Font size
WorksheetsARF C5: Risk, internal control and information flows
Total questions: 60
Worksheet time: 38mins
For financial statement audits, auditors need to understand controls that are relevant to the audit in order to
identify and assess the risks of material misstatements
perform preliminary analytical procedures
detect fraud
assess inherent risk
Narratives, flowcharts, and internal control questionnaires are three common methods of
testing the internal controls
designing the audit manual and procedures
documenting the auditor's understanding of internal controls
documenting the auditor's understanding of a client's organizational structure
Which type of evidence is not used by the auditor to obtain an understanding of the design and implementation of internal control?
inquiry
confirmation
inspection
observation
Walkthroughs combine observation, inspection, and inquiry to assure that the controls designed by management have been implemented.
True
False
Flowcharts have two advantages over narratives: typically, they are easier to read and easier to update.
True
False
You are performing the audit of internal control for Clifton Company. Which of the following would represent a material weakness in internal control?
The company's audit committee has experienced an unusual turnover of members
The company's CFO was indicted for embezzling from the company
Bank reconciliations are done monthly
The CEO retired after twenty years of service to the company
The employee in charge of authorizing credit to the company's customers does not fully understand the concept of credit risk. This lack of knowledge would
constitute a deficiency of management
constitute a deficiency in operation of internal controls
constitute a deficiency in design of internal controls
not constitute a deficiency
Which of the following parties is responsible for establishing a company's internal controls?
Auditors.
Management and auditors.
Committee of Sponsoring Organizations.
Management.
Which of the following best describes the inherent limitations that should be recognized by an auditor when considering the potential effectiveness of internal control?
The benefits expected to be derived from effective internal accounting control usually do not exceed the costs of such control.
Procedures whose effectiveness depends on segregation of duties can be circumvented by collusion.
The competence and integrity of client personnel provides an environment conducive to accounting control and provides assurance that effective control will be achieved.
Procedures designed to assure the execution and recording of
transactions in accordance with proper authorizations are effective against irregularities perpetrated by management.
When considering internal control, an auditor should be aware of the concept of reasonable assurance, which recognizes that the
Segregation of incompatible functions is necessary to ascertain that internal control is effective.
Costs of internal control should not exceed the benefits expected to be derived from internal control.
Employment of competent personnel provides assurance that the objectives of internal control will be achieved.
Establishment and maintenance of internal control is an important responsibility of the management and not of the auditor.
Which of the following is not one of the three primary objectives of effective internal control?
Efficiency and effectiveness of operations.
Reliability of financial reporting.
Compliance with laws and regulations.
Each of the above is a primary objective of effective internal control.
Internal controls can never be considered as absolutely effective because
Controls always have inherent weaknesses that can be exploited.
Their effectiveness is limited by the competency and dependability of employees.
Controls are designed to prevent and detect only material misstatements.
None of the above.
When management is evaluating the design of internal control, management evaluates whether the control can do all but which of the following?
Correct material misstatements.
Detect material misstatements.
Prevent material misstatements.
None of the above is correct.
Auditor's tests of operating effectiveness of internal controls might include which of the following types of procedures?
Inquiries of personnel.
Inspection of relevant documentation.
Reperformance of the application of controls.
All of the above.
Which of the following activities would be least likely to strengthen a company's internal control?
Separating accounting from other financial operations.
Fixing responsibility for the performance of employee duties. .
Maintaining insurance for fire and theft
Carefully selecting and training employees.
Management must disclose material weaknesses in internal control
Only if the auditor identifies the weakness as significant.
Whenever the weakness is significant to overall financial reporting objectives.
Whenever the weakness is deemed significant to a single class of transactions.
Even if just one weakness is found.
During which part of an audit examination is the preparation of flowcharts most appropriate?
When performing tests of controls.
When reviewing the system of internal control.
When evaluating the system of administrative control.
When performing preliminary analytical procedures.
What helps prevent fraud in organizations?
Collusion among employees
Segregation of duties
High costs
Complexity
Which of the following statements about the control environment is false?
