Deck 5: Risk Assessment: Internal Control Evaluation
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/69
Play
Full screen (f)
Deck 5: Risk Assessment: Internal Control Evaluation
1
Which of the following is not a component of internal controls?
A) Control environment
B) Control activities
C) Inherent risk
D) Monitoring
A) Control environment
B) Control activities
C) Inherent risk
D) Monitoring
C
2
Which of the following procedures is considered a test of controls?
A) An auditor reviews the entity's check register for unrecorded liabilities.
B) An auditor evaluates whether a general journal entry was recorded at the proper amount.
C) An auditor interviews and observes appropriate personnel to determine segregation of duties.
D) An auditor reviews the audit workpapers to ensure proper sign-off.
A) An auditor reviews the entity's check register for unrecorded liabilities.
B) An auditor evaluates whether a general journal entry was recorded at the proper amount.
C) An auditor interviews and observes appropriate personnel to determine segregation of duties.
D) An auditor reviews the audit workpapers to ensure proper sign-off.
C
3
A set of characteristics that helps to define a seriousness about employees' attitudes about the control activities in a company is referred to as
A) management assertions.
B) the control environment.
C) control risk assessment.
D) functional responsibilities.
A) management assertions.
B) the control environment.
C) control risk assessment.
D) functional responsibilities.
B
4
An auditor is evaluating a client's internal controls.Which of the following situations would be the most difficult internal control issue for an auditor to detect?
A) The accounting staff neglects the control, due to increased transactions to be processed.
B) The technology department writes a program that does not properly implement the control, due to a lack of understanding.
C) Two employees, who work in different departments, are circumventing an internal control.
D) Someone erroneously disables edit checks in a software program designed to identify control exceptions.
A) The accounting staff neglects the control, due to increased transactions to be processed.
B) The technology department writes a program that does not properly implement the control, due to a lack of understanding.
C) Two employees, who work in different departments, are circumventing an internal control.
D) Someone erroneously disables edit checks in a software program designed to identify control exceptions.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
5
The appropriate separation of duties does not include
A) authorization to execute transactions.
B) recording of transactions.
C) custody of assets involved in the transactions.
D) data preparation.
A) authorization to execute transactions.
B) recording of transactions.
C) custody of assets involved in the transactions.
D) data preparation.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
6
Which of the following is the best way to compensate for the lack of adequate segregation of duties in a small organization?
A) Disclosing lack of segregation of duties to the external auditors during the annual review
B) Replacing personnel every three or four years
C) Requiring accountants to pass a yearly background check
D) Allowing for greater management oversight of incompatible activities
A) Disclosing lack of segregation of duties to the external auditors during the annual review
B) Replacing personnel every three or four years
C) Requiring accountants to pass a yearly background check
D) Allowing for greater management oversight of incompatible activities
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
7
An auditor is concerned about a policy of management override as a limitation of internal control.Which of the following tests would best assess the validity of the auditor's concern?
A) Matching purchase orders to accounts payable
B) Verifying that approved spending limits are not exceeded
C) Tracing sales orders to the revenue account
D) Reviewing minutes of board meeting
A) Matching purchase orders to accounts payable
B) Verifying that approved spending limits are not exceeded
C) Tracing sales orders to the revenue account
D) Reviewing minutes of board meeting
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
8
Which of the following statements is correct regarding internal control?
A) A well-designed internal control environment ensures the achievement of an entity's control objectives.
B) An inherent limitation to internal control is the fact that controls can be circumvented by management override.
C) A well-designed and operated internal control environment should detect collusion perpetrated by two people.
D) Internal control is a necessary business function and should be designed and operated to detect all errors and fraud.
A) A well-designed internal control environment ensures the achievement of an entity's control objectives.
B) An inherent limitation to internal control is the fact that controls can be circumvented by management override.
C) A well-designed and operated internal control environment should detect collusion perpetrated by two people.
D) Internal control is a necessary business function and should be designed and operated to detect all errors and fraud.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
9
Obtaining an understanding of an internal control involves evaluating the design of the control and determining whether the control has been
A) authorized.
