Deck 11: Internal Control and Coso Framework

Full screen (f)
exit full mode
Question
Two key concepts that underlie management's design and implementation of internal control are

A) costs and materiality.
B) absolute assurance and costs.
C) inherent limitations and reasonable assurance.
D) collusion and materiality.
Use Space or
up arrow
down arrow
to flip the card.
Question
Other countries around the world have passed similar legislation to the Sarbanes-Oxley Act regarding mandating management and auditor reporting on internal controls over financial reporting.
Question
Section 404 of the Sarbanes-Oxley Act requires that both private and public companies issue an internal control report.
Question
Describe each of the three broad objectives management typically has for internal control. With which of these objectives is the auditor primarily concerned?
Question
Internal controls are not designed to provide reasonable assurance that

A) all frauds will be detected.
B) transactions are executed in accordance with management's authorization.
C) the company's resources are used efficiently and effectively.
D) company personnel comply with applicable rules and regulations.
Question
Management has a legal and professional responsibility to be sure that the financial statements are prepared in accordance with reporting requirements of applicable accounting frameworks.
Question
Sarbanes-Oxley requires management to issue an internal control report that includes two specific items. Which of the following is one of these two requirements?

A) a statement that management is responsible for establishing and maintaining an adequate internal control structure and procedures for financial reporting
B) a statement that management and the board of directors are jointly responsible for establishing and maintaining an adequate internal control structure and procedures for financial reporting
C) a statement that management, the board of directors, and the external auditors are jointly responsible for establishing and maintaining an adequate internal control structure and procedures for financial reporting
D) a statement that the external auditors are solely responsible for establishing and maintaining an adequate system of internal control
Question
Internal controls

A) are implemented by and are the responsibility of the auditors.
B) consist of policies and procedures designed to provide reasonable assurance that the company achieves its objectives and goals.
C) guarantee that the company complies with all laws and regulations.
D) only apply to SEC companies.
Question
Who is responsible for establishing a private company's internal control?

A) senior management
B) internal auditors
C) FASB
D) audit committee
Question
One of management's broad objectives in designing an effective internal control system is to help ensure that the organization follows laws and regulations impacting the organization.
Question
A system of internal controls consisting of policies and procedures are designed to provide management with reasonable assurance that the company can achieve its goals and objectives.
Question
Management has a legal and a professional responsibility to be sure external financial information, and the information contained therein, are fairly presented in accordance with generally accepted accounting principles and International Financial Reporting Standards, when required.
Question
The PCAOB places responsibility for the reliability of internal controls over the financial reporting process on

A) the company's board of directors.
B) the audit committee of the board of directors.
C) management.
D) the CFO and the independent auditors.
Question
An act of two or more employees to steal assets and cover their theft by misstating the accounting records would be referred to as

A) collusion.
B) a material weakness.
C) a control deficiency.
D) a significant deficiency.
Question
Which of the following parties provides an assessment of the effectiveness of internal control over financial reporting for public companies?

A) <strong>Which of the following parties provides an assessment of the effectiveness of internal control over financial reporting for public companies?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
B) <strong>Which of the following parties provides an assessment of the effectiveness of internal control over financial reporting for public companies?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
C) <strong>Which of the following parties provides an assessment of the effectiveness of internal control over financial reporting for public companies?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
D) <strong>Which of the following parties provides an assessment of the effectiveness of internal control over financial reporting for public companies?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
Question
The Sarbanes-Oxley Act requires either management of U.S. public companies or their auditors to report on the effectiveness of internal controls over financial reporting.
Question
When management is evaluating the design of internal control, management evaluates whether the control can do which of the following?

A) <strong>When management is evaluating the design of internal control, management evaluates whether the control can do which of the following?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
B) <strong>When management is evaluating the design of internal control, management evaluates whether the control can do which of the following?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
C) <strong>When management is evaluating the design of internal control, management evaluates whether the control can do which of the following?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
D) <strong>When management is evaluating the design of internal control, management evaluates whether the control can do which of the following?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
Question
Deficiencies in internal controls may cause significant losses, delay financial reporting, but cannot result in material misstatements in the financial statements.
Question
With which of management's assertions with respect to implementing internal controls is the auditor primarily concerned?

A) efficiency of operations
B) reliability of financial reporting
C) effectiveness of operations
D) compliance with applicable laws and regulations
Question
Which of the following is not one of the three primary objectives of effective internal control?

