Year Test 2 Flashcards

LA3, LA4, LA5 & LA6.1

1
Q

Interna auditors should have

A

-Excellent comm skills
-Listening skills
-Soft skills

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

IA’s should report

A

-Weaknesses in systems and;
-Make recommendations for improvement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CAE reports to…

A

…the Board

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the board?

A

Governing body that determines the strat and direction of the org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Role of internal auditing in supporting the AC

A

-Annually review the mandate and charter of AC
-Draft the AC’s meeting agenda for chairmans review and assist w/ distribution
-Enquire fromAC if any training of new members or risk and control is needed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Comm btwn AC and Internal auditing

A

-Ac should meet privately w/ CAE on regular basis to discuss sensitive matters
-CAE should review info submitted to AC for completeness and accuracy
-Ac should be kept informed n emerging trends and successful practices in internal auditing by CAE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What factors contribute to the need of governance

A

-Corporate failures and mismanagement
-Consideration for all stakeholders
-Consideration for the investors
-Need to restore investor confidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the origin and meaning of governance

A

-Origin: Derived from Greek word “gubernare” meaning to steer
Therefore governance means to steer/direct

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Governance definition according to Sir Cadbury

A

-Governance is the way in which orgs are directed and controlled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the Institute of Directors in SA in King IV report state about governance

A

Corporate governance is the exercise of ethical and effective leadership by the governing body towards the achievement of the following governance outcomes
-ethical culture
-good performance
-effective control
-legitimatacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Define stakeholders

A

ppl/groups that are either involved in the org, impacted by the others it or have an interest in the org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Types of stakeholders

A

-Shareholders
-Board of directors
-Management
-Assurance providers
-Employees
-Lendors
-Suppliers
-Gov’t
-Society and the local community

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are shareholders

A

-Owners of the org and their interest is represented by the shares they hold in the org
-Many investors know get little about the internal operations and management of the org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is management

A

Group of ppl employed by the org and tasked w/ executing the decisions of the governing body
-Senior management = executives (CEO, CFO, COO etc)
-Some members of management may also be members if the governing body making them executive directors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are assurance providers

A

-They provide assurance (verification) as a service to an individual stakeholder group/org
-Assurance provers are usually independent and objective
Eg: Internal or External auditors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does principle 7 of King IV state

A

The governing body (BoD) should comprise of the appropriate balance of knowledge, skills, XP, diversity and independence for it to discharge its governance roles and responsibilities objectively and effectively

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Board of Directors should comprise of…

A

…majority non-executive directors
And majority of this majority should be independent non-executive directors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

How many executives should be in the BoD

A

2 (CEO and another (preferably CFO)) as it provides BoD w/ a point of interaction w/ management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What are executive directors

A

-They form part of the day-to-day running of the org and receive a salary from the org
Eg: CEO, CFO, COO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are non-executive directors

A

Don’t form part of day-to-day running of the org
Eg: resigned director

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What’s an independent non-executive director

A

-someone w/ no interest or prior involvement in the org
-they aren’t a representative of a shareholder
-have no direct/indirect interest in the org
-in the past 3 financial years they have no been employed by the org or appointed as an external auditor
-they are not a family meme BER if an employee of the org
-free from business relationship

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Can the CEO be the chairperson of the BoD

A

NO!!!
Even a retired CEO cannot chair UNLESS 3 full years have passed since they left the org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

How should the audit committee be compromised of

A
  • 3-5members
    -All independent non-executive directors
    -have at least 1 financial expert
    -Should meet at least 3-4times a year
    -AC performance should be evaluated regularly
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Functions of AC

A

-Oversee various reporting initiatives
-Responsible for oversight function
-Report to BoD on activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Function of AC w/ regard to External Auditor

A

-Assist w/ selection and discharge of EA
-Approve each professional service provided by EA
-Review preliminary and final and annual financial statements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Function of AC w/ regard to Internal Auditor

A

-Approve internal audit charter
-Review scope of internal audit work
-Assess level of coordination btwn IAF and EAF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

When internal and external assurance providers work together it’s called…

A

Combined assurance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What does the IAF have to consider when performing governance assessment

A

-Relationship btwn governance, risk and control
-Result of other assurance providers work
-Results of the other governance related engagements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Roles of IAF in terms of governance

A

They have a dual role
1. IAF forms part of governance structure
2. IAF is responsible for performing assurance and advisory services regarding governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

