Deck 7: Auditing Internal Control Over Financial Reporting

Full screen (f)
exit full mode
Question
All companies must follow the guidelines of AS5.
Use Space or
up arrow
down arrow
to flip the card.
Question
Based on PCAOB guidelines,the audit of ICFR and financial statements audit should be conducted as an "integrated audit."
Question
In a public company,management's report on internal control must be signed by the members of the audit committee.
Question
When auditing a public company,the auditor must form an opinion on the effectiveness of internal control over financial reporting,or issue a disclaimer in the event of a scope limitation.
Question
The person in charge of authorizing credit to customers does not properly understand what constitutes a credit risk.This is an example of

A) A management deficiency.
B) A design deficiency.
C) A deficiency in operation.
D) This is not an internal control deficiency.
Question
The PCAOB makes it clear that the CEO and CFO are responsible for the internal control over financial reporting and the preparation of the statements.
Question
In determining the extent to which the auditor may use the work of others in the audit of ICFR,the auditor should do all of the following except:

A) Test some of the work performed by others to evaluate the quality and effectiveness of their work.
B) Evaluate the nature of the controls subjected to the work of others.
C) Evaluate the competence and objectivity of the individuals who performed the work.
D) All of these are required.
Question
Management documentation should include all of the following except:

A) Documentation regarding the auditor's evaluation of internal controls.
B) Documentation regarding management's testing and evaluation of the controls.
C) Documentation regarding the safeguarding of assets.
D) Documentation on the controls designed in all five components of internal control.
Question
An "integrated audit" as stated in Section 404 of the Sarbanes-Oxley Act means

A) The auditor must consider the integrated thoughts and ideas of everyone on the audit staff.
B) The auditor must conduct two audits, one on the effectiveness of internal control and one on the financial statements, in an integrated way.
C) The auditor must integrate the same objectives whether auditing internal control or auditing the financial statements.
D) Two independent CPA firms must work together on the audit.
Question
An auditor performing an audit of internal control over financial reporting would be required to

A) Rely on the work of internal auditors.
B) Test all of the entity's internal controls.
C) Form an opinion on the effectiveness of internal control.
D) Randomly identify accounts for an audit of internal control.
Question
Section 404 of the Sarbanes-Oxley Act requires the auditor to provide which of the following?

A) Reasonable assurance on the financial statements, absolute assurance on internal control.
B) Reasonable assurance on internal control, absolute assurance on the financial statements.
C) Absolute assurance on both the financial statements and internal control.
D) Reasonable assurance on both the financial statements and internal control.
Question
Most public companies must follow the guidelines of AS5.
Question
In order for an external auditor to complete an audit of a public company,the entity's management must comply with all of the following except:

A) Accept responsibility for the effectiveness of the entity's internal control over financial reporting.
B) Evaluate the effectiveness of the entity's internal control over financial reporting using suitable control criteria.
C) Support its evaluation with sufficient evidence, including documentation.
D) Present an oral assessment of the effectiveness of the entity's internal control over financial reporting as of the end of the entity's most recent fiscal year.
Question
According to the PCAOB,who is responsible for the reliability of the internal controls over financial reporting process of an entity?

A) The entity's CEO and/or CFO.
B) The entity's board of directors.
C) An internal control specialist.
D) The external auditor.
Question
Which of the following is not a primary objective of internal control as established by COSO?

A) Efficiency and effectiveness of operations.
B) Effective purchasing systems.
C) Compliance with laws and regulations.
D) Reliable financial reporting.
Question
A deficiency that implies that there is a reasonable possibility of misstatement in the financial statements that is significant but not material is

A) A material weakness.
B) A significant deficiency.
C) An insignificant deficiency.
D) A probable deficiency.
Question
The likelihood of an event is "more than remote" when it is "highly possible."
Question
In a public company,management must assess and report on internal control over financial reporting.
Question
Which of the following is not a topic that requires special consideration by management during management's internal control assessment process and by the auditor during the audit of internal control?

A) Multiple locations and business units.
B) Service organizations.
C) The role of the auditor in internal control.
D) Safeguarding assets.
Question
The main goal of auditing internal control is

A) To allow the auditor to fix any internal control deficiencies.
B) To form an opinion on the ability of internal controls to prevent fraud.
C) To assure management that internal control is preventing all material misstatements on the financial statements.
D) To evaluate the effectiveness of controls over all relevant financial statement disclosures in the financial statements.
Question
S&H Associates has just performed an audit of Bob's Bikes.S&H was unable to obtain a written representation from management about internal control.Which of the following is true?

