Free CGAP Risk-Control Frameworks Questions and Answers — Questions and Answers
Question 1: Auditors learn about internal control of an entity primarily for the following reasons:
- Providing documentary evidence to present to those charged with governance.
- Gathering sufficient appropriate evidence to provide a reasonable basis for an opinion on the financial statements.
- Determining the nature, extent and timing of subsequent audit procedures to be performed. (Correct answer)
- Determining whether interim audit testing is appropriate.
Correct answer: Determining the nature, extent and timing of subsequent audit procedures to be performed.
Auditors gain an understanding of an entity's internal control system primarily to assess control risk. This assessment directly influences the audit strategy, specifically determining the nature (type), extent (quantity), and timing (when) of the substantive audit procedures that will be performed. A stronger internal control system may allow for less extensive substantive testing.
Question 2: The main factor an auditor looks at when evaluating an entity's internal controls is whether they
- Relate to the control environment.
- Prevent management override.
- Affect the financial statement assertions. (Correct answer)
- Reflect management’s philosophy and operating style.
Correct answer: Affect the financial statement assertions.
When evaluating internal controls, an auditor's main concern is how these controls relate to the financial statement assertions (e.g., existence, completeness, valuation, rights and obligations). Effective controls reduce the risk of material misstatements related to these assertions, thereby impacting the auditor's assessment of control risk and the scope of substantive testing.
Question 3: Which of the following assertions regarding internal control is true?
- The cost-benefit relationship is a primary criterion that should be considered in designing an internal control system. (Correct answer)
- A properly maintained internal control system reasonably ensures that collusion among employees cannot occur.
- The establishment and maintenance of internal control is an important responsibility of the internal auditor.
- An exceptionally strong internal control system is enough for the auditor to eliminate substantive procedures on a significant account balance.
Correct answer: The cost-benefit relationship is a primary criterion that should be considered in designing an internal control system.
Internal control systems should be designed with a consideration of the cost-benefit relationship. The cost of implementing and maintaining a control should not exceed the expected benefits derived from it, such as reduced risk of error or fraud. While controls are important, they are not expected to be foolproof or infinitely expensive.
Question 4: All of the following, with the exception of, are aimed to help the organization meet its goals through internal controls:
- Reliability of financial reporting.
- Safeguarding of assets.
- Compliance with laws and regulations.
- Reduction of debt financing costs. (Correct answer)
Correct answer: Reduction of debt financing costs.
Internal controls are designed to help an organization achieve its objectives related to the reliability of financial reporting, the effectiveness and efficiency of operations (including safeguarding assets), and compliance with applicable laws and regulations. While strong internal controls can indirectly influence a company's creditworthiness, their direct aim is not the reduction of debt financing costs.
Question 5: Which of the following is not one of internal control's five main pillars?
- Control activities.
- Risk assessment.
- Human resource background checks. (Correct answer)
- Information and communication.
Correct answer: Human resource background checks.
The five main components of internal control, as per the COSO framework, are: Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring Activities. Human resource background checks are a specific control activity within the broader 'Control Activities' component, but they are not one of the five overarching pillars themselves.
Question 6: The COSO Internal Control—Integrated Framework's monitoring section is important. Which of the following statements regarding how the business can implement the monitoring component is false?
- Monitoring can be conducted as a separate evaluation.
- Monitoring can be an ongoing process.
- The independent auditor can serve as part of the entity’s control environment and continuous monitoring. (Correct answer)
- Monitoring and other audit work conducted by internal audit staff can reduce external audit costs.
Correct answer: The independent auditor can serve as part of the entity’s control environment and continuous monitoring.
The independent (external) auditor provides an objective opinion on the financial statements and is external to the entity's internal control system. They cannot be part of the entity's control environment or continuous monitoring activities, as this would compromise their independence. Monitoring is an internal management responsibility, which internal auditors can support.
Question 7: Which of the following is an acceptable excuse for skipping control test procedures?
- The auditor prefers the control risk to be the minimum.
- The company does not have any flowcharts of its system available for review.
- The internal control structure appears very strong.
- The procedures require more audit effort than the projected benefits to be obtained from lowering the control risk. (Correct answer)
Correct answer: The procedures require more audit effort than the projected benefits to be obtained from lowering the control risk.
Auditors perform tests of controls to assess their effectiveness and potentially reduce the extent of substantive testing. However, if the cost (audit effort) of testing controls outweighs the potential benefits (reduction in substantive testing), the auditor may decide to skip control tests and instead rely entirely on substantive procedures. This is a cost-benefit decision in audit planning.
Question 8: An auditor may determine that particular statements have a high control risk after learning about an entity's internal control system because
- Identifies internal controls that are likely to prevent material misstatements.
- Performs tests of controls to restrict detection risk to an acceptable level.
- Determines that the pertinent internal control components are not well documented.
- Believes the internal controls are unlikely to be effective. (Correct answer)
Correct answer: Believes the internal controls are unlikely to be effective.
An auditor determines a high control risk when they assess that the entity's internal controls are unlikely to effectively prevent, or detect and correct, material misstatements. This belief stems from understanding the control system and identifying weaknesses or deficiencies. A high control risk assessment leads to a more extensive substantive audit approach.
Question 9: Regardless of the estimated level of control risk, an auditor would complete some of the following
- Analytical procedures to verify the design of internal controls.
- Tests of controls to determine the effectiveness of internal controls.
