Accounting Information Systems, 11e (Bodnar/Hopwood)
Chapter 4 Transaction Processing and the Internal Control Process
1) The term risk is synonymous with exposure.
2) Selecting the best opportunities and managing uncertainties is part of Enterprise Risk
Management (ERM).
3) COBIT stands for Control Objectives for Businesses in Technology fields.
4) ISO 27002 is a widely accepted international standard for best practices in information
security.
5) Financial accounting is concerned with the prevention and detection of fraud and white-collar
crime.
6) Recent survey results indicate that the most frequent reason frauds are discovered is due to
internal controls.
7) COSO reports contain the most authoritative framework for internal control processes.
8) The production cycle is defined as the events related to the distribution of goods and services
to other entities and the collection of related payments.
9) Typically, an organization’s internal control process consists of five components.
10) Management’s consideration of the relative costs for benefits of internal controls will often
be subjective in nature.
11) For both public and privately held companies, the Sarbanes-Oxley Act of 2002 (SOA)
imposes certain requirements and restrictions on management, auditors, and company audit
committees.
12) The CEO and CFO must prepare a statement to accompany the audit report to certify that the
company’s reported financial statements are presented fairly in all material respects.
13) The Sarbanes-Oxley Act of 2002 (SOA) allows the purchase or sale of stock by officers and
directors and other insiders during blackout periods.
14) Many companies have adopted ethics codes of conduct which provide guidance for
conducting business in an ethical manner.
15) Some believe that every corporation has its own corporate culture, and it is such a culture
that ultimately either promotes or hinders ethical behavior within the corporation.
16) Most control processes can function irrespective of the competence of employees.
17) The board of directors serves as an interface between the stockholders of an organization and
its operating management.
18) Audit committees are usually charged with evaluation and assessment of a corporation’s
internal control processes.
19) Control is established in the budgeting process by comparing the results of activity to the
budget for each activity.
20) The third component of internal control is risk assessment.
21) The segregation of authorization from the recording of transactions and custody of assets is
an essential internal control process.
22) Physical theft is only a minor threat to the solvency of most business organizations.
23) Approval (authorization) limits the initiation of a transaction or performance of an activity to
selected individuals.
24) The audit trail concept is basic to the design and audit of an accounting information system.
25) In an internal audit function, the nature of independence is different than that of an external
auditor.
26) General controls can be a substitute for application controls.
27) The computer operations supervisor has a good attendance record, which demonstrates the
general operating procedure of competency of personnel.
28) A list of changes to on-line computer files is stored on magnetic tape to provide a transaction
trail.
29) Application controls are designed to provide assurance that processing has occurred.
30) A hash total is a meaningless number that only is important for internal control purposes.
31) The immediate return of input information to the sender for comparison and approval is
called feedback.
32) A trailer label is the last record of an inventory file, which contains a record count of the
number of records in the file.
33) Detective controls are not considered transaction processing controls, but rather internal
audit controls.
34) Internal control should be looked upon as part of a larger process within the organization.
35) Collusion occurs when a white-collar individual attempts to commit fraud within an
organization.
36) A negative answer given to a question on an internal control questionnaire almost always
indicates a weakness in an internal control process area.
37) A structured form of analysis relevant to internal control reviews is an applications control
matrix.
38) Someone who has personally observed the activities under review should complete an
internal control questionnaire.
39) Ratings of the relative strength or reliability of controls may be entered in a control matrix.
40) Corrective controls act to prevent errors and fraud before they happen.
41) An example of a suspense file is a file of back-ordered items awaiting shipment to
customers.
42) The chief goal of an information system is productivity.
43) Controls increase productivity and the reliability of resulting output.
44) Informal pressure from employees does not cause collusion.
45) COSO’s next report to be published will pertain to the monitoring of internal control systems
in order to keep them current and effective.
46) ________ tend to reduce ________, but they rarely affect the causes.
47) An exposure is a(n) ________ times its ________ consequences.
48) Deficient revenues and excessive costs reduce ________.
49) The diversion or misrepresentation of assets from either employees or third parties is known
as ________ ________.
50) Fraud examination draws on the fields of ________, ________, and ________.
51) White-collar crime that benefits an organization rather than individuals is ________ crime.
52) The ________ cycle involves events related to the acquisition and management of capital
funds, including ________.
53) The concept of internal control is based on ________ major premises: ________ and
reasonable ________.
54) Commitment and competence are factors included in the ________ environment.
55) All companies whose stock is traded on the New York Stock Exchange are required to have
a(n) ________ ________ composed of outside directors.
56) The ________ budget is the budget for the entire organization.
57) ________ bonding is common for employees who are directly responsible for the custody of
assets.
58) Employees can check and verify the operations of other employees when the employees are
forced to take a(n) ________.
59) Closely related to direct supervision is the concept of ________ ________ the assignment
of two individuals to perform the same work task in unison.
60) ________ controls affect all transaction processing, while ________ controls are specific to
individual applications.
61) In cases of ________, “the procedures did not fail, the people did.”
62) ERM is defined by ________ as a process applied in strategy setting and across the
enterprise, to manage risk.
63) ISO 27002 aids companies with Section ________ compliance.
64) Businesses without an IT department or IT expertise can rely on outside ________ ________
________ for their accounting, software and IT needs.
65) Which of the items below would not be considered a possible common exposure for a
corporation?
A) Excessive prices are paid for goods for use in the organization.