B) implemented.
C) tested.
D) monitored.
A) authorized.
B) implemented.
C) tested.
D) monitored.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
10
Which of the following payroll control activities would most effectively ensure that payment is made only for work performed?
A) Require all employees to record arrival and departure by using the time clock.
B) Have a payroll clerk recalculate all time cards.
C) Require all employees to sign their time cards.
D) Require employees to have their direct supervisors approve their time cards.
A) Require all employees to record arrival and departure by using the time clock.
B) Have a payroll clerk recalculate all time cards.
C) Require all employees to sign their time cards.
D) Require employees to have their direct supervisors approve their time cards.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
11
Which of the following statements best describes why an auditor would use only substantive procedures to evaluate specific relevant assertions and risks?
A) The relevant internal control components are not well documented.
B) The internal auditor already has tested the relevant controls and found them effective.
C) Testing the operating effectiveness of the relevant controls would not be efficient.
D) The cost of substantive procedures will exceed the cost of testing the relevant controls.
A) The relevant internal control components are not well documented.
B) The internal auditor already has tested the relevant controls and found them effective.
C) Testing the operating effectiveness of the relevant controls would not be efficient.
D) The cost of substantive procedures will exceed the cost of testing the relevant controls.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
12
Which of the following is a definition of control risk?
A) The risk that a material misstatement will not be prevented or detected on a timely basis by the client's internal controls.
B) The risk that the auditor will not detect a material misstatement.
C) The risk that the auditor's assessment of internal controls will be at less than the maximum level.
D) The susceptibility of material misstatement assuming there are no related internal controls, policies, or procedures.
A) The risk that a material misstatement will not be prevented or detected on a timely basis by the client's internal controls.
B) The risk that the auditor will not detect a material misstatement.
C) The risk that the auditor's assessment of internal controls will be at less than the maximum level.
D) The susceptibility of material misstatement assuming there are no related internal controls, policies, or procedures.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
13
Which of the following outcomes is a likely benefit of information technology used for internal control?
A) Processing of unusual or nonrecurring transactions
B) Enhanced timeliness of information
C) Potential loss of data
D) Recording of unauthorized transactions
A) Processing of unusual or nonrecurring transactions
B) Enhanced timeliness of information
C) Potential loss of data
D) Recording of unauthorized transactions
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
14
Which of the following activities performed by a department supervisor most likely would help in the prevention or detection of a payroll fraud?
A) Distributing paychecks directly to department store employees
B) Setting the pay rate for departmental employees
C) Hiring employees and authorizing them to be added to payroll
D) Approving a summary of hours each employee worked during the pay period
A) Distributing paychecks directly to department store employees
B) Setting the pay rate for departmental employees
C) Hiring employees and authorizing them to be added to payroll
D) Approving a summary of hours each employee worked during the pay period
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
15
Each of the following types of controls is considered to be an entity-level control,except those
A) relating to the control environment.
B) pertaining to the company's risk assessment process.
C) regarding the company's annual stockholder meeting.
D) addressing policies over significant risk management practices.
A) relating to the control environment.
B) pertaining to the company's risk assessment process.
C) regarding the company's annual stockholder meeting.
D) addressing policies over significant risk management practices.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
16
Which of the following is a factor in the control environment?
A) Segregation of duties
B) Information processing
C) Performance reviews
D) Management's philosophy and operating style
A) Segregation of duties
B) Information processing
C) Performance reviews
D) Management's philosophy and operating style
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
17
Which of the following should an auditor do when control risk is assessed at the maximum level?
A) Perform fewer substantive tests of details
B) Perform more tests of controls
C) Document the assessment
D) Document the control structure more extensively
A) Perform fewer substantive tests of details
B) Perform more tests of controls
C) Document the assessment
D) Document the control structure more extensively
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
18
Which of the following factors is most likely to affect the extent of the documentation of the auditor's understanding of a client's system of internal controls?
