WorksheetsCHAPTER 7: Visual Overview and Audit Planning Scope
Total questions: 83
Worksheet time: 42mins
Which pathway best describes the sequence emphasized in the overview: from planning through to handling identified risks and evidence gathering? Choose the option that reflects the flow shown in the diagram.
Planning (ISA 300) → Risk Assessment (ISA 315 Revised 2019) → Auditor’s Responses
Materiality (ISA 320) → Audit Risk → Planning (ISA 300)
Transnational Audits → Planning (ISA 300) → Analytical Procedures (ISA 315 Revised 2019)
Audit Risk → Risk Assessment (ISA 315 Revised 2019) → Planning (ISA 300)
Which statement best describes the overall audit strategy?
It specifies detailed procedures for each assertion and account balance.
It sets the scope, timing and direction of the audit and guides the development of the audit plan.
It documents only reporting deadlines for interim and final reporting.
It lists industry-specific regulations without linking them to audit work.
According to the material, what is the primary purpose of developing an audit plan?
To ensure the auditor follows the client’s internal timetable for reporting.
To reduce audit risk to an acceptably low level by describing the nature, timing and extent of planned procedures.
To eliminate the need for professional judgement by standardizing all tests.
To focus solely on substantive procedures while omitting tests of control.
Which of the following is NOT listed as an objective of audit planning?
To devote appropriate attention to important areas.
To identify potential problems and resolve them on a timely basis.
To maximize audit fees by expanding procedures unnecessarily.
To organise and manage the engagement in an effective and efficient way.
Professional scepticism at the planning stage is essential primarily to ensure which outcome?
That audit documentation is lengthy and detailed regardless of risk.
That the right level of professional judgement is used and resources are allocated to high-risk areas at the appropriate time.
That the auditor accepts management’s assertions unless contradicted by written evidence.
That audit procedures are identical across all clients for comparability.
Applying professional scepticism in planning includes which action?
Relying on management’s group consensus to streamline decisions.
Designing procedures to seek evidence that would contradict management assertions, such as on fair values or impairment.
Avoiding the use of external confirmations to reduce cost.
Assuming there are no unrecorded related party transactions unless proven otherwise.
Which factor is explicitly part of determining the scope of the audit engagement within the audit strategy?
The auditor’s staffing preferences.
The financial reporting framework used by the entity.
The audit firm’s marketing budget.
The prior year’s audit fee negotiations.
Which item is identified as part of establishing the direction of the audit in the overall strategy?
Designing detailed assertion-level tests for every account.
Determining appropriate materiality levels and identifying higher risks of material misstatement.
Preparing the auditor’s tax return for the year.
Scheduling client board meetings.
What components must the audit plan include at the assertion level for each material class of transactions, account balance, and disclosure?
Only analytical procedures performed at year-end.
Tests of control and substantive procedures responsive to assessed risks.
A summary of governance requirements with no procedures.
A list of internal control questionnaires completed by management.
Which example reflects using a high degree of knowledge of the entity’s business and operating environment when applying professional scepticism?
Monitoring going concern indicators relevant to the client’s industry.
Accepting management’s impairment estimates without challenge.
Relying solely on prior year workpapers for planning.
Deferring understanding of new disclosure requirements until after fieldwork.
Which of the following is included in the audit plan to comply with relevant ISAs for the assignment?
External confirmations, use of an expert, subsequent events work, going concern procedures, and management representations.
Only walkthroughs of significant processes documented by the client.
A complete replication of the internal audit plan without changes.
Procedures limited to interim testing to meet reporting deadlines.
How should direction and supervision of engagement team members change based on risk and experience, according to the section on Direction, Supervision and Review?
Increase as assessed risk of material misstatement increases and as team member experience decreases.
Remain constant regardless of risk or experience to ensure consistency.
Decrease as risk increases to avoid bias and allow independent work.
Be determined solely by the client’s reporting deadlines.
What documentation requirement is emphasized regarding planning?
