ITA Audit Planning & Methodology 2 — Questions and Answers
Question 1: Which audit methodology step involves evaluating whether internal controls are designed properly to mitigate identified risks?
- Substantive testing
- Design effectiveness assessment (Correct answer)
- Audit reporting
- Follow-up procedures
Correct answer: Design effectiveness assessment
Design effectiveness assessment evaluates whether controls are structured appropriately to address the risks they are intended to mitigate.
Question 2: What distinguishes 'operating effectiveness testing' from 'design effectiveness assessment' in an IT audit?
- Operating effectiveness testing evaluates whether a control is properly designed; design assessment tests if it works
- Design assessment determines if a control is properly structured; operating effectiveness testing determines if it actually functions as designed (Correct answer)
- Operating effectiveness testing is only performed on financial controls
- There is no meaningful distinction between the two
Correct answer: Design assessment determines if a control is properly structured; operating effectiveness testing determines if it actually functions as designed
Design assessment checks whether the control is properly structured to mitigate risk, while operating effectiveness testing determines if the control actually works as designed over a period of time.
Question 3: In an IT audit, 'sampling' is used primarily to:
- Select all transactions in a population for testing
- Test a representative subset of a population to draw conclusions about the whole (Correct answer)
- Choose which auditees to interview
- Determine the audit fee
Correct answer: Test a representative subset of a population to draw conclusions about the whole
Audit sampling allows auditors to test a representative portion of a large population and draw reasonable conclusions about all items in that population.
Question 4: Which type of audit evidence is generally considered most reliable?
- Verbal representations provided by management
- Documents produced by the auditee and provided to the auditor
- Evidence obtained directly by the auditor through observation or independent confirmation (Correct answer)
- Photocopies of original documents
Correct answer: Evidence obtained directly by the auditor through observation or independent confirmation
Evidence obtained directly by the auditor through independent observation, recalculation, or external confirmation is considered most reliable because it is not subject to manipulation by the auditee.
Question 5: What is the purpose of a 'walkthrough' procedure in an IT audit?
- To physically inspect the data center facility
- To trace a transaction from initiation through completion to confirm understanding of the process and controls (Correct answer)
- To review audit work papers from prior periods
- To walk auditors through the organization's financial statements
Correct answer: To trace a transaction from initiation through completion to confirm understanding of the process and controls
A walkthrough traces a transaction from beginning to end to confirm the auditor's understanding of the process flow and the controls that operate at each step.
Question 6: When developing the audit schedule, which factor should be given the highest priority?
- Auditor preferences for working hours
- Risk level and criticality of systems and processes to be audited (Correct answer)
- Alphabetical order of system names
- The availability of external auditors
Correct answer: Risk level and criticality of systems and processes to be audited
Scheduling should prioritize high-risk, high-criticality systems first so that the most important audit work is completed within available time and resources.
Question 7: Which of the following best describes 'audit evidence sufficiency'?
- Evidence is sufficient when it is stored in an auditor-controlled environment
- Evidence is sufficient when there is enough of it to support the auditor's conclusions (Correct answer)
- Evidence is sufficient only when obtained from external third parties
- Sufficiency refers to whether evidence was collected before the audit deadline
Correct answer: Evidence is sufficient when there is enough of it to support the auditor's conclusions
Sufficiency refers to the quantity of audit evidence — there must be enough evidence to support a reasonable and defensible audit conclusion.
Which audit methodology step involves evaluating whether internal controls are designed properly to mitigate identified risks?