFRS.

41. Which of the following is not a characteristic of the lower control risk approach?

a. The auditor usually plans to place considerable reliance on the controls.

b. The auditor plans to perform extensive tests of controls.

c. Control risk is usually assessed at maximum level.

d. Substantive tests are usually restricted.

42. A control that reduces the risk that an existing or potential control weakness will result in a failure to meet a control objective is referred to as:

a. Compensating control

b. Non-routine control

c. Conditional control

d. Offset control

43. When a compensating control exists, a weakness in the system:

a. is no longer a concern because the potential for misstatement has been sufficiently reduced.

b. is reduced but it is not removed; therefore, it is still of concern to the auditor.

c. Could cause a material loss, so it must be tested using substantive procedures.

d. is magnified and must be removed from the sampling process and examined in its entity.

44. If no changes have occurred since the controls were last tested, a CPA should

a. Rely on the prior year audit's assessment of internal controls and use this assessment in the current year.

b. Test the operating effectiveness of such controls at least once in every fourth audit.

c. Rely entirely on the performance of substantive audit procedures.

d. Test the operating effectiveness of such controls at least once in every third audit.

45. Regardless of the assessed level of control risk, an auditor would perform some

a. Test of controls to determine the operating effectiveness of internal control policies

b. Analytical procedures to verify the design of internal control procedures

c. Substantive test to restrict detection risk for significant classes of transactions

d. Dual-purpose test to evaluate both the risk of monetary misstatement and preliminary control risk