AT - CONSIDERATION OF INTERNAL CONTROL Flashcards
What is assessment of control risk?
It is the process of evaluating the design and operating effectiveness of an entity’s internal control as to how it prevents or detects material misstatements in the financial statements. The conclusion reached as a result of the assessment is the ASSESSED LEVEL OF CONTROL RISK.
What is internal control according to PSA 315?
Internal control is the process designed and effected by TCWG, management, and other personnel to provide reasonable assurance about the achievement of the entity’s objectives, with regard to reliability of financial reporting effectiveness of efficiency of operations and compliance with applicable laws and regulations.
What part of the internal and accounting systems is the auditor only concerned with?
The auditor is only concerned with those policies and procedures within the accounting and internal control systems that are RELEVANT TO THE FS ASSERTIONS.
What are the interrelated components of internal control?
- Control environment
- Risk assessment
- Information and communication systems
- Control activities
- Monitoring
What is control environment?
Control environment includes the ATTITUDES,AWARENESS, AND ACTIONS OF MANAGEMENT AND TCWG concerning the entity’s internal control. It is the FOUNDATION FOR EFFECTIVE INTERNAL CONTROL, PROVIDING DISCIPLINE AND STRUCTURE. Factors include:
a. Integrity and ethical values
b. Management philosophy and operating style
c. Active participation of TCWG
d. Commitment to competence
e. Personnel policies and procedures
f. Assignment of responsibility and authorized organizational structure
What is risk assessment?
It is the assessment of business risk, which is the RISK THAT THE ENTITY’S BUSINESS OBJECTIVES WILL NOT BE ATTAINED as a result of internal and external factors such as:
a. technological developments
b. changes in demand
c. other economic changes
What is Information and Communication Systems?
It consists of procedures and records established to initiate,record, process, and report entity transactions and to maintain accountability. It encompasses methods and records that IDENTIFY,DESCRIBE,MEASURE,DETERMINE, AND PRESENT PROPERLY TRANSACTIONS.
What are control activities?
Control activities are the policies and procedures that help ensure that management directives are carried out which could include:
a. Performance reviews
b. Information processing
c. Physical controls
d. Segregation of duties
e. Authorization - PRTC HANDOUTS
What is monitoring?
Monitoring is a process of assessing the quality of internal control performance over time and taking necessary corrective actions to ensure that controls continue to operate effectively. It has two forms:
Ongoing monitoring - routine monitoring
Separate evaluations - non routine monitoring
What are the steps taken by the auditor in the consideration of the internal control?
- Obtain an understanding of internal control - how it is designed and whether it is being implemented
- Document the understanding of accounting and internal control systems
- Assess the level of control risk
- Perform tests of controls
- Document the assessed level of control risks
What is a walk-through test?
It involves tracing transactions through the entire accounting system from the initial recording at source to the final destination as a component of an account balance in the FS.
When obtaining an understanding of the entity’s internal control, is the auditor required to obtain knowledge about the operating effectiveness of the internal control?
No, at that phase of the audit, the auditor is only concerned about the design of relevant control policies and procedures and whether it is actually being applied.
What kind of form is required when documenting the understanding of internal control?
The documentation need not be in any particular form. Common forms include:
- narrative description
- flowcharts
- internal control questionnaire
Explain the assessment of control risk. When does the auditor perform ToC?
The auditor should make a preliminary assessment of control risk at the assertion level for each material account balance or class transaction.
If the internal control is assessed as not effective, the auditor may simply assess control risk at a high level, and no ToC need to be performed and auditor will rely primarily on substantive tests.
If the internal control is assessed as effective and the auditor deems it to be more efficient by reducing substantive testing and relying on the internal control, the auditor performs test of controls.
Tests of controls support any assessment of control risk at less than high level. THE GREATER RELIANCE AUDITOR PLANS TO PLACE ON THE INTERNAL CONTROL, THE MORE EXTENSIVE THE TEST OF CONTROLS THAT NEED TO BE PERFORMED.
What are the evidence gathering techniques used in ToC?
- Inquiry
- Observation
- Inspection
- Reperformance