CPA Section 2 AUD Flashcards
When performing risk assessment procedures, the auditor should document all of the following concerning risks identified, the related controls evaluated, and the responses to the risks assessed including:
key elements of the understanding obtained regarding each of the aspects of the entity and its environment identified.
What is an accountant’s responsibility for using the work of other accountants in a review of group financial statements performed in accordance with the Statements on Standards for Accounting and Review Services (SSARSs)?
Read the review or audit reports of component accountants, considering any impact of report modifications on the group review report.
In assessing the objectivity of internal auditors, an independent auditor should:
determine the organizational level to which the internal auditors report.
Processing data through the use of simulated files provides an auditor with information about the operating effectiveness of control policies and procedures. One of the techniques involved in this approach makes use of:
an integrated test facility.
_____ creates a fictitious entity in an actual entity’s database in order to test transactions right along with live input. It is a control over PROCESSESING
An integrated test facility
An auditor most likely would test for the presence of unauthorized EDP program changes by running a:
source code comparison program.
____program compares the coding of the program from its last run with the original program
A source code comparison
The auditor should consider certain factors in assessing the efficiency and effectiveness of analytical procedures as compared to tests of details. In determining whether and to what extent analytical procedures should be used, which of the following should the auditor consider?
Interrelationships of financial information, The nature of the assertion tested, OR, Nonfinancial information that may affect financial information
Nature of assertion only
Fuck interrelationships
The primary objective of procedures performed to obtain an understanding of internal control is to provide an auditor with:
knowledge necessary for audit planning.
The extent and nature of the risk to internal control associated with IT are dependent on the nature and characteristics related to the entity’s:
Info system
The ultimate purpose of assessing control risk is to contribute to the auditor’s evaluation
of the risk that material misstatements may exist in the financial statements.
Test data is processed by the .
client’s computer programs under the auditor’s control
The test data need consist of only those valid and invalid conditions that interest the auditor.
Only one transaction of each type need be tested
The test data must consist of all possible valid and invalid conditions.
T/F
TRUE
TRUE
FALSE - It cant consist of all possible conditions b/c who can do that bro
Test data is data specifically designed and developed to test
the accuracy and completeness of a computer program.
Obtaining an understanding of internal control involves
evaluating the design of a control and determining whether it has been implemented.
Obtaining and understanding internal controls involves Understanding controls that exist in the audited company’s industry
False - fuck the existing controls
Since the production cycle handles raw products and materials, it is important to maintain proper
custody of the assets, as assets can easily be misappropriated during this cycle.
An auditor used test data to verify the existence of controls in a certain computer program. Even though the program performed well on the test, the auditor may still have a concern that:
the program tested is the same one used in regular production runs.
The test data method is a technique used with
audit software
Regarding test data, If the entire system is changed and the record formats are obsolete, then and only then will the
test data not be relevant in subsequent audit periods.
the ___should approve all sales
credit department
When trying to detect whether data was altered in a computer system, the auditor needs to
test the computer system by using test data
For a new client, reading a _____would help the auditor obtain an understanding of the industry in which the client operates,
specialized trade journal
Input controls, processing controls, and output controls are all examples of _____, which ARE NOT ____
application controls
general controls
Program change control is an example of what kind of control
general controls in an IT environment
Examples of general controls are
- program change controls,
- controls that restrict access to programs or data,
- controls over the implementation of new releases of packaged software applications
- controls over system software that restrict access to or monitor the use of system utilities that could change financial data
Risk assessment procedures include:
inquiries of management and others within the entity,
analytical procedures, and
observation and inspection.
auditing related party transactions, an auditor ordinarily places primary emphasis on:
the adequacy of the disclosure of the related party transactions.
Embedded audit modules:
enable continuous monitoring of transaction processing.
Analyzing the efficiency of programming is a characteristic of ___
mapping.
. The higher the risk of material misstatement, the ____the detection risk must be
lower
RMM x DR = what?
Audit Risk
Audit Risk = ( __ x __) x __
IR x CR x DR
Which of the following input controls is a numeric value computed to provide assurance that the original value has not been altered in construction or transmission?
Check digit
What input control is a nonsense total
hash total
when planning an examination, an auditor should (materiality)
make preliminary judgments about materiality levels for audit purposes.
Whether or not a real-time program contains adequate controls is most effectively determined by the use of:
integrated test facility
Which of the following audit risk components may be assessed in nonquantitative terms?
Control risk, detection risk, and inherent risk
Considering whether the client’s accounting estimates are reasonable in the circumstances is done in what phase
performance
Determining the extent of involvement of the client’s internal auditors is done in what phase
planning