A) The industry and the business and regulatory environments in which the client operates
B) The degree to which information technology is used in the accounting function
C) The relationship between management, the board of directors, and external stakeholders
D) The degree to which the auditor intends to use internal audit personnel to perform substantive tests
A) The industry and the business and regulatory environments in which the client operates
B) The degree to which information technology is used in the accounting function
C) The relationship between management, the board of directors, and external stakeholders
D) The degree to which the auditor intends to use internal audit personnel to perform substantive tests
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
19
When an auditor plans to rely on controls that have changed since they were last tested,which of the following courses of action would be most appropriate?
A) Test the operating effectiveness of such controls in the current audit.
B) Document that reliance and proceed with the original audit strategy.
C) Inquire of management as to the effectiveness of the controls.
D) Report the reliance in the report on internal controls.
A) Test the operating effectiveness of such controls in the current audit.
B) Document that reliance and proceed with the original audit strategy.
C) Inquire of management as to the effectiveness of the controls.
D) Report the reliance in the report on internal controls.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
20
An audit team's responsibility would not include
A) designing client's internal controls.
B) documentation of understanding of a client's internal controls.
C) communicating internal control deficiencies.
D) assessing the effectiveness a client's internal controls.
A) designing client's internal controls.
B) documentation of understanding of a client's internal controls.
C) communicating internal control deficiencies.
D) assessing the effectiveness a client's internal controls.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
21
The ultimate purpose of assessing control risk is to contribute to the auditor's evaluation of the
A) factors that raise doubts about the auditability of the financial statements.
B) operating effectiveness of internal control policies and procedures.
C) risk that material misstatements exist in the financial statements.
D) possibility that the nature and extent of substantive tests may be reduced.
A) factors that raise doubts about the auditability of the financial statements.
B) operating effectiveness of internal control policies and procedures.
C) risk that material misstatements exist in the financial statements.
D) possibility that the nature and extent of substantive tests may be reduced.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
22
Regardless of the assessed level of control risk,an auditor of a non-public company would perform some
A) tests of controls to determine the effectiveness of internal control policies.
B) analytical procedures to verify the design of internal control activities.
C) substantive tests to restrict detection risk for significant transaction classes.
D) dual purpose tests to evaluate both the risk of monetary misstatement and preliminary control risk.
A) tests of controls to determine the effectiveness of internal control policies.
B) analytical procedures to verify the design of internal control activities.
C) substantive tests to restrict detection risk for significant transaction classes.
D) dual purpose tests to evaluate both the risk of monetary misstatement and preliminary control risk.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
23
If auditors assess control risk at the maximum level,they will tend to
A) perform a great deal of additional tests of controls.
B) perform a great deal of substantive testing during the audit.
C) perform substantive tests at an interim date.
D) perform more audit procedures using internal evidence.
A) perform a great deal of additional tests of controls.
B) perform a great deal of substantive testing during the audit.
C) perform substantive tests at an interim date.
D) perform more audit procedures using internal evidence.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
24
Which of the following audit procedures most likely would provide an auditor with the most assurance about the effectiveness of the operation of an entity's internal control?
A) Confirmation with outside parties
B) Inquiry of client personnel
C) Successful re-performance of the control activity
D) Observation of client personnel
A) Confirmation with outside parties
B) Inquiry of client personnel
C) Successful re-performance of the control activity
D) Observation of client personnel
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
25
After obtaining an understanding of a client's financial reporting control activities,the auditor would next
A) test the client's control activities.
B) assess the final control risk.
C) document the understanding obtained.
D) plan the remainder of the audit work.
A) test the client's control activities.
B) assess the final control risk.
C) document the understanding obtained.
D) plan the remainder of the audit work.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
26
Which of the following client internal control activities is not usually performed in the treasurer's department?
A) Verifying the accuracy of checks and vouchers
B) Controlling the mailing of checks to vendors
C) Approving vendors' invoices for payment
D) Canceling payment vouchers when paid
A) Verifying the accuracy of checks and vouchers
B) Controlling the mailing of checks to vendors
C) Approving vendors' invoices for payment
D) Canceling payment vouchers when paid
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
27
The "obtaining an understanding" work phase (Phase 1)of internal control evaluation would not give auditors an overall acquaintance with the client's
A) control environment.