A) reliability of financial reporting
B) efficiency and effectiveness of operations
C) compliance with laws and regulations
D) assurance of elimination of business risk
Question
The auditor's primary purpose in auditing the client's system of internal control over financial reporting is

A) to prevent fraudulent financial statements from being issued to the public.
B) to evaluate the effectiveness of the company's internal controls over all relevant assertions in the financial statements.
C) to report to management that the internal controls are effective in preventing misstatements from appearing on the financial statements.
D) to efficiently conduct the Audit of Financial Statements.
Question
The internal control framework used by most U.S. companies is the ________ framework.

A) FASB
B) PCAOB
C) COSO
D) SEC
Question
Management's report on internal controls must identify the framework used to evaluate the effectiveness of internal controls, and this framework may include other internal control frameworks which exist around the world.
Question
An auditor should consider two key issues when obtaining an understanding of a client's internal controls. These issues are

A) the effectiveness and efficiency of the controls.
B) the frequency and effectiveness of the controls.
C) the design and operating effectiveness of the controls.
D) the implementation and operating effectiveness of the controls.
Question
Which of the following is most correct regarding the requirements under Section 404 of the Sarbanes-Oxley Act?

A) The audits of internal control and the financial statements provide reasonable assurance as to misstatements.
B) The audit of internal control provides absolute assurance of misstatement.
C) The audit of financial statements provides absolute assurance of misstatement.
D) The audits of internal control and the financial statements provide absolute assurance as to misstatements.
Question
Which of the following is an accurate statement regarding the auditor's responsibility for understanding internal control?

A) Transaction-related audit objectives typically have no impact on the rights and obligations objectives.
B) Transaction-related audit objectives typically have a significant impact on the balance-related audit objective of realizable value.
C) Auditors generally emphasize internal control over account balances rather than classes of transactions.
D) Auditors and management are both equally concerned about controls that affect the efficiency and effectiveness of company operations.
Question
Under the Dodd-Frank federal financial reform legislation, all public companies are required to obtain an audit report on internal control over financial reporting.
Question
Of the following statements about internal controls, which one is least likely to be correct?

A) No one person should be responsible for the custodial responsibility and the recording responsibility for an asset.
B) Transactions must be properly authorized before such transactions are processed.
C) Because of the cost-benefit relationship, a client may apply controls on a test basis.
D) Control procedures reasonably ensure that collusion among employees cannot occur.
Question
In performing the audit of internal control over financial reporting, the auditor emphasizes internal control over classes of transactions because

A) the accuracy of accounting system outputs depends heavily on the accuracy of inputs and processing.
B) the class of transaction is where most fraud schemes occur.
C) account balances are less important to the auditor then the changes in the account balances.
D) classes of transactions tests are the most efficient manner to compensate for inherent risk.
Question
When one material weakness is present at the end of the year, management of a public company must conclude that internal control over financial reporting is

A) insufficient.
B) inadequate.
C) ineffective.
D) inefficient.
Question
It is possible for management to design an ideal and effective system of internal controls for example over the counting of the physical inventory.
Question
Reasonable assurance allows for

A) low likelihood that material misstatements will not be prevented or detected by internal controls.
B) no likelihood that material misstatements will not be prevented or detected by internal control.
C) moderate likelihood that material misstatements will not be prevented or detected by internal control.
D) high likelihood that material misstatements will not be prevented or detected by internal control.
Question
The auditor's responsibilities for internal control include understanding and testing the audit client's internal controls over financial reporting.
Question
When a company designs and implements internal controls, the cost of the controls is not a valid consideration.
Question
Internal controls can never be regarded as completely effective. Even if company personnel could design an ideal system, its effectiveness depends on the

A) adequacy of the computer system.
B) proper implementation by management.
C) ability of the internal audit staff to maintain it.
D) competency and dependability of the people using it.
Question
The primary emphasis by auditors is on controls over

A) classes of transactions.
B) account balances.
C) both A and B, because they are equally important.
D) both A and B, because they vary from client to client.
Question
Two key concepts underlie management's design and implementation of internal controls are absolute assurance and inherent limitations.
Question
When considering internal controls,

A) auditors can ignore controls affecting internal management information.
B) auditors are concerned with the client's internal controls over the safeguarding of assets if they affect the financial statements.
C) management is responsible for understanding and testing internal control over financial reporting.
D) companies must use the COSO framework to establish internal controls.
Question
If required under special circumstances, an auditor must step in at an audit client and establish and maintain the audit client's system of internal controls to ensure reliable financial reporting.
Question
The Sarbanes-Oxley Act requires

A) all public companies to issue reports on internal controls.
B) all public companies to define adequate internal controls.
C) the auditor of public companies to design effective internal controls.
D) the auditor of public companies to withdraw from an engagement if internal controls are weak.
Question
It is important for the CPA to consider the competence of the clients' personnel because their competence has a direct impact upon the

A) cost/benefit relationship of the system of internal control.
B) achievement of the objectives of internal control.
C) comparison of recorded accountability with assets.
D) timing of the tests to be performed.
Question
Which of the following deals with ongoing or periodic assessment of the quality of internal control by management?