- Dual-purpose tests to evaluate both the risk of monetary misstatement and preliminary control risk.
- Substantive procedures to restrict detection risk for material transaction classes. (Correct answer)
Correct answer: Substantive procedures to restrict detection risk for material transaction classes.
Regardless of the assessed level of control risk (even if it's low), an auditor must always perform some substantive procedures for material account balances and transaction classes. This is because inherent risk and detection risk always exist, and substantive procedures are essential to gather direct evidence about the fairness of financial statement assertions.
Question 10: Auditors are likely to when preliminary control risk evaluations are set to high:
- Test controls extensively.
- Use a reliance strategy.
- Complete little or no tests of controls. (Correct answer)
- Complete interim testing of account balances.
Correct answer: Complete little or no tests of controls.
When preliminary control risk evaluations are set to high, it means the auditor believes the internal controls are ineffective or unreliable. In such a scenario, testing controls extensively would be inefficient and yield little benefit. Instead, the auditor will typically choose to perform little or no tests of controls and will rely more heavily on substantive procedures to gather sufficient appropriate audit evidence.
Question 11: After learning about and documenting the entity's internal controls, which of the following indicates the proper order of audit steps?
- Assess control risk, test of controls, reassess control risk, determine extent of substantive testing. (Correct answer)
- Assess control risk, determine extent of substantive testing, test of controls, reassess control risk.
- Assess control risk, test of controls, determine extent of substantive testing, reassess control risk.
- Test of controls, assess control risk, determine extent of substantive tests, reassess control risk.
Correct answer: Assess control risk, test of controls, reassess control risk, determine extent of substantive testing.
The proper order of audit steps related to internal controls begins with assessing control risk based on the auditor's understanding of the entity's controls. If controls are deemed potentially effective, the auditor then performs tests of controls to verify their operational effectiveness. Following these tests, the auditor reassesses control risk based on the evidence gathered, which then directly determines the nature, timing, and extent of the substantive testing required.
Question 12: Which of the following claims about the internal control documents by the auditor for the entity is true?
- Internal control questionnaires are specifically tailored to meet the needs of each individual entity.
- Documentation must include narrative memorandums.
- The auditor’s assessment of the level of control risk can be documented using a structured working paper, an internal control questionnaire or a memorandum. (Correct answer)
- No documentation is necessary to satisfy auditing standards, however, oral inquiry is required at minimum.
Correct answer: The auditor’s assessment of the level of control risk can be documented using a structured working paper, an internal control questionnaire or a memorandum.
Auditing standards require auditors to document their understanding and assessment of internal controls. The method for documenting the auditor's assessment of control risk is flexible and can be achieved through various means, including structured working papers, internal control questionnaires, or narrative memorandums. This allows auditors to choose the most efficient and effective documentation method for a given engagement.
Question 13: The auditor must do all of the activities listed below with the exception of:
- Perform tests of controls.
- Conclude on the achieved level of control risk.
- Identify all general IT controls. (Correct answer)
- Identify specific controls that will be relied upon.
Correct answer: Identify all general IT controls.
While auditors consider IT controls, their objective is not to identify *all* general IT controls within an entity. Instead, the auditor focuses on identifying specific controls, including relevant IT controls, that are necessary to address risks of material misstatement and upon which they intend to rely to reduce substantive testing. Identifying every single general IT control would be an overly exhaustive and unnecessary task for audit purposes.
Question 14: All of the following are involved in control risk assessment when it is not high.
- Concluding that controls are ineffective. (Correct answer)
- Identifying specific controls to rely on.
- Analysing the achieved level of control risk after performing tests of controls.
- Performing tests of controls.
Correct answer: Concluding that controls are ineffective.
If control risk is assessed as *not high*, it implies that the auditor believes the entity's controls are potentially effective and plans to rely on them to some extent. Therefore, concluding that controls are ineffective would contradict this initial assessment. The other options – identifying specific controls, performing tests of controls, and analyzing the achieved level of control risk – are all integral parts of the process when control risk is assessed as not high and controls are expected to be effective.
Question 15: Which of the following auditing procedures would most likely give an auditor the greatest peace of mind regarding the efficacy of a control's operation?
- Walk-through.
- Observation of entity personnel.
- Inquiry of entity personnel.
- Reperformance of the control by the auditor. (Correct answer)
Correct answer: Reperformance of the control by the auditor.
Reperformance of a control by the auditor involves the auditor independently executing the control activity to verify its operation. This procedure provides the highest level of assurance regarding the efficacy of a control's operation because the auditor directly observes and verifies the control's effectiveness, rather than relying on inquiries, observations (which are point-in-time), or walk-throughs (which confirm understanding but not necessarily consistent operation).
Question 16: The best and most trustworthy audit proof that segregation of roles is effectively used is obtained by
- Inquiries of employees who apply control activities.
- Inspection of a flowchart of duties performed and available personnel.
- Observation by the auditor of the employees performing control activities. (Correct answer)
- Inspection of documents prepared by a third party but which contain the initials of those applying entity controls.
Correct answer: Observation by the auditor of the employees performing control activities.
Direct observation by the auditor of employees performing control activities provides the most trustworthy audit evidence for the effective use of segregation of duties. While inquiries and flowcharts help the auditor understand the prescribed duties, observation confirms whether these duties are actually being performed as intended in practice. This real-time verification offers stronger evidence of operational effectiveness than other methods.
Auditors learn about internal control of an entity primarily for the following reasons: