Risk Based internal audit plan Flashcards

1
Q
Directors may use a tool called “risk analysis” in preparing work schedules. Which of the following wouldnotbe considered in performing a risk analysis?
Results of prior audits.
Major operating changes.
Skills available on the audit staff.
Financial exposure and potential loss.
A

Skills available on the audit staff.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Two major retail companies, both publicly traded and operating in the same geographic area, have recently merged. Both companies are approximately the same size and have audit departments. Company B has invested heavily in information technology and has electronic data interchange connections with its major vendors.
The audit committee has asked the internal auditors from both companies to analyze risk areas that should be addressed after the merger. The director of internal auditing of Company B has suggested that the two audit groups have a planning meeting to share audit programs, scope of audit coverage, and copies of audit reports that were delivered to their audit committees. Management has also suggested that the auditors review the compatibility of the companies’ two computer systems and control philosophy for individual store operations.
During the first meeting, a disagreement occurs over the approach taken regarding store compliance. The audit director for Company B questions Company A’s extensive use of store compliance testing, stating that the approach is neither responsive to materiality concepts nor an appropriate application of risk assessment. Company A’s audit director presents the following reasoning:
I.You have misconstrued materiality. Materiality is not based only on the size of individual stores; it is also based on the control structure that affects the whole organization.
II.Any deviation from a prescribed control procedure is, by definition, material.
III.The only way to ensure that a material amount of the company’s control structure is covered is to comprehensively audit all stores.
Which statement(s) by the audit director of Company A is (are) valid?
I and II only.
I only.
III only.
I, II, and III.

A

I only.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The first phase of the risk assessment process is to identify and catalog the auditable activities of the organization. Which of the following wouldnotbe considered an auditable activity?
Statutory laws and regulations as they affect the organization.
The agenda established by the audit committee for one of its quarterly meetings.
Computerized information systems.
General ledger account balances.

A

The agenda established by the audit committee for one of its quarterly meetings.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

In planning an audit, the internal auditor should design audit objectives and procedures to address the risk associated with the activity. Risk is defined as:
The failure to adhere to organizational policies, plans, and procedures, or not complying with relevant laws and regulations.
The risk that the balance or class of transactions and related assertions contain misstatements that could be material to the financial statements.
The probability that an event or action may adversely affect the activity under audit.
The failure to accomplish established objectives and goals for operations or programs.

A

The probability that an event or action may adversely affect the activity under audit.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Management is concerned with a recent increase in expenditures and lower profits at a division and has asked the internal audit department to perform an operational audit of the division. Management would like to have the audit completed as quickly as possible and has asked the internal audit department to allocate all possible resources to the task. The director of internal audit is concerned with the time pressure since the internal audit department is heavily involved in a major legal compliance audit that had been requested by the audit committee.
Which of the following factors would be considered theleastimportant in deciding whether existing internal audit resources should be moved from the ongoing legal compliance audit to the management-requested division audit?
The increase in expenditures at the division for the past year.
A financial audit of the division by the external auditor a year ago.
The potential for significant regulatory fines associated with the legal compliance audit.
The potential of fraud associated with the legal compliance audit.

A

A financial audit of the division by the external auditor a year ago.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Two major retail companies, both publicly traded and operating in the same geographic area, have recently merged. Both companies are approximately the same size and have audit departments. Company B has invested heavily in information technology and has electronic data interchange connections with its major vendors.
The audit committee has asked the internal auditors from both companies to analyze risk areas that should be addressed after the merger. The director of internal auditing of Company B has suggested that the two audit groups have a planning meeting to share audit programs, scope of audit coverage, and copies of audit reports that were delivered to their audit committees. Management has also suggested that the auditors review the compatibility of the companies’ two computer systems and control philosophy for individual store operations.
Company A’s audit director, who is also a Certified Internal Auditor, faces an ethical dilemma. For an audit in process, persuasive evidence indicates that a top manager has been involved in insider trading. The extent and type of trading is such that the trading would be considered fraudulent. However, the findings were encountered as a side issue of another audit and are not considered relevant to the compatibility of the computer systems. Regarding this finding, which of the following is the audit director’smostappropriate action?
Discontinue audit work associated with the insider trading since it is not an integral part of the existing audit and the audit committee has established higher priority work for the auditors.
Continue work on the insider trading sufficient to conclusively establish whether fraudulent activity has taken place, then report the findings to the chairperson of the audit committee. Report the matter to government officials if appropriate action is not taken.
Discontinue audit work associated with the insider trading and report the preliminary findings to the company’s external legal counsel for their investigation. Report the legal counsel findings to management.
Discontinue audit work associated with the insider trading. Report the preliminary findings to the chairperson of the audit committee and recommend an investigation.

