CH 3 - Internal control Flashcards
What is a control that would detect customer payment to the wrong account?
Mailing monthly statements to customers with outstanding balances
In an non-issuer, what is the auditor’s primary consideration regarding an entity’s internal control structure policies and procedures
Whether controls relate to financial statement assertions
In an audit of non-issuer, what is the auditors consideration of internal control?
The auditor should document the basis for conclusions about internal control is perceive to be effective or ineffective
What are 2 advantages to internal control questionnaires compared to a flow chart?
- Can prepare in advance for clients in various industry categories
- Deficiencies are easier to be identified
In an non-issuer what is the auditor evaluating in internal controls (2)
- Design of relevant controls
2. Determining whether relevant controls have been place in operation
What does it mean if the auditor assess the control risk below the maximum?
Auditor believes that there are controls in place which are believe to lessen the risk of a material misstatement occurring in the FS
What is the ultimate purpose of assessing control risk in an audit ?
Contribute to the auditors evaluation of the risk that material misstatements exist in the FS
According to COSO - policies an procedures involving ID, prioritization and analysis of relevant risks as a basis for managing those risks is known as
Risk assessment
Define a walkthrough
When the auditor selects a few transactions and traces them through the clients accounting system
In an non-issuer, what is the required communication timing for significant deficiencies and material weaknesses no later than?
no later than 60 days following the report release date
What is an entity level control?
Controls that have a pervasive effect on an entity’s internal control system and may pertain to multiple components such as Risk assessment and control monitoring
In a TOC - if there is no documentation, can an auditor still test the control?
Yes, auditor will use observation and inquiry
when a TOC is tested for operating effectiveness - what is a the auditor concerned with? (3)
- how internal control were applied
- consistency with which it was applied
- by whom it was applied
What are 3 examples of preventative controls?
- Fraud awareness training
- background checks
- data matching
What type of control is a surprise audit?
detective control