Auditing and Assurance Training Internal Controls and Risk Assessment 2 — Questions and Answers
Question 1: A 'material weakness' in internal control is defined as a deficiency (or combination of deficiencies) that results in a:
- Minor clerical error
- Reasonable possibility that a material misstatement will not be prevented or detected (Correct answer)
- Single transaction being misstated
- Violation of GAAP in one account
Correct answer: Reasonable possibility that a material misstatement will not be prevented or detected
A material weakness indicates there is a reasonable possibility that a material misstatement in the financial statements could go undetected.
Question 2: Under PCAOB standards, when must management include a report on internal control over financial reporting (ICFR)?
- Only when asked by shareholders
- Annually as part of the Form 10-K for accelerated filers (Correct answer)
- Only after a restatement
- Every quarter in Form 10-Q filings
Correct answer: Annually as part of the Form 10-K for accelerated filers
Section 404 of the Sarbanes-Oxley Act requires management of accelerated filers to assess and report on ICFR annually in the Form 10-K.
Question 3: Which risk assessment procedure involves the auditor directly tracing a transaction from its initiation through to recording in the financial statements?
- Analytical procedure
- Walkthrough (Correct answer)
- Confirmation
- Recalculation
Correct answer: Walkthrough
A walkthrough follows a single transaction end-to-end to help the auditor understand the flow of transactions and confirm controls are designed as documented.
Question 4: Control risk represents the risk that:
- The auditor will issue a wrong opinion
- A misstatement will not be prevented or detected by internal controls (Correct answer)
- The auditor's sample is not representative
- Management will override controls
Correct answer: A misstatement will not be prevented or detected by internal controls
Control risk is the probability that a material misstatement could occur and not be caught or corrected by the entity's internal control system.
Question 5: Segregation of duties is a key preventive control. Which combination of duties should be separated to reduce fraud risk?
- Budgeting and forecasting
- Authorization, custody, and recording (Correct answer)
- Hiring and payroll input only
- Purchasing and invoicing approval
Correct answer: Authorization, custody, and recording
Separating authorization, custody of assets, and recording of transactions reduces the opportunity for any one person to commit and conceal a fraud.
Question 6: IT general controls (ITGCs) are important because weaknesses in them can:
- Only affect payroll processing
- Undermine the reliability of all automated application controls (Correct answer)
- Increase the audit fee automatically
- Eliminate the need for substantive testing
Correct answer: Undermine the reliability of all automated application controls
ITGCs provide the foundation for automated controls; if they are unreliable, confidence in any application-level automated control is also reduced.
A 'material weakness' in internal control is defined as a deficiency (or combination of deficiencies) that results in a: