1. Audit Planning Flashcards

(34 cards)

1
Q

a systematic examination and evaluation of an organization’s IT
infrastructure, policies, and practices.

A

information system (IS) audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Goals of An IS Audit: “to ensure that the organization’s ISs are…”

A

secure, efficient, and aligned with business objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

By conducting IS audits, organizations can…

A

identify vulnerabilities, mitigate risks, and improve their
IT governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

a formal document that outlines the purpose, authority, scope, and objectives of an audit department

A

Audit Charter

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

True or False: The audit charter doesn’t cover the entire scope of audit activities.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

An audit charter must be approved by _________________.

A

senior management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

True or False: Frequent changes in the audit charter can create confusion and lack of clarity about the audit function’s role and responsibilities.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

True or False: procedural aspects should be included in the Audit Charter.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

True or False: Frequent changes to an Audit Charter can reduce the audit team’s effectiveness.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Why is it advisable to not include details that require frequent adjustment? (such as planning, resource allocation, and other details, such as audit fees and expenses)

A

Because the charter requires the approval of the board/senior management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True or False: An audit charter should be reviewed at a maximum annually to ensure that it is aligned with business objectives.

A

False, it should be reviewed at least every year.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

An audit charter includes the following: (hint; there are five points)

A
  • The mission, purpose, and objective of the audit function
  • The scope of the audit function
  • The responsibilities of management
  • The responsibilities of internal auditors
  • The authorized personnel of the internal audit work
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The initial stage of the audit process. It helps to establish the overall audit strategy and the technique to complete the audit.

A

Audit planning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Audit planning makes the audit process more _________
and ____________oriented.

A

structured and objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

An inventory of all the functions/processes/units in the organization.

A

Audit universe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

In a qualitative risk assessment, risk is assessed using qualitative
parameters such as ______, _______, and _____.

A

high, medium, and low.

17
Q

In a _____________ risk assessment, risk is assessed using numerical
parameters and is quantified

18
Q

These are factors that have an impact on risk

19
Q

True or False: if a Risk factor is present, then the risk is decreased.

A

False, Risk factors raise risk

20
Q

A diagram that shows the structure of an organization and the responsibilities and authorities of various positions and job roles.

A

An organization chart

21
Q

An audit plan helps to identify and determine the following: (five points)

A
  • objectives
  • scope
  • periodicity
  • team members
  • method
22
Q

A well-thought-out audit plan helps the auditor do the following: (four points)

A
  • Focus on high-risk areas
  • Identify the required resources for the audit
  • Estimate a budget for the audit
  • Work to a defined structure, which ultimately benefits the auditor as well as the auditee units
23
Q

The approved audit plan should be communicated promptly to the following groups: (three groups)

A
  • Senior management
  • Business functions and other stakeholders
  • The internal audit team
24
Q

a specific audit project conducted as part of the overall annual audit plan.

A

An individual audit assignment

25
Audit Process, Elements of input include:
* knowledge about the organization’s objective * processes and knowledge about regulatory requirements, audit resources, and logistics.
26
Involves the identification and review of policies, standards, and guidelines; setting the audit scope; conducting a risk analysis; and developing an audit approach.
Audit Processing
27
The output of the audit process is the ___________, which includes the auditor’s observations and recommendations.
audit report
28
What is the prime reason for the review of an organization chart?
An IS auditor reviews the organization chart to understand the authority and responsibility of individuals.
29
Who should approve the audit charter of an organization?
Senior Management
30
What should the contents of an audit charter be?
The scope, authority, and responsibilities of the audit function
31
The actions of an IS auditor are primarily influenced by:
Audit Charter
32
Which document provides the overall authority for an auditor to perform an audit?
Audit Charter
33
What is the primary reason for the audit function directly reporting to the audit committee?
The audit function must be independent of the business function and should have direct access to the audit committee of the board
34
Main Risks of Ecommerce Applications
1. Compromise of confidential user data 2. Data integrity issues 3. System unavailability 4. Repudiation of transactions