Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CHAPTER 7: Visual Overview and Audit Planning Scope

Total questions: 83

Worksheet time: 42mins

Name
Class
Date
1.

Which pathway best describes the sequence emphasized in the overview: from planning through to handling identified risks and evidence gathering? Choose the option that reflects the flow shown in the diagram.

a)

Planning (ISA 300) → Risk Assessment (ISA 315 Revised 2019) → Auditor’s Responses

b)

Materiality (ISA 320) → Audit Risk → Planning (ISA 300)

c)

Transnational Audits → Planning (ISA 300) → Analytical Procedures (ISA 315 Revised 2019)

d)

Audit Risk → Risk Assessment (ISA 315 Revised 2019) → Planning (ISA 300)

2.

Which statement best describes the overall audit strategy?

a)

It specifies detailed procedures for each assertion and account balance.

b)

It sets the scope, timing and direction of the audit and guides the development of the audit plan.

c)

It documents only reporting deadlines for interim and final reporting.

d)

It lists industry-specific regulations without linking them to audit work.

3.

According to the material, what is the primary purpose of developing an audit plan?

a)

To ensure the auditor follows the client’s internal timetable for reporting.

b)

To reduce audit risk to an acceptably low level by describing the nature, timing and extent of planned procedures.

c)

To eliminate the need for professional judgement by standardizing all tests.

d)

To focus solely on substantive procedures while omitting tests of control.

4.

Which of the following is NOT listed as an objective of audit planning?

a)

To devote appropriate attention to important areas.

b)

To identify potential problems and resolve them on a timely basis.

c)

To maximize audit fees by expanding procedures unnecessarily.

d)

To organise and manage the engagement in an effective and efficient way.

5.

Professional scepticism at the planning stage is essential primarily to ensure which outcome?

a)

That audit documentation is lengthy and detailed regardless of risk.

b)

That the right level of professional judgement is used and resources are allocated to high-risk areas at the appropriate time.

c)

That the auditor accepts management’s assertions unless contradicted by written evidence.

d)

That audit procedures are identical across all clients for comparability.

6.

Applying professional scepticism in planning includes which action?

a)

Relying on management’s group consensus to streamline decisions.

b)

Designing procedures to seek evidence that would contradict management assertions, such as on fair values or impairment.

c)

Avoiding the use of external confirmations to reduce cost.

d)

Assuming there are no unrecorded related party transactions unless proven otherwise.

7.

Which factor is explicitly part of determining the scope of the audit engagement within the audit strategy?

a)

The auditor’s staffing preferences.

b)

The financial reporting framework used by the entity.

c)

The audit firm’s marketing budget.

d)

The prior year’s audit fee negotiations.

8.

Which item is identified as part of establishing the direction of the audit in the overall strategy?

a)

Designing detailed assertion-level tests for every account.

b)

Determining appropriate materiality levels and identifying higher risks of material misstatement.

c)

Preparing the auditor’s tax return for the year.

d)

Scheduling client board meetings.

9.

What components must the audit plan include at the assertion level for each material class of transactions, account balance, and disclosure?

a)

Only analytical procedures performed at year-end.

b)

Tests of control and substantive procedures responsive to assessed risks.

c)

A summary of governance requirements with no procedures.

d)

A list of internal control questionnaires completed by management.

10.

Which example reflects using a high degree of knowledge of the entity’s business and operating environment when applying professional scepticism?

a)

Monitoring going concern indicators relevant to the client’s industry.

b)

Accepting management’s impairment estimates without challenge.

c)

Relying solely on prior year workpapers for planning.

d)

Deferring understanding of new disclosure requirements until after fieldwork.

11.

Which of the following is included in the audit plan to comply with relevant ISAs for the assignment?

a)

External confirmations, use of an expert, subsequent events work, going concern procedures, and management representations.

b)

Only walkthroughs of significant processes documented by the client.

c)

A complete replication of the internal audit plan without changes.

d)

Procedures limited to interim testing to meet reporting deadlines.

12.

How should direction and supervision of engagement team members change based on risk and experience, according to the section on Direction, Supervision and Review?

a)

Increase as assessed risk of material misstatement increases and as team member experience decreases.

b)

Remain constant regardless of risk or experience to ensure consistency.

c)

Decrease as risk increases to avoid bias and allow independent work.

d)

Be determined solely by the client’s reporting deadlines.

13.