A) verifying activities
B) monitoring activities
C) oversight activities
D) management activities
Question
Which of the following best describes the purpose of control activities?

A) the actions, policies and procedures that reflect the overall attitudes of management
B) the identification and analysis of risks relevant to the preparation of financial statements
C) the policies and procedures that help ensure that necessary actions are taken to address risks to the achievement of the entity's objectives
D) activities that deal with the ongoing assessment of the quality of internal control by management
Question
Once the auditor is satisfied with the transaction-related controls in the revenue and accounts receivable area, it is not important for the auditor to gain an understanding of the controls that exist over the ending account balances and the related disclosures made in the financial statements.
Question
Which of the following best describes an entity's accounting information and communication system?

A) <strong>Which of the following best describes an entity's accounting information and communication system?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
B) <strong>Which of the following best describes an entity's accounting information and communication system?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
C) <strong>Which of the following best describes an entity's accounting information and communication system?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
D) <strong>Which of the following best describes an entity's accounting information and communication system?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
Question
Proper segregation of functional responsibilities calls for separation of

A) authorization, execution, and payment.
B) authorization, recording, and custody.
C) custody, execution, and reporting.
D) authorization, payment, and recording.
Question
The auditor is always concerned with their audit client's controls that affect the efficiency and the effectiveness of company operations, as these controls will always influence the fair presentation of the financial statements.
Question
Without an effective ________, the other components of the COSO framework are unlikely to result in effective internal control, regardless of their quality.

A) risk assessment policy
B) monitoring policy
C) control environment
D) system of control activities
Question
It is possible, under certain circumstances, for financial statements to correctly reflect GAAP or IFRS even if internal controls over financial reporting are inadequate.
Question
Which of the following is a risk assessment principle?

A) accountability
B) use relevant, quality information to support the functioning of internal controls
C) consider the potential for fraud
D) develop general controls over technology
Question
Which of the following components of the control environment define the existing lines of responsibility and authority?

A) organizational structure
B) management philosophy and operating style
C) human resource policies and practices
D) management integrity and ethical values
Question
As a result of the Dodd-Frank federal financial reform legislation passed by Congress in 2010, only larger public companies (accelerated filers) are now required to obtain an audit report from their auditors on internal control over financial reporting.
Question
Which of the following is correct with respect to the design and use of business documents?

A) The documents should be in paper format.
B) Documents should be designed for a single purpose to avoid confusion in their use.
C) Documents should be designed to be understandable only by those who use them.
D) Documents should be prenumbered consecutively to facilitate control over missing documents.
Question
Which of the following is not an underlying principle related to risk assessment?

A) The organization should have clear objectives in order to be able to identify and assess the risks relating to the objectives.
B) The auditors should determine how the company's risks should be managed.
C) The organization should consider the potential for fraudulent behavior.
D) The organization should monitor changes that could impact internal controls.
Question
Authorizations can be either general or specific. Which of the following is not an example of a general authorization?

A) automatic reorder points for raw materials inventory
B) a sales manager's authorization for a sales return
C) credit limits for various classes of customers
D) a sales price list for merchandise
Question
Which of the following factors may increase risks to an organization?

A) <strong>Which of the following factors may increase risks to an organization?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
B) <strong>Which of the following factors may increase risks to an organization?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
C) <strong>Which of the following factors may increase risks to an organization?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
D) <strong>Which of the following factors may increase risks to an organization?</strong> A)   B)   C)   D)   <div style=padding-top: 35px>
Question
Which of the following activities would be least likely to strengthen a company's internal control?

A) separating accounting from other financial operations
B) maintaining insurance for fire and theft
C) fixing responsibility for the performance of employee duties
D) carefully selecting and training employees
Question
Which of the following is an accurate statement regarding control activities?