Only document significant changes to the audit plan; the strategy can remain verbal.
Document the overall audit strategy and the audit plan, including any significant changes made during the audit engagement.
Archive test schedules but exclude risk assessments to protect confidentiality.
Rely on email threads as sufficient documentation for planning decisions.
According to ISA 315 (Revised 2019), what is the primary purpose of identifying and assessing risks of material misstatement at the financial statement and assertion levels?
To reduce the scope of audit documentation
To provide a basis for designing and implementing responses to assessed risks
To eliminate the need for substantive procedures
To determine the audit fee structure
Which sequence best reflects the ISA 315 (Revised 2019) requirements an auditor must perform during planning?
Understand internal control; design overall responses; identify risks; perform further audit procedures
Design risk assessment procedures; understand the entity and environment; understand internal control; identify and assess risks
Identify risks; design further audit procedures at the assertion level; evaluate evidence; issue the report
Evaluate sufficiency of audit evidence; understand the financial reporting framework; design risk assessment procedures
ISA 315 (Revised 2019) includes scalability considerations. What does scalability mean in this context?
Requirements vary only for listed entities
Application guidance illustrates how requirements can be applied regardless of entity complexity
Auditors can ignore certain requirements for small clients
Scalability allows auditors to delegate planning to management
Link ISA 315 and ISA 330: Which action under ISA 330 directly follows the identification and assessment of risks under ISA 315?
Issuing the audit opinion
Designing and implementing overall responses at the financial statement level
Preparing the management representation letter
Recalculating prior-period balances
Under ISA 330, further audit procedures respond to risks of material misstatement at which level(s)?
Only the financial statement level
Only the assertion level (e.g., occurrence, completeness, accuracy)
Both the financial statement and disclosure levels only
Only the control activity level
Definition check: Risk assessment procedures are audit procedures designed to identify and assess risks of material misstatement at which levels?
Only at the disclosure level
At the financial statement and assertion levels
At the transaction cycle and account balance levels only
At the control and compliance levels only
Which of the following is NOT listed as a type of risk assessment procedure?
Analytical procedures on internal and external information
Enquiries of management and others in the entity
Inspection of premises, plans, and control documents
Reperformance of year-end closing entries by the auditor
A senior plans risk assessment work and wants to avoid bias. Which approach aligns with the guidance?
Seek only corroborative audit evidence that confirms existing beliefs
Include procedures that may yield contradictory audit evidence if relevant
Exclude external information to maintain confidentiality
Rely solely on prior-year conclusions if the client has not changed
Which mnemonic is suggested to help remember the main risk assessment procedures?
CAPE
AEIO or AEIOU
RADAR
TRACE
Which statement best describes the role of professional scepticism during risk assessment?
It is optional if prior audits found no issues
It is necessary for critically assessing audit evidence and discussing susceptibility to misstatement
It only applies to testing internal controls
It is primarily used for calculating materiality thresholds
When understanding the entity and its environment, which of the following is explicitly included?
Only ownership structure, excluding governance
Business model, including the extent of IT integration
Future stock price projections
Tax planning for shareholders
What must the auditor evaluate regarding accounting policies when considering the applicable financial reporting framework?
Whether policies minimize reported profit volatility
Whether policies are appropriate and consistent with the applicable financial reporting framework
Whether policies match those of industry leaders
Whether policies reduce the extent of substantive testing required
Which statement best defines a system of internal control for an entity preparing financial statements?
A set of informal practices used by staff to speed up operations regardless of risk
The system designed, implemented, and maintained by TCWG, management, and personnel to provide reasonable assurance about achieving objectives in reporting, operations, and compliance
A checklist used by auditors to detect every possible misstatement with absolute certainty
A software package that automates accounting entries and eliminates the need for oversight
According to the section, which objective is specifically supported by the system of internal control?