B) information and communication system.
C) control activity effectiveness.
D) monitoring activities.
A) control environment.
B) information and communication system.
C) control activity effectiveness.
D) monitoring activities.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
28
A sales clerk enters a customer's six-number customer account.The computer program uses the first five numbers to calculate a sixth number.This resulting number is then compared to the sixth number entered by the sales clerk.This is an example of a
A) a valid character test.
B) missing data test.
C) reasonableness test.
D) check digit.
A) a valid character test.
B) missing data test.
C) reasonableness test.
D) check digit.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
29
The internal control in small business is highly dependent on the
A) separation of functional responsibilities.
B) complexity of the client's internal controls.
C) owner-manager's competence, as well as his/her ethics and integrity.
D) bonding of employees.
A) separation of functional responsibilities.
B) complexity of the client's internal controls.
C) owner-manager's competence, as well as his/her ethics and integrity.
D) bonding of employees.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
30
When the audit team increases the planned assessed level of control risk because certain control activities were determined to be ineffective,the audit team would most likely increase the
A) extent of substantive tests of details.
B) level of inherent risk.
C) extent of tests of controls.
D) level of detection risk.
A) extent of substantive tests of details.
B) level of inherent risk.
C) extent of tests of controls.
D) level of detection risk.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
31
Tracing bills of lading to sales invoices provides evidence that
A) shipments to customers were invoiced.
B) shipments to customers were recorded as sales.
C) recorded sales were shipped.
D) invoiced sales were recorded as sales.
A) shipments to customers were invoiced.
B) shipments to customers were recorded as sales.
C) recorded sales were shipped.
D) invoiced sales were recorded as sales.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
32
In computer systems,the information technology general controls (ITGC)would not include
A) processing control activities.
B) separation of various computer system functions.
C) appropriate documentation of the data processing system.
D) control over physical access to computer hardware.
A) processing control activities.
B) separation of various computer system functions.
C) appropriate documentation of the data processing system.
D) control over physical access to computer hardware.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
33
After obtaining an understanding of the entity's internal control and assessing control risk,an auditor of a non-public company decided not to perform additional tests of controls.The auditor most likely concluded that the
A) additional evidence to support a further reduction in control risk was not cost beneficial.
B) assessed level of inherent risk exceeded the assessed level of control risk.
C) internal control structure was properly designed and justifiably may be relied on.
D) evidence obtainable through tests of controls would not support an increased level of control risk.
A) additional evidence to support a further reduction in control risk was not cost beneficial.
B) assessed level of inherent risk exceeded the assessed level of control risk.
C) internal control structure was properly designed and justifiably may be relied on.
D) evidence obtainable through tests of controls would not support an increased level of control risk.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
34
Control strengths and weaknesses should be documented in audit documentation,sometimes called
A) questionnaires, narratives, and flowcharts.
B) bridge working papers.
C) communications of significant deficiencies.
D) internal control letters.
A) questionnaires, narratives, and flowcharts.
B) bridge working papers.
C) communications of significant deficiencies.
D) internal control letters.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
35
Which of the following is not an input control activity?
A) Reasonableness tests
B) Record counts
C) Financial totals
D) Hash totals
A) Reasonableness tests
B) Record counts
C) Financial totals
D) Hash totals
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
36
Control activities intended to ensure that transactions are recorded in the right period are designed to achieve the ASB assertion of
A) occurrence.
B) accuracy.
C) valuation or allocation.
D) cutoff.
A) occurrence.
B) accuracy.
C) valuation or allocation.
D) cutoff.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
37
When obtaining an understanding of an entity's internal control in a financial statement audit at a non-public company,an auditor is not obligated to
A) determine whether the control activities have been placed in operation.
B) perform procedures to understand the design of the internal control system.
C) document the understanding of the company's internal control system.
