IC- Concepts and Standards Flashcards

1
Q

List the advantages of narratives (memos) to document the auditor’s understanding of internal controls.

A

1-Tailored to client;
2-Can be as detailed or as general as desired;
3-Easy to prepare;
4-Easy to read.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the purpose of performing a walkthrough?

A

Obtain some feedback as to whether the way the auditor has understood (and documented) the entity’s internal controls is consistent with the way the entity is actually processing such transactions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

List the disadvantages of narratives (memos) to document the auditor’s understanding of internal controls.

A
  • Writing such a memo is rather unstructured, lacking a systematic approach;
  • It may be rather easy to overlook relevant internal control issues.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Identify 3 ways auditors might document their understanding of internal controls?

A
  • Flowcharts of transaction cycles;
  • Internal control questionnaires;
  • Narrative write-ups (memos).
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Identify 2 reasons for assessing control risk at the maximum level.

A

1-The auditor believes that the design of internal control is ineffective; or
2-The auditor believes that reliance on internal control (and performing applicable tests of control) is not an efficient audit strategy compared to a wholly substantive audit approach.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

When should the auditor assess the design effectiveness of internal control?

A

In planning every audit under GAAS, as a basis for determining the nature, timing, and extent of further audit procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

When should the auditor assess the operating effectiveness of internal control?

A

Whenever the auditor contemplates a reliance strategy (which means the same thing as “assessing control risk at less than the maximum level”) and only after performing the appropriate tests of control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are some inherent limitations of internal controls?

A
  • Faulty human judgement
  • human error
  • collusion by two or more people
  • inappropriate management override of controls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Definition of substantive procedures and what they comprise?

A

An audit procedure designed to detect MM at the assertion level. They comprise:
Tests of details (transactions, account balances,etc)
Substantive analytical procedures (analytical procedures required at the start and review, while substantive procedures during the audit use professional judgement)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

List some examples of appropriate responses by the auditor to risks of material misstatement at the financial statement level.

A

Assign more experienced staff to the engagement;
Provide closer supervision;
Use specialists;
Use more unpredictable audit procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the 3 different types of audit procedures?

A

Risk assessment procedures
Tests of control
Substantive procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Define “significant deficiency.”

A

A deficiency (or combination of deficiencies) in internal control that is less severe than a material weakness, yet important enough to merit attention by those charged with governance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is meant by the term deficiency in design?

A

When a control necessary to meet the control objective is missing, or when the control objective is not always met, even if the control operates as designed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Define material weakness.

A

A deficiency (or combination of deficiencies) in internal control such that there is a reasonable possibility that a material misstatement of the entity’s financial statements will not be prevented or detected and corrected on a timely basis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Describe the timing of the required communication of significant deficiencies in internal control.

A

Under AICPA professional standards, written communication is required no later than 60 days after the audit report release date (including matters communicated orally during the audit).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is meant by the term deficiency in operation?

A

When a properly designed control does not operate as designed, or when the person performing the control does not have the authority or competence to effectively perform the control.

17
Q

When using the work of the internal audit function to obtain audit evidence, what three matters should the external auditor evaluate?

A

1-Objectivity—the internal audit function’s organizational status and the objectivity of the internal auditors;
2-Competence of the internal auditors; and
3-Whether the internal audit function applies a “systematic and disciplined approach, including quality control.”

18
Q

Objective of AU-C 315, Understanding the Entity and Its Environment

A

To identify/assess the RMM, whether due to fraud or error, at the FS/assertion level through understanding entity and environment, including the entity’s IC, thereby providing a basis for designing/implementing responses to the assessed RMM

19
Q

What are the 3 primary objectives of system of IC at the entity level?