What documentation requirement is emphasized regarding planning?

a)

Only document significant changes to the audit plan; the strategy can remain verbal.

b)

Document the overall audit strategy and the audit plan, including any significant changes made during the audit engagement.

c)

Archive test schedules but exclude risk assessments to protect confidentiality.

d)

Rely on email threads as sufficient documentation for planning decisions.

14.

According to ISA 315 (Revised 2019), what is the primary purpose of identifying and assessing risks of material misstatement at the financial statement and assertion levels?

a)

To reduce the scope of audit documentation

b)

To provide a basis for designing and implementing responses to assessed risks

c)

To eliminate the need for substantive procedures

d)

To determine the audit fee structure

15.

Which sequence best reflects the ISA 315 (Revised 2019) requirements an auditor must perform during planning?

a)

Understand internal control; design overall responses; identify risks; perform further audit procedures

b)

Design risk assessment procedures; understand the entity and environment; understand internal control; identify and assess risks

c)

Identify risks; design further audit procedures at the assertion level; evaluate evidence; issue the report

d)

Evaluate sufficiency of audit evidence; understand the financial reporting framework; design risk assessment procedures

16.

ISA 315 (Revised 2019) includes scalability considerations. What does scalability mean in this context?

a)

Requirements vary only for listed entities

b)

Application guidance illustrates how requirements can be applied regardless of entity complexity

c)

Auditors can ignore certain requirements for small clients

d)

Scalability allows auditors to delegate planning to management

17.

Link ISA 315 and ISA 330: Which action under ISA 330 directly follows the identification and assessment of risks under ISA 315?

a)

Issuing the audit opinion

b)

Designing and implementing overall responses at the financial statement level

c)

Preparing the management representation letter

d)

Recalculating prior-period balances

18.

Under ISA 330, further audit procedures respond to risks of material misstatement at which level(s)?

a)

Only the financial statement level

b)

Only the assertion level (e.g., occurrence, completeness, accuracy)

c)

Both the financial statement and disclosure levels only

d)

Only the control activity level

19.

Definition check: Risk assessment procedures are audit procedures designed to identify and assess risks of material misstatement at which levels?

a)

Only at the disclosure level

b)

At the financial statement and assertion levels

c)

At the transaction cycle and account balance levels only

d)

At the control and compliance levels only

20.

Which of the following is NOT listed as a type of risk assessment procedure?

a)

Analytical procedures on internal and external information

b)

Enquiries of management and others in the entity

c)

Inspection of premises, plans, and control documents

d)

Reperformance of year-end closing entries by the auditor

21.

A senior plans risk assessment work and wants to avoid bias. Which approach aligns with the guidance?

a)

Seek only corroborative audit evidence that confirms existing beliefs

b)

Include procedures that may yield contradictory audit evidence if relevant

c)

Exclude external information to maintain confidentiality

d)

Rely solely on prior-year conclusions if the client has not changed

22.

Which mnemonic is suggested to help remember the main risk assessment procedures?

a)

CAPE

b)

AEIO or AEIOU

c)

RADAR

d)

TRACE

23.

Which statement best describes the role of professional scepticism during risk assessment?

a)

It is optional if prior audits found no issues

b)

It is necessary for critically assessing audit evidence and discussing susceptibility to misstatement

c)

It only applies to testing internal controls

d)

It is primarily used for calculating materiality thresholds

24.

When understanding the entity and its environment, which of the following is explicitly included?

a)

Only ownership structure, excluding governance

b)

Business model, including the extent of IT integration

c)

Future stock price projections

d)

Tax planning for shareholders

25.

What must the auditor evaluate regarding accounting policies when considering the applicable financial reporting framework?

a)

Whether policies minimize reported profit volatility

b)

Whether policies are appropriate and consistent with the applicable financial reporting framework

c)

Whether policies match those of industry leaders

d)

Whether policies reduce the extent of substantive testing required

26.

Which statement best defines a system of internal control for an entity preparing financial statements?

a)

A set of informal practices used by staff to speed up operations regardless of risk

b)

The system designed, implemented, and maintained by TCWG, management, and personnel to provide reasonable assurance about achieving objectives in reporting, operations, and compliance

c)

A checklist used by auditors to detect every possible misstatement with absolute certainty

d)

A software package that automates accounting entries and eliminates the need for oversight

27.

According to the section, which objective is specifically supported by the system of internal control?

a)

Maximizing tax refunds for the entity

b)

Reliability of financial reporting

c)

Eliminating business risks entirely

d)

Guaranteeing profit growth each quarter

28.