A) S&H must still assume that management has assessed the effectiveness of internal control.
B) Depending on other factors in the audit, S&H can still issue an unqualified opinion.
C) S&H should consider this situation a limitation on the scope of the audit.
D) Management does not need to give S&H a letter if it has disclosed all known internal control deficiencies.
Question
Which of the following statements is false?

A) The PCAOB focuses on the financial reporting objective of internal controls.
B) Management is required to base internal controls on a recognized control framework.
C) Most U.S. companies use the internal control framework developed by COSO.
D) All controls relevant to financial reporting are accounting controls.
Question
Which of the following is true regarding management's documentation of internal controls?

A) Some documentation should focus on controls designed to detect fraud.
B) Documentation should focus on controls over the interim financial reporting process.
C) Documentation must be done on paper.
D) Inadequate documentation is usually considered an insignificant deficiency in internal control.
Question
Which of the following audit procedures would an auditor be least likely to perform using a generalized computer audit program?

A) Searching records of accounts receivable balances for credit balances.
B) Investigating inventory balances for possible damaged goods.
C) Selecting accounts receivable for positive and negative confirmations.
D) Listing of unusually large inventory balances.
Question
ACL is an example of

A) An EDI software package.
B) An IT software package.
C) Software that allows auditors to retrieve and evaluate data from entity systems.
D) A type of networking.
Question
Which of the following concerning the auditor's report on internal control over financial reporting is correct?

A) The auditor's report contains an opinion on the effectiveness of internal control over financial reporting based on the auditor's independent work.
B) In the report on internal control over financial reporting, the auditor can issue only a qualified or an unqualified opinion.
C) The auditor needs to state management's assessment of internal control over financial reporting, but does not necessarily need to comment on whether he or she agrees.
D) An unqualified opinion is required if a material weakness is identified.
Question
Which of the following is not an element of management's assessment process for the effectiveness of internal control?

A) Evaluating the likelihood that failure of a control could result in a misstatement.
B) Determining the locations and business units to include in the evaluation.
C) Determining significant deficiencies and material weaknesses in controls.
D) Obtaining the auditor's assessment of the internal control effectiveness.
Question
The auditor is least likely to use generalized audit software to

A) Perform analytical procedures on the entity's data.
B) Access information stored on the entity's IT files.
C) Identify material weaknesses in the entity's IT controls.
D) Test the accuracy of the entity's computations.
Question
The primary purpose of a generalized computer audit program is to allow the auditor to

A) Use the entity's employees to perform routine audit checks of the electronic data processing records that otherwise would be done by the auditor's staff accountants.
B) Test the logic of computer programs used in the entity's electronic data processing systems.
C) Select larger samples from the entity's electronic data processing records than would otherwise be selected without the generalized program.
D) Independently process electronic data processing records.
Question
Public reporting on the effectiveness of internal control over financial reporting,as required by the Sarbanes-Oxley Act,includes

A) A statement that the public accounting firm that audited the financial statements has provided input on the design of internal controls.
B) A statement of management's responsibility for establishing and maintaining adequate internal control over financial reporting.
C) An explicit statement as to whether management agrees with the public accounting firm's assessment of internal controls.
D) A detailed statement describing changes or additions to the internal control environment that occurred in the current year.
Question
Prior to issuing a report on internal controls over financial reporting,an auditor is required to

A) Perform procedures sufficient to identify all control deficiencies.
B) Communicate to management, in writing, all control deficiencies previously included in written communication from the internal auditors.
C) Communicate to management, in writing, all control deficiencies identified during the audit and inform the audit committee when such a communication has been made.
D) Represent that no significant deficiencies were noted during the audit of internal control.
Question
Which of the following is least likely to represent a material weakness in internal control for Flynt Corporation?

A) Flynt Corporation's computer systems were not working properly for two days; consequently, employees needed to do all reconciliations manually.
B) Flynt Corporation's CFO was arrested last year for embezzling money from the entity.
C) For the current year, the auditor found a material misstatement in Flynt's sales recognition that was undetected by the internal controls.
D) Flynt's audit committee is deemed to be ineffective.
Question
Which of the following is not true?

A) The auditor should not communicate with management until the audit of internal control over financial reporting is finished.
B) Written communication between the auditor and management about internal control over financial reporting should include the definitions of control deficiencies, significant deficiencies, and material weaknesses.
C) The auditor should not include in the audit report that no significant deficiencies were noted during an audit of internal control over financial reporting.
D) If fraud is discovered, the auditor must report it to the appropriate level of management.
Question
Which of the following is an advantage of generalized computer audit packages?