Maximizing tax refunds for the entity
Reliability of financial reporting
Eliminating business risks entirely
Guaranteeing profit growth each quarter
The diagram shows five inter‑related components of internal control. Which list correctly names these components?
Control environment, risk assessment, information systems, control activities, control monitoring
Governance structure, budgeting, staffing, outsourcing, auditing
Strategic planning, marketing, production, human resources, financing
Financial statements, cash flow, investments, payroll, compliance testing
A key point states that the auditor must perform risk assessment procedures to understand each component relevant to which task?
The preparation of the financial statements
Setting executive compensation
Approving tax filings
Designing the entity’s marketing plan
Which aspect is part of the control environment relevant to financial statement preparation?
How budgets are allocated among departments
How management’s oversight responsibilities are carried out, including commitment to integrity and ethical values
How sales targets are set for the marketing team
Which software vendor supports the ERP system
When TCWG are separate from management, what does the control environment require the auditor to consider?
The independence of TCWG and their oversight of the system of internal controls
The size of the boardroom and meeting frequency alone
The personal investment portfolios of TCWG members
Whether TCWG approve every journal entry
Which item is NOT listed as part of the control environment focus for financial statement preparation?
Assignment of authority and responsibility
How individuals are held accountable for responsibilities related to internal control
How competent individuals are attracted, developed, and retained
The selection of external auditors by shareholders
What should the auditor evaluate regarding management and the control environment?
Whether management has created and maintained a culture of honesty and ethical behaviour
Whether management can eliminate all control deficiencies entirely
Whether management writes the financial statements without estimates
Whether management outsources all key operations
The material notes that a dominant individual can have what type of effect on the control environment?
Only a positive effect by speeding decisions
No significant effect because controls are documented
A pervasive effect that may be positive or negative
Only a negative effect due to lack of delegation
In the example of a dominant individual, what heightened risk does concentration of knowledge and authority create?
Increased susceptibility to misstatement through management override of controls
Higher audit fees due to more controls
Reduced responsiveness to market opportunities
Guaranteed compliance with all regulations
The entity’s risk assessment process relevant to financial reporting includes which step?
Ignoring risks that are unlikely to occur
Identifying business risks relevant to financial reporting objectives
Eliminating risks by purchasing insurance
Delegating risk ownership to external auditors
Which statement about the auditor’s responsibility for understanding business risks is correct?
The auditor is required to understand all business risks of the entity
The auditor is not required to understand or identify all business risks because not all give rise to risks of material misstatement
The auditor must only understand tax-related risks
The auditor should document every informal conversation about risks as formal evidence
If the auditor identifies risks of material misstatement that management failed to identify, which action is included in the required response?
Immediately issue a qualified opinion without further procedures
Determine whether such risks should have been identified by management and understand why the process failed
Replace the management team
Ignore the risks if they are not documented
In less complex or owner-managed entities, how might an appropriate risk assessment be performed?
Through an automated scoring model only
Through the direct involvement of management or the owner-manager, such as monitoring competitors and market developments, even if not formally documented
Only by hiring an external consultant to conduct annual workshops
By relying solely on internal audit reports
When evaluating the entity’s process to monitor the system of internal control, what should the auditor understand?
How the entity monitors the effectiveness of controls and remediates deficiencies, and the nature, responsibilities, and activities of the internal audit function, if any
Only the number of controls documented in the manual
Only whether management meets quarterly
Which ERP modules are licensed
Which approach best confirms an auditor’s understanding of how transactions flow through the information system when the auditor can access the client’s databases?
Interviewing staff about typical journal entry procedures across departments
Applying automated tools to trace digital records from initiation in accounting records through posting in the general ledger
Sending external confirmations to customers for a sample of outstanding receivables
Observing end-of-period inventory counts to reconcile quantities to the ledger
According to the example of confirming the information system, analyzing complete or large sets of transactions primarily helps the auditor to:
Identify violations of tax laws unrelated to financial reporting
Benchmark company profitability against industry peers
Detect variations from expected processing procedures that may indicate risks of material misstatement
Estimate the useful lives of long-term assets
When understanding an entity’s information processing activities, which of the following is explicitly included?
