WorksheetsChapter 12
Total questions: 13
Worksheet time: 7mins
The tasks performed during an internal audit assurance engagement should address the following questions:
I. What are the reasons for the results?
II. How can performance be improved?
III. What results are being achieved?
The chronological order in which these questions should be addressed is
III, I, II
I, III, II
III, II, I
II, III, I
While planning an assurance engagement, the internal auditors obtains knowledge about the auditee's operations to, among other things:
Develop an attitude of professional skepticism concerning management assertions
Make constructive suggestions to management regarding internal control improvements
Evaluate whether misstatements in the auditee's performance reports should be communicated to senior management and the audit committee
Develop an understanding of the auditee's objectives, risks, and controls
Which of the following statements does not illustrate the concept of inherent business risk?
Cash is more susceptible to theft than an inventory of sheet metal
A broken lock on a security gate allows employees to access a restricted are that they are not authorized to enter.
Transactions involving complex calculations are more likely to be misstated than transactions involving simple calculations
Technological developments might make a particular product obsolete
Comprehensive risk assessment involves analysis of both cause and effects. Which of the following statements concerning the analysis of causes and effects is false?
Analyzing the causes and effects of a particular risk should only be performed after the internal auditor has first obtained evidence that a problem has occurred.
Analyzing the cause and effects of a particular risk provides insights about how to best manage the risk
Analyzing the effects of a particular risk provides insights about the relative size of the risk and the relative importance of the business objective threatened by the risk.
Analyzing the root causes of a particular risk helps the internal auditor formulate recommendations for reducing the risk to an acceptable level.
Internal auditors obtain an understanding of controls and perform tests of controls to:
Detect material misstatements in account balances
Reduce control risk to an acceptably low level
Evaluate the design adequacy and operating effectiveness of the controls.
Assess the inherent risks associated with transactions.
If an internal auditor's evaluation of internal control design indicates that the controls are designed adequately, the appropriate next step would be to:
Test the operating effectiveness of the controls
Prepare a flowchart depicting the system of internal controls.
Conclude that residual risk is low
Conclude that control risk is high
Reportable internal audit observations emerge by a process of comparing "what should be" with "what is." In determining "what should be" during an audit of a company's treasury function, which of the following would be the least desirable criterion against which to judge current operations?
Best practices of the treasury function in relevant industries.
Company policies and procedure delegating authority and assigning responsibilities
Performance standard established by senior management.
The operations of the treasury function as documented during the last audit.
Internal auditors sometimes express opinions in addition to stating observations in their reports. Due professional care requires that internal audit opinions be:
Based on sufficient appropriate evidence.
Limited to the effectiveness of internal controls
Expressed only when requested by management or the audit committee
Based on experience and free from error in judgment
Which of the following statements best describes an internal audit function's responsibility for assurance engagement follow-up activities?
The internal audit function should determine that corrective action has been taken and is achieving the desired results, or that senior management has assumed the risk associated with not taking corrective action on reported observations.
The internal audit function should determine whether management has initiated corrective action but has no responsibility to determine whether the corrective action is achieving the desired results. That determination is management's responsibility.
The CAE is responsible for scheduling audit follow-up activities only if asked to do so by senior management or the audit committee. Otherwise, such activities are discretionary.
Audit follow-up activities are not necessary if the auditee has agreed in writing to implement the internal audit function's recommendations.
Internal auditors perform both assurance engagements and consulting engagements. Which of the following would be classified as a consulting engagements?
Directly assessing the organization's compliance with laws and regulations.
Assessing the design adequacy of the organization's entity-level monitoring activities
Facilitating senior management's assessment of risks threatening the organization.
Assisting the independent outside auditor during the financial statement audit engagement.
When assessing the risk associated with an activity, an internal auditor should
Determine how the risk should best be managed
Provide assurance on the management of the risk
Update the risk management process based on risk exposures
Design controls to mitigate the identified risks
In deciding whether to schedule the purchasing or the personnel department for an audit engagement, which of the following would be the least important factor?
There have been major changes in operation in one of the department
The audit staff has recently added an individual with expertise in one of the areas
There are more opportunities to achieve operating benefits in one of the departments than in the other
The potential for loss is significantly greater in one department the in the other
A performance audit engagement typically involves:
Review of financial statement information, including the appropriateness of various accounting treatments
Tests of compliance with policies, procedures, laws, and regulations
Appraisal of the environment and comparison against established criteria
Evaluation of organizational and departmental structures, including assessments of process flows
