AUD-Lesson 3_GRADUAL_Internal Control Continued Flashcards

1
Q

What is AU-C 315?

A

Understanding the Entity and Its Environment and Assessing Risks of Material Misstatements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the name for entities that do not report to the SEC?

What is the name for entities that DO report to the SEC?

A

Nonissuers (do not report)

Issuers (Report)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is an integrated audit as it required of issuers per Sarbanes Oxley?

A

It requires an opinion on internal control over finanicial reporting (ICFR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What tests are performed if it is found that Internal Controls are 100% ineffective?

A

Substantive testsed are performed on Control Risk set at maximum

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the neumonic for what assurance that is needed from internal controls?

A

ACE

Accurate and Reliable Financial Reporting

Compliance with laws and regulations

Effectiveness and efficiency of operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the segregation of duties?

A

ARCC

Authorization of transactions

Recording (posting) of transactions

Custody of assets

Comparisons (Compare what got recorded actually got deposited)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the control activities?

A

PIPS

Performance Reviews

Information Processing

Physical Controls

Segregation of Duties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the control environment?

A

CHOPPER

Commitment to compentence

HR policies and practices

Org Structure

Participation of those charged w/ governance

Philosophy of management and Mgt operating style

Ethical values and Integrity

Responsibility assignment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the five components of internal control?

A

CRIME

Control Environment

Risk Assessment

Control Activities

Information and Communication

Monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the parts of Risk Assessment (R) in the components of internal control?

A

Some items are

Changes in operating environment
New personnel
New or revamped information systems
Rapid growth

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the parts of Information and Communication in the components of internal control?

A

Uses relevent information
Communicates internally
Communicates externally

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the parts of Monitoring (M) in the components of internal control?

A

Management conducts ongoing and/or seperate evaluations of controls
Management evaluates and communicates deficiencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the steps to understanding internal controls?

A
  1. Obtain understanding the design of internal controls (perform risk assessment procedures - CRIME)
  2. Document Understanding of Internal Control
  3. Assess Risk of RMM
  4. Perform Tests of Controls
  5. Reassess RMM
  6. Document Conclusions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is an ICQ?

A

It is an internal control questionnaire that consists of yes/no questions. Is part of documenting understanding of internal control
Yes is a strength, no is a weakeness

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a substantive approach audit?

A

An audit in which control risk is set at a maximum due to insufficient internal controls where there is extensive substantive testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a combined approach, or intergrated audit?

A

An audit in which control risk is not set to maximum since internal controls are operating. Thus the audit consists of a test of controls and substantive testing

17
Q

How do you test controls (Tests of ARCC)

A

RIO

Reperformance

Inspection

Inquiry

Observation

18
Q

What are the inherent limitations of controls?

Can still happen if internal controls are strong

A

COCO

Collusion

Override by management

Competence/Human error

Obsolescence

19
Q

What is tracing and vouching?

A

Tracing: Goes from source to books and records
Vouching: Goes from books back to the source

20
Q

What types of questions doe the Internal Control Questionnaire (ICQ) cover?

A

PRAISE

Physical Controls

Recording

Authorization

Independent Checks

Segregation of Duties

Evaluate Performance

21
Q

What is covered by AS #5?

A

Material weaknesses and signficant deficiencies must be communicated in writing to audit committee prior to issuance of auditor’s report

22
Q

What is covered by SOX Rule 404A?

A

Requires annual report to include a report for establishing and maintaining an adequate internal control and management’s assessment of internal control effectiveness

23
Q

What is covered by SOX Rule 404B?

A

Requires auditor to attest to and report on management’s assessment of internal control