Only how transactions are recorded in the general ledger
How information flows through the information system, the accounting records, the financial reporting process including disclosures, and relevant resources including the IT environment
Only controls over cash receipts and cash payments
Only management’s review of budget-to-actual variances
Which statement best reflects the auditor’s responsibility regarding accounting policies?
Ensure the entity adopts the same policies as industry leaders
Design the entity’s accounting policies and procedures
Evaluate whether the entity’s accounting policies are appropriate and consistent with the applicable financial reporting framework
Approve changes in accounting policies before management implements them
Which objective is part of the system of internal control as defined in the material?
Maximizing shareholder returns through aggressive investment strategies
Reliability of financial reporting, effectiveness and efficiency of operations, and compliance with applicable laws and regulations
Eliminating all business risks through insurance contracts
Setting executive compensation based on market benchmarks
Which components are shown as inter-related within the system of internal control in the diagram described?
Control environment, risk assessment, information systems, control activities, and control monitoring
Strategic planning, budgeting, variance analysis, forecasting, and performance bonuses
Cash management, procurement, payroll, sales, and taxation
Authorization, custody, recording, reconciliation, and reporting
In the monitoring example for a less complex entity, management’s handling of customer complaints is used primarily to:
Identify issues with the timing of recognition of customers’ payments and reference actions like credit notes or refunds to supporting documents in accounting records
Forecast sales by region using historical complaint trends
Perform a physical count of inventory at year-end
Determine the appropriate discount rate for impairment testing
Which element is part of understanding the entity and its environment for risk assessment purposes?
The auditor’s internal staffing plan for the engagement
The entity’s business model, including the extent of IT integration, and external factors such as industry and regulation
Only the client’s tax filing history for the past three years
A comparison of the client’s stock price to market indices
What does the guidance indicate about transactions information other than transactions within the information system?
Only transactions are captured; events and conditions are excluded
Information about events and conditions, other than transactions, is captured, processed and disclosed in the financial statements
Events and conditions are recorded only if they affect cash flows
Events are disclosed without processing in the accounting system
Which statement best links automated techniques with audit risk assessment when confirming the information system?
Automated techniques eliminate the need for professional judgment in assessing risk
Automated analysis of large transaction sets can reveal deviations from expected processing, helping identify risks of material misstatement
Automated tools are suitable only for small samples due to processing limits
Automated techniques are used only after the audit opinion is issued
Which aspect is included when evaluating the control environment relevant to preparing financial statements?
How individuals are held accountable for internal control responsibilities
The tax rates applicable to the entity’s jurisdiction
Customer satisfaction scores for the latest quarter
The brand recognition of the entity’s products
An auditor evaluating the control environment should determine whether management has created and maintained which of the following?
A culture of honesty and ethical behaviour
A focus on maximizing sales volume at any cost
An exclusive emphasis on cost reduction
A system that eliminates all manual controls
A single dominant individual may have a pervasive effect on an organisation’s culture and control environment. What is a potential negative consequence noted?
Increased susceptibility to misstatement through management override of controls
Reduced need for ethical standards
Elimination of business risks relevant to financial reporting
Automatic documentation of all processes
Regarding the entity’s risk assessment process relevant to financial statements, which sequence best reflects management’s responsibilities?
Identify business risks relevant to financial reporting, assess their significance and likelihood, and address those risks
Address risks first, then assess significance, then identify risks
Identify only operational risks, then outsource their assessment and ignore addressing them
Wait for the auditor to identify risks, then address only the most likely ones
Which statement about the auditor’s responsibility for understanding business risks is correct?
The auditor is not required to understand or identify all business risks because not all business risks give rise to risks of material misstatement
The auditor must identify every business risk regardless of relevance to financial reporting
The auditor focuses only on risks documented formally by management
The auditor evaluates only external risks, not internal ones
In less complex, owner-managed entities, what evidence might indicate that management is performing risk assessment procedures even if not formally documented?