A) They are all written in one identical computer language.
B) They can be used for audits of entities that use differing IT equipment and file formats.
C) They have reduced the need for the auditor to study input controls for IT-related procedures.
D) Their use can be substituted for a relatively large part of the required compliance testing.
Question
Management's written representations concerning internal control are

A) Addressed to the users of the financial statements.
B) Normally drafted by management.
C) Included in the auditor's final report.
D) Signed by the CEO and CFO.
Question
The five step process in the audit of ICFR includes

A) Form an opinion on the safeguarding of the entity's assets.
B) Identify controls to test using a top-down, risk-based approach.
C) Form an opinion on the fairness of the presentation of the financial statements.
D) Form an opinion on the effectiveness of internal controls in meeting operational goals.
Question
In the context of an audit of internal controls,the auditor must document all of the following except:

A) The extent to which he or she relied upon work performed by others.
B) The auditor's understanding and evaluation of the design of each of the components of the entity's internal control over financial reporting.
C) Transcripts of the auditor's discussion with management concerning the points at which misstatements could occur.
D) The evaluation of any deficiencies discovered that could result in a modification of the auditor's report.
Question
The PCAOB's definition of internal control over financial reporting specifically mentions all of the following control activities except:

A) The maintenance of asset records.
B) The segregation of duties.
C) The authorization by management of receipts and expenditures.
D) The safeguarding of assets.
Question
An "integrated audit"

A) Will, in most cases, lead to a substantive audit strategy.
B) Denies the auditor access to information about the entity's controls.
C) May be performed by two separate audit firms.
D) Is comprised of audits of internal control over financial reporting and of financial statements.
Question
To obtain an understanding of significant processes and relevant subprocesses,auditors would be least likely to use which of the following techniques?

A) Reviewing management documentation.
B) Inquiry.
C) Scanning.
D) Transaction walkthroughs.
Question
You are performing an audit on North South Natural Gas (NSNG).Alana,an NSNG employee,has responsibility for reconciling bank statements with the entity's cash accounts.You determine,however,that Alana has never been taught how to reconcile statements.In effect,the statements have not been properly reconciled for two years.How would you judge the significance of this control deficiency? How would you classify this deficiency?
Question
Trumpeter Corporation is a small publicly traded company that specializes in the restoration and sale of fine musical instruments.The audit committee is made up of a CEO from a technology company,a college accounting professor,and a local marketing executive.All are sufficiently independent from management.Members of the audit committee meet three times a year.Each time they meet,a different member,who chooses the topics to discuss,leads the meeting.The audit committee then sends the minutes of its meetings to the entity's CFO.Solely from this information,what are your conclusions about this audit committee's role within the control environment?
Question
Identify indicators of a material weakness in internal control over financial reporting.
Question
Section 404 of the Sarbanes-Oxley Act includes which of the following?

A) A requirement that management of a publicly traded company issues an assessment of internal control that covers the entire year.
B) Specific guidance on what constitutes adequate internal control.
C) A requirement that management of a publicly traded company accepts responsibility for establishing and maintaining adequate internal controls.
D) A requirement that management of a publicly traded company issues an assessment regarding the efficiency of internal control for the year.
Question
Which of the following is false?

A) Regardless of the achieved level of control risk in connection with the audit of the financial statements, auditing standards require the auditor to perform some substantive procedures for all significant accounts and disclosures.
B) The absence of misstatements in financial statements is considered convincing evidence that existing controls are effective.
C) The audit of internal control is intended to draw conclusions about the effectiveness of internal control over financial reporting as of a specific date.
D) The auditor is required by AS5 to evaluate the implications of the financial statement audit for the effectiveness of internal control over financial reporting.
Question
According to the COSO definition of safeguarding of assets

A) Controls over financial reporting are effective if they provide reasonable assurance that asset losses will not occur.
B) Controls over financial reporting are effective if they provide reasonable assurance that losses are properly reflected in the financial statements.
C) Controls over financial reporting are effective if they provide reasonable assurance that asset losses will not occur and that losses are properly reflected in the financial statements.
D) There is no way to create controls that will provide reasonable assurance that asset losses will not occur.
Question
AS5 requires that the auditor appropriately document the processes,procedures,judgments,and results relating to the audit of internal control.Specifically,what must this documentation include?
Question
When an auditor tests a computerized accounting system,which of the following is true of the test data approach?