The diagram shows five inter‑related components of internal control. Which list correctly names these components?

a)

Control environment, risk assessment, information systems, control activities, control monitoring

b)

Governance structure, budgeting, staffing, outsourcing, auditing

c)

Strategic planning, marketing, production, human resources, financing

d)

Financial statements, cash flow, investments, payroll, compliance testing

29.

A key point states that the auditor must perform risk assessment procedures to understand each component relevant to which task?

a)

The preparation of the financial statements

b)

Setting executive compensation

c)

Approving tax filings

d)

Designing the entity’s marketing plan

30.

Which aspect is part of the control environment relevant to financial statement preparation?

a)

How budgets are allocated among departments

b)

How management’s oversight responsibilities are carried out, including commitment to integrity and ethical values

c)

How sales targets are set for the marketing team

d)

Which software vendor supports the ERP system

31.

When TCWG are separate from management, what does the control environment require the auditor to consider?

a)

The independence of TCWG and their oversight of the system of internal controls

b)

The size of the boardroom and meeting frequency alone

c)

The personal investment portfolios of TCWG members

d)

Whether TCWG approve every journal entry

32.

Which item is NOT listed as part of the control environment focus for financial statement preparation?

a)

Assignment of authority and responsibility

b)

How individuals are held accountable for responsibilities related to internal control

c)

How competent individuals are attracted, developed, and retained

d)

The selection of external auditors by shareholders

33.

What should the auditor evaluate regarding management and the control environment?

a)

Whether management has created and maintained a culture of honesty and ethical behaviour

b)

Whether management can eliminate all control deficiencies entirely

c)

Whether management writes the financial statements without estimates

d)

Whether management outsources all key operations

34.

The material notes that a dominant individual can have what type of effect on the control environment?

a)

Only a positive effect by speeding decisions

b)

No significant effect because controls are documented

c)

A pervasive effect that may be positive or negative

d)

Only a negative effect due to lack of delegation

35.

In the example of a dominant individual, what heightened risk does concentration of knowledge and authority create?

a)

Increased susceptibility to misstatement through management override of controls

b)

Higher audit fees due to more controls

c)

Reduced responsiveness to market opportunities

d)

Guaranteed compliance with all regulations

36.

The entity’s risk assessment process relevant to financial reporting includes which step?

a)

Ignoring risks that are unlikely to occur

b)

Identifying business risks relevant to financial reporting objectives

c)

Eliminating risks by purchasing insurance

d)

Delegating risk ownership to external auditors

37.

Which statement about the auditor’s responsibility for understanding business risks is correct?

a)

The auditor is required to understand all business risks of the entity

b)

The auditor is not required to understand or identify all business risks because not all give rise to risks of material misstatement

c)

The auditor must only understand tax-related risks

d)

The auditor should document every informal conversation about risks as formal evidence

38.

If the auditor identifies risks of material misstatement that management failed to identify, which action is included in the required response?

a)

Immediately issue a qualified opinion without further procedures

b)

Determine whether such risks should have been identified by management and understand why the process failed

c)

Replace the management team

d)

Ignore the risks if they are not documented

39.

In less complex or owner-managed entities, how might an appropriate risk assessment be performed?

a)

Through an automated scoring model only

b)

Through the direct involvement of management or the owner-manager, such as monitoring competitors and market developments, even if not formally documented

c)

Only by hiring an external consultant to conduct annual workshops

d)

By relying solely on internal audit reports

40.

When evaluating the entity’s process to monitor the system of internal control, what should the auditor understand?

a)

How the entity monitors the effectiveness of controls and remediates deficiencies, and the nature, responsibilities, and activities of the internal audit function, if any

b)

Only the number of controls documented in the manual

c)

Only whether management meets quarterly

d)

Which ERP modules are licensed

41.

Which approach best confirms an auditor’s understanding of how transactions flow through the information system when the auditor can access the client’s databases?

a)

Interviewing staff about typical journal entry procedures across departments

b)

Applying automated tools to trace digital records from initiation in accounting records through posting in the general ledger

c)

Sending external confirmations to customers for a sample of outstanding receivables

d)

Observing end-of-period inventory counts to reconcile quantities to the ledger

42.

According to the example of confirming the information system, analyzing complete or large sets of transactions primarily helps the auditor to:

a)

Identify violations of tax laws unrelated to financial reporting

b)

Benchmark company profitability against industry peers

c)

Detect variations from expected processing procedures that may indicate risks of material misstatement

d)

Estimate the useful lives of long-term assets

43.

