โ† All CBA Flashcard Decks

Auditing Internal Controls Flashcards

7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Auditing Internal Controls flashcards as text
  1. Under the COSO framework, which component addresses the ongoing processes that monitor the quality of internal control performance over time?

    Answer: Monitoring Activities

    Monitoring Activities is the COSO component focused on evaluating whether controls are present and functioning effectively on an ongoing basis.

  2. When auditing IT general controls, which area is MOST critical to assess first because weaknesses there can undermine all application controls?

    Answer: Access controls and logical security

    Access controls and logical security are foundational IT general controls; compromised access can invalidate the effectiveness of all other controls.

  3. A bank auditor discovers that loan officers can both approve loans AND record disbursements in the general ledger. This violates which key internal control principle?

    Answer: Segregation of duties

    Segregation of duties requires that authorization, custody, and recording functions be performed by different individuals to prevent fraud and error.

  4. Which sampling method requires the auditor to select every nth item from a population, starting from a random point?

    Answer: Systematic sampling

    Systematic sampling selects items at uniform intervals (every nth item) after a random start, making it efficient for large populations.

  5. In a bank's loan review process, which compensating control is MOST effective when full segregation of duties cannot be achieved in a small branch?

    Answer: Enhanced supervisory review of transactions

    Enhanced supervisory review compensates for lack of segregation by having a manager independently review and approve transactions processed by the same employee.

  6. The term 'control deficiency' in bank auditing refers to a situation where:

    Answer: A control does not allow timely prevention or detection of misstatements

    A control deficiency exists when the design or operation of a control does not allow management or employees to prevent or detect misstatements in a timely manner.

  7. Which audit procedure is MOST appropriate for testing the operating effectiveness of an automated system access control?

    Answer: Attempting to access the system with revoked credentials

    Attempting to access the system with revoked or unauthorized credentials directly tests whether the access control is actually operating as designed.