D) search for significant deficiencies in the operation of the internal control system.
A) determine whether the control activities have been placed in operation.
B) perform procedures to understand the design of the internal control system.
C) document the understanding of the company's internal control system.
D) search for significant deficiencies in the operation of the internal control system.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
38
Which of the following is an Information Technology General Control?
A) Check digit
B) Run-to-run totals
C) Distribution of computerized output
D) Separation of duties in the IT department
A) Check digit
B) Run-to-run totals
C) Distribution of computerized output
D) Separation of duties in the IT department
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
39
Which of the following is the least important audit reason for the auditor's obtaining an understanding of a company's internal control?
A) To serve as a basis for constructive suggestions
B) To plan subsequent substantive tests
C) To identify types of possible misstatements that may occur
D) To consider factors that may affect the risk of material misstatement
A) To serve as a basis for constructive suggestions
B) To plan subsequent substantive tests
C) To identify types of possible misstatements that may occur
D) To consider factors that may affect the risk of material misstatement
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
40
Sound internal control can be described as separating all of the following duties and responsibilities except for
A) transaction authorization.
B) recordkeeping.
C) custody of, or direct access to, assets.
D) hiring of employees.
A) transaction authorization.
B) recordkeeping.
C) custody of, or direct access to, assets.
D) hiring of employees.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
41
Below are several of the ASB management assertions.
A. Occurrence
B. Completeness
C. Rights and obligations
D. Allocation or valuation
E. Classification
F. Existence
G. Cutoff
H. Accuracy
I. Understandability
For each of the following control activities, identify the management assertion that best applies by placing the correct letter in the blank space above.
____ 1. Match shipping documents with sales invoices before a sale is recorded.
____ 2. Balance total of individual customers' receivables with the control account.
____ 3. Sales manager approves taking discounts.
____ 4. Computer check for billing the quantity shipped, list price, and total.
____ 5. Account for numerical sequence of pre-numbered shipping documents
A. Occurrence
B. Completeness
C. Rights and obligations
D. Allocation or valuation
E. Classification
F. Existence
G. Cutoff
H. Accuracy
I. Understandability
For each of the following control activities, identify the management assertion that best applies by placing the correct letter in the blank space above.
____ 1. Match shipping documents with sales invoices before a sale is recorded.
____ 2. Balance total of individual customers' receivables with the control account.
____ 3. Sales manager approves taking discounts.
____ 4. Computer check for billing the quantity shipped, list price, and total.
____ 5. Account for numerical sequence of pre-numbered shipping documents
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
42
In an audit of financial statements of a non-public company in accordance with generally accepted auditing standards,an auditor is required to
A) document the auditor's understanding of the entity's internal control.
B) search for significant deficiencies in the operation of the internal controls.
C) perform tests of controls to evaluate the effectiveness of the entity's accounting system.
D) determine whether control activities are operating effectively to prevent or detect material misstatements.
A) document the auditor's understanding of the entity's internal control.
B) search for significant deficiencies in the operation of the internal controls.
C) perform tests of controls to evaluate the effectiveness of the entity's accounting system.
D) determine whether control activities are operating effectively to prevent or detect material misstatements.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
43
Generally accepted auditing standards (GAAS)give auditors considerable discretion to decide the amount of work required to satisfy auditing standards guiding internal control evaluation and related audit planning.Which of the descriptions below best expresses the minimum amount of work permitted by GAAS for nonpublic companies?
A) Do not obtain an understanding of client environment, accounting, or control activities. Do not document the decision to assess control risk at maximum. Perform 100% substantive audit on all financial statement transactions and balances.
B) Obtain an understanding of client environment, accounting, and control activities. Document the decision to assess control risk at maximum. Perform an extensive but not 100% substantive audit on financial statement transactions and balances.
C) Obtain an understanding of client environment, accounting, and control activities, and perform detail tests of controls. Document the decision to assess control risk below the maximum. Perform restricted substantive audit on financial statement transactions and balances, considering the control risk assessment.