A) Test data are processed by the entity's computer programs under the auditor's control.
B) Test data must consist of all possible valid and invalid conditions.
C) Testing a program at year end provides assurance that the entity's processing was accurate for the entire year.
D) Several transactions of each type must be tested.
Question
When testing a computerized accounting system,which of the following is false regarding the test data approach?

A) The test data need to consist of only those valid and invalid conditions in which the auditor is interested.
B) Only one transaction of each type needs be tested.
C) Test data are processed by the entity's computer programs under the auditor's control.
D) The test data must consist of all possible valid and invalid conditions.
Question
A modification of the standard report is required for all of the following conditions except:

A) There is a restriction on the scope of the engagement.
B) There is other information contained in management's report on internal control.
C) Management has concluded that internal controls are not effective.
D) A significant subsequent event has occurred since the date being reported on.
Question
An auditor will use the IT test data method in order to gain certain assurances with respect to the

A) Input data.
B) Machine capacity.
C) Procedures contained within the program.
D) Degree of keypunching accuracy.
Question
Which of the following statements included in management's assessment of the effectiveness of internal control over financial reporting would be considered acceptable for issuing an unqualified opinion?

A) Nothing has come to management's attention to suggest that the entity's internal control is less than effective.
B) Statements suggesting only negative assurance.
C) A conclusion that the entity's internal control over financial reporting is effective when a material weakness exists at the end of the reporting period.
D) Disclosure of material weaknesses corrected during the period.
Question
AAA & Associates recently finished auditing LinktheEarth Corporation's internal control over financial reporting.AAA found a number of material weaknesses in the entity's internal control.LinktheEarth's management remediated all of the weaknesses that AAA found.However,the auditors did not have sufficient time to retest the controls.What report should AAA issue with regards to internal control over financial reporting at year-end?

A) Unqualified report.
B) Adverse report.
C) Qualified report.
D) Disclaimer on opinion.
Question
For which of the following internal controls would an auditor be least likely to perform tests of internal controls closer to the "as of" date?

A) Withdrawals from Federal Bank of more than $5 million must include a manager's signature.
B) At the end of each day at Federal Bank, the total cash in the vault is reconciled with daily registers of deposits and withdrawals.
C) Federal Bank has just started establishing trusts for its customers and it has only set up ten such trusts. Before making an investment for a trust, bank employees must verify that the investment is in accordance with stated investment policies.
D) On an annual basis, Federal Bank management performs credit checks on its loan customers before determining the value of loans it will not be able to collect on.
Question
You are an experienced audit senior.The new staff accountant on your audit team does not understand what a control deficiency is.Give him a definition of "control deficiency." Include examples of two types of control deficiencies.
Question
CBA Associates is auditing a large publicly traded company.The audit of internal controls over financial reporting has been properly planned and the auditors have already identified controls to test using a top-down,risk-based approach.What is the next step? Give three examples of procedures that may be completed in the next step in the audit.
Question
The advantages of generalized audit software include all of the following except:

A) It involves auditing while the data are being processed (real-time).
B) It is easy to use.
C) The time to develop the application is usually short.
D) An entire population can be examined in some instances.
Question
On the audit of Technology Unlimited,a leading manufacturer of computer chips,the external audit staff discovers that the internal audit staff has performed extensive evaluation and testing on the control environment.What should the external auditors do to determine the extent to which they may use the work of the internal audit staff? Can the external audit staff rely on the internal audit staff for evaluating and testing the control environment?
Question
Examples of entity-level controls include

A) Management's risk assessment process.
B) Controls to monitor results of operations.
C) The period-end financial reporting process.
D) All of these are examples of entity-level controls.
Question
Which of the following is true of generalized audit software packages?

A) They can be used only in auditing online computer systems.
B) They can be used on any computer without modification.
C) They each have their own characteristics that the auditor must carefully consider before using in a given audit situation.
D) They enable the auditor to perform all manual test procedures less expensively.
Question
Discuss entity-level controls and provide examples of these types of controls.
Question
Information Nation has two hundred locations spread across the fifty states.Twenty of the locations are considered to be individually important,but fifty of the locations are not important even when aggregated from the others.Five locations deal with foreign exchange trading.These locations are not considered important,but they are important when aggregated with the other locations.As an auditor,discuss the considerations involved in testing multiple locations and group the locations accordingly (provide how many locations are included in each group).Include the treatment that each group should receive from the auditor.
Question
Discuss the differences between a control deficiency,a significant deficiency,a material weakness,and the two dimensions of the control deficiency - likelihood and magnitude.
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/63
auto play flashcards
Play
simple tutorial
Full screen (f)
exit full mode
Deck 7: Auditing Internal Control Over Financial Reporting
1
All companies must follow the guidelines of AS5.
False
2
Based on PCAOB guidelines,the audit of ICFR and financial statements audit should be conducted as an "integrated audit."
True
3
In a public company,management's report on internal control must be signed by the members of the audit committee.
False
4
When auditing a public company,the auditor must form an opinion on the effectiveness of internal control over financial reporting,or issue a disclaimer in the event of a scope limitation.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
5
The person in charge of authorizing credit to customers does not properly understand what constitutes a credit risk.This is an example of