A) As the level of complexity of IT systems increases, the separation of duties often becomes blurred.
B) Segregation of duties would be violated if the same person authorizes the payment of a vendor's invoice and also approves the disbursement of funds to pay the bill.
C) The most important type of protective measure for safeguarding assets and records is the use of physical precautions.
D) All of the above.
Question
Which of the following statements is most correct with respect to separation of duties?

A) A person who has temporary or permanent custody of an asset should account for that asset.
B) Employees who authorize transactions should not have custody of the related assets.
C) Employees who open cash receipts should record the amounts in the subsidiary ledgers.
D) Employees who authorize transactions should have recording responsibility for these transactions.
Question
Which of the following is not one of the subcomponents of the control environment?

A) management's philosophy and operating style
B) organizational structure
C) adequate separation of duties
D) commitment to competence
Question
If an auditor wishes to rely on the work of internal auditors (IA), the auditor must obtain satisfactory evidence related to the IA's competence, integrity, and objectivity.
Question
The COSO framework, updated in 2013, provides a rules-based approach that provides additional guidance on designing and implementing an effective system of internal controls.
Question
The ________ is helpful in preventing classification errors if it accurately describes which type of transaction should be in each account.

A) general ledger
B) general journal
C) trial balance
D) chart of accounts
Question
Adequate documents and records are a subcomponent of the control environment.
Question
If a company has an effective internal audit department,

A) the internal auditors can express an opinion on the fairness of the financial statements.
B) their work cannot be used by the external auditors per PCAOB Standard 5.
C) it can reduce external audit costs by providing direct assistance to the external auditors.
D) the internal auditors must be CPAs in order for the external auditors to rely on their work.
Question
A small business has four employees, including the owner of the business, working for the business on a daily basis processing cash receipts, making cash disbursements, processing payroll, and invoicing customers. In this situation, separation of duties is impossible.
Question
The company forms a committee to identify specific risks inside of the company related to information technology. As shown in the COSO cube, this action is related to organizational structure.
Question
The audit committee of the board of directors must exercise oversight over the design and the performance of internal controls over financial reporting, as well as not delegating the responsibilities for these internal controls to management.
Question
External financial statement auditors must obtain evidence regarding what attributes of an internal audit (IA) department if the external auditors intend to rely on IA's work?

A) integrity
B) objectivity
C) competence
D) all of the above
Question
Personnel responsible for performing internal verification procedures must be independent of those originally responsible for preparing the data.
Question
Control activities are a subcomponent of the information and communication component of internal control.
Question
Certain principles dictate the proper design and use of documents and records. Briefly describe several of these principles.
Question
To promote operational efficiency, the internal audit department would ideally report to

A) line management.
B) the PCAOB.
C) the Chief Accounting Officer.
D) the audit committee.
Question
The chart of accounts is helpful in preventing classification errors if it accurately describes which type of transaction should be in each account.
Question
An example of a specific authorization is management setting a policy authorizing the ordering of inventory when less than a one-week supply is on hand.
Question
Auditing standards prohibit reliance on the work of internal auditors due to the lack of independence of the internal auditors.
Question
To obtain an understanding of an entity's control environment, an auditor should concentrate on the substance of management's policies and procedures rather than their form because

A) management may establish appropriate policies and procedures but not act on them.
B) the board of directors may not be aware of management's attitude toward the control environment.
C) the auditor may believe that the policies and procedures are inappropriate for that particular entity.
D) the policies and procedures may be so weak that no reliance is contemplated by the auditor.
Question
Control activities help assure that the necessary actions are taken to address risks to the achievement of the company's objectives. List the five types of control activities.
Question
Even without an effective control environment, it is likely that the other four components of the COSO framework can result in effective internal controls.
Question
Hanlon Corp. maintains a large internal audit staff that reports directly to the accounting department. Audit reports prepared by the internal auditors indicate that the system is functioning as it should and that the accounting records are reliable. An independent auditor will probably

A) eliminate tests of controls.
B) increase the depth of the study and evaluation of administrative controls.
C) avoid duplicating the work performed by the internal audit staff.
D) place limited reliance on the work performed by the internal audit staff.
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/152
auto play flashcards
Play
simple tutorial
Full screen (f)
exit full mode
Deck 11: Internal Control and Coso Framework
1
Two key concepts that underlie management's design and implementation of internal control are