A

Discontinue audit work associated with the insider trading. Report the preliminary findings to the chairperson of the audit committee and recommend an investigation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Risk models or risk analysis is often used in conjunction with development of long-range audit schedules. The key input in the evaluation of risk is:
Management concerns and preferences.
Specific requirements of the IIAStandards.
Judgment of the internal auditor.
Previous audit results.

A

Judgment of the internal auditor.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Two major retail companies, both publicly traded and operating in the same geographic area, have recently merged. Both companies are approximately the same size and have audit departments. Company B has invested heavily in information technology and has electronic data interchange connections with its major vendors.
The audit committee has asked the internal auditors from both companies to analyze risk areas that should be addressed after the merger. The director of internal auditing of Company B has suggested that the two audit groups have a planning meeting to share audit programs, scope of audit coverage, and copies of audit reports that were delivered to their audit committees. Management has also suggested that the auditors review the compatibility of the companies’ two computer systems and control philosophy for individual store operations.
Assume the auditor concludes that the most reasonable explanation of the observed data in the prior question is that inventory fraud is taking place in the three stores. Which of the following audit activities would provide themostpersuasive evidence that fraud is taking place?
Schedule a surprise inventory audit to include a physical inventory. Investigate areas of inventory shrinkage.
Take a sample of individual store prices and compare them with the sales entered on the cash register for the same items.
Use an integrated test facility (ITF) to compare individual sales transactions with test transactions submitted through the ITF. Investigate all differences.
Interview the three individual store managers to determine if their explanations about the observed differences are the same, then compare their explanations to that of the section manager.

A

Schedule a surprise inventory audit to include a physical inventory. Investigate areas of inventory shrinkage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Corporate management has just implemented a policy that every department must downsize by immediately cutting 10% of each department’s staff and budget. The director of internal auditing has reacted to the organization’s recent plans for downsizing (reducing the size of staff across the board) by notifying the audit managers that the time allocated for all jobs must be cut by 10%. Which of the following statements regarding the director’s action and potential manager’s action would becorrect?
I.The director’s action should result in approximately the same amount of risk coverage as the previous audit plan but reduced by 10%.
II.Individual audit managers can attain 90% of the previously defined audit coverage by uniformly cutting audit procedures by 10%.
III.The director should have reprioritized risks and cut out specific audit engagements rather than cutting 10% across the board.
IV.I, II, and III

A

III only.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Two major retail companies, both publicly traded and operating in the same geographic area, have recently merged. Both companies are approximately the same size and have audit departments. Company B has invested heavily in information technology and has electronic data interchange connections with its major vendors.
The audit committee has asked the internal auditors from both companies to analyze risk areas that should be addressed after the merger. The director of internal auditing of Company B has suggested that the two audit groups have a planning meeting to share audit programs, scope of audit coverage, and copies of audit reports that were delivered to their audit committees. Management has also suggested that the auditors review the compatibility of the companies’ two computer systems and control philosophy for individual store operations.
The audit director for Company B decides to review selected store compliance audit reports issued by the internal audit department of Company A. Upon reviewing the reports, the director comments that most items included in the report are inappropriate because they are very minor and cannot be considered material. The director states that such reports would not be tolerated by the management of Company B. Which assertion(s) by the audit director of Company A is (are) valid?
I.These are the kinds of reports we have provided since the company has been in operation, and they have served our company well.
II.The reports are consistent with management’s control philosophy and are an integral part of the overall control environment.
III.Materiality is in the eyes of the beholder. Any deviation is considered material by my management.
I only.
II only.
III only.
II and III.

A

II only.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

The audit process is one of critical thinking, analysis, and careful evaluation. All mechanical procedures are integrated into a larger context of thoughtful inquiry. All audits include a description and analysis of internal controls. Auditees are selected in a number of ways, with risk being the primary basis for selection. The departments being considered for possible audit in the coming year and attributes of those departments are listed below.
Department Assets Ann Costs Prob
Production A $50k $700k 10%
Production B $5M $10M 1%
Production C $1M $1M 1%
Purchasing $50k $150k 10%
Marketing $50k $500k 10%
Shipping $60k $100k 50%
Security $10k $100k 90%
Travel $6k $30k 50%
All of these departments except two are on the potential list of auditees because of a risk analysis performed by the audit director. Production Department A is on the list because the president thinks too many bottlenecks occur in that department. The marketing department is on the list because the chief of security received an anonymous phone call accusing a marketing manager of accepting substantial financial kickbacks from a media outlet. Internal controls seem adequate in all departments, with the possible exception of marketing.
What is the audit director’s most logical definition of risk of loss to be used in selecting auditees?
Probability of loss.
Amount of risk exposure times the probability of loss.
Amount of assets in a department.
Amount of annual costs in department.