Supervision is especially important in organizations that cannot afford elaborate responsibility reporting or are too small to have an adequate separation of duties
A written policy and procedures manual is an important tool for assigning authority and responsibility.
Management’s attitudes toward internal control and ethical behavior have little impact on employee beliefs or actions
An overly complex or unclear organizational structure may be indicative of problems that are more serious.
To achieve effective segregation of duties, certain functions must be separated. Which of the following is the correct listing of the accounting-related functions that must be segregated?
control, custody, and authorization
monitoring, recording, and planning
control, recording, and monitoring
authorization, recording, and custody
The purpose of internal control is solely to safeguard assets and prevent fraud.
True
False
Which of the following controls is likely to be least relevant when evaluating the design adequacy of a cash collections process?
Calculating the amount of cash received
Documenting the rationale for selecting the bank account into which the deposit will be made
Matching the total deposits to the amounts credited to customers' accounts receivable balances
Segregating the preparation of deposit slips from the adjustment of customer account balances
Internal control is the process designed, implemented and maintained by those charged with governance, management and other personnel to provide reasonable assurance about the achievement of the entity’s objectives
True
False
Internal control provide reasonable assurance about the achievement of the entity’s objectives with regard to:
Reliability of financial reporting
Efficiency/effectiveness of operations
Compliance with applicable laws and regulations
All of these answers
Inherent limitation of internal control
The benefit of control not outweighing their cost
The potential for human error
Collusion between employees
The possibility of controls being bypassed or overridden by management
Controls being designed to cope with routine and not non-routine transactions
Relationship among management, internal control and internal audit in an entity
Management in an organization is a process of using resources effectively to achieve targets.
Internal control is a part of the management process and it has an impact on elements of that process.
Internal auditing is a continuous process that occurs in parallel with management activities and is an important function of management. It helps managers to achieve their goals in management and operation.
All of these answers
Components of internal control
The control environment
Risk assessment
Control activities
Information and communication
Monitoring of controls
Control Environment means (3A) the understanding, attitude, awareness and actions of members of the boards of management and directors regarding the ICS and its importance in the entity.
True
False
Subcomponent of control environment:
• Communication and enforcement of integrity and ethical values
• Commitment to competence
• Participation by those charged with governance
• Management’s philosophy and operating style
• Organizational structure
• Assignment of authority and responsibility
• Human resource policies and practices.
Risk assessment process: The auditor should obtain an understanding of whether the entity has a process for:
Identify business risks relevant to financial reporting objectives
Estimating the significance of the risk
Assessing the likelihood of their occurrence
Deciding on actions to address those risks
All of the steps
Control activities are policies and procedures in addition to the control environment which are established to achieve the entity’s specific objectives.
True
False
Specific control activities can be summarized into the following 5 types:
Authorization
Performance review
Information processing
Physical controls
Segregation of duties
The information system relevant to financial reporting is a component of Internal Control that includes a financial reporting system and consists of the procedures and records established to initiate, record, process, and report entity transactions (as well as events and conditions) and to maintain accountability for the related assets, liabilities, and equity.
True
False
Monitoring of controls
Monitoring of controls is a process to assess the effectiveness of internal control performance over time.
It includes: -assessing the design and operation of controls on a timely basis and;
- taking necessary corrective actions modified for changes in conditions.
All of these above answer are true
The process of understanding of the Internal Control in audit and assessment of control risk
Obtain of understanding of designing and implementing entity's internal control
Assess control risk
Test of control
Decide planned detection risk and substantive procedures
Report on internal control
Effective internal control provides the auditor with an absolute assurance that an organization will achieve its objective of reliable reporting.
True
False
The control environment is considered as the foundation for all other components of internal control.
True
False
Only organizations in high-risk industries face a risk that they will not achieve their objective of reliable financial reporting.
True
False
An organization’s risk assessment process should identify risks to reliable financial reporting from both internal and external sources.
True
False
There is one set of control activities that all organizations should implement.
True
False
An organization’s accounting system is part of its information and communication component of internal control.
True
False
An organization needs information from both internal and external sources to carry out its internal control responsibilities.
True
False
If management identifies even one material weakness in internal control, then management will conclude that the organization’s internal control over financial reporting is not effective.
True
False
Management will classify a control deficiency as a material weakness only if there has been a material misstatement in the financial statements.
True
False
Tests of controls are designed to detect material misstatements in the financial statements.
True
False
The auditor is responsible for reporting all deficiencies to management in writing.
True
False
Internal control questionnaires are used to determine whether there are controls, which present or detect specified errors or omissions.
True
False
The quality of an organisation’s internal controls affects which of the following
Reliability of financial data
Ability of management to make good decisions
Ability of the organisation to remain in business
Approach used by the auditor in auditing the financial statements
All of the above
Which of the following creates an opportunity for committing fraudulent financial reporting in an organisation?
Management demands financial success
Poor internal control
Commitments tied to dept covenants
Management is aggressive in its application of accounting rules
Which of the following statements regarding internal control is true?
Internal control is a process consisting of ongoing tasks and activities
Internal control is primarily about policy manuals, forms, and procedures
Internal control is geared toward the achievement of multiple objectives
A limitation of internal control is faulty human judgement
All of the above statements are true
Which one of the following represents a control deficiency
A missing control that is required for achieving objectives.
A control that operates as designed.
A control that provides reasonable, but not absolute assurance, about the reliability of financial reporting
An immaterial individual misstatement in internal control
Which of the following methods of recording an accounting and controls system is a series of questions used to determine whether controls exist which meet specific control objectives?
Internal control questionnaire
Internal control evaluation questionnaire
Flowchart
One of the control objectives of the sales system of B Co is to ensure that goods and services are sold to credit-worthy customers. Which of the following control activities would assist B Co in achieving this objective?
All sales orders are based on authorized price lists.
Credit limits are checked before sales orders are accepted.
Overdue debts are chased each month by the credit controller.
The aged-debt listing is reviewed by the finance director on a monthly basis
Which of the following is not a test of control?
a. Inspection of purchase order documentation to confirm that it has been authorized
a. Review of monthly bank reconciliations performed by the audit client
a. Examination of purchase invoices for evidence of mathematical accuracy checks
a. Agreement of the cost of non-current asset additions to purchase documentation
The external auditor has identified a deficiency in the internal controls of S Co. Which of the following factors would indicate that the deficiency is a significant deficiency?
(1) The likelihood of the deficiency leading to material misstatement is low
(2) There is a risk of fraud
(3) The number of transactions affected by the deficiency is low
(4) The deficiency interacts with other deficiencies identified
(1) and (2)
(1) and (3)
(2) and (4)
(3) and (4)
Which of the following statements is true regarding the controls in a small company?
(1) The external auditor will never be able to rely on the controls in a small company.
(2) Segregation of duties may be inadequate due to staff numbers.
(3) Evidence of the operation of controls is more likely to be available in documentary form.
(4) The external auditor will assess the attitudes, awareness and actions of management.
a. (1) and (3)
a. (1) and (4)
a. (2) and (3)
a. (2) and (4)
During the course of the audit the auditor may identify deficiencies in internal control which must be reported to management. Which of the following statements is correct regarding the report to management sent by the auditor?
(1) The report must include a description of the deficiencies and an explanation of their potential effects
(2) The report includes an explanation of the purpose of the audit
(3) The report states that the results of the audit work have enabled the auditor to express an opinion on the operating effectiveness of internal control.
a. (1) and (2) only
a. (1) and (3) only
a. (2) and (3) only
a. (1), (2) and (3)
Which of the following is a primary objective of internal control systems?
To provide absolute assurance of financial accuracy
To eliminate all risks associated with business operations
To maximize profits at any cost
To ensure compliance with laws and regulations
What is the role of management in the internal control process?
To delegate all responsibilities to the auditor
To monitor and evaluate the effectiveness of controls
To ignore the internal control system
To design and implement controls only
Which of the following is an example of a preventive control?
Training employees on compliance policies
Reviewing transactions after they occur
Segregation of duties in the accounting department
Regular audits of financial statements
