Year Test 2 Flashcards

LA3, LA4, LA5 & LA6.1

1
Q

Interna auditors should have

A

-Excellent comm skills
-Listening skills
-Soft skills

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

IA’s should report

A

-Weaknesses in systems and;
-Make recommendations for improvement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CAE reports to…

A

…the Board

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the board?

A

Governing body that determines the strat and direction of the org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Role of internal auditing in supporting the AC

A

-Annually review the mandate and charter of AC
-Draft the AC’s meeting agenda for chairmans review and assist w/ distribution
-Enquire fromAC if any training of new members or risk and control is needed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Comm btwn AC and Internal auditing

A

-Ac should meet privately w/ CAE on regular basis to discuss sensitive matters
-CAE should review info submitted to AC for completeness and accuracy
-Ac should be kept informed n emerging trends and successful practices in internal auditing by CAE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What factors contribute to the need of governance

A

-Corporate failures and mismanagement
-Consideration for all stakeholders
-Consideration for the investors
-Need to restore investor confidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the origin and meaning of governance

A

-Origin: Derived from Greek word “gubernare” meaning to steer
Therefore governance means to steer/direct

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Governance definition according to Sir Cadbury

A

-Governance is the way in which orgs are directed and controlled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the Institute of Directors in SA in King IV report state about governance

A

Corporate governance is the exercise of ethical and effective leadership by the governing body towards the achievement of the following governance outcomes
-ethical culture
-good performance
-effective control
-legitimatacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Define stakeholders

A

ppl/groups that are either involved in the org, impacted by the org or have an interest in the org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Types of stakeholders

A

-Shareholders
-Board of directors
-Management
-Assurance providers
-Employees
-Lendors
-Suppliers
-Gov’t
-Society and the local community

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are shareholders

A

-Owners of the org and their interest is represented by the shares they hold in the org
-Many investors know get little about the internal operations and management of the org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is management

A

Group of ppl employed by the org and tasked w/ executing the decisions of the governing body
-Senior management = executives (CEO, CFO, COO etc)
-Some members of management may also be members if the governing body making them executive directors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are assurance providers

A

-They provide assurance (verification) as a service to an individual stakeholder group/org
-Assurance provers are usually independent and objective
Eg: Internal or External auditors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does principle 7 of King IV state

A

The governing body (BoD) should comprise of the appropriate balance of knowledge, skills, XP, diversity and independence for it to discharge its governance roles and responsibilities objectively and effectively

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Board of Directors should comprise of…

A

…majority non-executive directors
And majority of this majority should be independent non-executive directors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

How many executives should be in the BoD

A

2 (CEO and another (preferably CFO)) as it provides BoD w/ a point of interaction w/ management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What are executive directors

A

-They form part of the day-to-day running of the org and receive a salary from the org
Eg: CEO, CFO, COO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are non-executive directors

A

Don’t form part of day-to-day running of the org
Eg: resigned director

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What’s an independent non-executive director

A

-someone w/ no interest or prior involvement in the org
-they aren’t a representative of a shareholder
-have no direct/indirect interest in the org
-in the past 3 financial years they have no been employed by the org or appointed as an external auditor
-they are not a family meme BER if an employee of the org
-free from business relationship

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Can the CEO be the chairperson of the BoD

A

NO!!!
Even a retired CEO cannot chair UNLESS 3 full years have passed since they left the org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

How should the audit committee be compromised of

A
  • 3-5members
    -All independent non-executive directors
    -have at least 1 financial expert
    -Should meet at least 3-4times a year
    -AC performance should be evaluated regularly
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Functions of AC

