- Published: September 26, 2022
- Updated: September 26, 2022
- University / College: University of Colorado Boulder
- Language: English
- Downloads: 4
- Which of the following would beleastlikely to be regarded as a test of control?
- Tests of the additions to property by physical inspection
- Tests of the signatures on cancelled checks to the authorized check signer list
- Test of signatures on purchase orders
- Recalculation of payroll deductions
- Which of the following isleastlikely to be evidence of operating effectiveness?
- Cancelled supporting documents
- Confirmations of accounts payable
- Records of documenting usage of computer programs
- Signatures on authorized forms
- Which is the most likely change, among the following, in audit procedures when the assessed level of control risk increases?
- Change from performing substantive tests at year-end to an interim date.
- Perform substantive tests directed inside the entity rather than tests directed toward parties outside the entity.
- Use the maximum number of dual purpose tests.
- Use a larger sample size for substantive tests.
- The definition of internal control developed by the Committee of Sponsoring Organizations (COSO) includes the reliability of financial reporting, the effectiveness and efficiency of operations, and
- compliance with applicable laws and regulations.
- effectiveness of prevention of fraudulent occurrences.
- safeguarding of entity assets.
- incorporation of ethical business practice standards.
5. After considering the client’s internal control, the auditors have concluded that it is well designed and is functioning as anticipated. Under the circumstances, the auditors would most likely
- cease to perform further substantive tests.
- reduce substantive tests in areas where the internal control was found to be effective.
- increase the extent of anticipated analytical procedures.
- perform all tests of controls to the extent outlined in the preplanned audit program.
- Which of the following isleastlikely to be considered an appropriate response relating to risks the auditors identify at thefinancial statementlevel?
- Assign more experienced staff.
- Incorporate additional elements of unpredictability in the selection of audit procedures.
- Increase the scope of auditor procedures.
- Emphasize the need to remain neutral, rather than to exercise professional skepticism.
- A client’s internal control appears strong, but the CPA has chosen not to test it. The planned assessed level of control risk is at what level?
- Zero
- Low
c. Moderate
- Maximum
- Which of the following matters would an auditor most likely consider to be a significant deficiency to be communicated to the audit committee?
- Management’sfailureto renegotiate unfavorable long-term purchase commitments.
- Recurring operating losses that may indicate going concern problems.
- Evidence of a lack of objectivity by those responsible for accounting decisions.
- Management’s current plans to reduce its ownership equity in the entity.
- The internal control provisions of the Sarbanes-Oxley Act of 2002 apply to which companies in the United States?
- All companies
- SEC registrants
- Only those companies included in the Fortune 500
- All nonpublic companies
- In assessing the objectivity of a client’s internal auditors, the CPA would be most likely to consider the internal auditors’
- educationlevels.
- experience.
c. organizational status within the company.
- training and supervisory skills.
- he Sarbanes-Oxley Act of 2002 requires that the audit committee
- annually reassess control risk using information from the CPA firm.
- be directly responsible for the appointment, compensation and oversight of the work of the CPA firm .
- require that the company’s CPA firm rotate the partner in charge of the audit.
- review the level of management compensation.
- When performing an audit of internal controls under PCAOB requirements, auditors evaluate the controls of
- both design effectiveness and operating effectiveness.
- design effectiveness but not operating effectiveness.
- operating effectiveness but not design effectiveness.
- neither design effectiveness nor operating effectiveness.
- For effective internal control, which of the following functions shouldnotbe assigned to the company’s accounting department?
- Reconciling accounting records with existing assets
- Recording financial transactions
- Signing payroll checks
- Preparing financial reports
- Which of the following is an advantage of describing internal control through the use of a standardized questionnaire?
- Questionnaires highlight weaknesses in the system .
- Questionnaires are more flexible than other methods of describing internal control.
- Questionnaires usually identify situations in which internal control weaknesses are compensated for by other strengths in the system.
- Questionnaires provide a clearer and more specific portrayal of a client’s system than other methods of describing internal control.
- (CPA, adapted) The primary objective of procedures performed to obtain an understanding of internal control is to provide an auditor with
- knowledge necessary for audit planning .
- evidential matter to use in assessing inherent risk.
- a basis for modifying tests of controls.
- an evaluation of the consistency of application of management’s policies.
- (CPA, adapted) An advantage of using systems flowcharts to document information about internal control instead of using internal control questionnaires is that systems flowcharts
- identify internal control weaknesses more prominently.
- provide a visual depiction of clients’ activities .
- indicate whether controls are operating effectively.
- reduce the need to observe clients’ employees performing routine tasks.
- (CPA, adapted) Which of the following most likely would not be considered an inherent limitation of the potential effectiveness of an entity’s internal control?
- Incompatible duties
- Management override
- Faulty judgment
- Collusion among employees
- An auditor may decidenotto perform tests of controls related to the control activities within the computer portion of the client’s internal control. Which of the following wouldnotbe a valid reason for choosing to omit such tests?
- The controls duplicate operative controls existing elsewhere.
- There appear to be major weaknesses that would preclude reliance on the stated procedure.
- The time and dollar costs of testing exceed the time and dollar savings in substantive testing if the tests show the controls to be operative.
- The controls appear adequate .
- Which of the following would the auditors consider to be a weakness in an IT system?
- Operators have access to terminals.
- Programmers are allowed access to the file library .
- A data control group handles reprocessing of exceptions detected by the computer.
- More than one employee is present when the computer facility is in use.
- A problem for a CPA associated with advanced IT systems is that
- the audit trail normally does not exist.
- the audit trail is sometimes generated only in machine readable form.
c. the client’s internal auditors may have been involved at the design stage.
- tests of controls are not possible.
- When erroneous data are detected by computer program controls, such data may be excluded from processing and printed on an exception report. The exception report should most probably be reviewed and followed up on by the
- supervisor of computer operations.
- systems analyst.
- data control group .
- computer programmer.
- The report of a service auditor may provide assurance on whether
- (CPA, adapted) For control purposes, which of the following should be organizationally segregated from the computer operations function?
- Data conversion
- Surveillance of CRT messages
c. Systems development
- Minor maintenance according to a schedule
- (CPA, adapted) Which of the following passwords would be most difficult to crack?
- O? Ca! FiSi
- language
- 12 HOUSE 24
- pass56word
- (CPA, adapted) When online, real-time processing is used, the grandfather-father-son updating backup concept is relatively difficult to implement because
- locating information points on files is an extremely time-consuming task .
- magnetic fields and other environmental factors cause off-site storage to be impracticable.
- information must be dumped in the form of hard copy if it is to be reviewed before used in updating.
- the process of updating old records is destructive.
- (CPA, adapted) Which of the following is a computer program that appears to be legitimate but performs some illicit activity when it is run?
- Hoax virus
- Web crawler
- Trojan horse
- Killer application