Chapter 7 Flashcards

1
Q

What does COSO stand for?

A

Committee of Sponsoring Organizations. They make some rules of Internal Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The three broad internal control objectives are

A

Compliance with laws and regulations

Reliability of financial reporting

Efficiency/effectiveness of operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Internal Control is defined as

A

a process, effected by the entity’s board of directors, management, and other personnel designed to provide reasonable assurance regarding achievement of objectives in the following categories:

  • Reliability of financial reporting
  • Effectiveness and efficiency of operations
  • Compliance with applicable laws and regulations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Auditor’s focus towards internal control is the on internal control over _____, or ICOFR

A

Internal Control Over Financial Reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

This act, in addition to making bribes to foreign officials illegal, requires an effective system of internal control

A

Foreign Corrupt Practices Act of 1977

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Define Segregation of Duties, a component

A

No one department or person shall handle all aspects of transaction from beginning to end to perpetrate and conceal errors/fraud.
• MUST segregate duties along the “arc” – must separate the authorizing of transactions, recording of transactions, and custody of related assets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Does management or the internal auditor establish internal controls?

A

Management does, along with preparation of financial statements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Is reasonable or absolute assurance required?

A

Reasonable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Name the five components of internal control

A

The Control Environment

Risk Assessment Process

Control Activities

The Accounting Information and Communication system

Monitoring of Controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Detailed employee responsibilities, open communication channels, and reporting exceptions/unusual items to management are also key in information and communication system. True or False?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Define Physical Controls, a component

A

providesw physical security over records and assets
 Physical Controls – provide physical security over records and assets
• Maintaining control over unissued pre-numbered documents
• Restricting access to computer programs and data
• Restricting physical access in safes, locks, fences, guards etc
• Accounting records should be maintained independent of custody-related assets, and company should periodically compare/reconcile accounting records to assert on hand (to detect loss, waste, or theft)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Define the Risk Assessment Process component

A

management’s process for identifying, analyzing, and responding to such risks.

• Financial Reporting Risks
 Changes in the regulatory or operating environment
 Changes in personnel
 Implementation of a new or modified information system
 Rapid growth of the organization
 Changes in technology affecting production processes or information systems
 Introduction of new lines of business, products, or processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Define a Performance Review

A

provide management with an overall indication of employee effectiveness at meeting objectives. By investigating deviations¸ management takes timely action to change strategy or take and other appropriate action.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Control Activities, a component of internal control, can be defined as

A

policies and procedures that address and mitigate risks identified by risk assessment process.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Actions, policies, and procedures that reflect overall attitudes of top management, directors, and owners of an entity establish which component of Internal control?

A

The Control Environment.

  • Commitment to integrity and ethical values
  • Effective BOD and audit committee
  • Effective organizational structure
  • Commitment to attract, develop, and retain competent employees
  • Individual accountability for internal control responsibilities
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Describe the six limitations of Internal Control

A

Human Errors

Systematic Errors

Collusion circumventing segregation of Duties

Override of internal Control by Management

Cot considerations

Compliance deteriorating over time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Should management perform ongoing monitoring to determine if controls are present and functioning?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Describe The Accounting Information and Communication System

A

Information is needed throughout company to meet objectives. Therefore, management must obtain, use, and communicate relevant, quality information to support controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Monitoring activities assess the quality of internal control over time. True or False?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What does ERM stand for?

A

Enterprise Risk Management.

  • COSO, but doesn’t replace internal control framework
  • Goes beyond internal control to focus on how organizations may be able to maximize value for stakeholders most effectively by managing risks and opportunities
  • More robust, or strong and stable, for companies to manage business risk
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Define Corporate Governance

A

“the system by which companies are directed and controlled.” It includes the policies, procedures, and mechanism that are established to ensure that the company operates in the best interests of its major stakeholders - including owners, customers, suppliers, employees, and society as a whole.

For example, for a corporation, the major instruments of corporate governance include management compensation systems, the boards of directors (including major committees), external auditors, internal auditors, attorneys, regulators, creditors, securities analysts, and internal control systems.governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Define how systematic errors may occur

A

in designing, maintaining, or monitoring automated controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Once again - steps of audit in order

A

Plan Audit - Obtain Understanding - Assess Risks of Material Misstatement - Perform further audit procedures - Complete the Audit - Form an Opinion - Issue audit report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Corporate Governance Mechanisms include

A
	External auditors
	Regulators (such as the SEC)
	Creditors
	Securities analysts
	Major shareholders
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

revenue, purchases, and cash receipts and disbursements are names of what types of transactions?

A

routine transactions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Stage 2, obtaining understanding, regarding internal control:

A

 Identify types of potential misstatements and consider factors that affect risk
 Design tests of controls
 Auditors must first understand the internal control design, so the client can provide narratives here or flowcharts of controls
 Only test controls that work. No point in testing ineffective ones, because cant increase detection.

