CH 5

Ace your homework & exams now with Quizwiz!

Which of the following most likely would not be considered an inherent limitation of the potential effectiveness of an entity's internal controls? A. Incompatible duties B. Management override C. Mistakes in judgment D. Collusion among employees

A. Incompatible duties

Which of the following is not an input control activity? A. Reasonableness tests B. Record counts C. Financial totals D. Hash totals

A. Reasonableness tests

When an auditor plans to rely on controls that have changed since they were last tested, which of the following courses of action would be most appropriate? A. Test the operating effectiveness of such controls in the current audit. B. Document that reliance and proceed with the original audit strategy. C. Inquire of management as to the effectiveness of the controls. D. Report the reliance in the report on internal controls.

A. Test the operating effectiveness of such controls in the current audit.

Which of the following is a definition of control risk? A. The risk that a material misstatement will not be prevented or detected on a timely basis by the client's internal controls. B. The risk that the auditor will not detect a material misstatement. C. The risk that the auditor's assessment of internal controls will be at less than the maximum level. D. The susceptibility of material misstatement assuming there are no related internal controls, policies, or procedures.

A. The risk that a material misstatement will not be prevented or detected on a timely basis by the client's internal controls.

Which of the following is the least important audit reason for the auditor's obtaining an understanding of a company's internal control? A. To serve as a basis for constructive suggestions B. To plan subsequent substantive tests C. To identify types of possible misstatements that may occur D. To consider factors that may affect the risk of material misstatement

A. To serve as a basis for constructive suggestions

After obtaining an understanding of the entity's internal control and assessing control risk, an auditor of a non-public company decided not to perform additional tests of controls. The auditor most likely concluded that the A. additional evidence to support a further reduction in control risk was not cost beneficial. B. assessed level of inherent risk exceeded the assessed level of control risk. C. internal control structure was properly designed and justifiably may be relied on. D. evidence obtainable through tests of controls would not support an increased level of control risk.

A. additional evidence to support a further reduction in control risk was not cost beneficial.

An audit team's responsibility would not include A. designing client's internal controls. B. documentation of understanding of a client's internal controls. C. communicating internal control deficiencies. D. assessing the effectiveness a client's internal controls.

A. designing client's internal controls.

In an audit of financial statements of a non-public company in accordance with generally accepted auditing standards, an auditor is required to A. document the auditor's understanding of the entity's internal control. B. search for significant deficiencies in the operation of the internal controls. C. perform tests of controls to evaluate the effectiveness of the entity's accounting system. D. determine whether control activities are operating effectively to prevent or detect material misstatements.

A. document the auditor's understanding of the entity's internal control.

When the audit team increases the planned assessed level of control risk because certain control activities were determined to be ineffective, the audit team would most likely increase the A. extent of substantive tests of details. B. level of inherent risk. C. extent of tests of controls. D. level of detection risk.

A. extent of substantive tests of details.

After obtaining an understanding of internal controls and assessing control risk on the audit of a non-public company, an auditor decided to perform tests of controls. The auditor most likely decided that A. it would be efficient to perform tests of controls that would result in a reduction in planned substantive tests. B. additional evidence to support a further reduction in control risk is not available. C. an increase in the assessed level of control risk is justified for certain financial statement assertions. D. there were many internal control weaknesses that could allow errors to enter the accounting system.

A. it would be efficient to perform tests of controls that would result in a reduction in planned substantive tests.

The primary objective of procedures performed to obtain an understanding of the entity's internal control is to provide an auditor with A. knowledge necessary for audit planning. B. evidential matter to use in assessing inherent risk. C. a basis for modifying tests of controls. D. an evaluation of the consistency of application of management's policies.

A. knowledge necessary for audit planning.

In computer systems, the information technology general controls (ITGC) would not include A. processing control activities. B. separation of various computer system functions. C. appropriate documentation of the data processing system. D. control over physical access to computer hardware.

A. processing control activities.

Tracing bills of lading to sales invoices provides evidence that A. shipments to customers were invoiced. B. shipments to customers were recorded as sales. C. recorded sales were shipped. D. invoiced sales were recorded as sales.

A. shipments to customers were invoiced.

A report on internal control effectiveness by the management team of public companies is required by A. the Sarbanes-Oxley Act of 2002. B. the PCAOB. C. the AICPA. D. the auditors.

A. the Sarbanes-Oxley Act of 2002.

Which of the following statements is correct regarding internal control? A. A well-designed internal control environment ensures the achievement of an entity's control objectives. B. An inherent limitation to internal control is the fact that controls can be circumvented by management override. C. A well-designed and operated internal control environment should detect collusion perpetrated by two people. D. Internal control is a necessary business function and should be designed and operated to detect all errors and fraud.