D) Obtain an understanding of client environment, accounting, and control activities, and perform detail tests of controls. Document the decision to assess control risk at zero. Perform no substantive audit on financial statement transactions and balances, since zero control risk means that no errors or fraud can reach the accounts.
A) Do not obtain an understanding of client environment, accounting, or control activities. Do not document the decision to assess control risk at maximum. Perform 100% substantive audit on all financial statement transactions and balances.
B) Obtain an understanding of client environment, accounting, and control activities. Document the decision to assess control risk at maximum. Perform an extensive but not 100% substantive audit on financial statement transactions and balances.
C) Obtain an understanding of client environment, accounting, and control activities, and perform detail tests of controls. Document the decision to assess control risk below the maximum. Perform restricted substantive audit on financial statement transactions and balances, considering the control risk assessment.
D) Obtain an understanding of client environment, accounting, and control activities, and perform detail tests of controls. Document the decision to assess control risk at zero. Perform no substantive audit on financial statement transactions and balances, since zero control risk means that no errors or fraud can reach the accounts.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
44
After obtaining an understanding of internal controls and assessing control risk on the audit of a non-public company,an auditor decided to perform tests of controls.The auditor most likely decided that
A) it would be efficient to perform tests of controls that would result in a reduction in planned substantive tests.
B) additional evidence to support a further reduction in control risk is not available.
C) an increase in the assessed level of control risk is justified for certain financial statement assertions.
D) there were many internal control weaknesses that could allow errors to enter the accounting system.
A) it would be efficient to perform tests of controls that would result in a reduction in planned substantive tests.
B) additional evidence to support a further reduction in control risk is not available.
C) an increase in the assessed level of control risk is justified for certain financial statement assertions.
D) there were many internal control weaknesses that could allow errors to enter the accounting system.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
45
Which of the following is a step in an auditor's decision to assess control risk at below the maximum?
A) Apply analytical procedures to both financial data and nonfinancial information to detect conditions that may indicate weak controls.
B) Perform tests of details of transactions and account balances to identify potential errors and fraud.
C) Identify specific internal control policies and activities that are likely to detect or prevent material misstatements.
D) Document that the additional audit effort to perform tests of controls exceeds the potential reduction in substantive testing.
A) Apply analytical procedures to both financial data and nonfinancial information to detect conditions that may indicate weak controls.
B) Perform tests of details of transactions and account balances to identify potential errors and fraud.
C) Identify specific internal control policies and activities that are likely to detect or prevent material misstatements.
D) Document that the additional audit effort to perform tests of controls exceeds the potential reduction in substantive testing.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
46
Which of the following areas can external auditors rely on internal auditors' work in auditing internal controls?
A) Evaluation of the auditing environment
B) Testing of low risk internal control activities
C) All testing of the operating effectiveness of internal control activities
D) As providing the principle evidence for the external auditors' opinion
A) Evaluation of the auditing environment
B) Testing of low risk internal control activities
C) All testing of the operating effectiveness of internal control activities
D) As providing the principle evidence for the external auditors' opinion
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
47
The overall attitude and awareness of an entity's board of directors concerning the importance of the client's internal control usually is reflected in its
A) computer-based control activities.
B) system of separation of duties.
C) control environment.
D) safeguards over access to assets.
A) computer-based control activities.
B) system of separation of duties.
C) control environment.
D) safeguards over access to assets.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
48
Management's report on internal controls must include each of the following except
A) a statement that management is responsible for establishing and maintaining adequate internal control over financial reporting.
B) a statement identifying the framework management uses to evaluate the effectiveness of the company's internal control.
C) a statement providing management's assessment of the effectiveness of the company's internal control.
D) a statement providing management's evaluation of the company's control environment.
A) a statement that management is responsible for establishing and maintaining adequate internal control over financial reporting.
B) a statement identifying the framework management uses to evaluate the effectiveness of the company's internal control.
C) a statement providing management's assessment of the effectiveness of the company's internal control.
