#5 Internal Control - Concepts and Standards Flashcards

1
Q

List the disadvantages of flowcharts to document the auditor’s understanding of internal controls.

A
  1. Tedious and time consuming to initially prepare.

2. Might fail to recognize deficiencies by getting overly absorbed in details.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Identify 3 Ways auditor’s might document their understanding of internal controls.

A
  1. Flowcharts of transaction cycles
  2. Internal Control Questionnaires
  3. Narrative write-ups (memos)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

List the disadvantages of ICQ’s to document the auditor’s understanding of internal control.

A
  1. These are generic and not tailored to any client specifically
  2. Irrelevant questions may annoy clients
  3. Client might conceal deficiencies by incorrect answers.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the purpose of performing a walkthrough?

A

Obtain some feedback as to whether the way the auditor has understood (and documented) the entity’s internal controls is consistent with the way the entity is actually processing such transactions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Identify 3 procedures an auditor might perform to obtain an understanding of internal controls?

A
  1. Inquiry of appropriate personnel
  2. Observation of client’s activities
  3. Review entity’s documentation of internal controls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

List the advantages of narratives (memos) to document the auditor’s understanding of internal controls?

A
  1. Tailored to client
  2. Can be detailed or as general as desired
  3. Easy to prepare
  4. Easy to read
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

List the disadvantages of narratives (memos) to document the auditor’s understanding of internal controls.

A
  1. Writing such a memo is rather unstructured, lacking a systematic approach
  2. It may be rather easy to overlook relevant internal control issues.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Define transaction cycle.

A

A group of essentially homogeneous transactions, that is, transactions of the same basic type.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

List the advantages of using flowcharts to document the auditor’s understanding of internal controls.

A
  1. Systematic approach with emphasis on important Accounting records
  2. Tailored to client
  3. Fairly easy for others to review and understand
  4. Easy to update from year to year.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

List the advantages of ICQ’s to document the auditor’s understanding of internal controls.

A
  1. Can have a standard form for many clients

2. Deficiencies are easily indicated by “no” answers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

When should the auditor assess the design effectiveness of internal control?

A

In planning every audit under GAAS, as a basis for determining the nature, timing and extent of further audit procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Identify 3 inherent limitations. Of internal controls.

A
  1. Cost of controls should not exceed expected benefits.
  2. Mistakes may occur due to carelessness, fatigue, misjudgements, etc.
  3. Segregation of duties mat break down due to collusion or management override of internal controls.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

When should the auditor assess the operating effectiveness of internal control?

A

Whenever the auditor contemplates a reliance strategy (which means the same thing as “assessing control Risk at less than the maximum level”) and only after performing the appropriate tests of control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Identify 2 reasons for assessing control Risk at the maximum level.

A
  1. The auditor believe s that the design of internal control is ineffective.
  2. The auditor believes that reliance on internal control (and performing applicable tests of controls) is not an efficient audit strategy compared to a wholly substantive audit approach
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Identify 3 risk assessment procedures that might be used by an auditor to obtain an understanding of the entity and its environment, including its internal control.

A

1 Inquires of management and others;

  1. Observation and inspection;
  2. Analytical procedures.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Define Internal Control

A

A process - effected by those charged with governance, management, and other personnel - designed to provide reasonable assurance about the achievement of the entity’s objectives with regards to reliability of financial reporting, effectiveness and efficiency of operations, and compliance with applicable laws and regulations.

17
Q

Identify the five interrelated components of internal controls.

A
  1. Control Environment
  2. Risk Assessment
  3. Control Activities
  4. Information and Communication systems
  5. Monitoring
18
Q

What is meant by the term Monitoring as it relates to internal controls?

A

The policies and procedures involving the ongoing assessment of the effectiveness of internal control over time.

19
Q

What is meant by the term control activities?

A

The policies and procedures that help ensure that management directives are carried out especially those related to (1) segregation of duties, (2) physical controls, (3) authorization of transactions, (4) Performance reviews, and (5) information processing.

20
Q

What is meant by the term Control Environment?