When understanding an entity’s information processing activities, which of the following is explicitly included?

a)

Only how transactions are recorded in the general ledger

b)

How information flows through the information system, the accounting records, the financial reporting process including disclosures, and relevant resources including the IT environment

c)

Only controls over cash receipts and cash payments

d)

Only management’s review of budget-to-actual variances

44.

Which statement best reflects the auditor’s responsibility regarding accounting policies?

a)

Ensure the entity adopts the same policies as industry leaders

b)

Design the entity’s accounting policies and procedures

c)

Evaluate whether the entity’s accounting policies are appropriate and consistent with the applicable financial reporting framework

d)

Approve changes in accounting policies before management implements them

45.

Which objective is part of the system of internal control as defined in the material?

a)

Maximizing shareholder returns through aggressive investment strategies

b)

Reliability of financial reporting, effectiveness and efficiency of operations, and compliance with applicable laws and regulations

c)

Eliminating all business risks through insurance contracts

d)

Setting executive compensation based on market benchmarks

46.

Which components are shown as inter-related within the system of internal control in the diagram described?

a)

Control environment, risk assessment, information systems, control activities, and control monitoring

b)

Strategic planning, budgeting, variance analysis, forecasting, and performance bonuses

c)

Cash management, procurement, payroll, sales, and taxation

d)

Authorization, custody, recording, reconciliation, and reporting

47.

In the monitoring example for a less complex entity, management’s handling of customer complaints is used primarily to:

a)

Identify issues with the timing of recognition of customers’ payments and reference actions like credit notes or refunds to supporting documents in accounting records

b)

Forecast sales by region using historical complaint trends

c)

Perform a physical count of inventory at year-end

d)

Determine the appropriate discount rate for impairment testing

48.

Which element is part of understanding the entity and its environment for risk assessment purposes?

a)

The auditor’s internal staffing plan for the engagement

b)

The entity’s business model, including the extent of IT integration, and external factors such as industry and regulation

c)

Only the client’s tax filing history for the past three years

d)

A comparison of the client’s stock price to market indices

49.

What does the guidance indicate about transactions information other than transactions within the information system?

a)

Only transactions are captured; events and conditions are excluded

b)

Information about events and conditions, other than transactions, is captured, processed and disclosed in the financial statements

c)

Events and conditions are recorded only if they affect cash flows

d)

Events are disclosed without processing in the accounting system

50.

Which statement best links automated techniques with audit risk assessment when confirming the information system?

a)

Automated techniques eliminate the need for professional judgment in assessing risk

b)

Automated analysis of large transaction sets can reveal deviations from expected processing, helping identify risks of material misstatement

c)

Automated tools are suitable only for small samples due to processing limits

d)

Automated techniques are used only after the audit opinion is issued

51.

Which aspect is included when evaluating the control environment relevant to preparing financial statements?

a)

How individuals are held accountable for internal control responsibilities

b)

The tax rates applicable to the entity’s jurisdiction

c)

Customer satisfaction scores for the latest quarter

d)

The brand recognition of the entity’s products

52.

An auditor evaluating the control environment should determine whether management has created and maintained which of the following?

a)

A culture of honesty and ethical behaviour

b)

A focus on maximizing sales volume at any cost

c)

An exclusive emphasis on cost reduction

d)

A system that eliminates all manual controls

53.

A single dominant individual may have a pervasive effect on an organisation’s culture and control environment. What is a potential negative consequence noted?

a)

Increased susceptibility to misstatement through management override of controls

b)

Reduced need for ethical standards

c)

Elimination of business risks relevant to financial reporting

d)

Automatic documentation of all processes

54.

Regarding the entity’s risk assessment process relevant to financial statements, which sequence best reflects management’s responsibilities?

a)

Identify business risks relevant to financial reporting, assess their significance and likelihood, and address those risks

b)

Address risks first, then assess significance, then identify risks

c)

Identify only operational risks, then outsource their assessment and ignore addressing them

d)

Wait for the auditor to identify risks, then address only the most likely ones

55.

Which statement about the auditor’s responsibility for understanding business risks is correct?

a)

The auditor is not required to understand or identify all business risks because not all business risks give rise to risks of material misstatement

b)

The auditor must identify every business risk regardless of relevance to financial reporting

c)

The auditor focuses only on risks documented formally by management

d)

The auditor evaluates only external risks, not internal ones

56.

