Auditing and Assurance Training Internal Controls and Risk Assessment 1 — Questions and Answers
Question 1: Which framework is most widely used in the US for evaluating the effectiveness of internal controls?
- COBIT
- COSO (Correct answer)
- ISO 31000
- PCAOB AS 2201
Correct answer: COSO
The COSO Internal Control–Integrated Framework is the most widely accepted standard for evaluating internal controls in the United States.
Question 2: What is the primary purpose of a risk assessment in an audit engagement?
- To calculate materiality thresholds
- To identify and evaluate risks of material misstatement (Correct answer)
- To determine audit fees
- To select the audit team members
Correct answer: To identify and evaluate risks of material misstatement
Risk assessment helps auditors identify areas where material misstatements are most likely so they can focus their procedures accordingly.
Question 3: Inherent risk is best described as the susceptibility of an assertion to material misstatement assuming:
- Strong internal controls are in place
- No related internal controls exist (Correct answer)
- Management has reviewed all transactions
- The auditor has tested all balances
Correct answer: No related internal controls exist
Inherent risk is evaluated before considering the effect of any related internal controls, representing the raw likelihood of misstatement.
Question 4: Which component of the COSO framework addresses how an organization communicates information relevant to internal control objectives?
- Control Environment
- Risk Assessment
- Information and Communication (Correct answer)
- Monitoring Activities
Correct answer: Information and Communication
The Information and Communication component covers how relevant information is identified, captured, and exchanged to support internal control functioning.
Question 5: A control that prevents an error from occurring is classified as a:
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Preventive controls are designed to stop errors or irregularities from happening in the first place rather than finding them after the fact.
Question 6: What does the term 'control deficiency' mean in US auditing standards?
- A complete absence of internal controls
- A shortcoming in the design or operation of a control that fails to prevent or detect misstatements (Correct answer)
- An error discovered during substantive testing
- A disagreement between management and the auditor
Correct answer: A shortcoming in the design or operation of a control that fails to prevent or detect misstatements
A control deficiency exists when a control is missing or not operating effectively enough to prevent or detect misstatements on a timely basis.
Which framework is most widely used in the US for evaluating the effectiveness of internal controls?