A

[ACE] in the hole:
Accurate and reliable financial reporting
Compliance w/ applicable laws/regulations
Efficient and effective operations

20
Q

Events and Transactions (5 assertions):

A
[CPA-CO] I/S
Completeness
Period cutoff
Accuracy
Classification
Occurrence
21
Q

Account Balances (4 assertions):

A
[RACE] B/S
Rights and Obligations
Allocation and Valuation
Completeness
Existence
22
Q

Presentation (5 assertions):

A
[RACOU-n] Notes
Rights and Obligations
Accuracy and Valuation
Completeness
Occurrence
Understandably and Classification
23
Q

As far as IC, Mngmt is responsible for the …

A

[DIM]
Development, Implementation, and Maintenance of IC, while the auditor seeks reasonable assurance that IC are achieving objectives (ACE)

24
Q

5 components of IC

A

[CRIME]
control Environment- “tone at the top” [CHOPPER]
Risk assessment- internal and external
Control activities- policies/procedures carried out [PIPS, ARCC-S]
Information and communication
Monitoring controls/if they are effective

25
Q

Control Environment

A
[CHOPPER] Foundation for all other components
Commitment to competence
HR policies/practices 
Organizational structure
Participation of TCWG
Philosophy of mngmt/operating style
Ethical values/integrity
Responsibility assignment
26
Q

Control Activities

A

[PIPS]
Performance reviews- controls evaluate performance against a criteria
Information processing- controls that prevent processing of info unless criteria are met
Physical controls- limit access to assets
Segregation of duties [ARCC-S Authorization, Recording, Custody, Comparisons, Segregate all of these

27
Q

Risk Assessment

A

The entity’s, not the auditors done during planning. Obtain understanding about whether entity has process for identifying, est the sig., assessing likelihood of occurrence, and actions taken.

  • If has process, then understand what failed (MW or SD?)
  • If no process, does the absence represent a SD or MW?
28
Q

Steps to understanding of entity’s IC structure:

A
  1. Obtain understanding of all 5 components [CRIME] through risk assessment procedures (form? [AIIO] is risk assessment procedures: AP, Inquiries, Inspection, Observation)
  2. Document the understanding of IC [FIND]: Flowchart, ICQ, Narrative, Decision tree
  3. Assessing RMM (No rely=high RMM=more sub testing; Yes rely=low RMM=combined approach)
  4. Tests of controls (public issuers must perform)- test operating effectiveness through [RIIO]: Reperformance, Inspection, Inquiry, Observation (most effective)
  5. Reassess RMM to determine DR- based on results of #4, modify sub procedures; Rely high, CR low, DR high, Sub low.
  6. Document basis for conclusions- must document assessment of RMM, basis for assessment, sig risks identified, risks that req ToC to obtain suff evidence.
29
Q

DR in equation form

A

RMM x DR=AR

or.. AR/RMM = DR

30
Q

What are the internal control inherent limitations

A
[COCO]
Collusion
Override by management
Competence/human error
Obsolescence 
* Reasonable assurance and cost/benefit factor
31
Q

List managements assertions

A
[U-PERCV]
Understandability and classification
Presentation and disclosure
Existence or occurrence
Rights and obligations
Completeness and cutoff
Valuation, allocation and accuracy
32
Q

The acceptable level of detection risk is inversely related to the…

A

Assurance provided by substantive tests.

* DR is the risk of overlooking a mistake, as sub testing increases DR decreases a

33
Q

What opinion is expressed when there is a material weakness on effectiveness of IC report for an integrated audit of a nonissuer?

A

Adverse

34
Q

Diff between information processing controls and segregation of duties?

A

Info processing is designed to prevent certain information from being processed, in the form of fulfilling a sales order, without adhering to a specific control, obtaining credit approval.
Segregation of duties involves making certain that the same parties are not responsible for two or more of functions involving ARCC-s

35
Q

What type of work does internal auditor perform?

A

AU-C 610
Procedures to obtain understanding of the entity
Procedures when assigning risk
Substantive procedures

36
Q

What are the risk assessment procedures?

A
[AIIO]
AP
Inquiries
Inspection
Observation of applicable controls
37
Q

How to document the understanding of IC?

A
[FIND]
Flowcharts
IC questionnaire
Narrative or memo
Decision tree
38
Q

How to test of controls?

A

Test cycles for ARCC-s by doing RIIO (reperformance, inspection, inquiry, observation)
PCAOB has to do this
Test operating effectiveness of design (substance, not form)

39
Q

For an issuer (public) company audit of internal control, walkthroughs provide the auditor with primary evidence to

A

Evaluate the effectiveness of the design of controls and confirm whether controls have been implemented.