A) costs and materiality.
B) absolute assurance and costs.
C) inherent limitations and reasonable assurance.
D) collusion and materiality.
C
2
Other countries around the world have passed similar legislation to the Sarbanes-Oxley Act regarding mandating management and auditor reporting on internal controls over financial reporting.
True
3
Section 404 of the Sarbanes-Oxley Act requires that both private and public companies issue an internal control report.
False
4
Describe each of the three broad objectives management typically has for internal control. With which of these objectives is the auditor primarily concerned?
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
5
Internal controls are not designed to provide reasonable assurance that

A) all frauds will be detected.
B) transactions are executed in accordance with management's authorization.
C) the company's resources are used efficiently and effectively.
D) company personnel comply with applicable rules and regulations.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
6
Management has a legal and professional responsibility to be sure that the financial statements are prepared in accordance with reporting requirements of applicable accounting frameworks.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
7
Sarbanes-Oxley requires management to issue an internal control report that includes two specific items. Which of the following is one of these two requirements?

A) a statement that management is responsible for establishing and maintaining an adequate internal control structure and procedures for financial reporting
B) a statement that management and the board of directors are jointly responsible for establishing and maintaining an adequate internal control structure and procedures for financial reporting
C) a statement that management, the board of directors, and the external auditors are jointly responsible for establishing and maintaining an adequate internal control structure and procedures for financial reporting
D) a statement that the external auditors are solely responsible for establishing and maintaining an adequate system of internal control
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
8
Internal controls

A) are implemented by and are the responsibility of the auditors.
B) consist of policies and procedures designed to provide reasonable assurance that the company achieves its objectives and goals.
C) guarantee that the company complies with all laws and regulations.
D) only apply to SEC companies.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
9
Who is responsible for establishing a private company's internal control?

A) senior management
B) internal auditors
C) FASB
D) audit committee
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
10
One of management's broad objectives in designing an effective internal control system is to help ensure that the organization follows laws and regulations impacting the organization.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
11
A system of internal controls consisting of policies and procedures are designed to provide management with reasonable assurance that the company can achieve its goals and objectives.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
12
Management has a legal and a professional responsibility to be sure external financial information, and the information contained therein, are fairly presented in accordance with generally accepted accounting principles and International Financial Reporting Standards, when required.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
13
The PCAOB places responsibility for the reliability of internal controls over the financial reporting process on

A) the company's board of directors.
B) the audit committee of the board of directors.
C) management.
D) the CFO and the independent auditors.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
14
An act of two or more employees to steal assets and cover their theft by misstating the accounting records would be referred to as

A) collusion.
B) a material weakness.
C) a control deficiency.
D) a significant deficiency.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
15
Which of the following parties provides an assessment of the effectiveness of internal control over financial reporting for public companies?

A) <strong>Which of the following parties provides an assessment of the effectiveness of internal control over financial reporting for public companies?</strong> A)   B)   C)   D)
B) <strong>Which of the following parties provides an assessment of the effectiveness of internal control over financial reporting for public companies?</strong> A)   B)   C)   D)
C) <strong>Which of the following parties provides an assessment of the effectiveness of internal control over financial reporting for public companies?</strong> A)   B)   C)   D)
D) <strong>Which of the following parties provides an assessment of the effectiveness of internal control over financial reporting for public companies?</strong> A)   B)   C)   D)
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
16
The Sarbanes-Oxley Act requires either management of U.S. public companies or their auditors to report on the effectiveness of internal controls over financial reporting.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
17
When management is evaluating the design of internal control, management evaluates whether the control can do which of the following?

A) <strong>When management is evaluating the design of internal control, management evaluates whether the control can do which of the following?</strong> A)   B)   C)   D)
B) <strong>When management is evaluating the design of internal control, management evaluates whether the control can do which of the following?</strong> A)   B)   C)   D)
C) <strong>When management is evaluating the design of internal control, management evaluates whether the control can do which of the following?</strong> A)   B)   C)   D)
D) <strong>When management is evaluating the design of internal control, management evaluates whether the control can do which of the following?</strong> A)   B)   C)   D)
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
18
Deficiencies in internal controls may cause significant losses, delay financial reporting, but cannot result in material misstatements in the financial statements.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
19
With which of management's assertions with respect to implementing internal controls is the auditor primarily concerned?

A) efficiency of operations
B) reliability of financial reporting
C) effectiveness of operations
D) compliance with applicable laws and regulations
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
20
Which of the following is not one of the three primary objectives of effective internal control?

