Chapter 9 Flashcards

1
Q

CAS 315 requires all five components of _____ internal control to be addressed and understood

A

COSO framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what are the five components of COSO?

A
  1. control environment
  2. risk assessment
  3. control activities
  4. information and communication
  5. monitoring
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

auditor uses his understanding of COSO to

A

identify potential errors or fraud and other irregularities that can increase risk material misstatement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

the risk of material misstatement must be monitored at both

A

overall financial statement level and assertion level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

once potential errors or fraud risks are identified

A

use to design the audit procedure to respond to the risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

items to understand information system and communication (7)

A
  1. financial reporting process (accounting estimates and disclosures)
  2. nature and details of procedures
  3. controls surrounding journal entries
  4. major classes of transactions of entity
  5. how transactions initiate and recorded
  6. accounting records exist and nature
  7. how information system get other events significant to fin. statements
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

methods to document understanding of control activities (3)

A
  1. narrative
  2. flowchart
  3. internal control questionnaire
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

def: narrative

A

written description of internal controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what elements are included in narrative (4)

A
  1. origin
  2. processing
  3. disposition of documents and records
  4. relevant control activities
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

def: flowchart

A

diagrammatic representation of client’s documents and records and sequence in which processed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

def: internal control questionnaire

A

series of questions about controls in each audit area

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

if questions in questionnaire are answered no?

A

failure of internal control so completeness objective not completed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

how to evaluate if controls have been implemented

A
  1. consider if the control when in operation would achieve this objective
  2. is the control implemented
  3. is it carried out by appropriately qualified persons
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

methods to evaluate implementation of controls (6)

A
  1. previous experience with entity
  2. make inquiries of client personnel
  3. examine doc and records
  4. observe activities and operations
  5. walk through of accounting system or transaction
  6. assess control risk
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

before making preliminary assessment of control risk for each class of transactions

A

must see if entity is auditable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

3 criteria for auditable entity

A
  1. management lacks integrity
  2. accounting records are deficient (lack evidence)
  3. complex IT environments (must have skills)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

how to assess control risk at assertion level

A

control risk matrix

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Def: control risk matrix

A

method used to help auditor assess control risk by matching key internal controls and internal control weaknesses with transaction related audit objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

purpose of control risk matrix

A

provide a convenient way of organizing control risk for each assertion and related audit objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

process of assessing control risk with matrix

A
  1. identify audit objectives (assertions)
  2. identify specific relevant controls
  3. associate controls with objective (assertion)
  4. identify and evaluate control deficiencies, significant deficiencies and material weaknesses
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

a C in control matrix means

A

affects the objective listed at the top

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

a D in control matrix means

A

deficiency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

a lot of Ds means

A

increase in control risk depending on importance of deficiency

24
Q

three levels of absence of internal controls (CAS 265)

A
  1. control deficiency
  2. significant deficiency
  3. material weakness
25
Q

def: control deficiency

A

design or operation of controls does not detect and correct misstatements in timely manner

26
Q

def: significant deficiency

A

one or more control deficiencies exist that are less severe than material weakness

27
Q

def: material weakness

A

significant deficiency results in reasonable possibility that internal control will not prevent or detect material financial misstatements on timely basis

28
Q

five step approach to identify significant and/or material internal control weaknesses

A
  1. identify existing controls
  2. identify absence of key controls
  3. possibility of compensating or mitigating controls
  4. significant deficiency or material weakness
  5. potential material misstatements that could result
29
Q

def: test of controls

A

procedures to test effectiveness of controls in support of reduced assessed control risk

30
Q

five types of audit procedures to support operation of key internal controls

A
  1. inquiries of appropriate entity personnel
  2. inspect documents, records and reports
  3. observe control-related activities
  4. test data
  5. re-perform client procedures
31
Q

def: procedures to obtain an understanding of internal controls

A

are applied to all controls identified while test of controls when assessed control risk has not been satisfied by procedure

32
Q

CAS 402 requires auditor to consider the need to understand service center’s controls if

A

they process significant financial data

33
Q

name for auditors who issue reports on the internal control of service orgs

A

service auditors

34
Q

Type 1 report

A

management description of a service organization’s system and suitability of the design of controls

35
Q

type 2 report

A

type 1 + operating effectiveness of controls

36
Q

tests of controls are more ________ than substantive procedures in certain situations

A

cost efficient

37
Q

in highly automated systems, the auditor has to

A

rely on internal controls

38
Q

if the auditor relies on internal controls

A

they must be tested

39
Q

if risk with simple IT system the IT specialist can (5)

A
  1. assist in documenting and assessing IT control environment
  2. test general controls
  3. document and assess key automated controls
  4. develop CAATs to test controls and perform substantive tests
  5. evaluate weaknesses and develop recommendations
40
Q

audit in more complex IT environments

A

through the computer by testing automated internal controls and account balances electronically (since general controls exists)

41
Q

3 approaches to test effectiveness of automated controls when audit through computer

A
  1. test data approach
  2. parallel simulation
  3. embedded audit module approach
42
Q

def: test data approach

A

use auditor’s test data to determine whether the client’s computer program correctly processes valid and invalid transactions

43
Q

when using a test data approach, auditors have three main considerations

A
  1. test data should include all relevant conditions that the auditor wants tested
  2. application programs used by auditor must be the same as those used by client throughout the year
  3. test data must be eliminated from client’s records
44
Q

def: parallel simulation testing

A

auditor use of audit software to replicate some part of a client’s application system

45
Q

auditors commonly do parallel simulation testing with

A

GAS (generalized audit software)

46
Q

GAS provide

A

data retrieval, data manipulation and reporting capabilities oriented to needs of auditor

47
Q

def: embedded audit module approach

A

audit transactions processed by IT where auditor embeds a module in client’s app software to identify transactions with characteristics of interest to the auditor

48
Q

purpose of embedded audit module

A

analyze these transactions on a real-time, continuous basis as client transactions are processed

49
Q

when the auditor finds significant control deficiencies he must

A

communicate in writing to the audit committee or equivalent

50
Q

when must a report on internal controls be given to management AND board of directors

A

if it has significant impacts on financial statements

51
Q

how must it be reported to management and board of directors

A

internal control letter

52
Q

the description of internal control deficiency and recommendation is usually included

A

in a year end report or internal control letter to the audit committee

53
Q

def: management letter

A

auditor’s written communication to management to point out less significant weaknesses in internal controls and possibilities to improve operations

54
Q

difference between internal control audit and financial statements audit

A

IC: perform tests of control for ALL significant account balances, transactions and disclosures and related assertions while in financial statement audit they might or might not. only the controls that the auditor plans to rely on must be tested

55
Q

in a financial statement audit the auditor is providing

A

assurance over financial statements and not internal controls