When performing governance assessments what do EA have to consider

A
  1. Their focus is on information provided by management and less on auditing or assessing governance
  2. Governance issues considered in certain phases
  3. Consider governance structures if the integrity of the client is in question
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

What is the nature of the internal audit work

A

-To audit/assess/evaluate the governance, risk management and control processes of the org

32
Q

For the CAE to understand the orgs GRMC processes, they must consider how the org…

A

-Oversees risk management and control
-Promotes an ethical culture
-Delivers effective performance management and accountability
-Structures its management and operating functions

33
Q

According to IIA what is internal control

A

-IC is action taken by management to enhance that the likelihood that established objectives will be achieved

34
Q

According to SAICA what is internal control

A

-Methods and procedures accepted by management to help in achievement of management’s goal

35
Q

According to COSO what is internal control

A

A process effected by an entity’s BoD, management and other personnel to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting and compliance

36
Q

What are control objectives

A

-Operational activities
-Reporting objectives
-Compliance objectives

37
Q

What are the 5 elements of COSO ll

A

-Control environment
-Risk assessment
-Control activities
-Information and communication
-Monitoring

38
Q

What does COSO stand for

A

-Committee of Sponsoring Organisations

38
Q

What factors affect control environment

A

-Philosophy and style of SM
-Organisational structure
-Methods used for communication
-HR management

39
Q

SM philosophy and style has 4 elements…

A

POLC w/ a D
-Planning
-Organising
-Directing
-Controlling

40
Q

What are control activities

A

Policies (what is XP’d) and procedures (policies in action) that management has put in place to ensure that the necessary actions are take to address risks and achieve managements objectives in the org

41
Q

Classifications of control activities

A

Preventative
Detective
corrective

42
Q

Types of control activities

A

-Segregation of duties
-Proper authorisation of transactions and activities
-Adequate documents and records
-Safeguarding of assets and info
-Independent reviews

43
Q

Describe segregation of duties

A

-Purpose is to reduce the opportunities for an individual to make and conceal errors while performing tasks
-To achieve this, no individual should be responsible for more than one of
-authorising a transaction
-recording a transaction
-executing a
transaction/having custody
of assets
-Collusion is when @ least personnel members work together to avoid complying w/ an established control

44
Q

Describe adequate documents and records

A

-Source documents are any electronic/manual document that could explain/give proof of a transaction
-SD’s should be
…Sequentially pre-numbered to facilitate control over completeness of recording, unused or missing documents
…Prepared at the time the transaction takes place to increase the likelihood of accurately recording details
…Designed to obtain sufficient details to fulfill business and accounting needs

45
Q

What is the responsibility of management in regards to IC

A

-Design an implement control activities
-Keep in mind objectives of control when designing control systems

46
Q

What is the responsibility of EA in regards to IC

A

-Focus more on financial controls and accounting systems

47
Q

What is the responsibility of IA in regards to IC

A

-Assess adequacy and test effectiveness
-to achieve engagement objectives
-IA’s DO NOT IMPLEMENT IC

48
Q

What is the purchases and payments cycle

A
  1. Determine the need for goods/services
  2. Ordering of goods/services
  3. Receiving of goods/services
  4. Record of purchases
  5. Payment and recording of credit purchases
  6. Goods returned
49
Q

Describe Determining the need for goods and service

A

-First function of procurement process is to determine need for materials and to communicate this to purchasing section
-OG requisition form is forwarded to purchasing dept and the copy is kept for reference purposes

50
Q

Describe process of ordering of goods and service

A

-On receipt of authorised requisition form, purchasing clerk selects a supplier from a pre-approved suppliers list
-Purchases order must be authorised by head of purchasing dept based on availability of funds, supplier used and a duly authorised purchase requisition
-Copies of PO’s are generated and distributed as follows
–>OG goes to supplier
—>1x copy goes to acc dept
–>1x copy goes to receiving section of warehouse
–>1x copy goes to dept requesting the goods
–>1x copy is filled for reference

51
Q

Describe process of receiving of goods and service

A

-The receiving dept of the warehouse is responsible for accepting and acknowledging the delivery of goods from suppliers that match valid POs
-Prior to acceptance, physical inspection of quantity, quality and description of goods should be carried out
-A good received note (GRN) is generated as proof distributed as follows
–>OG goes to supplier
–>1x copy goes to purchased dept
–>1x copy goes to accounting dept
–.1x copy goes used to update warehouse records

52
Q

Describe process of recording of purchase

A

-Purpose is to record purchase in financial accounting records
-After receipt of goods, invoice received from supplier s matched to PO, supplier delivery note and goods received note for the following info
–>quality check
–>quantity
–>supplier info
–>dates etc
-Creditors recons should be performed on regular basis by independent person to ensure that the journalsing and posting activity is performed accurately

53
Q

Describe process of payment and recording of credit purchases

A

-Extremely important as invalid payments/fictitious payments to creditors may be made
-Timing of payments is important as interest may be charged on late payments
-2 senior ppl should review supporting docs before payment is authorised
-Independent person should reconcile the creditors control acc and creditors ledger monthly

53
Q

Name risks and controls of determining need for goods/services

A

Risk
»Incorrect/unnecessary goods ordered
»Wastage and liquidity issues
Controls
»Stores/production personnel need to confirm that goods are really needed
»Goods only ordered based on authorized requisition

54
Q

Name risks and controls of ordering goods/services

A

Risk
»Invalid purchase orders for goods/serv
Controls
»PO’s should be recorded on pre-numbered forms
»Suppliers should be rotated and reviewed on regular basis
»Approved electronic requisitions should be converted to electronic order forms

55
Q

Name risks and controls of receiving of goods/services

A

Risk
»Quantities of goods received are incorrect
»Goods received are not in good order
Control
»Receiving clerk inspects goods to establish condition
»Pre-numbered GRN’s used
»Store man signs transfer note or GRN as proof of receipt

56
Q

Name risks and controls of recording of purchases

A

Risk
»Purchase transactions are not recorded
»Purchase transactions recorded incorrectly
Controls
»Invoiced should be compared to PO’s, debit note (DN’s) and GRN’s
»All GRNs received should be kept in pending file and matched to incoming invoices

57
Q

Name risks and controls of payment and recording of creditors

A

Risk
»Incorrect payments made
»Transactions recorded inaccurately
Controls
»Cheque signatories should agree beneficiary and amount w/ supporting documents
»All supporting doc should be cancelled/stamped “paid”
»EFT payments approved electronically through passwords by 2 supervisor employees

58
Q

Name risks and controls of retruning goods

A

Risk
»Incorrect goods returned
»Goods that aren’t damaged returned
»Inventory records incorrect
Controls
»Update inventory records
»Pre numbered DN’s are issued

59
Q

Name general risks and controls

A

Risk
»Collusion btwn 2+ employees
»Staff not being skilled enough
Controls
»Competent personnel employed
»Segregation, rotation of duties with adequate supervision

60
Q

Exampled of fraud in terms of purchases and payments cycle

A

Tender fraud
Nepotism
Cronyism
Purchases for personal use
Fictitious suppliers paid

61
Q

What are preventative control activities

A

They prevent undesirable events before they happen

62
Q

What are detective control activities

A

They identify undesirable events when they do happen

63
Q

What are corrective control activities

A

They reverse undesirable events

64
Q

Adv + Disadv/limitations of IC

A

Adv
-Achievement of goal
-Builds reputation
-Prevention of resource losses
Diasadv/Limitations
-Does not ensure success for the org
-Provides reasonable assurance and not absolute assurance

65
Q

Do IC objectives change in IT environment

A

NO

66
Q

Name the 2 IT controls

A

General controls
Application controls

67
Q

Describe general controls in IT env

A

-Applied to whole IT env
-Controls relating to facilities and hardware
-Not software specific
EG: passwords, insurance, keycards etc
-Have pervasive effect

68
Q

Describe application controls in IT env

A

-Relate to specific software
-Built into specific system to assist in reaching set objectives
-Designed to create completeness, accuracy, authorization and validity of data captured and processed
Eg: Edit checks, limit test, value test

69
Q

Steps to writing a weakness

A
  1. Start w/ “Inadequate…” or “Lack of…”
  2. Follow w/ control act (Seg of dut, independent rev, safeguarding of assets and info…)
    “Lack of safegaurding of assests…”
    3.Then explain using info from scenario
70
Q

When asked to identify a control…

A

-Who (control operator)
-What (type of ctrl)
-How (How ctrl is performed)
-When (Frequency)

71
Q

When asked to recommend a control

A

…Make use of should

72
Q

When asked to identify risk

A

-Identify what could go wrong
-make use of the words “could”/”may”
-explain impact of risk on org

73
Q

Name the 5 elements of COSO

A
  1. Control Environment
  2. Risk Assessment
  3. Control Activities
  4. Information and Communication
  5. Monitoring