ch 7 review (exam 2) Flashcards

1
Q

management must do what in regards to assessment of internal controls
- ________________ for effectiveness of ICs over financial reporting
- _________________ the effectiveness of ICs over financial reporting
- _________________ to support its evaluation
- _________________ of effectiveness of ICs over financial reporting at the end of the fiscal year

A

-accept responsibility
- evaluate
-document
-present written assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what is SOC section 404

A

management assessment of internal controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what is SOX section 302

A

CEO and CFO must annually certify, in writing, the effectiveness of ICs over financial reporting only

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CEO and CFO must annually certify, in writing, _____________________________

A

the effectiveness of IC over financial reporting only

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

In the PCAOB, an audit of ICFR is ____________ with an audit of financial statements

A

integrated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

an auditor must _______________ on whether the company maintained effective internal control over financial reporting

A

issue an opinion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What two audit reports are issued at the conclusion of the audit (separate or combined)

A
  1. opinion on financial statements
  2. opinion on ICs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what is an integrated audit

A

two audit reports at the conclusion of the audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what are two types of controls

A

preventive and detective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what is a preventive control

A

applied to each transaction to stop or prevent error from happening

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what is a detective controls

A

applies. after the transaction has occurred

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what is a manual control

A

do not rely on the client’s IT environment for their operation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what is an automated control

A

controls generally rely on the client’s IT applications (or software) in some way

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

examples of preventive controls

A

-accuracy, valuation, and allocation
- occurence
- accuracy
- classification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

examples of detective controls

A
  • completeness
  • occurence
  • completeness, occurrence,
    cutoff
  • completeness, classification
  • accuracy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what is the acronym for procedures for testing internal controls

A

R I I O

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What do the letters in R I I O stand for

A

Reperformance, Inquiry, Inspection of physical evidence, Observation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

what controls should be tested?

A

matter of professional judgement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

what are relevant controls

A

relevant controls are controls the auditor plans to rely on

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

significant changes equals a(n) ___________ in risk

A

increase

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

the extent that controls should be tested refers to _________

A

sample size

22
Q

what are three things determined by the auditor before selecting a sample size

A

-desired level of assurance
-expected rate of deviation in the population
- tolerable deviation rate

23
Q

what is the desired level of assurance

A

how confident does the auditor need to be that control is working

24
Q

a higher level of desired assurance means a ________ sample size

A

larger

25
Q

expected rate of deviation

A

the rate at which the auditor expects controls to NOT function

26
Q

tolerable deviation rate (TDR)-

A

maximum rate of deviation from the control the auditor is willing to accept and still rely on the control

27
Q

Example of tolerable deviation rate: TDR is 6%. If there were 50 voucher packages sampled for AP and found 4 exceptions would the control function as intended?

A

NO; 4/50 = 8%; do not rely on the IC

28
Q

Example of tolerable deviation rate: TDR is 6%. If there were 50 voucher packages sampled for AP and found 2 exceptions would the control function as intended?

A

YES; 2/50=4% ; may rely on internal controls

29
Q

how do auditors determine sampling size

A

professional judgement

30
Q

when is interim

A

3rd quarter/ early 4th quarter

31
Q

What part of NET is when should controls be tested?

A

Timining

32
Q

Updated from interim to YE by ____________ and __________

A

inquiry and observation

33
Q

benchmarking for computer application control

A

use evidence from PY of nothing has changed with IT application controls

34
Q

In step 7 of the assessing control risk, your IC testing will

A

confirm expectations or not

35
Q

in step seven review/ revise ___________ as needed

A

audit strategy

36
Q

what is step 8 in assessing control risk

A

reporting IC deficiencies to managememt

37
Q

What is the management letter

A

An in writing communication from the auditors to those charged with governance with observations regarding material weaknesses and significant deficiencies

38
Q

Which reporting standards require a management letter

A

ASB and PCAOB (private and public)

39
Q

are management letters provided to the public for private companies?

A

NO

40
Q

are management letters provided to the public for public companies?

A

NO

41
Q

Can there be more than one management letter throughout the audit?

A

Yes

42
Q

management letter allows management to ________________________

A

take action to improve ICs in a timely manner

43
Q

For public companies, auditors form an _________________

A

opinion on the effectiveness of IC over financial reporting

44
Q

is an opinion on the effectiveness of IC over financial reporting provided for private companies

A

no

45
Q

what is an unqualified opinion on ICFR

A

no material weaknesses in internal controls (company maintained effective internal controls)

46
Q

what is an adverse opinion on the effectiveness of ICFR

A

1 material weakness (or more) ; did not maintain effective internal controls

47
Q

what is a disclaimer on ICFR

A

material scope limitation; could not do work; no opinion

48
Q

is an attestation service say __________ instead of audit

A

examined

49
Q

a SOC 1 Type 2 report is prepared by __________ and _______________

A

service organization and service auditor

50
Q

the SOC 1 Type 2 report in provided to the ____________- and _______________

A

user entity and user auditor

51
Q
A