A

The policies and procedures that determine the overall control consciousness of the entity, sometimes called “the tone at the top.”

21
Q

What is meant by the term information and communication systems?

A

The policies and procedures related to the identification, capture, and exchange of information in a form and time frame that enable people to carry out their responsibilities.

22
Q

What are three objectives of internal control as identified in the definition of internal control?

A
  1. Reliability of financial reporting
  2. Effectiveness and efficiency of operations
  3. Compliance with applicable laws and regulations.
23
Q

What is meant by the term risk assessment?

A

The policies and procedures involving the identification, prioritization and analysis of relevant risks as a basis for managing those risks.

24
Q

Define the term risk assessment procedures.

A

Procedures performed to obtain an understanding of the entity and its environment, including its internal control.

25
Q

List some examples of appropriate responses by the auditor to risks of material misstatement at the financial statement level.

A

Assign more experienced staff to the engagement;
Provide closer supervision;
Use specialists;
Use more unpredictable audit procedures.

26
Q

When must tests of control be performed?

A

When the auditor’s risk assessment includes and “expectation of the operating effectiveness of controls.” Note that this is frequently referred to as “relying” on internal control as a partial basis for the auditor’s conclusions, or “assessing control risk at less than the maximum level.”

27
Q

What specific matters should the auditor document regarding the auditor’s assessment of the risks of material misstatement?

A

The discussion with key members of the audit team about the risks of material fraud and errors;
The major elements of the understanding of the five components of internal control;
The assessment of the risks of material misstatement ( at the financial statement and relevant assertion levels) and the basis for that assessment;
The risks identified and the related controls the auditor evaluated.

28
Q

Define the term significant risks.

A

Risks that the auditor believes require special audit consideration.

29
Q

What is the auditors responsibility for assessing the risk of material misstatment

A

The auditor should identify and assess the risks of material misstatement (1) at the financial statement level and (2) at the relevant assertion level related to classes of transactions, account balances, and disclosures.

30
Q

Describe the auditor’s requirements for communicating deficiencies in an entity’s internal controls?

A
  1. The auditor must communicate in writing the significant deficiencies (including material weaknesses) identified in the audit.
  2. The auditor may choose to communicate lesser matter, too.
31
Q

Define material weakness.

A
A deficiency 
(or combination of deficiencies) internal control such that there is a reasonable possibility that a material misstatement of the entity's financial statements will not be prevented or detected and corrected on a timely basis.
32
Q

What is meant by the term deficiency in design?

A

When a control necessary to meet the control objective is missing, or when the control objective is not always met, even if the control operates as designed.

33
Q

Define “significant deficiency.”

A

A deficiency (or combination of deficiencies) internal control that is less severe than a material weakness, yet important enough to merit attention by those charged with governance.

34
Q

What is meant by the term deficiency in operation?

A

When a properly designed control does not operate as designed, or when the person performing the control doesnt have the authority or competence to effectively perform the control.

35
Q

Describe the timing of the required communication of significant deficiencies in internal control.

A

Under AICPA Professional standards, written communication is required no later than 60 days after the audit report release date (including matters communicated orally during the audit.)

36
Q

Why isnt a “systematic and disciplined approach, including quality control” a relevant consideration when the external auditor uses an internal audit function to provide direct assistance?

A

Because the work performed by the internal audit function is subject to the external auditor’s direction, supervision and review.

37
Q

When using the work of the internal audit function to obtain audit evidence, what three matter should the external auditor evaluate?

A
  1. Objectivity-The internal audit function’s organizational status and the objectivity of the internal auditors;
  2. Competence of the internal auditors; and
  3. Whether the internal audit function applies a “systematic and disciplined approach, including quality control.”
38
Q

What are the two ways the external auditor might use the work of an internal audit function?

A
  1. To obtain audit evidence; and

2 To provide direct assistance.

39
Q

When using the internal audit function to provide direct assistance, what two matters should the external auditor evaluate?

A
  1. Objectivity - the internal audit function’s organizational status and the objectivity of the internal auditors; and
  2. Competence of the internal auditors.