Chapters 6 and 7 Flashcards

1
Q

There is an _____ relationship between the reliability of internal control and the amount of substantive evidence required by the auditor.

A

Inverse.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Internal control is the method by which an entity’s board of directors, management, and other personnel provide reasonable assurance about the achievement of objectives in the following categories:

A

(1) reliability of financial reporting,
(2) effectiveness and efficiency of operations, and
(3) compliance with applicable laws and regulations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The controls that are of most direct relevance to a financial statement audit are those that contribute to the…

A

reliability, timeliness, and transparency of external financial reporting.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Internal control as defined by the COSO Framework consists of five components:

A
  • Control Environment.
  • Entity’s Risk -Assessment.
  • Control Activities.
  • Information and Communication.
  • Monitoring Activities.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

COSO

A

The Committee of Sponsoring Organizations of the Treadway Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Control environment

A

The board of directors and senior management establish the tone at the top regarding the importance of internal control and expected standards of conduct.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Entity’s Risk Assessment

A

A dynamic and iterative process for identifying and analyzing risks to achieving the entity’s objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Information and Communication

A

Enable personnel to understand internal control responsibilities and their importance to the achievement of objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Control activities

A

The actions established by policies and procedures to help ensure that management directives to mitigate risks to the achievement of objectives are carried out.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Control activities are commonly categorized into the following four types:

A
  • Performance reviews (sometimes called “independent checks”).
  • Physical controls.
  • Segregation of duties.
  • Information processing controls, including authorization and document-based controls.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Monitoring Activities

A

Ascertain whether each of the five components of internal control are present and functioning.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The effectiveness of any internal control system is subject to certain inherent limitations:

A
  1. Management override of internal control
  2. Personnel errors or mistakes
  3. Collusion.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

To set control risk below high (e.g., at moderate or low), the auditor must:

A
  1. Identify specific controls that will be relied upon.
  2. Perform tests of the identified controls.
  3. Conclude on the achieved level of control risk given results of testing.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Interim Tests of Controls

A
  • An auditor might test controls at an interim date because the assertion being tested:
    A. May not be significant
    B. The control has been effective in prior audits
    C. More efficient to conduct the tests at that time.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What companies must comply to auditing internal control?

A

Large publicly traded corporations - called “accelerated filers.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is an Accelerated filer?

A

A public company with common equity > 75 million.

17
Q

Section 404 of the Sarbanes-Oxley Act requires managements of publicly traded companies to:

A

A. Issue a report that accepts responsibility for establishing and maintaining adequate ICFR (internal control over financial reporting).
B. Assert whether ICFR is effective as of the end of the fiscal year

18
Q

What are the auditor’s responsibilities for reporting on internal control under Section 404 of the Sarbanes-Oxley Act?

A

A. The auditor must audit (give an opinion on) management’s assertion about the effectiveness of ICFR.
B. The auditor must conduct the audit in an integrated way (integrated with the financial statement audit)

19
Q

Control deficiency (REPORT TO MANAGEMENT)

A

A weakness in the design or operation of a control such that management or employees, in the normal course of performing their assigned functions, fail to prevent or detect misstatements on a timely basis.

20
Q

Significant deficiency (REPORT TO AUDIT COMMITTEE and MANAGEMENT)

A

A deficiency, or a combination of deficiencies, in ICFR that is less severe than a material weakness yet important enough to merit attention by those responsible for oversight of the entity’s financial reporting.

21
Q

Material weakness (REPORT EXTERNALLY!!, REPORT TO AUDIT COMMITTEE and MANAGEMENT)

A

A deficiency, or combination of deficiencies, in internal control, such that there is a reasonable possibility that a material misstatement of the entity’s financial statements will not be prevented, or detected and corrected, on a timely basis.

22
Q

In order to issue a report on the effectiveness of internal control, management needs to first…

A

Design and implement an effective system of ICFR and then develop an ongoing assessment process.

23
Q

The evaluation process has three steps:

A
  1. Identify financial reporting risks and related controls.
  2. Consider which locations to include in the evaluation.
  3. Evaluate evidence about the operating effectiveness of ICFR.