In less complex, owner-managed entities, what evidence might indicate that management is performing risk assessment procedures even if not formally documented?

a)

Discussions showing the owner-manager monitors competitors and market developments to identify emerging risks

b)

A complete absence of any mention of risks in meetings

c)

Exclusive reliance on external auditors for risk identification

d)

A policy stating risks will be addressed after year-end close only

57.

If the auditor identifies risks of material misstatement that management failed to identify, what should the auditor do first according to the guidance?

a)

Determine whether such risks should have been identified by management

b)

Immediately issue an adverse opinion

c)

Ignore the risks if they are not documented

d)

Assume the risk assessment process is appropriate without further inquiry

58.

To understand the entity’s monitoring of internal control, the auditor needs to know which of the following?

a)

How the entity identifies and remediates control deficiencies through periodic or ongoing evaluations

b)

How the entity prices its products across regions

c)

How marketing campaigns are scheduled

d)

How payroll tax tables are set by the government

59.

In an owner-managed entity with limited formal monitoring, which activity could serve as a monitoring control related to financial statements?

a)

Recording and signing off customer complaints and referencing related credit notes or refunds to supporting documents and accounting entries

b)

Launching a new product line based on customer feedback

c)

Revising the company logo after complaints

d)

Outsourcing all accounting to eliminate internal records

60.

Understanding the entity’s information processing activities includes knowing how transactions are handled. Which is included in this understanding?

a)

How transactions are initiated, recorded, processed, corrected as necessary, incorporated in the general ledger, and reported in the financial statements

b)

How the entity designs advertising for new products

c)

How office seating arrangements are assigned

d)

How shareholder meetings are scheduled by the legal team

61.

Which activity best illustrates how automated tools can help confirm an auditor’s understanding of the information system’s transaction flows?

a)

Scanning final financial statements for formatting inconsistencies

b)

Tracing journal entries from initiation through posting in the general ledger using digital records

c)

Interviewing only external parties about the client’s reporting responsibilities

d)

Comparing the client’s budget to industry averages without accessing transaction data

62.

An auditor downloads a large set of transaction data and identifies variations from expected processing procedures. What is the primary audit implication of these variations?

a)

They automatically prove fraud has occurred

b)

They indicate risks of material misstatement may be present

c)

They show that controls are operating effectively

d)

They eliminate the need for further substantive procedures

63.

According to the guidance, the auditor should understand how significant matters supporting financial statement preparation are communicated. Which channels are explicitly included?

a)

Within the entity, between management and those charged with governance, and with external parties

b)

Only between management and the audit committee

c)

Only within the IT department

d)

Only with external regulators after year-end

64.

At the assertion level, the auditor must identify control activities that address risks of material misstatement. Which is an example of a control that addresses a significant risk?

a)

Automated bank reconciliations performed quarterly

b)

Review of assumptions by senior management or experts

c)

Written job descriptions for all employees

d)

Use of a standard chart of accounts

65.

Which control activity focuses specifically on journal entries, including non-standard entries for unusual transactions or adjustments?

a)

Segregation of duties between initiation, authorisation, posting, and review of journal entries

b)

Monthly variance analysis by department heads

c)

Reconciliation of sub-ledgers to the general ledger annually

d)

Physical inventory counts once a year

66.

When the auditor plans to test operating effectiveness of controls to determine the nature, timing, and extent of substantive procedures, which examples align with this focus?

a)

Authorisations and approvals; edit and validation checks; physical controls such as periodic counting of inventory or cash

b)

Quarterly board strategy sessions; staff training plans

c)

External benchmarking studies; customer satisfaction surveys

d)

Insurance policy renewals; legal representation letters

67.

Which is an example of a control identified based on the auditor’s professional judgement when a service organisation is used?

a)

Complementary user entity controls

b)

Internal audit’s annual report

c)

Budgetary control oversight

d)

Shareholder meeting minutes

68.

What is the stated purpose of general IT controls within the IT environment?

a)

To replace the need for information processing controls entirely

b)

To support the continued proper operation of the IT environment and the integrity of information, including completeness, accuracy, and validity

c)

To ensure only manual processes are used for critical transactions

d)

To focus solely on cybersecurity insurance coverage

69.

Which description best defines the IT environment as used in the guidance?

a)

Only the accounting software used to record journal entries

b)

IT applications and supporting IT infrastructure, along with the IT processes and personnel that support business operations and strategies

c)

External cloud vendors and internet connections only

d)

Hardware devices without related processes or personnel

70.

