2: Assurance Engagements Flashcards

1
Q

Define assurance services.

A

Assurance services are an objective examination of evidence for the purpose of providing an independent assessment on governance, risk management, and control processes for the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the types of assurance services?

A

Financial
Compliance
Operational
IT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Define compliance assurance.

A

Compliance assurance is the review of financial and operating controls to assess conformance with established laws, standards, regulations, policies, plans, procedures, contracts, and other requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Define operational assurance.

A

Operational assurance is the review of a function or process to appraise the efficiency and economy of operations and their effectiveness.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

According to COSO, what process is designed to provide reasonable assurance regarding the achievement of objectives?

A

Internal control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

List the three parties involved in an assurance engagement.

A

Responsible party or auditee
Users
Practitioner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the basic philosophy of Control Self-Assessment?

A

Control is the responsibility of everyone in the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

________ should oversee the processes of risk management and control.

A

Senior management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

List some benefits of a control self-assessment (CSA) program.

A

A CSA program
Augments the traditional role of the internal audit activity (IAA),
Assists management in risk management and control processes,
Allows the IAA and business units to collaborate to produce better information,
May reduce efforts in gathering information and testing of control processes, and
Increases coverage of assessments of control processes across the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the three primary approaches of control self-assessment programs?

A

Workshop facilitation
Survey/questionnaire
Self-certification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the different formats and focuses of the facilitation approach?

A

Format
Objective-based: The best way to accomplish a business objective
Risk-based: Listing risks to achieve objective(s)
Control-based: How well the controls in place are working
Process-based: Selected activities that are elements of a chain of processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Who provides varying degrees of assurance about the state of effectiveness of the risk management and control processes of the organization?

A

Internal and external auditors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

List examples of external business relationships.

A

Service providers
Supply-side partners
Demand-side partners
Strategic alliances
Joint ventures
Intellectual property partners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

List examples of significant risks of external business relationships (EBRs).

A

Risks may not be identified, managed, assessed, or monitored.
EBRs may adversely affect the organization’s reputation.
EBRs may have inadequate insurance coverage.
Service levels or products may be unsatisfactory.
Conflicts of interest may arise.
Licensing of intellectual property may result in misuse, theft, or loss of revenue.
The organization may be overcharged for services.
The EBR partner may become insolvent.
The organization’s confidential information may be lost.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is contract auditing?

A

An engagement to monitor and evaluate significant
Construction contracts and
Operating contracts that involve the provision of goods or services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Typical contracts subject to audit include

A

Lump-sum contracts,
Cost-plus contracts, and
Unit-price contracts.

17
Q

The internal audit activity helps management and the board ___[1]___, ___[2]___, and ___[3]___ risks, including reputation and economic risks.

A

1.Identify
2.Assess
3.Manage

18
Q

Explain the traditional vs. the modern views of quality.

A

The traditional view emphasizes detection of products that do not meet standards. The modern view is that quality is a value-added activity performed throughout all business processes.

19
Q

Total Quality Management is the continuous pursuit of quality in every aspect of organizational activities through

A

A philosophy of doing it right the first time,
Employee training and empowerment,
Promotion of teamwork,
Improvement of processes, and
Attention to satisfaction of internal and external customers.

20
Q

What is the internal audit activity’s role as it relates to quality auditing?

A

To provide assurance that the approved quality structures are in place and quality processes are functioning as intended.

21
Q

Quality is best viewed from what perspectives?

A

Attributes of the product (performance, serviceability, durability, etc.)
Customer satisfaction
Conformity with manufacturing specifications
Value (relation of quality and price)

22
Q

The internal audit activity performs procedures to provide assurance that what basic quality management objectives are reached?

A

Customer satisfaction
Continuous improvement
Promotion of teamwork

23
Q

What do privacy engagements address?

A

Security of personal information, especially information stored in computer systems.

24
Q

Information reliability and integrity includes

A

Accuracy
Completeness
Security

25
Q

List the elements of privacy.

A

Personal privacy (physical and psychological)
Privacy of space (freedom from surveillance)
Privacy of communication (freedom from monitoring)
Privacy of information (collection, use, and disclosure of personal information by others)

26
Q

Assurance about the organization’s key performance indicators is assessed through what type of audit?

A

Performance auditing.

27
Q

What is a balanced scorecard?

A

A report that connects critical success factors with financial and nonfinancial measures.

28
Q

What four categories or measures are found on a typical balanced scorecard?

A

1.Financial
2.Customer
3.Internal
4.Learning, growth, and innovation

29
Q

Identifying critical success factors by analyzing internal and external factors is called

A

SWOT analysis.

30
Q

Performance audit engagements involve review of

A

The business,
Control environment, and
Key performance indicators against established criteria.

31
Q

An operational audit assesses the

A

Efficiency and effectiveness of an organization’s operations.

32
Q

What are process (functional) engagements?

A

Operational audit engagements that follow process-crossing organizational lines, service units, and geographical locations.

33
Q

_____________ programs assist organizations in preventing unintended employee violations, detecting illegal acts, and discouraging intentional employee violations.

A

Compliance.

34
Q

The chief compliance officer should report directly to

A

The chief executive officer.

35
Q

What should an ombudsperson do to be more effective?

A

Report directly to the chief compliance officer or the board.
Keep names of informants secret.
Provide guidance to informants.
Follow up to ensure retaliation has not occurred.

36
Q

Organizational compliance standards and procedures to reduce misconduct include

A

Business code of conduct,
Organizational chart identifying personnel responsible for compliance programs, and
Financial incentives that do not reward misconduct.

37
Q

Applicant screening serves the purpose of

A

Detecting evidence of past wrongdoing, especially that within the organization’s industry.