B. An inherent limitation to internal control is the fact that controls can be circumvented by management override.

Which of the following outcomes is a likely benefit of information technology used for internal control? A. Processing of unusual or nonrecurring transactions B. Enhanced timeliness of information C. Potential loss of data D. Recording of unauthorized transactions

B. Enhanced timeliness of information

Generally accepted auditing standards (GAAS) give auditors considerable discretion to decide the amount of work required to satisfy auditing standards guiding internal control evaluation and related audit planning. Which of the descriptions below best expresses the minimum amount of work permitted by GAAS for nonpublic companies? A. Do not obtain an understanding of client environment, accounting, or control activities. Do not document the decision to assess control risk at maximum. Perform 100% substantive audit on all financial statement transactions and balances. B. Obtain an understanding of client environment, accounting, and control activities. Document the decision to assess control risk at maximum. Perform an extensive but not 100% substantive audit on financial statement transactions and balances. C. Obtain an understanding of client environment, accounting, and control activities, and perform detail tests of controls. Document the decision to assess control risk below the maximum. Perform restricted substantive audit on financial statement transactions and balances, considering the control risk assessment. D. Obtain an understanding of client environment, accounting, and control activities, and perform detail tests of controls. Document the decision to assess control risk at zero. Perform no substantive audit on financial statement transactions and balances, since zero control risk means that no errors or fraud can reach the accounts.

B. Obtain an understanding of client environment, accounting, and control activities. Document the decision to assess control risk at maximum. Perform an extensive but not 100% substantive audit on financial statement transactions and balances.

Which of the following areas can external auditors rely on internal auditors' work in auditing internal controls? A. Evaluation of the auditing environment B. Testing of low risk internal control activities C. All testing of the operating effectiveness of internal control activities D. As providing the principle evidence for the external auditors' opinion

B. Testing of low risk internal control activities

Which of the following factors is most likely to affect the extent of the documentation of the auditor's understanding of a client's system of internal controls? A. The industry and the business and regulatory environments in which the client operates B. The degree to which information technology is used in the accounting function C. The relationship between management, the board of directors, and external stakeholders D. The degree to which the auditor intends to use internal audit personnel to perform substantive tests

B. The degree to which information technology is used in the accounting function

An auditor is concerned about a policy of management override as a limitation of internal control. Which of the following tests would best assess the validity of the auditor's concern? A. Matching purchase orders to accounts payable B. Verifying that approved spending limits are not exceeded C. Tracing sales orders to the revenue account D. Reviewing minutes of board meeting

B. Verifying that approved spending limits are not exceeded

In an audit of financial statements, an auditor's primary consideration regarding an internal control policy or activity is whether the policy or activity A. reflects management's philosophy and operating style. B. affects management's financial statement assertions. C. provides adequate safeguards over access to assets. D. enhances management's decision making processes.

B. affects management's financial statement assertions.

Control strengths and weaknesses should be documented in audit documentation, sometimes called A. questionnaires, narratives, and flowcharts. B. bridge working papers. C. communications of significant deficiencies. D. internal control letters.

B. bridge working papers.

Obtaining an understanding of an internal control involves evaluating the design of the control and determining whether the control has been A. authorized. B. implemented. C. tested. D. monitored.

B. implemented.

If auditors assess control risk at the maximum level, they will tend to A. perform a great deal of additional tests of controls. B. perform a great deal of substantive testing during the audit. C. perform substantive tests at an interim date. D. perform more audit procedures using internal evidence.

B. perform a great deal of substantive testing during the audit.

In testing control activities, an auditor ordinarily selects from a variety of techniques, including A. inquiry and analytical procedures. B. reperformance and observation. C. comparison and confirmation. D. inspection and verification.

B. reperformance and observation.

A set of characteristics that helps to define a seriousness about employees' attitudes about the control activities in a company is referred to as A. management assertions. B. the control environment. C. control risk assessment. D. functional responsibilities.

B. the control environment.

Which of the following procedures is considered a test of controls? A. An auditor reviews the entity's check register for unrecorded liabilities. B. An auditor evaluates whether a general journal entry was recorded at the proper amount. C. An auditor interviews and observes appropriate personnel to determine segregation of duties. D. An auditor reviews the audit workpapers to ensure proper sign-off.

C. An auditor interviews and observes appropriate personnel to determine segregation of duties.

Which of the following client internal control activities is not usually performed in the treasurer's department? A. Verifying the accuracy of checks and vouchers B. Controlling the mailing of checks to vendors C. Approving vendors' invoices for payment D. Canceling payment vouchers when paid

C. Approving vendors' invoices for payment

Which of the following should an auditor do when control risk is assessed at the maximum level? A. Perform fewer substantive tests of details B. Perform more tests of controls C. Document the assessment D. Document the control structure more extensively

C. Document the assessment

Which of the following is a step in an auditor's decision to assess control risk at below the maximum? A. Apply analytical procedures to both financial data and nonfinancial information to detect conditions that may indicate weak controls. B. Perform tests of details of transactions and account balances to identify potential errors and fraud. C. Identify specific internal control policies and activities that are likely to detect or prevent material misstatements. D. Document that the additional audit effort to perform tests of controls exceeds the potential reduction in substantive testing.

