Midterm 2 Flashcards
Study
Which of the following is a proper reason for not conducting tests of controls for nonpublic companies?
The procedures require more audit effort than the projected benefits to be obtained from lowering the control risk.
A reliance strategy is chosen when the auditor:
Plans on conducting tests of controls and Has set the control risk at a lower level.
Internal control is a process designed to provide reasonable assurance regarding the achievement of which objective?
effectiveness and efficiency of operations, compliance with applicable laws and regulations, & reliability of financial reporting
Which of the following statements regarding auditor documentation of the entity’s internal control is correct?
No one particular form of documentation is necessary, and the extent of documentation may vary.
Which of the following is not considered a general control?
Reconciliation of payroll record count with the number of active employees.
An auditor’s flowchart of an entity’s accounting system is a diagrammatic representation that depicts the auditor’s:
understanding of the system.
After obtaining an understanding of an entity’s internal control system, an auditor may set control risk at high for some assertions because the auditor:
believes the internal controls are unlikely to be effective.
The auditor must report the following to the audit committee or others charged with governance:
Significant deficiencies and material weaknesses.
An auditor’s primary consideration regarding an entity’s internal controls is whether they:
affect the financial statement assertions.
Internal controls are designed to achieve company objectives in all of the following areas except:
Reduction of debt financing costs.
Monitoring is a major component of the COSO Internal Control—Integrated Framework. Which of the following is not correct in how the company can implement the monitoring component?
The independent auditor can serve as part of the entity’s control environment and continuous monitoring.
Regardless of the assessed level of control risk, an auditor would perform some:
substantive procedures to restrict detection risk for significant transaction classes.
For nonpublic companies with preliminary control risk assessments set at high, auditors are likely to:
Complete little or no tests of controls.
Significant deficiencies are matters that come to an auditor’s attention that should be communicated to an entity’s audit committee because they represent:
significant deficiencies in the design or operation of the internal control.
SOC 1, Type 2 reports issued by the service organization’s auditor typically:
assess whether the service organization’s controls are suitably designed and operating effectively.
Which of the following represents the correct sequence of audit steps that come after first obtaining an understanding and documenting the entity’s internal control?
Assess Control Risk, Test of Controls, Reassess Control Risk, Determine Extent of Substantive Testing.
Which of the following statements about internal control is correct?
The cost-benefit relationship is a primary criterion that should be considered in designing an internal control system.
Assessing control risk below high involves all of the following except:
concluding that controls are ineffective.
The highest-quality and most reliable audit evidence that segregation of duties is properly implemented is obtained by:
observation by the auditor of the employees performing control activities.
Auditors obtain an understanding of a nonpublic entity’s internal control for the primary purpose of:
Determining the nature, extent, and timing of subsequent audit procedures to be performed.
Understanding each of the components of internal control provides knowledge about:
The design of tests of controls & Factors that affect the risk of material misstatement.
Which of the following is not one of the five major components of internal control?
Human resource background checks.
An auditor anticipates assessing control risk at a low level in an IT environment. Under these circumstances, on which of the following controls would the auditor initially focus?
general controls
An auditor may need to obtain a service auditor’s report when an entity receives accounting services such as payroll from a service organization. Which of the following statements is true regarding this service audit report?
It should include an opinion.
Which of the following audit techniques would most likely provide an auditor with the least assurance about the effectiveness of the operation of a control?
inquiry of entity personnel