A

Amount of risk exposure times the probability of loss.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The audit process is one of critical thinking, analysis, and careful evaluation. All mechanical procedures are integrated into a larger context of thoughtful inquiry. All audits include a description and analysis of internal controls. Auditees are selected in a number of ways, with risk being the primary basis for selection. The departments being considered for possible audit in the coming year and attributes of those departments are listed below.
Department Assets Ann Costs Prob
Production A $50k $700k 10%
Production B $5M $10M 1%
Production C $1M $1M 1%
Purchasing $50k $150k 10%
Marketing $50k $500k 10%
Shipping $60k $100k 50%
Security $10k $100k 90%
Travel $6k $30k 50%
All of these departments except two are on the potential list of auditees because of a risk analysis performed by the audit director. Production Department A is on the list because the president thinks too many bottlenecks occur in that department. The marketing department is on the list because the chief of security received an anonymous phone call accusing a marketing manager of accepting substantial financial kickbacks from a media outlet. Internal controls seem adequate in all departments, with the possible exception of marketing.
Which department would most likely need a pure operational (nonfinancial) audit?
Production A.
Marketing.
Production C.
Purchasing.

A

Production A.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The internal auditor is considering performing risk analysis as a basis for determining which areas of the organization ought to be examined. Which one of the following statements iscorrectregarding risk analysis?
The highest risk assessment should always be assigned to the area with the largest potential loss.
The highest risk assessment should always be assigned to the area with highest probability of occurrence.
The extent to which management judgments are required in an area could serve as a risk factor in assisting the auditor in making a comparative risk analysis.
Risk analysis must be reduced to quantitative terms in order to provide meaningful comparisons across an organization.
Audit risk.
Detection risk.
Inherent risk.
Control risk.

A

The extent to which management judgments are required in an area could serve as a risk factor in assisting the auditor in making a comparative risk analysis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
Which one of the following items includes the other three items?
Audit risk.
Detection risk.
Inherent risk.
Control risk.
A

Audit risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

In an audit of a purchasing department, which of the following generally would be considered a risk factor?
Purchase specifications are developed by the department requesting the material.
There is a failure to rotate purchases among suppliers included on an approved vendor list.
Purchases are made from parties related to buyers or other company officials.
Purchases are made against blanket or open purchase orders for certain types of items.

A

Purchases are made from parties related to buyers or other company officials.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which of the following represent(s) appropriate internal audit action in response to the risk assessment process?
I.The low-risk areas may be delegated to the external auditor, but the high-risk areas should be performed by the internal auditing function.
II.The high-risk areas should be integrated into an audit plan along with the high-priority requests of management and the audit committee.
III.The risk analysis should be used in determining an annual audit work plan; therefore, the risk analysis should be performed only on an annual basis.
II only.
III only.
I only.
I and III only.

A

II only.

17
Q

When gathering data, an audit team identified both subjective and objective criteria for measuring audit risk. Which one of the following risk factors ismostobjective?
Prior audit findings.
Changes in staff, systems, or the environment.
Size of the audit unit.
Comfort with operating management.

A

Size of the audit unit.

18
Q

Employees using personal computers have been reporting occupational injuries and claiming substantial worker?s compensation benefits. Working papers of an operational audit to determine the extent of company exposure to such personal injury liability should include:
Reviews of documentation supporting purchases of personal computers.
Analysis of claims by type of equipment and extensiveness of use by individual employees.
Listings of all personal computers in use and the employees who are assigned to use them.
Confirmations from insurance carriers as to claims paid under worker?s compensation policies in force.

A

Analysis of claims by type of equipment and extensiveness of use by individual employees.

