CGA Auditing & Assurance 3 — Questions and Answers
Question 1: Which of the following is an example of a preventive control in an internal control system?
- Bank reconciliations
- Physical inventory counts
- Segregation of duties (Correct answer)
- Variance analysis
Correct answer: Segregation of duties
Segregation of duties prevents errors or fraud from occurring by ensuring no single individual controls all aspects of a transaction.
Question 2: An engagement letter for an audit should include all of the following EXCEPT:
- The objective and scope of the audit
- Management's responsibility for the financial statements
- A guarantee that fraud will be detected (Correct answer)
- The expected form of any reports to be issued
Correct answer: A guarantee that fraud will be detected
Auditors cannot guarantee fraud detection; the engagement letter sets out responsibilities and scope but makes no such guarantee.
Question 3: During an audit, an auditor identifies a significant deficiency in internal controls. To whom must this be communicated?
- The SEC and external regulators
- Those charged with governance (e.g., the audit committee) (Correct answer)
- Only the CFO
- The external auditors of the parent company
Correct answer: Those charged with governance (e.g., the audit committee)
Significant deficiencies and material weaknesses must be communicated in writing to management and those charged with governance.
Question 4: Which analytical procedure would best identify potential revenue overstatement?
- Comparing current-year gross margin ratio to prior years and industry benchmarks (Correct answer)
- Recounting physical inventory at year-end
- Confirming accounts payable balances with vendors
- Reviewing minutes of board meetings
Correct answer: Comparing current-year gross margin ratio to prior years and industry benchmarks
Comparing gross margin ratios can reveal unexplained improvements that may indicate inflated revenue or understated cost of goods sold.
Question 5: A company uses electronic data interchange (EDI) for all purchases. Which internal control is most critical in this environment?
- Prenumbered purchase orders in paper format
- Application controls that validate transaction completeness and accuracy (Correct answer)
- Physical separation of purchasing and receiving staff
- Manual approval signatures on invoices
Correct answer: Application controls that validate transaction completeness and accuracy
In an EDI environment, automated application controls replace manual controls to ensure transactions are complete, accurate, and authorized.
Question 6: The primary purpose of a review engagement, as opposed to an audit, is to provide:
- Absolute assurance on the financial statements
- Reasonable assurance that the statements are free of material misstatement
- Limited assurance that no material modifications are needed (Correct answer)
- No assurance but factual findings only
Correct answer: Limited assurance that no material modifications are needed
A review provides limited (negative) assurance that nothing came to the auditor's attention indicating material modifications are needed.
Question 7: Which factor would most likely increase the acceptable level of detection risk for a specific audit assertion?
- High inherent risk for the assertion
- Effective internal controls related to the assertion (Correct answer)
- Prior-year audit findings indicating errors in the assertion
- High volume of transactions affecting the assertion
Correct answer: Effective internal controls related to the assertion
When internal controls are effective (low control risk), the auditor can accept higher detection risk and perform less extensive substantive testing.
Which of the following is an example of a preventive control in an internal control system?