A

-Oversee various reporting initiatives
-Responsible for oversight function
-Report to BoD on activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Function of AC w/ regard to External Auditor
-Assist w/ selection and discharge of EA -Approve each professional service provided by EA -Review preliminary and final and annual financial statements
26
Function of AC w/ regard to Internal Auditor
-Approve internal audit charter -Review scope of internal audit work -Assess level of coordination btwn IAF and EAF
27
When internal and external assurance providers work together it’s called…
Combined assurance
28
What does the IAF have to consider when performing governance assessment
-Relationship btwn governance, risk and control -Result of other assurance providers work -Results of the other governance related engagements
29
Roles of IAF in terms of governance
They have a dual role 1. IAF forms part of governance structure 2. IAF is responsible for performing assurance and advisory services regarding governance
30
When performing governance assessments what do EA have to consider
1. Their focus is on information provided by management and less on auditing or assessing governance 2. Governance issues considered in certain phases 3. Consider governance structures if the integrity of the client is in question
31
What is the nature of the internal audit work
-To audit/assess/evaluate the governance, risk management and control processes of the org
32
For the CAE to understand the orgs GRMC processes, they must consider how the org...
-Oversees risk management and control -Promotes an ethical culture -Delivers effective performance management and accountability -Structures its management and operating functions
33
According to IIA what is internal control
-IC is action taken by management to enhance that the likelihood that established objectives will be achieved
34
According to SAICA what is internal control
-Methods and procedures accepted by management to help in achievement of management's goal
35
According to COSO what is internal control
A process effected by an entity's BoD, management and other personnel to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting and compliance
36
What are control objectives
-Operational activities -Reporting objectives -Compliance objectives
37
What are the 5 elements of COSO ll
-Control environment -Risk assessment -Control activities -Information and communication -Monitoring
38
What does COSO stand for
-Committee of Sponsoring Organisations
38
What factors affect control environment
-Philosophy and style of SM -Organisational structure -Methods used for communication -HR management
39
SM philosophy and style has 4 elements...
POLC w/ a D -Planning -Organising -Directing -Controlling
40
What are control activities
Policies (what is XP'd) and procedures (policies in action) that management has put in place to ensure that the necessary actions are take to address risks and achieve managements objectives in the org
41
Classifications of control activities
Preventative Detective corrective
42
Types of control activities
-Segregation of duties -Proper authorisation of transactions and activities -Adequate documents and records -Safeguarding of assets and info -Independent reviews
43
Describe segregation of duties
-Purpose is to reduce the opportunities for an individual to make and conceal errors while performing tasks -To achieve this, no individual should be responsible for more than one of -authorising a transaction -recording a transaction -executing a transaction/having custody of assets -Collusion is when @ least personnel members work together to avoid complying w/ an established control
44
Describe adequate documents and records
-Source documents are any electronic/manual document that could explain/give proof of a transaction -SD's should be ...Sequentially pre-numbered to facilitate control over completeness of recording, unused or missing documents ...Prepared at the time the transaction takes place to increase the likelihood of accurately recording details ...Designed to obtain sufficient details to fulfill business and accounting needs
45
What is the responsibility of management in regards to IC
-Design an implement control activities -Keep in mind objectives of control when designing control systems
46
What is the responsibility of EA in regards to IC
-Focus more on financial controls and accounting systems
47
What is the responsibility of IA in regards to IC
-Assess adequacy and test effectiveness -to achieve engagement objectives -IA's DO NOT IMPLEMENT IC
48
What is the purchases and payments cycle
1. Determine the need for goods/services 2. Ordering of goods/services 3. Receiving of goods/services 4. Record of purchases 5. Payment and recording of credit purchases 6. Goods returned
49
Describe Determining the need for goods and service
-First function of procurement process is to determine need for materials and to communicate this to purchasing section -OG requisition form is forwarded to purchasing dept and the copy is kept for reference purposes
50
Describe process of ordering of goods and service
-On receipt of authorised requisition form, purchasing clerk selects a supplier from a pre-approved suppliers list -Purchases order must be authorised by head of purchasing dept based on availability of funds, supplier used and a duly authorised purchase requisition -Copies of PO's are generated and distributed as follows -->OG goes to supplier --->1x copy goes to acc dept -->1x copy goes to receiving section of warehouse -->1x copy goes to dept requesting the goods -->1x copy is filled for reference