Discussions showing the owner-manager monitors competitors and market developments to identify emerging risks
A complete absence of any mention of risks in meetings
Exclusive reliance on external auditors for risk identification
A policy stating risks will be addressed after year-end close only
If the auditor identifies risks of material misstatement that management failed to identify, what should the auditor do first according to the guidance?
Determine whether such risks should have been identified by management
Immediately issue an adverse opinion
Ignore the risks if they are not documented
Assume the risk assessment process is appropriate without further inquiry
To understand the entity’s monitoring of internal control, the auditor needs to know which of the following?
How the entity identifies and remediates control deficiencies through periodic or ongoing evaluations
How the entity prices its products across regions
How marketing campaigns are scheduled
How payroll tax tables are set by the government
In an owner-managed entity with limited formal monitoring, which activity could serve as a monitoring control related to financial statements?
Recording and signing off customer complaints and referencing related credit notes or refunds to supporting documents and accounting entries
Launching a new product line based on customer feedback
Revising the company logo after complaints
Outsourcing all accounting to eliminate internal records
Understanding the entity’s information processing activities includes knowing how transactions are handled. Which is included in this understanding?
How transactions are initiated, recorded, processed, corrected as necessary, incorporated in the general ledger, and reported in the financial statements
How the entity designs advertising for new products
How office seating arrangements are assigned
How shareholder meetings are scheduled by the legal team
Which activity best illustrates how automated tools can help confirm an auditor’s understanding of the information system’s transaction flows?
Scanning final financial statements for formatting inconsistencies
Tracing journal entries from initiation through posting in the general ledger using digital records
Interviewing only external parties about the client’s reporting responsibilities
Comparing the client’s budget to industry averages without accessing transaction data
An auditor downloads a large set of transaction data and identifies variations from expected processing procedures. What is the primary audit implication of these variations?
They automatically prove fraud has occurred
They indicate risks of material misstatement may be present
They show that controls are operating effectively
They eliminate the need for further substantive procedures
According to the guidance, the auditor should understand how significant matters supporting financial statement preparation are communicated. Which channels are explicitly included?
Within the entity, between management and those charged with governance, and with external parties
Only between management and the audit committee
Only within the IT department
Only with external regulators after year-end
At the assertion level, the auditor must identify control activities that address risks of material misstatement. Which is an example of a control that addresses a significant risk?
Automated bank reconciliations performed quarterly
Review of assumptions by senior management or experts
Written job descriptions for all employees
Use of a standard chart of accounts
Which control activity focuses specifically on journal entries, including non-standard entries for unusual transactions or adjustments?
Segregation of duties between initiation, authorisation, posting, and review of journal entries
Monthly variance analysis by department heads
Reconciliation of sub-ledgers to the general ledger annually
Physical inventory counts once a year
When the auditor plans to test operating effectiveness of controls to determine the nature, timing, and extent of substantive procedures, which examples align with this focus?
Authorisations and approvals; edit and validation checks; physical controls such as periodic counting of inventory or cash
Quarterly board strategy sessions; staff training plans
External benchmarking studies; customer satisfaction surveys
Insurance policy renewals; legal representation letters
Which is an example of a control identified based on the auditor’s professional judgement when a service organisation is used?
Complementary user entity controls
Internal audit’s annual report
Budgetary control oversight
Shareholder meeting minutes
What is the stated purpose of general IT controls within the IT environment?
To replace the need for information processing controls entirely
To support the continued proper operation of the IT environment and the integrity of information, including completeness, accuracy, and validity
To ensure only manual processes are used for critical transactions
To focus solely on cybersecurity insurance coverage
Which description best defines the IT environment as used in the guidance?
