AAT L4 Accounting Systems & Controls 3 — Questions and Answers
Question 1: The purpose of physical controls (e.g., locked safes, restricted access) is to:
- Record assets accurately in the accounting records
- Safeguard physical assets and confidential records from theft, loss, or damage (Correct answer)
- Speed up transaction processing
- Reduce the number of journal entries required
Correct answer: Safeguard physical assets and confidential records from theft, loss, or damage
Physical controls protect tangible assets (cash, inventory, equipment) and sensitive records by restricting access to authorised personnel — preventing theft, unauthorised use, and accidental damage.
Question 2: A system of internal controls can never provide absolute assurance against fraud because:
- Controls are always too expensive to implement
- Controls can be circumvented through management override or collusion between employees (Correct answer)
- Internal auditors always fail to find fraud
- Only external auditors can detect fraud
Correct answer: Controls can be circumvented through management override or collusion between employees
Even well-designed controls have limitations: management can override them; employees may collude; and controls designed for routine transactions may not detect unusual or complex fraudulent schemes.
Question 3: Cash controls in a business typically include:
- Allowing any employee to handle cash without supervision
- Daily counting and reconciliation of cash, with receipts banked promptly and handled by separate people (Correct answer)
- Keeping large cash balances in the business to avoid banking charges
- Having the same person receive and record cash payments
Correct answer: Daily counting and reconciliation of cash, with receipts banked promptly and handled by separate people
Cash controls include: counting and reconciling cash daily, banking receipts promptly, segregating cash handling from recording, using prenumbered receipts, and restricting access to the cash register.
Question 4: IT general controls in an accounting system include:
- Application-specific controls such as data entry validation
- Access controls, change management procedures, and backup and recovery policies (Correct answer)
- Only firewall and antivirus software
- Spreadsheet formulas and macros
Correct answer: Access controls, change management procedures, and backup and recovery policies
IT general controls (ITGCs) provide the framework supporting all applications: user access management, change management controls (testing before live implementation), backup and disaster recovery, and physical security of IT infrastructure.
Question 5: An accounting system review (systems evaluation) typically results in a report that:
- Certifies that all transactions are correct
- Identifies weaknesses in the current system and recommends improvements (Correct answer)
- Confirms the entity's compliance with tax legislation
- Replaces the annual statutory audit
Correct answer: Identifies weaknesses in the current system and recommends improvements
A systems review or evaluation identifies control weaknesses, inefficiencies, and risks in the accounting and control environment, recommending cost-effective improvements to address them.
Question 6: Which of the following best describes the role of the internal audit function?
- Preparing the year-end financial statements
- Providing independent assurance to management and the board on risk management, controls, and governance (Correct answer)
- Filing the company's tax returns
- Preparing the external audit file for the statutory auditor
Correct answer: Providing independent assurance to management and the board on risk management, controls, and governance
Internal audit provides independent assurance on the adequacy and effectiveness of internal controls, risk management, and governance — reporting to the audit committee and/or board, not to operational management.
The purpose of physical controls (e.g., locked safes, restricted access) is to: