Final Review II Flashcards
What is the audit strategy
outlines the scope of the audit engagement,
reporting objectives
timing of the audit
req communications
factors that determine the focus of the audit
What is the audit plan?
outlines the nature, extent, and timing of the procedures to be performed during the audit :
- risk assessment
- further audit procedures
- other audit procedures
What is internal control
process to provide assurance that an entitys objectives will be achieved
What are the 5 components of internal control?
- control environment
- risk assessment
- information and communication systems
- monitoring
- existing control activities
What is existing control activities and what are the key points?
policies and procedures est to ensure that mgmt objectives are carried out
PAID TIPS
What is PAID TIPS
- Prenumbering documents
- authorization of transactions
- independent checks to maintain asset accountability
- documentation
- timely and appropriate performance reviews
- information processing controls
- physicals controls for safeguarding assets
- segregation of duties
How is a service organization related to user entity’s IC
considered to be part of user entity’s information system when such services affect initiation, execution, processing or reporting of the user transactions
What are the 2 types of user reports from a service organization?
- report on controls placed in operation
- report on controls placed in operation and tests of operating effectiveness
What is the auditors use of IT on the audit
effects both the eval and gathering evidence but audit objectives remain the same
What are computer assisted auditing techniques
auditing through the computer
What is transaction tagging
electronically marks a transaction and allows the auditor to follow it though the clients system
what is an embedded audit module?
application program collects transaction data for the auditor. auditor must be involved in program design
What is test data (deck)
uses application program to process test data the results of which are already known
What is integrated test facility?
test data is mixed with live data
What is a parallel simulation
auditor reprocesses clients live data and compares results
what is generalized audit software packages
auditor to perform test of controls and substantive tests directly on the clients system
What are some IT risks
- potential reliance on inaccurate
- loss of data
- unauthorized changes to data
- failure to make req changes
What are some IT benefits ?
- accurate and consistent processing
- timeliness
- facilitation of data analysis
When should fraud be reported to 3rd parties?
- to SEC in order to comply with certain legal and regulatory req.
- successor auditor
- in response to a subpoena
- to a funding agency