Audit of Internal Control Steps Flashcards
what is the first step in the audit of I/C
obtaining understanding of the entity
what is done in the understanding step
the I/C of the client must be understood sufficently enough to be able to plan examination and risk assesemen
when must the understnding me donw
early in the audit
what 4 outlined methods can be used in obtaining undertadnig
- walkthrough
- narrative
- questionaire
- flowchart
what is the most important I/C compoenent to know for the understading step
the control environment
what is the second step in assessing I/C
evaluating desgin effectiveness
what is done in hte design effectiveness evaluation step
evaluate whether statements are auditable
why must it be evaluated if statemnets are auditable, what are the 2 outcomes
I/C evalauted as weak - effectiveness issue
I/C testing evaluated as expensive - efficiency issue
what is the third step in I/C assessment
assessment of control risk
what model is used in hte control risk assessment stage
the ARM model
in the assessment of control risk, do we asses weaknesses or strenghts
strenghts, because weaknesses are just lack of contorls
what are the three conclusions that we can come to after assessing controls risk
CR is high - pure substantive
CR is low - combined (common)
CR is low - pure substantive due to cost reasons (rare)
what is the 4th step in I/C audit
identify and asses RMM
what level is RMM assesed at?
at assertion level
what is the 5th step in audit I/C controls
design the control tests