A) reliability of financial reporting
B) efficiency and effectiveness of operations
C) compliance with laws and regulations
D) assurance of elimination of business risk
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
21
The auditor's primary purpose in auditing the client's system of internal control over financial reporting is

A) to prevent fraudulent financial statements from being issued to the public.
B) to evaluate the effectiveness of the company's internal controls over all relevant assertions in the financial statements.
C) to report to management that the internal controls are effective in preventing misstatements from appearing on the financial statements.
D) to efficiently conduct the Audit of Financial Statements.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
22
The internal control framework used by most U.S. companies is the ________ framework.

A) FASB
B) PCAOB
C) COSO
D) SEC
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
23
Management's report on internal controls must identify the framework used to evaluate the effectiveness of internal controls, and this framework may include other internal control frameworks which exist around the world.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
24
An auditor should consider two key issues when obtaining an understanding of a client's internal controls. These issues are

A) the effectiveness and efficiency of the controls.
B) the frequency and effectiveness of the controls.
C) the design and operating effectiveness of the controls.
D) the implementation and operating effectiveness of the controls.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
25
Which of the following is most correct regarding the requirements under Section 404 of the Sarbanes-Oxley Act?

A) The audits of internal control and the financial statements provide reasonable assurance as to misstatements.
B) The audit of internal control provides absolute assurance of misstatement.
C) The audit of financial statements provides absolute assurance of misstatement.
D) The audits of internal control and the financial statements provide absolute assurance as to misstatements.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
26
Which of the following is an accurate statement regarding the auditor's responsibility for understanding internal control?

A) Transaction-related audit objectives typically have no impact on the rights and obligations objectives.
B) Transaction-related audit objectives typically have a significant impact on the balance-related audit objective of realizable value.
C) Auditors generally emphasize internal control over account balances rather than classes of transactions.
D) Auditors and management are both equally concerned about controls that affect the efficiency and effectiveness of company operations.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
27
Under the Dodd-Frank federal financial reform legislation, all public companies are required to obtain an audit report on internal control over financial reporting.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
28
Of the following statements about internal controls, which one is least likely to be correct?

A) No one person should be responsible for the custodial responsibility and the recording responsibility for an asset.
B) Transactions must be properly authorized before such transactions are processed.
C) Because of the cost-benefit relationship, a client may apply controls on a test basis.
D) Control procedures reasonably ensure that collusion among employees cannot occur.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
29
In performing the audit of internal control over financial reporting, the auditor emphasizes internal control over classes of transactions because

A) the accuracy of accounting system outputs depends heavily on the accuracy of inputs and processing.
B) the class of transaction is where most fraud schemes occur.
C) account balances are less important to the auditor then the changes in the account balances.
D) classes of transactions tests are the most efficient manner to compensate for inherent risk.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
30
When one material weakness is present at the end of the year, management of a public company must conclude that internal control over financial reporting is

A) insufficient.
B) inadequate.
C) ineffective.
D) inefficient.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
31
It is possible for management to design an ideal and effective system of internal controls for example over the counting of the physical inventory.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
32
Reasonable assurance allows for

A) low likelihood that material misstatements will not be prevented or detected by internal controls.
B) no likelihood that material misstatements will not be prevented or detected by internal control.
C) moderate likelihood that material misstatements will not be prevented or detected by internal control.
D) high likelihood that material misstatements will not be prevented or detected by internal control.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
33
The auditor's responsibilities for internal control include understanding and testing the audit client's internal controls over financial reporting.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
34
When a company designs and implements internal controls, the cost of the controls is not a valid consideration.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
35
Internal controls can never be regarded as completely effective. Even if company personnel could design an ideal system, its effectiveness depends on the

A) adequacy of the computer system.
B) proper implementation by management.
C) ability of the internal audit staff to maintain it.
D) competency and dependability of the people using it.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
36
The primary emphasis by auditors is on controls over

A) classes of transactions.
B) account balances.
C) both A and B, because they are equally important.
D) both A and B, because they vary from client to client.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
37
Two key concepts underlie management's design and implementation of internal controls are absolute assurance and inherent limitations.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
38
When considering internal controls,

A) auditors can ignore controls affecting internal management information.
B) auditors are concerned with the client's internal controls over the safeguarding of assets if they affect the financial statements.
C) management is responsible for understanding and testing internal control over financial reporting.
D) companies must use the COSO framework to establish internal controls.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
39
If required under special circumstances, an auditor must step in at an audit client and establish and maintain the audit client's system of internal controls to ensure reliable financial reporting.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
40
The Sarbanes-Oxley Act requires

A) all public companies to issue reports on internal controls.
B) all public companies to define adequate internal controls.
C) the auditor of public companies to design effective internal controls.
D) the auditor of public companies to withdraw from an engagement if internal controls are weak.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
41
It is important for the CPA to consider the competence of the clients' personnel because their competence has a direct impact upon the

A) cost/benefit relationship of the system of internal control.
B) achievement of the objectives of internal control.
C) comparison of recorded accountability with assets.
D) timing of the tests to be performed.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
42
Which of the following deals with ongoing or periodic assessment of the quality of internal control by management?