C. Identify specific internal control policies and activities that are likely to detect or prevent material misstatements.

Which of the following is not a component of internal controls? A. Control environment B. Control activities C. Inherent risk D. Monitoring

C. Inherent risk

Which of the following is not an objective of internal controls over financial reporting as defined by the Sarbanes-Oxley Act? A. Policies and procedures that pertain to the maintenance of records that in reasonable detail accurately and fairly reflect the transactions and dispositions of the assets of the registrant. B. Policies and procedures that provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and receipts and expenditures of the registrant are being made only in accordance with authorizations of management and directors of the registrant. C. Policies and procedures that provide reasonable assurance regarding the compliance with applicable laws and regulations. D. Policies and procedures that provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of the registrant's assets that could have a material effect on the financial statements.

C. Policies and procedures that provide reasonable assurance regarding the compliance with applicable laws and regulations.

When auditing financial statements of a private company, the minimum work an auditor must perform in connection with a company's internal control is best described by which of the following statements. A. Perform exhaustive tests of accounting controls and evaluate the company's control system effectiveness. B. Determine whether the company's control policies are designed well enough to prevent material misstatements. C. Prepare auditing working papers that document the auditor's understanding of the company's internal control. D. Design procedures to search for significant deficiencies in the actual operation of the company's internal control.

C. Prepare auditing working papers that document the auditor's understanding of the

Which of the following audit procedures most likely would provide an auditor with the most assurance about the effectiveness of the operation of an entity's internal control? A. Confirmation with outside parties B. Inquiry of client personnel C. Successful re-performance of the control activity D. Observation of client personnel

C. Successful re-performance of the control activity

Which of the following statements best describes why an auditor would use only substantive procedures to evaluate specific relevant assertions and risks? A. The relevant internal control components are not well documented. B. The internal auditor already has tested the relevant controls and found them effective. C. Testing the operating effectiveness of the relevant controls would not be efficient. D. The cost of substantive procedures will exceed the cost of testing the relevant controls.

C. Testing the operating effectiveness of the relevant controls would not be efficient.

An auditor is evaluating a client's internal controls. Which of the following situations would be the most difficult internal control issue for an auditor to detect? A. The accounting staff neglects the control, due to increased transactions to be processed. B. The technology department writes a program that does not properly implement the control, due to a lack of understanding. C. Two employees, who work in different departments, are circumventing an internal control. D. Someone erroneously disables edit checks in a software program designed to identify control exceptions.

C. Two employees, who work in different departments, are circumventing an internal control.

The "obtaining an understanding" work phase (Phase 1) of internal control evaluation would not give auditors an overall acquaintance with the client's A. control environment. B. information and communication system. C. control activity effectiveness. D. monitoring activities.

C. control activity effectiveness.

The overall attitude and awareness of an entity's board of directors concerning the importance of the client's internal control usually is reflected in its A. computer-based control activities. B. system of separation of duties. C. control environment. D. safeguards over access to assets.

C. control environment.

After obtaining an understanding of a client's financial reporting control activities, the auditor would next A. test the client's control activities. B. assess the final control risk. C. document the understanding obtained. D. plan the remainder of the audit work.

C. document the understanding obtained.

The internal control in small business is highly dependent on the A. separation of functional responsibilities. B. complexity of the client's internal controls. C. owner-manager's competence, as well as his/her ethics and integrity. D. bonding of employees.

C. owner-manager's competence, as well as his/her ethics and integrity.

Each of the following types of controls is considered to be an entity-level control, except those A. relating to the control environment. B. pertaining to the company's risk assessment process. C. regarding the company's annual stockholder meeting. D. addressing policies over significant risk management practices.

C. regarding the company's annual stockholder meeting.

The ultimate purpose of assessing control risk is to contribute to the auditor's evaluation of the A. factors that raise doubts about the auditability of the financial statements. B. operating effectiveness of internal control policies and procedures. C. risk that material misstatements exist in the financial statements. D. possibility that the nature and extent of substantive tests may be reduced.

C. risk that material misstatements exist in the financial statements.

Regardless of the assessed level of control risk, an auditor of a non-public company would perform some A. tests of controls to determine the effectiveness of internal control policies. B. analytical procedures to verify the design of internal control activities. C. substantive tests to restrict detection risk for significant transaction classes. D. dual purpose tests to evaluate both the risk of monetary misstatement and preliminary control risk.