A) A management deficiency.
B) A design deficiency.
C) A deficiency in operation.
D) This is not an internal control deficiency.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
6
The PCAOB makes it clear that the CEO and CFO are responsible for the internal control over financial reporting and the preparation of the statements.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
7
In determining the extent to which the auditor may use the work of others in the audit of ICFR,the auditor should do all of the following except:

A) Test some of the work performed by others to evaluate the quality and effectiveness of their work.
B) Evaluate the nature of the controls subjected to the work of others.
C) Evaluate the competence and objectivity of the individuals who performed the work.
D) All of these are required.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
8
Management documentation should include all of the following except:

A) Documentation regarding the auditor's evaluation of internal controls.
B) Documentation regarding management's testing and evaluation of the controls.
C) Documentation regarding the safeguarding of assets.
D) Documentation on the controls designed in all five components of internal control.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
9
An "integrated audit" as stated in Section 404 of the Sarbanes-Oxley Act means

A) The auditor must consider the integrated thoughts and ideas of everyone on the audit staff.
B) The auditor must conduct two audits, one on the effectiveness of internal control and one on the financial statements, in an integrated way.
C) The auditor must integrate the same objectives whether auditing internal control or auditing the financial statements.
D) Two independent CPA firms must work together on the audit.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
10
An auditor performing an audit of internal control over financial reporting would be required to

A) Rely on the work of internal auditors.
B) Test all of the entity's internal controls.
C) Form an opinion on the effectiveness of internal control.
D) Randomly identify accounts for an audit of internal control.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
11
Section 404 of the Sarbanes-Oxley Act requires the auditor to provide which of the following?

A) Reasonable assurance on the financial statements, absolute assurance on internal control.
B) Reasonable assurance on internal control, absolute assurance on the financial statements.
C) Absolute assurance on both the financial statements and internal control.
D) Reasonable assurance on both the financial statements and internal control.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
12
Most public companies must follow the guidelines of AS5.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
13
In order for an external auditor to complete an audit of a public company,the entity's management must comply with all of the following except:

A) Accept responsibility for the effectiveness of the entity's internal control over financial reporting.
B) Evaluate the effectiveness of the entity's internal control over financial reporting using suitable control criteria.
C) Support its evaluation with sufficient evidence, including documentation.
D) Present an oral assessment of the effectiveness of the entity's internal control over financial reporting as of the end of the entity's most recent fiscal year.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
14
According to the PCAOB,who is responsible for the reliability of the internal controls over financial reporting process of an entity?

A) The entity's CEO and/or CFO.
B) The entity's board of directors.
C) An internal control specialist.
D) The external auditor.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
15
Which of the following is not a primary objective of internal control as established by COSO?

A) Efficiency and effectiveness of operations.
B) Effective purchasing systems.
C) Compliance with laws and regulations.
D) Reliable financial reporting.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
16
A deficiency that implies that there is a reasonable possibility of misstatement in the financial statements that is significant but not material is

A) A material weakness.
B) A significant deficiency.
C) An insignificant deficiency.
D) A probable deficiency.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
17
The likelihood of an event is "more than remote" when it is "highly possible."
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
18
In a public company,management must assess and report on internal control over financial reporting.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
19
Which of the following is not a topic that requires special consideration by management during management's internal control assessment process and by the auditor during the audit of internal control?

A) Multiple locations and business units.
B) Service organizations.
C) The role of the auditor in internal control.
D) Safeguarding assets.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
20
The main goal of auditing internal control is

A) To allow the auditor to fix any internal control deficiencies.
B) To form an opinion on the ability of internal controls to prevent fraud.
C) To assure management that internal control is preventing all material misstatements on the financial statements.
D) To evaluate the effectiveness of controls over all relevant financial statement disclosures in the financial statements.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
21
S&H Associates has just performed an audit of Bob's Bikes.S&H was unable to obtain a written representation from management about internal control.Which of the following is true?