D) a statement providing management's evaluation of the company's control environment.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
49
In testing control activities,an auditor ordinarily selects from a variety of techniques,including
A) inquiry and analytical procedures.
B) reperformance and observation.
C) comparison and confirmation.
D) inspection and verification.
A) inquiry and analytical procedures.
B) reperformance and observation.
C) comparison and confirmation.
D) inspection and verification.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
50
Assessing control risk at below the maximum level most likely would involve
A) performing more extensive substantive tests with larger sample sizes than originally planned.
B) reducing inherent risk for most of the assertions relevant to significant account balances.
C) changing the timing of substantive tests by omitting interim-date testing and performing the tests at year end.
D) identifying specific internal control activities that are relevant to specific financial statement assertions.
A) performing more extensive substantive tests with larger sample sizes than originally planned.
B) reducing inherent risk for most of the assertions relevant to significant account balances.
C) changing the timing of substantive tests by omitting interim-date testing and performing the tests at year end.
D) identifying specific internal control activities that are relevant to specific financial statement assertions.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
51
If a control total were to be computed on each of the following data items,which would best be identified as a hash total for a payroll IT application?
A) Hours worked
B) Total debits and total credits
C) Net pay
D) Department numbers
A) Hours worked
B) Total debits and total credits
C) Net pay
D) Department numbers
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
52
When auditing financial statements of a private company,the minimum work an auditor must perform in connection with a company's internal control is best described by which of the following statements.
A) Perform exhaustive tests of accounting controls and evaluate the company's control system effectiveness.
B) Determine whether the company's control policies are designed well enough to prevent material misstatements.
C) Prepare auditing working papers that document the auditor's understanding of the company's internal control.
D) Design procedures to search for significant deficiencies in the actual operation of the company's internal control.
A) Perform exhaustive tests of accounting controls and evaluate the company's control system effectiveness.
B) Determine whether the company's control policies are designed well enough to prevent material misstatements.
C) Prepare auditing working papers that document the auditor's understanding of the company's internal control.
D) Design procedures to search for significant deficiencies in the actual operation of the company's internal control.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
53
Which of the following most likely would not be considered an inherent limitation of the potential effectiveness of an entity's internal controls?
A) Incompatible duties
B) Management override
C) Mistakes in judgment
D) Collusion among employees
A) Incompatible duties
B) Management override
C) Mistakes in judgment
D) Collusion among employees
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
54
In an audit of financial statements,an auditor's primary consideration regarding an internal control policy or activity is whether the policy or activity
A) reflects management's philosophy and operating style.
B) affects management's financial statement assertions.
C) provides adequate safeguards over access to assets.
D) enhances management's decision making processes.
A) reflects management's philosophy and operating style.
B) affects management's financial statement assertions.
C) provides adequate safeguards over access to assets.
D) enhances management's decision making processes.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
55
A report on internal control effectiveness by the management team of public companies is required by
A) the Sarbanes-Oxley Act of 2002.
B) the PCAOB.
C) the AICPA.
D) the auditors.
A) the Sarbanes-Oxley Act of 2002.
B) the PCAOB.
C) the AICPA.
D) the auditors.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
56
Which of the following is not an objective of internal controls over financial reporting as defined by the Sarbanes-Oxley Act?
A) Policies and procedures that pertain to the maintenance of records that in reasonable detail accurately and fairly reflect the transactions and dispositions of the assets of the registrant.
B) Policies and procedures that provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and receipts and expenditures of the registrant are being made only in accordance with authorizations of management and directors of the registrant.
C) Policies and procedures that provide reasonable assurance regarding the compliance with applicable laws and regulations.
D) Policies and procedures that provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of the registrant's assets that could have a material effect on the financial statements.
A) Policies and procedures that pertain to the maintenance of records that in reasonable detail accurately and fairly reflect the transactions and dispositions of the assets of the registrant.
B) Policies and procedures that provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and receipts and expenditures of the registrant are being made only in accordance with authorizations of management and directors of the registrant.
C) Policies and procedures that provide reasonable assurance regarding the compliance with applicable laws and regulations.