Only the accounting software used to record journal entries
IT applications and supporting IT infrastructure, along with the IT processes and personnel that support business operations and strategies
External cloud vendors and internet connections only
Hardware devices without related processes or personnel
Which general IT control helps ensure that users access only information necessary for their job responsibilities, facilitating appropriate segregation of duties?
Authentication
Authorisation
Provisioning
Physical access
What is the primary purpose of deprovisioning as a general IT control?
To assign initial log-in credentials to new users
To modify existing users’ access privileges for promotions
To remove user access upon termination or transfer
To conduct periodic penetration testing
Which activity is an example of a user access review within general IT controls?
Recertifying or evaluating user access for authorisation
Resetting passwords after three failed attempts
Encrypting backups stored offsite
Monitoring internet usage for policy violations
Why is physical access to the data centre and hardware a key general IT control?
Because physical access can be used to override other controls
Because it eliminates the need for logical access controls
Because it only affects employee attendance records
Because it guarantees compliance with all regulations
For each control activity and general IT control identified, what is the first required evaluation step the auditor must perform?
Test operating effectiveness through sampling
Evaluate its design to determine if it is capable of effectively preventing or detecting misstatements, individually or in combination with other controls
Obtain external confirmations from third parties
Prepare a management letter with recommendations
Scenario: You are planning an audit of a client that relies on a service organisation for payroll processing. To address potential risks of material misstatement at the assertion level, which control focus would be most strategic to identify and understand first?
Controls over marketing campaigns that increase sales volume
Complementary user entity controls relevant to the service organisation’s processing
Inventory valuation models used for slow-moving items
Office access policies for visitors during public tours
Which statement best defines when a risk of material misstatement (RoMM) exists?
Whenever any error is identified regardless of size or likelihood
When there is a reasonable possibility of a misstatement occurring and it would be material if it occurred
Only when fraud is suspected by management
When the auditor cannot obtain any audit evidence
RoMM may exist at two levels. Which pairing correctly describes these levels?
Organizational level and department level
Financial statement level affecting many assertions, and assertion level for classes of transactions, account balances, and disclosures
Subsidiary level and consolidated level
Operational level and strategic level
According to the material, RoMM is assessed at the assertion level primarily to determine which of the following?
The size of the audit engagement team
The nature, timing, and extent of further audit procedures to obtain sufficient appropriate audit evidence
Whether management’s budget is reasonable
The need to rotate the audit partner
Which pair correctly matches the two components embedded in the definition of RoMM?
Control design and control implementation
Likelihood of misstatement and magnitude if it occurs
Detection risk and sampling risk
Inherent risk and control risk
Select the scenario that most clearly indicates a financial statement level RoMM rather than an assertion level RoMM.
Revenue recognition for a specific product line is complex due to multiple-element contracts
A pervasive IT system failure could impact multiple account balances and disclosures
Inventory valuation for a single warehouse requires significant estimates
Classification of one lease contract is unclear
When planning audit procedures in response to RoMM, which option best applies the concept of assessing at the assertion level?
Design one uniform substantive test that covers all accounts equally
Tailor procedures for specific assertions (e.g., existence, completeness) for classes of transactions, account balances, and disclosures based on identified risks
Rely solely on analytical procedures at the overall financial statement level
Delay all testing until year-end to maximize sample sizes
Which statement best explains the role of inherent risk factors in the spectrum of inherent risk?
Inherent risk factors are eliminated when controls operate effectively, so they are not considered in RoMM
Inherent risk factors drive where a risk sits on a spectrum from lower to higher inherent risk, influencing how much audit work is needed
Inherent risk factors only apply to fraud risks and not to error risks
Inherent risk factors are measured solely by the number of prior-year adjustments
A risk is identified where a misstatement is unlikely but, if it occurred, would be highly material. Based on the RoMM definition, which interpretation is most appropriate?
It does not constitute RoMM because likelihood must be certain
It may still constitute RoMM because reasonable possibility considers both likelihood and magnitude
It automatically becomes a control deficiency rather than RoMM
It should be ignored until an actual misstatement is found