A) verifying activities
B) monitoring activities
C) oversight activities
D) management activities
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
43
Which of the following best describes the purpose of control activities?

A) the actions, policies and procedures that reflect the overall attitudes of management
B) the identification and analysis of risks relevant to the preparation of financial statements
C) the policies and procedures that help ensure that necessary actions are taken to address risks to the achievement of the entity's objectives
D) activities that deal with the ongoing assessment of the quality of internal control by management
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
44
Once the auditor is satisfied with the transaction-related controls in the revenue and accounts receivable area, it is not important for the auditor to gain an understanding of the controls that exist over the ending account balances and the related disclosures made in the financial statements.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
45
Which of the following best describes an entity's accounting information and communication system?

A) <strong>Which of the following best describes an entity's accounting information and communication system?</strong> A)   B)   C)   D)
B) <strong>Which of the following best describes an entity's accounting information and communication system?</strong> A)   B)   C)   D)
C) <strong>Which of the following best describes an entity's accounting information and communication system?</strong> A)   B)   C)   D)
D) <strong>Which of the following best describes an entity's accounting information and communication system?</strong> A)   B)   C)   D)
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
46
Proper segregation of functional responsibilities calls for separation of

A) authorization, execution, and payment.
B) authorization, recording, and custody.
C) custody, execution, and reporting.
D) authorization, payment, and recording.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
47
The auditor is always concerned with their audit client's controls that affect the efficiency and the effectiveness of company operations, as these controls will always influence the fair presentation of the financial statements.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
48
Without an effective ________, the other components of the COSO framework are unlikely to result in effective internal control, regardless of their quality.

A) risk assessment policy
B) monitoring policy
C) control environment
D) system of control activities
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
49
It is possible, under certain circumstances, for financial statements to correctly reflect GAAP or IFRS even if internal controls over financial reporting are inadequate.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
50
Which of the following is a risk assessment principle?

A) accountability
B) use relevant, quality information to support the functioning of internal controls
C) consider the potential for fraud
D) develop general controls over technology
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
51
Which of the following components of the control environment define the existing lines of responsibility and authority?

A) organizational structure
B) management philosophy and operating style
C) human resource policies and practices
D) management integrity and ethical values
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
52
As a result of the Dodd-Frank federal financial reform legislation passed by Congress in 2010, only larger public companies (accelerated filers) are now required to obtain an audit report from their auditors on internal control over financial reporting.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
53
Which of the following is correct with respect to the design and use of business documents?

A) The documents should be in paper format.
B) Documents should be designed for a single purpose to avoid confusion in their use.
C) Documents should be designed to be understandable only by those who use them.
D) Documents should be prenumbered consecutively to facilitate control over missing documents.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
54
Which of the following is not an underlying principle related to risk assessment?

A) The organization should have clear objectives in order to be able to identify and assess the risks relating to the objectives.
B) The auditors should determine how the company's risks should be managed.
C) The organization should consider the potential for fraudulent behavior.
D) The organization should monitor changes that could impact internal controls.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
55
Authorizations can be either general or specific. Which of the following is not an example of a general authorization?

A) automatic reorder points for raw materials inventory
B) a sales manager's authorization for a sales return
C) credit limits for various classes of customers
D) a sales price list for merchandise
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
56
Which of the following factors may increase risks to an organization?

A) <strong>Which of the following factors may increase risks to an organization?</strong> A)   B)   C)   D)
B) <strong>Which of the following factors may increase risks to an organization?</strong> A)   B)   C)   D)
C) <strong>Which of the following factors may increase risks to an organization?</strong> A)   B)   C)   D)
D) <strong>Which of the following factors may increase risks to an organization?</strong> A)   B)   C)   D)
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
57
Which of the following activities would be least likely to strengthen a company's internal control?

