Audit Planning & Methodology Flashcards
7 cards from real ITA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Audit Planning & Methodology flashcards as text
Which audit methodology step involves evaluating whether internal controls are designed properly to mitigate identified risks?
Answer: Design effectiveness assessment
Design effectiveness assessment evaluates whether controls are structured appropriately to address the risks they are intended to mitigate.
What distinguishes 'operating effectiveness testing' from 'design effectiveness assessment' in an IT audit?
Answer: Design assessment determines if a control is properly structured; operating effectiveness testing determines if it actually functions as designed
Design assessment checks whether the control is properly structured to mitigate risk, while operating effectiveness testing determines if the control actually works as designed over a period of time.
In an IT audit, 'sampling' is used primarily to:
Answer: Test a representative subset of a population to draw conclusions about the whole
Audit sampling allows auditors to test a representative portion of a large population and draw reasonable conclusions about all items in that population.
Which type of audit evidence is generally considered most reliable?
Answer: Evidence obtained directly by the auditor through observation or independent confirmation
Evidence obtained directly by the auditor through independent observation, recalculation, or external confirmation is considered most reliable because it is not subject to manipulation by the auditee.
What is the purpose of a 'walkthrough' procedure in an IT audit?
Answer: To trace a transaction from initiation through completion to confirm understanding of the process and controls
A walkthrough traces a transaction from beginning to end to confirm the auditor's understanding of the process flow and the controls that operate at each step.
When developing the audit schedule, which factor should be given the highest priority?
Answer: Risk level and criticality of systems and processes to be audited
Scheduling should prioritize high-risk, high-criticality systems first so that the most important audit work is completed within available time and resources.
Which of the following best describes 'audit evidence sufficiency'?
Answer: Evidence is sufficient when there is enough of it to support the auditor's conclusions
Sufficiency refers to the quantity of audit evidence — there must be enough evidence to support a reasonable and defensible audit conclusion.