A) S&H must still assume that management has assessed the effectiveness of internal control.
B) Depending on other factors in the audit, S&H can still issue an unqualified opinion.
C) S&H should consider this situation a limitation on the scope of the audit.
D) Management does not need to give S&H a letter if it has disclosed all known internal control deficiencies.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
22
Which of the following statements is false?

A) The PCAOB focuses on the financial reporting objective of internal controls.
B) Management is required to base internal controls on a recognized control framework.
C) Most U.S. companies use the internal control framework developed by COSO.
D) All controls relevant to financial reporting are accounting controls.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
23
Which of the following is true regarding management's documentation of internal controls?

A) Some documentation should focus on controls designed to detect fraud.
B) Documentation should focus on controls over the interim financial reporting process.
C) Documentation must be done on paper.
D) Inadequate documentation is usually considered an insignificant deficiency in internal control.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
24
Which of the following audit procedures would an auditor be least likely to perform using a generalized computer audit program?

A) Searching records of accounts receivable balances for credit balances.
B) Investigating inventory balances for possible damaged goods.
C) Selecting accounts receivable for positive and negative confirmations.
D) Listing of unusually large inventory balances.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
25
ACL is an example of

A) An EDI software package.
B) An IT software package.
C) Software that allows auditors to retrieve and evaluate data from entity systems.
D) A type of networking.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
26
Which of the following concerning the auditor's report on internal control over financial reporting is correct?

A) The auditor's report contains an opinion on the effectiveness of internal control over financial reporting based on the auditor's independent work.
B) In the report on internal control over financial reporting, the auditor can issue only a qualified or an unqualified opinion.
C) The auditor needs to state management's assessment of internal control over financial reporting, but does not necessarily need to comment on whether he or she agrees.
D) An unqualified opinion is required if a material weakness is identified.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
27
Which of the following is not an element of management's assessment process for the effectiveness of internal control?

A) Evaluating the likelihood that failure of a control could result in a misstatement.
B) Determining the locations and business units to include in the evaluation.
C) Determining significant deficiencies and material weaknesses in controls.
D) Obtaining the auditor's assessment of the internal control effectiveness.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
28
The auditor is least likely to use generalized audit software to

A) Perform analytical procedures on the entity's data.
B) Access information stored on the entity's IT files.
C) Identify material weaknesses in the entity's IT controls.
D) Test the accuracy of the entity's computations.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
29
The primary purpose of a generalized computer audit program is to allow the auditor to

A) Use the entity's employees to perform routine audit checks of the electronic data processing records that otherwise would be done by the auditor's staff accountants.
B) Test the logic of computer programs used in the entity's electronic data processing systems.
C) Select larger samples from the entity's electronic data processing records than would otherwise be selected without the generalized program.
D) Independently process electronic data processing records.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
30
Public reporting on the effectiveness of internal control over financial reporting,as required by the Sarbanes-Oxley Act,includes

A) A statement that the public accounting firm that audited the financial statements has provided input on the design of internal controls.
B) A statement of management's responsibility for establishing and maintaining adequate internal control over financial reporting.
C) An explicit statement as to whether management agrees with the public accounting firm's assessment of internal controls.
D) A detailed statement describing changes or additions to the internal control environment that occurred in the current year.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
31
Prior to issuing a report on internal controls over financial reporting,an auditor is required to

A) Perform procedures sufficient to identify all control deficiencies.
B) Communicate to management, in writing, all control deficiencies previously included in written communication from the internal auditors.
C) Communicate to management, in writing, all control deficiencies identified during the audit and inform the audit committee when such a communication has been made.
D) Represent that no significant deficiencies were noted during the audit of internal control.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
32
Which of the following is least likely to represent a material weakness in internal control for Flynt Corporation?

A) Flynt Corporation's computer systems were not working properly for two days; consequently, employees needed to do all reconciliations manually.
B) Flynt Corporation's CFO was arrested last year for embezzling money from the entity.
C) For the current year, the auditor found a material misstatement in Flynt's sales recognition that was undetected by the internal controls.
D) Flynt's audit committee is deemed to be ineffective.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
33
Which of the following is not true?

A) The auditor should not communicate with management until the audit of internal control over financial reporting is finished.
B) Written communication between the auditor and management about internal control over financial reporting should include the definitions of control deficiencies, significant deficiencies, and material weaknesses.
C) The auditor should not include in the audit report that no significant deficiencies were noted during an audit of internal control over financial reporting.
D) If fraud is discovered, the auditor must report it to the appropriate level of management.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
34
Which of the following is an advantage of generalized computer audit packages?