Also, Auditors must consider all five of the internal control components

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Corporate Governance would be considered ____ (broader/smaller) than internal control

A

Broader, it also encompasses ethical treatment of all major stakeholders, compliance with laws, regulations, customary business practices, and effective risk management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Determining the allowance for doubtful accounts would be an example of which type of transaction?

A

Estimation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Test of controls include the following: (there are four)

A

Inquiries of appropriate client personnel

Inspection of documents and reports

Observation of the application

Reperformance of the controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

taking of inventory, calculating depreciation expense are examples of what type of transactions?

A

nonroutine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Results of ____ are often used to determine nature, extent, and timing of substantive proceudres

A

Tests of Controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Which of the three types of transactions generally has the strongest control compared the other two?

A

Routine transactions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

If controls have changed from prior year, new controls must be tested. True or false?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Advantages and disadvantages of Internal Control Questionnaires

A

A: Asks a series of questions about controls in each transaction cycle in order to identify deficiencies

D: 1. Inability to provide a system overview

  1. Inapplicability of many questions for some audits, especially smaller ones
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Define a Narrative

A

Written description of each transaction cycle in

an accounting system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

If controls have not changed, can one rely on past tests of controls?

A

Sure, but in a limited fashion.

AICPA and International Auditing Standards – tests of control must be performed at least every third year

PCAOB – more stringent – tests of controls must be performed to some extent annually when controls are relied upon

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

The four procedures to obtain understanding of control design and implementation include (usually a combo of):

A
  • Inquiring of entity personnel
  • Observing the application of specific controls
  • Inspecting documents and reports
  • Tracing transactions through the information system relevant to financial reporting (walk-throughs)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

If tests of control show numerous control deviations, is substantive testing expanded or reduced?

A

Expanded to test the assertions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

• Auditing standards require auditors to obtain and document an understanding of internal control. True or False?

A

True, through

  • Internal Control Questionnaires
  • Narratives
  • Flowcharts
  • Walk-throughs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

Is a walk-through the same as a tour of the audit property?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Define a significant deficiency

A

control deficiency that is important but less severe than material weakness

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

Describe considerations taken if the work of internal auditors must be used

A
  • CPA may rely on work of internal audit to reduce amount of testing if found to be effective
  • CPA must assess internal audit competence (education, experience, certifications) and objectivity (report directly to audit committee?) and quality of their work (examine working papers)
  • If intent is to rely upon work of internal audit, must test that work
43
Q

Define Flowcharts

A

Diagram of each cycle in an accounting system that

serves as a visual representation of the series of procedures that occur in each sequence of processing

44
Q

Define an advantage of a Narrative

A

Kind of like writing out a walk-through. Advantage is that it gives a good understanding of what a transaction look like.

45
Q

Which report documents the organization’s suitability and effectiveness?

A

Type 2

46
Q

Advantages of flowcharts?

A

Contains the same information as a narrative,
with the advantages of being:
1. Easier to read/visualize
2. Easier to update.

***Narratives/flowcharts to understand the system accompanied
by internal control questionnaires for checklist of potential
deficiencies = highly useful!

47
Q

Define a walk-through

A

After documentation of internal controls, trace one or two transactions through cycle to ensure proper implementation

If auditor finds implementation of internal controls is different from description, modify working papers accordingly

48
Q

Potential disadvantages of flowcharts are

A

that it’s not as clearly identifying areas of weakness/omitted controls

49
Q

An Unqualified opinion on Internal Control means that

A

No material weaknesses or scope restrictions

50
Q

Can a CPA obtain direct assistance from internal auditors?

A

Sure, for certain procedures (nothing high risk or subjective), but CPA remains responsible for the audit

51
Q

A type _ (1/2) report is Management’s description of the system and the suitability of the design of controls

A

Type 1

52
Q

• Auditors may also assist in effective internal control and improving client effectiveness and efficiency by communicating the following in a management letter:

A
  • Internal control deficiencies (even less significant ones)
  • Explanation of potential effects
  • Recommendations for corrective action
53
Q

Audit standards require WRITTEN communication of _____ (significant deficiencies/material weaknesses) to management no later than 60 days after report release date

A

Both, actually

54
Q

SOX Section 404a Establishes a form 10k each year. This is a report that includes the following affects on management:

A

Acknowledges responsibility for establishing and maintaining adequate internal control over financial reporting
 Assesses internal control effectiveness as of the last day of the company’s fiscal year using suitable criteria

55
Q

Define a material weakness

A

control deficiency that creates a reasonable possibility of a material misstatement

56
Q

An adverse opinion on Internal Control means that

A

there are one or more material weaknesses

57
Q

A Qualified or Disclaimer opinion on Internal control means that

A

there is a Scope Limitation

58
Q

Due to lack of employees, internal control is generally _____ (strong/weak) in small businesses

A

weak since, for example, adequate segregation of duties is not feasible. Auditors must rely much more on substantive procedures of account balances and transactions

