ch 6 review (exam 2) Flashcards

1
Q

Internal Control Integrated Framework (COSO) addresses what three objectives of internal controls

A
  1. operations
  2. reporting
  3. compliance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

why bother gaining an understanding of Internal COntrols

A

assess the control risk portion of risk of material misstatement (IR * CR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what are the 8 steps in assessing controls risk

A
  1. understand document at entity level
  2. understand the flow of transactions
  3. WCGW for FS assertions
  4. identify and document relevant transaction-level controls
  5. evaluate strengths and weaknesses and determine preliminary audit strategy
  6. perform test of controls
  7. evaluate the evidence, assess control risk, and reevaluate audit strategy (if necessary)
  8. report internal control weaknesses to those charged with governance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the acronym for Step 1 in assessing control risk- the five components of internal controls (entity-level controls)

A

CRIME

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what do the letters in CRIME stand for

A

C- control environment
R- risk assessment
I- information and communication systems
M- monitoring
E- existing control activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what are some factors in control environment

A
  1. organization demonstrates commitment to integrity and ethical values
  2. BOD directors is independent from management and oversees IC
  3. management establishes appropriate org structure
  4. quality HR policies
  5. org holds individuals accountable for IC responsibilites
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Things management does is risk assessment

A

-specifies clear objectives to enable identification and assessment of risk
- analyzes risk to determine how it should be managed
- considers fraud risk
- identifies changes that could affect IC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

things the organization does in Information and Communication systems

A
  • uses relevant quality information to support IC
  • internally communicates information to support IC
  • communicates with external parties about IC
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

things the organization does in Monitoring

A

-performs ongoing evaluations of IC
- communicates IC deficiencies in a timely manner to those responsible for taking action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the acronym for step 2 in assessing control risk- understanding the flow of transactions and control activities at the transaction level

A

PAID TIPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What do the letters in paid tips (step 2) stand for

A

P- prenumbering of documents
A- authorization of transactions
I- independent checks to maintain asset accountability
D- documentation

T-timely and appropriate performance reviews
I- information processing controls (computer controls)
P- physical controls for safeguarding assets
S- segregation of duties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what are auditors looking for under prenumbering of documents

A
  • all transactions are recorded
  • no transactions recorded more than once
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what is being looked for under the authorization of transactions

A

signed approval before commitment of resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what are some independent checks to maintain asset accountability

A
  • internal auditors
  • verify work of others (mgt/ owners)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

what are some documentation in step 2

A
  • evidence of transactions
    -evidence of authorization
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what are some timely and appropriate performance reviews

A

compare actual results to budgets

17
Q

what are some information processing controls (computer controls)

A
  • general controls
  • application controls
18
Q

what are some physical controls for safeguarding assets

A

locks, security guard, alarm system

19
Q

what happens in step three in assessing control risks

A

identify what can go wrong for financial statement assertions

20
Q

what happens in step five in assessing control risks

A

identify strengths and weaknesses in a system of internal control and determine preliminary audit strategy

21
Q

what are some key terms used in step five

A

control deficiency, material weakness. significant deficiency

22
Q

what is a control deficiency

A

exists when the design or operation of a control does not allow management or employees, in the normal course of performing their assigned functions, to prevent or detect misstatements on a timely basis

23
Q

what is a material weakness

A

very bad; a deficiency, or combo of deficiencies, in Internal Controls over financial reporting, such that there is reasonable possibility that a material misstatement of the FS will not be prevented or detected on timely basis

24
Q

what is significant deficiency

A

kinda bad; a control deficiency, or combo of deficiencies, in IC over financial reporting that is less severe that a material weakness, yet important enough to merit attention by those responsible for oversight of the company’s financial reporting

25
Q

what is magnitude

A

is it material or immaterial

26
Q

what is likelihood

A

the possibility of a misstatement

27
Q

what are the 4 types of likelihood

A

remote, reasonable, possibility, probable

28
Q

what are the two types of Systems Organization and Controls (SOC) 1 report

A

Type I and Type II

29
Q

which SOC 1 report is typically used more

A

Type II

30
Q

what do service auditors do in a SOC 1 Type I report

A

obtains an understanding of service organization controls

31
Q

what do service auditors do in a SOC Type II report

A

obtains an understanding of service organization controls and tests the operating effectiveness of these controls

32
Q

what type of service is the service auditor for a SOC 1 report performing

A

attestation service

33
Q

does a service auditor performing a SOC 1 report have to be independent

A

yes

34
Q

what are the 4 trust factor criteria the SOC 2 report that focuses on a service organization’s controls

A
  1. information security
  2. information availability
  3. processing integrity of the user’s data by the service organization’s information system
  4. confidentiality and privacy of the information processes by the service organization’s systems
35
Q
A