D) Policies and procedures that provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of the registrant's assets that could have a material effect on the financial statements.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
57
Proper separation of duties reduces the opportunities to allow persons to be in positions to both
A) journalize entries and prepare financial statements.
B) record cash receipts and cash disbursements.
C) establish internal controls and authorize transactions.
D) perpetrate a fraud and then conceal it in the books.
A) journalize entries and prepare financial statements.
B) record cash receipts and cash disbursements.
C) establish internal controls and authorize transactions.
D) perpetrate a fraud and then conceal it in the books.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
58
Which of the following would most likely be classified as a material weakness?
A) Absence of appropriate separation of duties
B) Absence of appropriate reviews and approvals of transactions
C) Evidence of failure of control activities
D) Ineffective oversight of the financial reporting process by the company's audit committee
A) Absence of appropriate separation of duties
B) Absence of appropriate reviews and approvals of transactions
C) Evidence of failure of control activities
D) Ineffective oversight of the financial reporting process by the company's audit committee
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
59
As part of understanding the internal control,an auditor is not required to
A) consider factors that affect the risk of material misstatement.
B) ascertain whether internal control policies and activities have been placed in operation.
C) identify the types of potential misstatements that can occur.
D) obtain knowledge about the operating effectiveness of the client's internal control activities.
A) consider factors that affect the risk of material misstatement.
B) ascertain whether internal control policies and activities have been placed in operation.
C) identify the types of potential misstatements that can occur.
D) obtain knowledge about the operating effectiveness of the client's internal control activities.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
60
The primary objective of procedures performed to obtain an understanding of the entity's internal control is to provide an auditor with
A) knowledge necessary for audit planning.
B) evidential matter to use in assessing inherent risk.
C) a basis for modifying tests of controls.
D) an evaluation of the consistency of application of management's policies.
A) knowledge necessary for audit planning.
B) evidential matter to use in assessing inherent risk.
C) a basis for modifying tests of controls.
D) an evaluation of the consistency of application of management's policies.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
61
Explain the different opinions that auditors can issue for an entity's internal control over financial reporting.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
62
What constitutes a material weakness?
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
63
Auditors are required to obtain a sufficient understanding of an entity's internal control.This understanding is required by the performance principle of GAAS.
Required:
A.What are some of the goals (purposes)for conducting an evaluation of an entity's internal control?
B.What is the impact on substantive testing procedures if the auditor assesses control risk at the "maximum" level? What is the impact on substantive testing procedures if the auditor assesses control risk below the "maximum" level?
C.Should auditors always try to obtain enough evidence to assess control risk below the "maximum" level? Explain.
Required:
A.What are some of the goals (purposes)for conducting an evaluation of an entity's internal control?
B.What is the impact on substantive testing procedures if the auditor assesses control risk at the "maximum" level? What is the impact on substantive testing procedures if the auditor assesses control risk below the "maximum" level?
C.Should auditors always try to obtain enough evidence to assess control risk below the "maximum" level? Explain.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
64
List several elements of a company's control environment.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
65
What is the difference between a significant deficiency and a material weakness?
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
66
List and explain briefly the phases of an internal control evaluation.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
67
What is the difference between an internal control's design effectiveness and its operating effectiveness?
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
68
What are some of the problems in establishing an internal control system in small business?
A. Separation of functional responsibilities would be difficult because of the small number of employees.
B. The owner manager has to assume a greater role to oversee and supervise authorization, recordkeeping, and custodial functions.
C. The owner manager must be diligent, competent, and have a high degree of integrity.
A. Separation of functional responsibilities would be difficult because of the small number of employees.
B. The owner manager has to assume a greater role to oversee and supervise authorization, recordkeeping, and custodial functions.
C. The owner manager must be diligent, competent, and have a high degree of integrity.
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck
69
What are the six steps auditors of public companies should use to audit internal control over financial reporting (ICOFR)?
Unlock Deck
Unlock for access to all 69 flashcards in this deck.
Unlock Deck
k this deck