19
Q

Two major retail companies, both publicly traded and operating in the same geographic area, have recently merged. Both companies are approximately the same size and have audit departments. Company B has invested heavily in information technology and has electronic data interchange connections with its major vendors.
The audit committee has asked the internal auditors from both companies to analyze risk areas that should be addressed after the merger. The director of internal auditing of Company B has suggested that the two audit groups have a planning meeting to share audit programs, scope of audit coverage, and copies of audit reports that were delivered to their audit committees. Management has also suggested that the auditors review the compatibility of the companies’ two computer systems and control philosophy for individual store operations.
The two organizations agree to share data on store operations. The data reveal that three stores in Company A are characterized by:
+Significantly lower gross margins.
+Higher-than-average sales volume.
+Higher levels of employee bonuses.
The three stores are part of a set of six that are managed by a relatively new section manager. In addition, the store managers of the three stores are also relatively new. Themostlikely cause of the observed data is:
Problems with employee training and employee ability to meet customer needs.
Promotional activities that offer large discounts coupled with the payment of commissions to employees who reach targeted sales goals.
The relative inexperience of the store managers.
Fraudulent activity whereby goods are taken from the stores thus results in the lower gross margins.

A

Promotional activities that offer large discounts coupled with the payment of commissions to employees who reach targeted sales goals.

20
Q

The audit process is one of critical thinking, analysis, and careful evaluation. All mechanical procedures are integrated into a larger context of thoughtful inquiry. All audits include a description and analysis of internal controls. Auditees are selected in a number of ways, with risk being the primary basis for selection.
All of these departments except two are on the potential list of auditees because of a risk analysis performed by the audit director. Production Department A is on the list because the president thinks too many bottlenecks occur in that department. The marketing department is on the list because the chief of security received an anonymous phone call accusing a marketing manager of accepting substantial financial kickbacks from a media outlet. Internal controls seem adequate in all departments, with the possible exception of marketing.
If there is fraud in the marketing department, which of the following would be beyond the scope of the auditor’s responsibility?
Determining the effects of the wrongdoing.
Discussing the wrongdoing with an appropriate level of management.
Including the wrongdoing in a report that will go to the audit committee.
Informing the wrongdoer of his or her legal rights.

A

Informing the wrongdoer of his or her legal rights.

21
Q

Two major retail companies, both publicly traded and operating in the same geographic area, have recently merged. Both companies are approximately the same size and have audit departments. Company B has invested heavily in information technology and has electronic data interchange (EDI) connections with its major vendors.
The audit committee has asked the internal auditors from both companies to analyze risk areas that should be addressed after the merger. The director of internal auditing of Company B has suggested that the two audit groups have a planning meeting to share audit programs, scope of audit coverage, and copies of audit reports that were delivered to their audit committees. Management has also suggested that the auditors review the compatibility of the companies’ two computer systems and control philosophy for individual store operations.
Which of the following would be theleastimportant risk factor when considering the ability to integrate the two companies’ computer systems?
The compatibility of existing operating systems and database structures.
The number of programmers and systems analysts employed by each company.
The size of company databases and the number of database servers used.
The extent of EDI connections with vendors.

A

The number of programmers and systems analysts employed by each company.

22
Q
Which of the following would not be considered in performing a risk analysis exercise?
Auditor skills.
Results of prior audits.
System changes.
System complexity.
A

Auditor skills.

23
Q
Which of the following auditable activities represents thegreatestrisk to a postmerger manufacturing corporation and would therefore most likely be subjected to an audit?
Combining purchasing functions.
Combining imprest funds.
Combining marketing functions.
Combining legal functions.
A

Combining purchasing functions.

24
Q

The director of internal auditing for an organization has just completed a risk assessment process, identified the areas with the highest risks, and assigned an audit priority to each. Which of the following conclusions logically follows from such a risk assessment and is (are) consistent with the IIAStandards?
I.Items should be quantified as to risk in the rank order of quantifiable dollar exposure to the organization.
II.The risk priorities should be in order of major control deficiencies.
III.The risk process, though quantified, is the result of professional judgments about both exposures and probability of occurrences.
II and III only.
I only.
III only.
I, II, and III.

A

III only.

25
Q

The director of internal auditing was reviewing recent reports that had recommended additional audits because of risk and exposure to the company. Which of the following represents thegreatestrisk to the company and should be the next assignment?
Payment had been made for routine inventory items without a purchase order or receiving report.
Three prenumbered receiving reports were missing.
Several times cash receipts had been held over an extra day before depositing.
Several purchase orders were issued without purchase requisitions.

A

Payment had been made for routine inventory items without a purchase order or receiving report.

26
Q
During a computer risk assessment process, which of the following wouldnotbe considered an auditable activity?
Systems software.
Print software.
Telecommunications software.
Application software.
A

Print software.

27
Q
What should the audit strategy be?
It should be cycle based.
It should be request based.
It should be knowledge based.
It should be risk based.
A

It should be risk based.