Which general IT control helps ensure that users access only information necessary for their job responsibilities, facilitating appropriate segregation of duties?

a)

Authentication

b)

Authorisation

c)

Provisioning

d)

Physical access

71.

What is the primary purpose of deprovisioning as a general IT control?

a)

To assign initial log-in credentials to new users

b)

To modify existing users’ access privileges for promotions

c)

To remove user access upon termination or transfer

d)

To conduct periodic penetration testing

72.

Which activity is an example of a user access review within general IT controls?

a)

Recertifying or evaluating user access for authorisation

b)

Resetting passwords after three failed attempts

c)

Encrypting backups stored offsite

d)

Monitoring internet usage for policy violations

73.

Why is physical access to the data centre and hardware a key general IT control?

a)

Because physical access can be used to override other controls

b)

Because it eliminates the need for logical access controls

c)

Because it only affects employee attendance records

d)

Because it guarantees compliance with all regulations

74.

For each control activity and general IT control identified, what is the first required evaluation step the auditor must perform?

a)

Test operating effectiveness through sampling

b)

Evaluate its design to determine if it is capable of effectively preventing or detecting misstatements, individually or in combination with other controls

c)

Obtain external confirmations from third parties

d)

Prepare a management letter with recommendations

75.

Scenario: You are planning an audit of a client that relies on a service organisation for payroll processing. To address potential risks of material misstatement at the assertion level, which control focus would be most strategic to identify and understand first?

a)

Controls over marketing campaigns that increase sales volume

b)

Complementary user entity controls relevant to the service organisation’s processing

c)

Inventory valuation models used for slow-moving items

d)

Office access policies for visitors during public tours

76.

Which statement best defines when a risk of material misstatement (RoMM) exists?

a)

Whenever any error is identified regardless of size or likelihood

b)

When there is a reasonable possibility of a misstatement occurring and it would be material if it occurred

c)

Only when fraud is suspected by management

d)

When the auditor cannot obtain any audit evidence

77.

RoMM may exist at two levels. Which pairing correctly describes these levels?

a)

Organizational level and department level

b)

Financial statement level affecting many assertions, and assertion level for classes of transactions, account balances, and disclosures

c)

Subsidiary level and consolidated level

d)

Operational level and strategic level

78.

According to the material, RoMM is assessed at the assertion level primarily to determine which of the following?

a)

The size of the audit engagement team

b)

The nature, timing, and extent of further audit procedures to obtain sufficient appropriate audit evidence

c)

Whether management’s budget is reasonable

d)

The need to rotate the audit partner

79.

Which pair correctly matches the two components embedded in the definition of RoMM?

a)

Control design and control implementation

b)

Likelihood of misstatement and magnitude if it occurs

c)

Detection risk and sampling risk

d)

Inherent risk and control risk

80.

Select the scenario that most clearly indicates a financial statement level RoMM rather than an assertion level RoMM.

a)

Revenue recognition for a specific product line is complex due to multiple-element contracts

b)

A pervasive IT system failure could impact multiple account balances and disclosures

c)

Inventory valuation for a single warehouse requires significant estimates

d)

Classification of one lease contract is unclear

81.

When planning audit procedures in response to RoMM, which option best applies the concept of assessing at the assertion level?

a)

Design one uniform substantive test that covers all accounts equally

b)

Tailor procedures for specific assertions (e.g., existence, completeness) for classes of transactions, account balances, and disclosures based on identified risks

c)

Rely solely on analytical procedures at the overall financial statement level

d)

Delay all testing until year-end to maximize sample sizes

82.

Which statement best explains the role of inherent risk factors in the spectrum of inherent risk?

a)

Inherent risk factors are eliminated when controls operate effectively, so they are not considered in RoMM

b)

Inherent risk factors drive where a risk sits on a spectrum from lower to higher inherent risk, influencing how much audit work is needed

c)

Inherent risk factors only apply to fraud risks and not to error risks

d)

Inherent risk factors are measured solely by the number of prior-year adjustments

83.

A risk is identified where a misstatement is unlikely but, if it occurred, would be highly material. Based on the RoMM definition, which interpretation is most appropriate?

a)

It does not constitute RoMM because likelihood must be certain

b)

It may still constitute RoMM because reasonable possibility considers both likelihood and magnitude

c)

It automatically becomes a control deficiency rather than RoMM

d)

It should be ignored until an actual misstatement is found