Chapter 9 Flashcards
(100 cards)
All audit process steps (7)
- Client acceptance
- Audit planning
- Assess RMM
- Develop risk response
- Perform risk response
- Conclusion
- Reporting
Risk Assessment Procedures (2)
- Understand entity and environment
- Obtain evidence on design and implementation of controls
Auditor goals in risk assessment (2)
- Understand internal controls
- Evaluate components of the system of internal control
Type of risk assessment procedures (6)
- Inspection
- Inquiry
- Examination
- Observation
- Information system walkthrough
- Understanding IT general controls
Documenting the System of Internal Control (3)
- Narrative
- Flowchart
- Internal control questionnaire
Narrative written description of a client’s internal control areas (4)
- The origin of every doc & rec in the system
- All processing that takes place
- The disposition of every document and record in the system
- Key control relevant to control risk assessment (separation of duties, authorization and approval, and verification)
Flowchart (3)
- Symbolic/diagrammatic representation of the client’s doc
- Include the same 4 characteristics as narratives
- Helps identify inadequacies with a clear understanding of how the system operates
Internal Control Questionnaire (2)
- Questions about control in each audit area, including control environment
- Yes/no response
Flowchart advantage
Easy to read and update compared to narratives
Internal control questionnaire disadvantages (2)
- No overview of the system
- Bias from poor design
Which documenting strategies work well together?
Flowchart & questionnaire
Why evaluate system of internal control?
To evaluate the strengths and weaknesses of the system
How to test effectiveness of strong control?
Effective if it minimize RMM of transaction, balance, disclosure, and assertions
What to do if there is no control test
Gather evidence to support understanding of internal control
Consideration when deciding to rely on controls (2)
- Will it improve audit efficiency?
- Is it necessary? (Because of automated transactions)
What do to when identifying a control deficiency?
Identify RMM and adjust RR at overall assertion level
What happens when auditor concludes that substantive procedures are not enough?
Consider modifying opinion due to scope limitation
Levels of absence of internal control (3)
- Control deficiency
- Significant deficiency
- Material weakness
Control deficiency
Misstatement are not detected/corrected on a timely basis
Control deficiency component (2)
- Design deficiency
- Operation deficiency
Design deficiency
Missing or poorly designed controls
Operation deficiency
Well designed but not well operated by a person
Significant deficiency
Important control deficiencies
Significant deficiency components (4)
- Fraud
- Uncorrected communicated deficiencies by the auditor
- Management’s failure to respond to significant risk
- Restatement of previously issued FS