28
Q

Two major retail companies, both publicly traded and operating in the same geographic area, have recently merged. Both companies are approximately the same size and have audit departments. Company B has invested heavily in information technology and has electronic data interchange connections with its major vendors.
The audit committee has asked the internal auditors from both companies to analyze risk areas that should be addressed after the merger. The director of internal auditing of Company B has suggested that the two audit groups have a planning meeting to share audit programs, scope of audit coverage, and copies of audit reports that were delivered to their audit committees. Management has also suggested that the auditors review the compatibility of the companies’ two computer systems and control philosophy for individual store operations.
In analyzing the differences between the two companies, the audit director of Company A notes that Company A has a formal corporate code of ethics while Company B does not. The code of ethics covers such things as purchase agreements and relationships with vendors as well as a host of other issues to guide individual behavior within the firm. Which of the following statements regarding the existence of the code of ethics in Company A can be logically inferred?
I.Company A exhibits a higher standard of ethical behavior than does Company B.
II.Company A has established objective criteria by which an individual’s actions can be evaluated.
III.The absence of a formal corporate code of ethics in Company B would prevent a successful audit of ethical behavior in that company.
I and II.
III only.
II only.
II and III.

A

II only.

29
Q

Management is concerned with a recent increase in expenditures and lower profits at a division and has asked the internal audit department to perform an operational audit of the division. Management would like to have the audit completed as quickly as possible and has asked the internal audit department to allocate all possible resources to the task. The director of internal audit is concerned with the time pressure since the internal audit department is heavily involved in a major legal compliance audit that had been requested by the audit committee.
Which of the following comments are correct regarding the assessment of risk associated with the two projects?
I.Activities requested by the audit committee should always be considered higher risk than those requested by management.
II.Activities with higher-dollar budgets should always be considered higher risk than those with lower-dollar budgets.
III.Risk should always be measured by the potential dollar or adverse exposure to the organization.
I and III.
I only.
III only.
II only.

A

III only.

30
Q

The director of internal auditing set up a computerized spreadsheet to facilitate the risk assessment process involving a number of different divisions in the organization. The spreadsheet included the following factors:
+Pressure on divisional management to meet profit goals.
+Complexity of operations.
+Competence of divisional personnel.
+The dollar amount of subjectively influenced accounts in the division, such as accounts where management’s judgment can affect the expense. Example: postretirement benefits.
The director used a group meeting of audit managers to reach a consensus on the competence of divisional personnel. Other factors were assessed as high, medium, or low by either the director or an audit manager who had audited the division. The director assigned a weight ranging from 0.5 to 1.0 to each factor and then computed a composite risk score. Which of the following statements iscorrectregarding the risk assessment process?
The weighting is subjective and should have been determined through a process such as multiple regression analysis.
The risk analysis would not be appropriate because it mixes both quantitative and qualitative factors, thereby making expected values calculation impossible.
Using a subjective group consensus to assess personnel competence is appropriate.
Assessing factors at discrete levels such as high, medium, and low is inappropriate for the risk assessment process because the ratings are not quantifiable.

A

Using a subjective group consensus to assess personnel competence is appropriate.

31
Q
Factors that should be considered when evaluating audit risk in a functional area include:
1 Volume of transactions.
2 Degree of system integration.
3 Years since last audit.
4 Significant management turnover.
5 (Dollar) value of “assets at risk.”
6 Average value per transaction.
7 Results of last audit.
Factors thatbestdefine materiality of audit risk are:
3, 4, and 6.
1, 5, and 6.
1 through 7.
2, 4, and 7.
A

1, 5, and 6.

32
Q

The audit process is one of critical thinking, analysis, and careful evaluation. All mechanical procedures are integrated into a larger context of thoughtful inquiry. All audits include a description and analysis of internal controls. Auditees are selected in a number of ways, with risk being the primary basis for selection.
All of these departments except two are on the potential list of auditees because of a risk analysis performed by the audit director. Production Department A is on the list because the president thinks too many bottlenecks occur in that department. The marketing department is on the list because the chief of security received an anonymous phone call accusing a marketing manager of accepting substantial financial kickbacks from a media outlet. Internal controls seem adequate in all departments, with the possible exception of marketing.
The internal auditing department is assigned responsibility for investigating fraud by its charter. If obtaining access to outside media outlet records and personnel were not possible, thebestaction an auditor could take to investigate the allegation of marketing kickbacks would be to:
Vouch any material past charge-off of receivables.
Develop a financial/behavioral profile of the suspect.
Obtain a list of approved media outlets.
Search for unrecorded liabilities from media outlets.

A

Develop a financial/behavioral profile of the suspect.