A) separating accounting from other financial operations
B) maintaining insurance for fire and theft
C) fixing responsibility for the performance of employee duties
D) carefully selecting and training employees
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
58
Which of the following is an accurate statement regarding control activities?

A) As the level of complexity of IT systems increases, the separation of duties often becomes blurred.
B) Segregation of duties would be violated if the same person authorizes the payment of a vendor's invoice and also approves the disbursement of funds to pay the bill.
C) The most important type of protective measure for safeguarding assets and records is the use of physical precautions.
D) All of the above.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
59
Which of the following statements is most correct with respect to separation of duties?

A) A person who has temporary or permanent custody of an asset should account for that asset.
B) Employees who authorize transactions should not have custody of the related assets.
C) Employees who open cash receipts should record the amounts in the subsidiary ledgers.
D) Employees who authorize transactions should have recording responsibility for these transactions.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
60
Which of the following is not one of the subcomponents of the control environment?

A) management's philosophy and operating style
B) organizational structure
C) adequate separation of duties
D) commitment to competence
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
61
If an auditor wishes to rely on the work of internal auditors (IA), the auditor must obtain satisfactory evidence related to the IA's competence, integrity, and objectivity.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
62
The COSO framework, updated in 2013, provides a rules-based approach that provides additional guidance on designing and implementing an effective system of internal controls.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
63
The ________ is helpful in preventing classification errors if it accurately describes which type of transaction should be in each account.

A) general ledger
B) general journal
C) trial balance
D) chart of accounts
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
64
Adequate documents and records are a subcomponent of the control environment.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
65
If a company has an effective internal audit department,

A) the internal auditors can express an opinion on the fairness of the financial statements.
B) their work cannot be used by the external auditors per PCAOB Standard 5.
C) it can reduce external audit costs by providing direct assistance to the external auditors.
D) the internal auditors must be CPAs in order for the external auditors to rely on their work.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
66
A small business has four employees, including the owner of the business, working for the business on a daily basis processing cash receipts, making cash disbursements, processing payroll, and invoicing customers. In this situation, separation of duties is impossible.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
67
The company forms a committee to identify specific risks inside of the company related to information technology. As shown in the COSO cube, this action is related to organizational structure.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
68
The audit committee of the board of directors must exercise oversight over the design and the performance of internal controls over financial reporting, as well as not delegating the responsibilities for these internal controls to management.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
69
External financial statement auditors must obtain evidence regarding what attributes of an internal audit (IA) department if the external auditors intend to rely on IA's work?

A) integrity
B) objectivity
C) competence
D) all of the above
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
70
Personnel responsible for performing internal verification procedures must be independent of those originally responsible for preparing the data.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
71
Control activities are a subcomponent of the information and communication component of internal control.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
72
Certain principles dictate the proper design and use of documents and records. Briefly describe several of these principles.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
73
To promote operational efficiency, the internal audit department would ideally report to

A) line management.
B) the PCAOB.
C) the Chief Accounting Officer.
D) the audit committee.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
74
The chart of accounts is helpful in preventing classification errors if it accurately describes which type of transaction should be in each account.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
75
An example of a specific authorization is management setting a policy authorizing the ordering of inventory when less than a one-week supply is on hand.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
76
Auditing standards prohibit reliance on the work of internal auditors due to the lack of independence of the internal auditors.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
77
To obtain an understanding of an entity's control environment, an auditor should concentrate on the substance of management's policies and procedures rather than their form because

A) management may establish appropriate policies and procedures but not act on them.
B) the board of directors may not be aware of management's attitude toward the control environment.
C) the auditor may believe that the policies and procedures are inappropriate for that particular entity.
D) the policies and procedures may be so weak that no reliance is contemplated by the auditor.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
78
Control activities help assure that the necessary actions are taken to address risks to the achievement of the company's objectives. List the five types of control activities.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
79
Even without an effective control environment, it is likely that the other four components of the COSO framework can result in effective internal controls.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
80
Hanlon Corp. maintains a large internal audit staff that reports directly to the accounting department. Audit reports prepared by the internal auditors indicate that the system is functioning as it should and that the accounting records are reliable. An independent auditor will probably

A) eliminate tests of controls.
B) increase the depth of the study and evaluation of administrative controls.
C) avoid duplicating the work performed by the internal audit staff.
D) place limited reliance on the work performed by the internal audit staff.
Unlock Deck
Unlock for access to all 152 flashcards in this deck.
Unlock Deck
k this deck
locked card icon
Unlock Deck
Unlock for access to all 152 flashcards in this deck.