A) They are all written in one identical computer language.
B) They can be used for audits of entities that use differing IT equipment and file formats.
C) They have reduced the need for the auditor to study input controls for IT-related procedures.
D) Their use can be substituted for a relatively large part of the required compliance testing.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
35
Management's written representations concerning internal control are

A) Addressed to the users of the financial statements.
B) Normally drafted by management.
C) Included in the auditor's final report.
D) Signed by the CEO and CFO.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
36
The five step process in the audit of ICFR includes

A) Form an opinion on the safeguarding of the entity's assets.
B) Identify controls to test using a top-down, risk-based approach.
C) Form an opinion on the fairness of the presentation of the financial statements.
D) Form an opinion on the effectiveness of internal controls in meeting operational goals.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
37
In the context of an audit of internal controls,the auditor must document all of the following except:

A) The extent to which he or she relied upon work performed by others.
B) The auditor's understanding and evaluation of the design of each of the components of the entity's internal control over financial reporting.
C) Transcripts of the auditor's discussion with management concerning the points at which misstatements could occur.
D) The evaluation of any deficiencies discovered that could result in a modification of the auditor's report.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
38
The PCAOB's definition of internal control over financial reporting specifically mentions all of the following control activities except:

A) The maintenance of asset records.
B) The segregation of duties.
C) The authorization by management of receipts and expenditures.
D) The safeguarding of assets.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
39
An "integrated audit"

A) Will, in most cases, lead to a substantive audit strategy.
B) Denies the auditor access to information about the entity's controls.
C) May be performed by two separate audit firms.
D) Is comprised of audits of internal control over financial reporting and of financial statements.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
40
To obtain an understanding of significant processes and relevant subprocesses,auditors would be least likely to use which of the following techniques?

A) Reviewing management documentation.
B) Inquiry.
C) Scanning.
D) Transaction walkthroughs.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
41
You are performing an audit on North South Natural Gas (NSNG).Alana,an NSNG employee,has responsibility for reconciling bank statements with the entity's cash accounts.You determine,however,that Alana has never been taught how to reconcile statements.In effect,the statements have not been properly reconciled for two years.How would you judge the significance of this control deficiency? How would you classify this deficiency?
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
42
Trumpeter Corporation is a small publicly traded company that specializes in the restoration and sale of fine musical instruments.The audit committee is made up of a CEO from a technology company,a college accounting professor,and a local marketing executive.All are sufficiently independent from management.Members of the audit committee meet three times a year.Each time they meet,a different member,who chooses the topics to discuss,leads the meeting.The audit committee then sends the minutes of its meetings to the entity's CFO.Solely from this information,what are your conclusions about this audit committee's role within the control environment?
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
43
Identify indicators of a material weakness in internal control over financial reporting.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
44
Section 404 of the Sarbanes-Oxley Act includes which of the following?

A) A requirement that management of a publicly traded company issues an assessment of internal control that covers the entire year.
B) Specific guidance on what constitutes adequate internal control.
C) A requirement that management of a publicly traded company accepts responsibility for establishing and maintaining adequate internal controls.
D) A requirement that management of a publicly traded company issues an assessment regarding the efficiency of internal control for the year.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
45
Which of the following is false?

A) Regardless of the achieved level of control risk in connection with the audit of the financial statements, auditing standards require the auditor to perform some substantive procedures for all significant accounts and disclosures.
B) The absence of misstatements in financial statements is considered convincing evidence that existing controls are effective.
C) The audit of internal control is intended to draw conclusions about the effectiveness of internal control over financial reporting as of a specific date.
D) The auditor is required by AS5 to evaluate the implications of the financial statement audit for the effectiveness of internal control over financial reporting.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
46
According to the COSO definition of safeguarding of assets

A) Controls over financial reporting are effective if they provide reasonable assurance that asset losses will not occur.
B) Controls over financial reporting are effective if they provide reasonable assurance that losses are properly reflected in the financial statements.
C) Controls over financial reporting are effective if they provide reasonable assurance that asset losses will not occur and that losses are properly reflected in the financial statements.
D) There is no way to create controls that will provide reasonable assurance that asset losses will not occur.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
47
AS5 requires that the auditor appropriately document the processes,procedures,judgments,and results relating to the audit of internal control.Specifically,what must this documentation include?
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
48
When an auditor tests a computerized accounting system,which of the following is true of the test data approach?

A) Test data are processed by the entity's computer programs under the auditor's control.
B) Test data must consist of all possible valid and invalid conditions.
C) Testing a program at year end provides assurance that the entity's processing was accurate for the entire year.
D) Several transactions of each type must be tested.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
49
When testing a computerized accounting system,which of the following is false regarding the test data approach?

