โ† All CCS Flashcard Decks

Internal Controls & Auditing Flashcards

7 cards from real CCS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Internal Controls & Auditing flashcards as text
  1. Which concept describes the idea that controls should be designed so the cost does not exceed the benefit derived?

    Answer: Cost-benefit principle

    The cost-benefit principle holds that organizations should not implement controls whose cost exceeds the risk reduction or benefit they provide.

  2. An internal auditor identifies a control deficiency but concludes it is not material. This finding is BEST classified as a:

    Answer: Control deficiency

    A control deficiency exists when a control's design or operation does not allow management to prevent, detect, or correct misstatements on a timely basis, but does not rise to the level of a significant deficiency.

  3. Which of the following is an example of a DETECTIVE control?

    Answer: Performing monthly bank reconciliations

    Monthly bank reconciliations detect errors or unauthorized transactions after they have occurred, making them detective rather than preventive controls.

  4. Under PCAOB Auditing Standard AS 2201, which parties are required to assess internal control over financial reporting for public companies?

    Answer: Both management and the external auditor

    AS 2201 requires both management (per SOX 404(a)) and the registered public accounting firm (per SOX 404(b)) to assess and report on ICFR for accelerated filers.

  5. An organization relies solely on IT system controls to enforce a critical compliance requirement. If the system malfunctions, the organization has no other check in place. This situation is called:

    Answer: Single point of control failure

    A single point of control failure occurs when only one control protects against a risk, so its failure leaves the risk completely unmitigated.

  6. Which element is NOT typically included in an internal audit finding?

    Answer: Auditor's personal opinion on management competence

    Audit findings traditionally include condition, criteria, cause, and effect (impact); personal opinions about management competence are not appropriate audit findings.

  7. Which regulatory framework specifically governs the independence standards for external auditors of U.S. public companies?

    Answer: PCAOB Ethics and Independence Rules

    The PCAOB establishes and enforces auditor independence standards for registered public accounting firms that audit U.S. public company financial statements.