51
Describe process of receiving of goods and service
-The receiving dept of the warehouse is responsible for accepting and acknowledging the delivery of goods from suppliers that match valid POs -Prior to acceptance, physical inspection of quantity, quality and description of goods should be carried out -A good received note (GRN) is generated as proof distributed as follows -->OG goes to supplier -->1x copy goes to purchased dept -->1x copy goes to accounting dept --.1x copy goes used to update warehouse records
52
Describe process of recording of purchase
-Purpose is to record purchase in financial accounting records -After receipt of goods, invoice received from supplier s matched to PO, supplier delivery note and goods received note for the following info -->quality check -->quantity -->supplier info -->dates etc -Creditors recons should be performed on regular basis by independent person to ensure that the journalsing and posting activity is performed accurately
53
Describe process of payment and recording of credit purchases
-Extremely important as invalid payments/fictitious payments to creditors may be made -Timing of payments is important as interest may be charged on late payments -2 senior ppl should review supporting docs before payment is authorised -Independent person should reconcile the creditors control acc and creditors ledger monthly
53
Name risks and controls of determining need for goods/services
Risk >>Incorrect/unnecessary goods ordered >>Wastage and liquidity issues Controls >>Stores/production personnel need to confirm that goods are really needed >>Goods only ordered based on authorized requisition
54
Name risks and controls of ordering goods/services
Risk >>Invalid purchase orders for goods/serv Controls >>PO's should be recorded on pre-numbered forms >>Suppliers should be rotated and reviewed on regular basis >>Approved electronic requisitions should be converted to electronic order forms
55
Name risks and controls of receiving of goods/services
Risk >>Quantities of goods received are incorrect >>Goods received are not in good order Control >>Receiving clerk inspects goods to establish condition >>Pre-numbered GRN's used >>Store man signs transfer note or GRN as proof of receipt
56
Name risks and controls of recording of purchases
Risk >>Purchase transactions are not recorded >>Purchase transactions recorded incorrectly Controls >>Invoiced should be compared to PO's, debit note (DN's) and GRN's >>All GRNs received should be kept in pending file and matched to incoming invoices
57
Name risks and controls of payment and recording of creditors
Risk >>Incorrect payments made >>Transactions recorded inaccurately Controls >>Cheque signatories should agree beneficiary and amount w/ supporting documents >>All supporting doc should be cancelled/stamped "paid" >>EFT payments approved electronically through passwords by 2 supervisor employees
58
Name risks and controls of retruning goods
Risk >>Incorrect goods returned >>Goods that aren't damaged returned >>Inventory records incorrect Controls >>Update inventory records >>Pre numbered DN's are issued
59
Name general risks and controls
Risk >>Collusion btwn 2+ employees >>Staff not being skilled enough Controls >>Competent personnel employed >>Segregation, rotation of duties with adequate supervision
60
Exampled of fraud in terms of purchases and payments cycle
Tender fraud Nepotism Cronyism Purchases for personal use Fictitious suppliers paid
61
What are preventative control activities
They prevent undesirable events before they happen
62
What are detective control activities
They identify undesirable events when they do happen
63
What are corrective control activities
They reverse undesirable events
64
Adv + Disadv/limitations of IC
Adv -Achievement of goal -Builds reputation -Prevention of resource losses Diasadv/Limitations -Does not ensure success for the org -Provides reasonable assurance and not absolute assurance
65
Do IC objectives change in IT environment
NO
66
Name the 2 IT controls
General controls Application controls
67
Describe general controls in IT env
-Applied to whole IT env -Controls relating to facilities and hardware -Not software specific EG: passwords, insurance, keycards etc -Have pervasive effect
68
Describe application controls in IT env
-Relate to specific software -Built into specific system to assist in reaching set objectives -Designed to create completeness, accuracy, authorization and validity of data captured and processed Eg: Edit checks, limit test, value test
69
Steps to writing a weakness
1. Start w/ "Inadequate..." or "Lack of..." 2. Follow w/ control act (Seg of dut, independent rev, safeguarding of assets and info...) "Lack of safegaurding of assests..." 3.Then explain using info from scenario
70
When asked to identify a control...
-Who (control operator) -What (type of ctrl) -How (How ctrl is performed) -When (Frequency)
71
When asked to recommend a control
...Make use of should
72
When asked to identify risk
-Identify what could go wrong -make use of the words "could"/"may" -explain impact of risk on org
73
Name the 5 elements of COSO
1. Control Environment 2. Risk Assessment 3. Control Activities 4. Information and Communication 5. Monitoring