A) The test data need to consist of only those valid and invalid conditions in which the auditor is interested.
B) Only one transaction of each type needs be tested.
C) Test data are processed by the entity's computer programs under the auditor's control.
D) The test data must consist of all possible valid and invalid conditions.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
50
A modification of the standard report is required for all of the following conditions except:

A) There is a restriction on the scope of the engagement.
B) There is other information contained in management's report on internal control.
C) Management has concluded that internal controls are not effective.
D) A significant subsequent event has occurred since the date being reported on.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
51
An auditor will use the IT test data method in order to gain certain assurances with respect to the

A) Input data.
B) Machine capacity.
C) Procedures contained within the program.
D) Degree of keypunching accuracy.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
52
Which of the following statements included in management's assessment of the effectiveness of internal control over financial reporting would be considered acceptable for issuing an unqualified opinion?

A) Nothing has come to management's attention to suggest that the entity's internal control is less than effective.
B) Statements suggesting only negative assurance.
C) A conclusion that the entity's internal control over financial reporting is effective when a material weakness exists at the end of the reporting period.
D) Disclosure of material weaknesses corrected during the period.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
53
AAA & Associates recently finished auditing LinktheEarth Corporation's internal control over financial reporting.AAA found a number of material weaknesses in the entity's internal control.LinktheEarth's management remediated all of the weaknesses that AAA found.However,the auditors did not have sufficient time to retest the controls.What report should AAA issue with regards to internal control over financial reporting at year-end?

A) Unqualified report.
B) Adverse report.
C) Qualified report.
D) Disclaimer on opinion.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
54
For which of the following internal controls would an auditor be least likely to perform tests of internal controls closer to the "as of" date?

A) Withdrawals from Federal Bank of more than $5 million must include a manager's signature.
B) At the end of each day at Federal Bank, the total cash in the vault is reconciled with daily registers of deposits and withdrawals.
C) Federal Bank has just started establishing trusts for its customers and it has only set up ten such trusts. Before making an investment for a trust, bank employees must verify that the investment is in accordance with stated investment policies.
D) On an annual basis, Federal Bank management performs credit checks on its loan customers before determining the value of loans it will not be able to collect on.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
55
You are an experienced audit senior.The new staff accountant on your audit team does not understand what a control deficiency is.Give him a definition of "control deficiency." Include examples of two types of control deficiencies.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
56
CBA Associates is auditing a large publicly traded company.The audit of internal controls over financial reporting has been properly planned and the auditors have already identified controls to test using a top-down,risk-based approach.What is the next step? Give three examples of procedures that may be completed in the next step in the audit.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
57
The advantages of generalized audit software include all of the following except:

A) It involves auditing while the data are being processed (real-time).
B) It is easy to use.
C) The time to develop the application is usually short.
D) An entire population can be examined in some instances.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
58
On the audit of Technology Unlimited,a leading manufacturer of computer chips,the external audit staff discovers that the internal audit staff has performed extensive evaluation and testing on the control environment.What should the external auditors do to determine the extent to which they may use the work of the internal audit staff? Can the external audit staff rely on the internal audit staff for evaluating and testing the control environment?
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
59
Examples of entity-level controls include

A) Management's risk assessment process.
B) Controls to monitor results of operations.
C) The period-end financial reporting process.
D) All of these are examples of entity-level controls.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
60
Which of the following is true of generalized audit software packages?

A) They can be used only in auditing online computer systems.
B) They can be used on any computer without modification.
C) They each have their own characteristics that the auditor must carefully consider before using in a given audit situation.
D) They enable the auditor to perform all manual test procedures less expensively.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
61
Discuss entity-level controls and provide examples of these types of controls.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
62
Information Nation has two hundred locations spread across the fifty states.Twenty of the locations are considered to be individually important,but fifty of the locations are not important even when aggregated from the others.Five locations deal with foreign exchange trading.These locations are not considered important,but they are important when aggregated with the other locations.As an auditor,discuss the considerations involved in testing multiple locations and group the locations accordingly (provide how many locations are included in each group).Include the treatment that each group should receive from the auditor.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
63
Discuss the differences between a control deficiency,a significant deficiency,a material weakness,and the two dimensions of the control deficiency - likelihood and magnitude.
Unlock Deck
Unlock for access to all 63 flashcards in this deck.
Unlock Deck
k this deck
locked card icon
Unlock Deck
Unlock for access to all 63 flashcards in this deck.