APP Auditing Principles & Procedures 3 — Questions and Answers
Question 1: Under the COSO internal control framework, which component directly addresses an organization's ethical values and the oversight responsibility of management?
- Risk Assessment
- Control Activities
- Control Environment (Correct answer)
- Monitoring Activities
Correct answer: Control Environment
The Control Environment is the foundation of COSO and encompasses the tone at the top, ethical values, and management's commitment to competence and oversight.
Question 2: A procurement auditor is conducting a risk-based audit. Which area should receive the highest audit priority?
- Low-dollar, high-volume routine purchases with established controls
- High-dollar, complex contracts in areas with weak controls (Correct answer)
- Purchases from vendors with a long, clean payment history
- Transactions processed through an automated ERP system with no exceptions
Correct answer: High-dollar, complex contracts in areas with weak controls
Risk-based auditing directs resources toward high-dollar, complex areas with weak controls because these represent the greatest potential for material error or fraud.
Question 3: Which audit procedure is specifically designed to detect fictitious vendors in the purchasing system?
- Recalculating invoice extensions for mathematical accuracy
- Comparing vendor master file addresses to employee addresses (Correct answer)
- Confirming outstanding purchase orders with vendors
- Reviewing approval signatures on purchase requisitions
Correct answer: Comparing vendor master file addresses to employee addresses
Matching vendor addresses to employee addresses is a key test for shell vendor fraud, where employees create fictitious suppliers using their own or related addresses.
Question 4: What is the meaning of 'segregation of duties' in the context of a purchasing cycle audit?
- Dividing the audit work among multiple auditors
- Ensuring that no single person controls all phases of a transaction (Correct answer)
- Separating capital purchases from operating expense purchases
- Rotating vendor assignments among buyers annually
Correct answer: Ensuring that no single person controls all phases of a transaction
Segregation of duties prevents fraud and error by ensuring authorization, custody, and record-keeping functions are performed by different individuals.
Question 5: An audit of contract management reveals that a vendor's performance has not been formally evaluated in over two years. Which risk does this oversight most directly create?
- The organization may be overpaying relative to market rates
- Underperforming vendors may continue receiving contract renewals (Correct answer)
- Contract amendments may be processed without proper authorization
- Invoices may be paid before goods are received
Correct answer: Underperforming vendors may continue receiving contract renewals
Without regular performance evaluations, poor-performing vendors may go undetected and continue being awarded renewals, wasting organizational resources.
Question 6: Which term describes the auditor's responsibility to maintain an unbiased attitude and avoid conflicts of interest throughout an audit engagement?
- Due professional care
- Independence and objectivity (Correct answer)
- Confidentiality
- Competency
Correct answer: Independence and objectivity
Independence and objectivity require that auditors maintain an impartial mental attitude and avoid conflicts of interest that could bias their judgment or conclusions.
Question 7: During a follow-up audit, an auditor finds that a previously reported high-risk finding has not been corrected. What is the auditor's most appropriate next step?
- Close the finding since sufficient time has passed
- Re-issue the original report with an updated date
- Escalate the unresolved finding to senior management or the audit committee (Correct answer)
- Remove the finding from future audit scope to avoid duplication
Correct answer: Escalate the unresolved finding to senior management or the audit committee
Persistent unresolved high-risk findings must be escalated to senior management or the audit committee to ensure accountability and timely corrective action.
Under the COSO internal control framework, which component directly addresses an organization's ethical values and the oversight responsibility of management?