WorksheetsAuditing-CIS Environemnt
Total questions: 25
Worksheet time: 6mins
1. Which statement is incorrect when auditing in a CIS environment?
CIS environment exists when a computer of any type or size is involved in the processing by the entity of financial information of significance to the audit, whether that computer is operated by the entity or by a third party.
The auditor should consider how a
CIS environment affects the audit.
The use of a computer changes the processing, storage and communication of financial information and may affect the accounting and internal control systems employed by the entity.
A CIS environment changes the overall objective and scope of an audit.
Which of the following standards or group of standards is mostly affected by a computerized information system environment?
General Standards
Reporting Standards
Second Standard of Field Work
Standards of Fieldwork
1. Which of the following is least considered if the auditor has to determine whether specialized CIS skills are needed in an audit?
The auditor needs to obtain a
sufficient understanding of the accounting and internal control system affected by the CIS environment.
The auditor needs to determine the effect of the CIS environment on the assessment of overall risk and of risk at the account balance and class of transactions level.
Design and perform appropriate tests of controls and substantive procedures.
The need of the auditor to make analytical procedures during the completion stage of audit
It relates to materiality of the financial statement assertions affected by the computer processing.
Threshhold
Relevance
Complexity
Significance
Which of the following least likely indicates a complexity of computer processing?
Transactions are exchanged electronically with other organizations without manual review of their propriety.
The volume of the transactions is such that users would find it difficult to identify and correct errors in processing.
The computer automatically generates material transactions or entries directly to another applications.
The system generates a daily exception report
The nature of the risks and the internal characteristics in CIS environment that the auditors are mostly concerned include the following except:
Lack of segregation of functions.
Lack of transaction trails.
Dependence of other control over computer processing.
Cost-benefit ratio
Which of the following is least likely a risk characteristic associated with CIS environment?
Errors embedded in an application program logic maybe difficult to manually detect on a timely basis.
Many control procedures that would ordinarily be performed by separate individuals in manual system maybe concentrated in CIS.
The potential unauthorized access to data or to alter them without visible evidence maybe greater.
Initiation of changes in the master file is exclusively handled by respective users
Which of the following is not normally a removable storage media?
Compact disk
Tapes
Diskettes
Hard disk
The auditor may often assume that control risk is high in personal computer systems since, it may not be practicable or costeffective for management to implement sufficient controls to reduce the risks of undetected errors to a minimum level. This
least likely entail
More physical examination and confirmation of assets.
More analytical procedures than tests of details
Larger sample sizes.
Greater use of computer-assisted
audit techniques, where appropriate.
Which of the following least likely protects critical and sensitive information from unauthorized access in a personal computer environment?
Using secret file names and hiding the files
Keeping of back up copies offsite
Employing passwords
Segregating data into files organized under separate file directories
CIS application controls include, except
Controls over input
Controls over processing and computer data files
Controls over output
Monitoring Controls
Which statement is incorrect regarding internal controls in a CIS environment?
Manual and computer control procedures comprise the overall controls affecting the CIS environment (general CIS controls) and the specific controls over the accounting applications (CIS application controls).
The purpose of general CIS controls is to establish a framework of overall control over the CIS activities and to provide a reasonable level of assurance that the overall objectives of internal control are achieved.
The purpose of CIS application controls is to establish specific control procedures over the application systems in order to provide reasonable assurance that all transactions are authorized and recorded, and are processed completely, accurately and on a timely basis.
The internal controls over computer processing, which help to achieve the overall objectives of internal control, include only the procedures designed into computer programs.
System characteristics that may result from the nature of CIS processing include, except
Absence of input documents
Lack of visible transaction trail
Lack of visible output
Difficulty of access to data and computer programs
Whether or not a real time program contains adequate controls is most effectively determined by the use of
Audit software
A tracing routine
An integrated test facility
A traditional test deck
In an automated payroll processing environment, a department manager substituted the time card for a terminated employee with a time card for a fictitious employee. The fictitious employee had the same pay rate and hours worked as the terminated employee. The best control technique to detect this action using employee identification numbers would be a
Batch Total
Hash Total
Record Count
Subsequent Check
An employee in the receiving department keyed in a shipment from a remote terminal and inadvertently omitted the purchase order number. The best systems control to detect this error would be
Batch total
Sequence check
Completeness check
Reasonableness check
Using microcomputers in auditing may affect the methods used to review the work of staff assistants because
The audit field work standards for supervision may differ.
Documenting the supervisory review may require assistance of consulting services personnel.
Supervisory personnel may not have an understanding of the capabilities and limitations of microcomputers.
Working paper documentation may not contain readily observable details of calculations.
Which of the following is not a major reason for maintaining an audit trail for a computer system?
Deterrent to irregularities
Analytical Procedures
Monitoring Purposes
Query Answering
An auditor most likely would introduce test data into a computerized payroll system to test internal controls related to the
Existence of unclaimed payroll checks held by supervisors.
Early cashing of payroll checks by employees
Discovery of invalid employee ID numbers
Proper approval of overtime by supervisors
When an auditor tests a computerized accounting system, which of the following is true of the test data approach?
Test data must consist of all possible valid and invalid conditions.
The program tested is different from the program used throughout the year by the client.
Several transactions of each type must be tested.
Test data are processed by the client’s computer programs under the auditor’s control
Which of the following statements is not true to the test data approach when testing a computerized accounting system?
The test need consist of only those valid and invalid conditions which interest the auditor
Only one transaction of each type need be tested.
The test data must consist of all possible valid and invalid conditions.
Test data are processed by the client’s computer programs under the auditor’s control.
Which of the following is a computer test made to ascertain whether a given characteristic belongs to the group?
Parity Check
Echo Check
Validity Check
Limit Check
Which of the following methods of testing application controls utilizes a generalized audit software package prepared by the auditors?
Parallel Simulation
Test Data Approach
Integrated testing facility approach
Exception report tests
Generalized audit software is a computer-assisted audit technique. It is one of the widely used technique for auditing computer application systems. Generalized audit software is most often used to
Verify computer processing
Process data fields under the control of the operation manager.
Independently analyze data files
All of the above
Reconciling processing control totals is an example of
An input control
An output control
A processing control
A file management control
