Internal Control Flashcards

1
Q

What is the primary purpose for obtaining an understanding of internal controls?

A

to determine the nature, timing, and extent of further audit procedures, including tests of controls and substantive procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

the A can document the understanding of IC by:

A

using flow charts of transaction cycles, completing internal control questionnaires, or y preparing written memoranda

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what is a mgmt control method that could improve mgmt’s ability to supervise company activities effectively

A

est. budgets and forecasts to identify variances from expectations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Detection risk is effectively set by the A when

A

decisions about the nature, timing, and extent of substantive audit procedures are made.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A need to make a preliminary evaluation of the effectiveness of internal control. if ineffective -
if effective -

A

assess control risk at the maximum level.

Consider the possibility of assessing control risk at less than the max. consider cost-benefit issues

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is an example of the inherent limitation of internal controls?

A

possibility of mgmt override

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A must collect evidence to support the reduction in control risk below the max. what kind of evidence should they collect?

A

identifying specific internal controls relevant to specific assertions and then performing test of controls to evaluate the effectiveness of the controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

In what ways does an A gain an understanding of IC?

A

Consider factors that affect the risk of material misstatement.
Identify the types of potential misstatements that can occur.
Ascertain whether the IC have been placed in operation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Why does an A test IC?

A

in order to rely on them and to reduce substantive testing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Inherent risk

A

the risk of a MM occuring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What makes up Control Activities?

A
Segregation of Duties
Controls 
Authorization
Review 
EDP/IT (info processing)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What should an auditor do if they discover a deviation from the prescribed control procedures?

A

Make inquiries to understand the potential consequence of the deviation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a way to compensate for the lack of segregation of duties in a small organization?

A

Allowing for mgmt oversight of incompatible activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Does GAAS require tests of controls to be performed?

A

Only if the auditor plans to assess control risk below maximum.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

auditors are primarily concerned with internal controls that…

A

provide reasonable assurance as to an entity’s ability to prepare FSs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

the A uses the knowledge provided by the understanding of IC and the assessed level of the risk of MM primarily to…

A

Determine the nature, timing, and extent of substantive tests for FS assertions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Why does an A obtain sufficient understanding of IC?

A

To assess the risks of MM.

To design the nature, timing, and extent of further audit procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Foreign Corrupt Practices Act

A

Every publicly held company must devise, document, and maintain internal control sufficient to provide reasonable assurance that IC objectives are met.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What should an A do when the Control risk is assessed at the maximum level?

A

document the assessment of the risks of MM at the FS level and at the relevant assertion level. (this is true whether control risk is assessed at the max level or below)

20
Q

Def: Significant Deficieny

A

A deficiency in internal control that is less severe than a material weakness, yet important enough to merit attention by those charged with governance

21
Q

Def: Material Weakness

A

a deficiency in internal control such that there is a reasonable possibility that a material misstatement of the entity’s financial statements will not be prevented, or detected and corrected on a timely basis.

22
Q

How should deficiencies be communicated?

A

sig def and mat. weaknesses MUST be communicated in WRITING to mgmt and those charged with governance. (no later than 60 days following the report release date) Lesser matters - may be communicated orally, but should be doc.

23
Q

Can an A include in a statement in the A’s communication related to IC that no sig def or mat weak were found?

A

Can say no Material weaknesses found. Cannot say no sig def were found.

24
Q

Is an auditor required to search for sig def?

A

NO

25
Q

What are factors that should be considered in evaluating deficiencies?

A

Entity’s size
Complexity
The nature and diversity of its business activities

26
Q

A control deficiency that is more than a sig def is most likely to result in what form of audit opinion?

A

Adverse

27
Q

How does an A evaluate the competence of an internal auditor?

A

Educational level and professional experience
Professional certification and cont. education
Audit policies programs and procedures
Assignment practices
Supervision and review
Quality of working paper documentation.
Performance evaluation

28
Q

How does an auditor assess the objectivity of internal auditors

A

Consider the org. status and reporting structure of the dept as well as policies est. to maintain objectivity.. This would include determining the org level to which the internal auditors report and includes policies prohibiting the internal auditor from auditing areas where recently assigned.

29
Q

What are the 2 ways the external auditor might use the work of an internal audit function?

A

To provide direct assistance

To obtain audit evidence

30
Q

When using the work of an IA function to obtain audit evidence, what 3 matters should the external auditor evaluate?

A

Objectivity
Competence
Whether the IAF applies a systematic and disciplined approach including quality control

31
Q

What could be so serious that the auditor concludes that a FS audit cannot be performed?

A

There is a substantial risk of intentional misapplication of acct principles.

32
Q

An auditor may decide to assess the control risk at the max level for certain assertions bc the auditor believes

A

control policies and procedures are unlikely to pertain to the assertions

33
Q

What is the objective of tests of details performed as tests of controls?

A

to evaluate whether internal controls operated effectively. It will enable the auditor to detect a control failure

34
Q

regardless of the assessed level of control risk, an auditor would perform some

A

substantive tests to restrict detection risk for significant transaction classes.

35
Q

An auditor may decide to assess the control risk at the mac level for certain assertions bc the auditor believes

A

control policies and procedures are unlikely to pertain to the assertions.

36
Q

What are control activities?

A

policies and procedures that help ensure that mgmt directives are carried out

37
Q

What make up control activities?

A
SCARE
Segregation of duties
Controls (physical)
Authorization
Review (performance)
EDP/IT (info processing)
38
Q

A transaction cycle

A

a group of transactions of a similar type

39
Q

How is segregation of duties best tested?

A

By observing employees as they perform control activities

40
Q

Why do auditors emphasize transaction cycles?

A

Control risk is generally constant within a particular category of transactions, as all transactions are processed the same way. The trans. cycle is the highest level of aggregation for which control risk may be viewed as a constant.

41
Q

Examples of transaction cycles

A
revenue/receipts
disbursements
payroll
inventory
fixed assets
investing
42
Q

What are the 3 duties that must be separated?

A

Authorization of trans. (authorization)
Accounting/record keeping (recording)
Access to assets (custody)

43
Q

Immediately upon receiving checks from customers by mail, a resp employee should

A

Prepare a duplicate listing of checks received.

44
Q

There should be segregation between receiving cash and..

A

posting the AR ledger

45
Q

Debit Memo

A

advises acct that the vendor invoice should not be paid in full due to returned goods. When the shipping dept returns nonconforming goods to a vendor, purchasing should send acct a debit memo.

46
Q

Mailing disbursement checks and remittance advices should be controlled by the EE who

A

signs the check last

47
Q

The authority to accept incoming goods in receiving should be based on a

A

approved purchase order. This will prevent the erroneous acceptance of goods never ordered.