C. substantive tests to restrict detection risk for significant transaction classes.

Which of the following is the best way to compensate for the lack of adequate segregation of duties in a small organization? A. Disclosing lack of segregation of duties to the external auditors during the annual review B. Replacing personnel every three or four years C. Requiring accountants to pass a yearly background check D. Allowing for greater management oversight of incompatible activities

D. Allowing for greater management oversight of incompatible activities

Which of the following activities performed by a department supervisor most likely would help in the prevention or detection of a payroll fraud? A. Distributing paychecks directly to department store employees B. Setting the pay rate for departmental employees C. Hiring employees and authorizing them to be added to payroll D. Approving a summary of hours each employee worked during the pay period

D. Approving a summary of hours each employee worked during the pay period

If a control total were to be computed on each of the following data items, which would best be identified as a hash total for a payroll IT application? A. Hours worked B. Total debits and total credits C. Net pay D. Department numbers

D. Department numbers

Which of the following would most likely be classified as a material weakness? A. Absence of appropriate separation of duties B. Absence of appropriate reviews and approvals of transactions C. Evidence of failure of control activities D. Ineffective oversight of the financial reporting process by the company's audit committee

D. Ineffective oversight of the financial reporting process by the company's audit committee

Which of the following is a factor in the control environment? A. Segregation of duties B. Information processing C. Performance reviews D. Management's philosophy and operating style

D. Management's philosophy and operating style

Which of the following payroll control activities would most effectively ensure that payment is made only for work performed? A. Require all employees to record arrival and departure by using the time clock. B. Have a payroll clerk recalculate all time cards. C. Require all employees to sign their time cards. D. Require employees to have their direct supervisors approve their time cards.

D. Require employees to have their direct supervisors approve their time cards.

Which of the following is an Information Technology General Control? A. Check digit B. Run-to-run totals C. Distribution of computerized output D. Separation of duties in the IT department

D. Separation of duties in the IT department

Management's report on internal controls must include each of the following except A. a statement that management is responsible for establishing and maintaining adequate internal control over financial reporting. B. a statement identifying the framework management uses to evaluate the effectiveness of the company's internal control. C. a statement providing management's assessment of the effectiveness of the company's internal control. D. a statement providing management's evaluation of the company's control environment.

D. a statement providing management's evaluation of the company's control environment.

A sales clerk enters a customer's six-number customer account. The computer program uses the first five numbers to calculate a sixth number. This resulting number is then compared to the sixth number entered by the sales clerk. This is an example of a A. a valid character test. B. missing data test. C. reasonableness test. D. check digit.

D. check digit.

Control activities intended to ensure that transactions are recorded in the right period are designed to achieve the ASB assertion of A. occurrence. B. accuracy. C. valuation or allocation. D. cutoff.

D. cutoff.

The appropriate separation of duties does not include A. authorization to execute transactions. B. recording of transactions. C. custody of assets involved in the transactions. D. data preparation.

D. data preparation.

Sound internal control can be described as separating all of the following duties and responsibilities except for A. transaction authorization. B. recordkeeping. C. custody of, or direct access to, assets. D. hiring of employees.

D. hiring of employees.

Assessing control risk at below the maximum level most likely would involve A. performing more extensive substantive tests with larger sample sizes than originally planned. B. reducing inherent risk for most of the assertions relevant to significant account balances. C. changing the timing of substantive tests by omitting interim-date testing and performing the tests at year end. D. identifying specific internal control activities that are relevant to specific financial statement assertions.

D. identifying specific internal control activities that are relevant to specific financial statement assertions.

As part of understanding the internal control, an auditor is not required to A. consider factors that affect the risk of material misstatement. B. ascertain whether internal control policies and activities have been placed in operation. C. identify the types of potential misstatements that can occur. D. obtain knowledge about the operating effectiveness of the client's internal control activities.

D. obtain knowledge about the operating effectiveness of the client's internal control activities.

Proper separation of duties reduces the opportunities to allow persons to be in positions to both A. journalize entries and prepare financial statements. B. record cash receipts and cash disbursements. C. establish internal controls and authorize transactions. D. perpetrate a fraud and then conceal it in the books.

D. perpetrate a fraud and then conceal it in the books.

When obtaining an understanding of an entity's internal control in a financial statement audit at a non-public company, an auditor is not obligated to A. determine whether the control activities have been placed in operation. B. perform procedures to understand the design of the internal control system. C. document the understanding of the company's internal control system. D. search for significant deficiencies in the operation of the internal control system.

D. search for significant deficiencies in the operation of the internal control system.


Related study sets

13.3 determining the amount of life insurance

View Set

Peripheral Vascular and Lymphatics

View Set

NCLEX 10000 Genitourinary Disorders

View Set

PTAC 1302 Final Exam Review Questions

View Set

Federal Income Tax Final Questions

View Set

IB Chemistry - Organic Chemistry

View Set

Blood Types, Antigens, & Antibodies

View Set