59
Q

Some key measures to ensure better control include

A
  • Segregation of duties of cash handling and record keeping

* Active oversight and participation by the owner

60
Q

Auditors selected by a service organization to assess systems are called

A

Service Auditors

61
Q

Define a Service Organization

A

Organization that performs data processing/computer/or IT services, like payroll processing, for various clients

62
Q

Preventive, Detective, or Corrective control? - Segregation of Duties

A

Preventive

63
Q

Preventive, Detective, or Corrective control? - Requirement to prepare bank reconciliations

A

Detective

64
Q

Preventive, Detective, or Corrective control? - Maintaining Backups of Data

A

Corrective

65
Q

Preventive, Detective, or Corrective control? - Finding a misstatement that has already been made

A

Detective

66
Q

Preventive, Detective, or Corrective control? - Finding a misstatement

A

Corrective

67
Q

Preventive, Detective, or Corrective control? - Approving journal entries

A

Preventive

68
Q

A common way to help detect misstatements that have been made is to

A

Prepare bank Reconciliations

69
Q

Lifo calculations, Depreciation, Physical inventory, and financial statement closes are what type of transactions?

A

Nonroutine

70
Q

Bad debt expense is what type of transaction?

A

Estimation

71
Q

Cash receipts, payroll, cash disbursement, and inventory costing is considered what type of transaction?

A

Routine

72
Q

The significance of accounts should be considered ______ (with/without) regard to internal control.

A

without

73
Q

The first step of planning steps of the audit of internal control is

A

Management’s report on internal control

74
Q

What kind of approach is sued to identify controls to a tesT?

A

top-down

75
Q

An account is significant if there is a reasonable possibility that it could contain a misstatement that has a material effect on the financial statements. True or False

A

True

76
Q

Accounting ______ (disclosures/estimates) involve management’s judgment or assumptions.

A

estimates

77
Q

Is design or operating effectiveness tested first?

A

Design

78
Q

Efficient planning of the evaluation of internal control requires coordination the financial statement audit. True or false?

A

True

79
Q

Evidence as to the design of internal control and its operating effectiveness should be considered ____________ (as of, before, or after) the date specified in the assessment

A

as of

80
Q

The audit committee is especially important as it exercises oversight responsibility over the financial statements. True or False

A

True

81
Q

Who should develop a statement of ethical values?

A

Senior Management

82
Q

Management’s evaluation process of internal control ____________ (concludes/begins with) with the management report on internal control–the first step of the audit process.

A

concludes

83
Q

Organizational structure provides a basis for planning, directing, and controlling operations. True or False?

A

True

84
Q

To enhance the control environment, management develops job descriptions. True or False?

A

True!

85
Q

For well controlled operations, the same employee that maintains custody of assets should also keep the accounting records for the assets. True or False?

A

False

86
Q

An employee has incompatible duties if the person is in a position to perpetrate and conceal errors or fraud in the normal course of performing his or her duties. True or False?

A

True

87
Q

The controls over a client’s sales cycle are part of that client’s control environment. True or False?

A

False

88
Q

The establishment of sales terms is an example of a control. True or False?

A

True

89
Q

The internal audit function is an important part of the monitoring component of internal control. True or False?

A

True

90
Q

All material weaknesses are also control deficiencies. True or False??

A

True

91
Q

Both the design of controls and the operating effectiveness of controls is considered in an audit of internal control performed under PCAOB standards. True or False?

A

True

92
Q

A control activity that leaves evidence of compliance is usually tested by inquiry and observation. True or False?

A

True

93
Q

An advantage of an internal control questionnaire is that weaknesses in internal control are highlighted by the questionnaire. True or False?

A

True

94
Q

In audits of both public and nonpublic companies significant deficiencies and material weaknesses noted by the auditors must be communicated to management in writing. True or false??

A

True

95
Q

Before assessing control risk at a level lower than the maximum, the auditor obtains reasonable assurance that controls are in use and operating effectively. This assurance is most likely obtained in part by:

Analyzing tests of trends and ratios

preparing flowcharts

inspecting documents

performing substantive procedures

A

inspecting documents

96
Q

Examine signatures on checks is considered a test of control?

A

Yes

97
Q

When performing an audit of internal control, the period or date on which the opinion relates under PCAOB standards is the: as of date or the entire period under audit?

A

As of Date

98
Q

Counting and listing cash on hand considered a test of control?

A

No

99
Q

No one particular form of documentation of client’s internal control is required, and the extent of documentation may vary. True or false?

A

True

100
Q

Obtaining or preparing reconciliations of bank accounts as of the balance sheet date considered a test of control?

A

No

101
Q

Observation of client personnel applying the control is most likely to provide an auditor with utmost assurance about the effectiveness of the operation of internal control. True or false?

A

True

102
Q

An auditor’s flowchart of a client’s internal control is a diagrammatic representation which depicts the auditors’:

documentation of control risk

understanding of the system

planned tests of controls

program for tests of controls

A

understanding of the system

103
Q

Is monitoring considered a component of internal control?

A

Yes