CDFM Auditing and Internal Controls 4 — Questions and Answers
Question 1: Which assertion tested during a financial statement audit addresses whether all transactions and accounts that should be recorded have actually been recorded?
- Existence
- Completeness (Correct answer)
- Valuation
- Rights and obligations
Correct answer: Completeness
The completeness assertion ensures that all transactions and balances that should be included in the financial statements are not omitted.
Question 2: Under DoD's audit readiness initiatives, which framework is used to assess the maturity of financial management business processes?
- COSO Internal Control Framework
- Financial Improvement and Audit Readiness (FIAR) Methodology (Correct answer)
- COBIT IT Governance Framework
- ISO 31000 Risk Management
Correct answer: Financial Improvement and Audit Readiness (FIAR) Methodology
The FIAR Methodology provides DoD components with a structured approach to improve financial management processes and achieve audit readiness.
Question 3: When assessing control risk in a DoD audit, what does a higher assessed control risk indicate?
- Management has implemented strong internal controls
- The auditor can reduce substantive testing procedures
- Internal controls are less effective at preventing or detecting misstatements (Correct answer)
- The entity has a clean audit opinion history
Correct answer: Internal controls are less effective at preventing or detecting misstatements
Higher control risk means controls are less reliable, requiring the auditor to perform more extensive substantive procedures to obtain sufficient audit evidence.
Question 4: Which type of audit sampling approach allows every item in the population an equal chance of selection, without using any structured interval or stratification?
- Systematic sampling
- Stratified sampling
- Simple random sampling (Correct answer)
- Judgmental sampling
Correct answer: Simple random sampling
Simple random sampling gives every item in the population an equal probability of selection, making it a statistically valid method for projecting results.
Question 5: A DoD component finds that its accounting system cannot produce reliable data for year-end closing. This represents a weakness in which COSO component?
- Monitoring Activities
- Control Environment
- Information and Communication (Correct answer)
- Control Activities
Correct answer: Information and Communication
The Information and Communication component addresses whether relevant, quality information is captured and communicated to support financial reporting and decision-making.
Question 6: The Federal Financial Management Improvement Act (FFMIA) of 1996 requires federal agencies to implement financial management systems that comply with which standards?
- GAAP only
- Federal financial management system requirements, applicable federal accounting standards, and the U.S. Government Standard General Ledger (Correct answer)
- COSO framework and PCAOB standards
- FAR cost principles and DFAS policies
Correct answer: Federal financial management system requirements, applicable federal accounting standards, and the U.S. Government Standard General Ledger
FFMIA requires agencies to comply with federal financial management system requirements, applicable federal accounting standards, and the U.S. Government Standard General Ledger at the transaction level.
Question 7: An auditor performing a walk-through of a DoD payroll process would primarily accomplish which audit objective?
- Confirm the mathematical accuracy of payroll calculations
- Obtain an understanding of the flow of transactions and identify key controls (Correct answer)
- Substantiate that employees received correct pay amounts
- Test the completeness of personnel records
Correct answer: Obtain an understanding of the flow of transactions and identify key controls
Walk-throughs trace transactions from initiation through recording to help auditors understand the process flow and identify where key controls exist and operate.
Which assertion tested during a financial statement audit addresses whether all transactions and accounts that should be recorded have actually been recorded?