B) The corporation never was billed for a sale of merchandise shipped to a customer.
C) A flash flood destroys the merchandise contained in a warehouse.
D) Certain equipment was accidentally misplaced and not depreciated.
66) Intentional or reckless conduct, whether intentional or not, and which results in materially
misleading financial statements, is called
A) fraudulent financial reporting.
B) corporate crime.
C) management fraud.
D) None of these answers are correct.
67) DWB Corporation suffered a loss due to the spoilage of certain raw materials used in the
manufacturing of its products. The business transaction cycle in which this loss occurred is the
A) revenue cycle.
B) expenditure cycle.
C) finance cycle.
D) production cycle.
68) Which of the objectives listed below is not considered part of the internal control process?
A) Compliance with applicable laws and regulations
B) The prevention of fraud and embezzlement
C) Effectiveness and efficiency of operations
D) Reliability of financial reporting
69) “Amounts due to vendors should be accurately and promptly classified, summarized, and
reported” is a representative control objective of the
A) revenue cycle.
B) finance cycle.
C) production cycle.
D) expenditure cycle.
70) The internal control premise that concerns the relative costs and benefits of controls is
known as
A) responsibility.
B) risk.
C) reasonable assurance.
D) exposure.
71) Section 102 of the Federal Foreign Corrupt Practices Act of 1977 (FCPA) applies to
A) all public and privately held U.S.-based companies.
B) all companies subject to the Securities Exchange Act of 1934.
C) any publicly held company, whether it is a for-profit or non-profit entity.
D) all foreign-owned companies currently operating in the United States.
72) The Omnibus Trade and Competitiveness Act of 1988 (OTCA) amends the
A) Securities Exchange Act of 1934.
B) accounting provisions of the FCPA.
C) antibribery provisions of the FCPA.
D) accounting and antibribery provisions of the FCPA.
73) The Sarbanes-Oxley Act of 2002 imposes certain requirements and restrictions on
A) management.
B) auditors.
C) audit committees.
D) All of these answers are correct.
74) The Sarbanes-Oxley Act of 2002 explicitly deals with the non-audit services which auditors
can provide to their audit clients. Certain non-audit services may be permissible, without prior
approval of a company’s audit committee, if the non-audit services
A) constitute less than 5% of the audit fees for the corporation.
B) constitute less than 5% of the audit fees for the corporation and are not specifically identified
as being barred by SOA 2002.
C) constitute less than 20% of the audit fees for the corporation.
D) Auditors are barred from any and all non-audit services for their audit clients according to
SOA 2002.
75) The component of internal control that is the foundation for all other components is
A) risk assessment.
B) information and communication.
C) control activities.
D) control environment.
76) One way in which a company can produce a corporate culture that supports ethical behavior
is through
A) emphasis on sales quotas and deadlines.
B) emphasis on short-run goals and objectives.
C) a cultural audit to bring to light the corporation’s true culture and ethical behavior.
D) All of these answers are correct.
77) The formal communications patterns within an organization can be communicated using
A) a specific, precise management philosophy.
B) an organizational chart.
C) a cultural audit.
D) an ethical code of conduct.
78) Assets fraudulently appropriated for one’s own use from an organization is considered
A) fraud.
B) theft.
C) embezzlement.
D) a corporate loan.
79) An interesting aspect of white-collar crime is that
A) it often seems to be victimless.
B) it usually amounts to less than $1,000 per organization per year on average.
C) internal controls almost never reveal the perpetrators of such crimes.
D) None of these answers are correct.
80) Many aspects of computer processing tend to significantly
A) decrease an organization’s exposure to undesirable events.
B) strengthen the corporate culture’s ethical behavior in the long-term analysis.
C) increase employee productivity through the use of monitoring software.
D) increase an organization’s exposure to undesirable events.
81) The department or division of larger organizations which is responsible for monitoring and
evaluating controls on an ongoing basis is
A) internal auditing.
B) external auditing.
C) internal affairs.
D) division monitoring.
82) The two broad categories of transaction control are
A) general controls and specific controls.
B) general controls and application controls.
C) general controls and basic controls.
D) basic controls and application controls.
83) Application controls are often classified as
A) general, processing, and specific.
B) basic, specific, and accounting.
C) general, application, and output.
D) input, processing, and output.
84) An agreement or conspiracy among two or more people to commit fraud is known as
A) embezzlement.
B) misappropriation.
C) collusion.
D) misrepresentation.
85) An analytical technique commonly used to analyze and examine an internal control process
is known as a(n)
A) control flowchart.
B) internal control questionnaire.
C) exposure checklist.
D) segregation of duties.
86) An exposure is
A) synonymous with risk.
B) equal to risk multiplied by the likelihood of detection.
C) equal to risk multiplied by the financial consequences.
D) not possible with a good system of internal controls in place.
87) Fraudulent financial reporting
A) involves intentional or reckless conduct.
B) may be due to an act of omission or commission.
C) results in misleading financial statements.
D) All of these answers are correct.
88) Internal control is affected by an organization’s
A) board of directors, management, and other personnel.
B) management and internal auditors.
C) management and external auditors.
D) board of directors, management, and shareholders.
89) Management’s philosophy and operating style are part of which component of internal
control?
A) Control activities
B) Control environment
C) Information and communication
D) Monitoring
90) Organizational structure is part of which component of internal control?
A) Control activities
B) Control environment
C) Information and communication
D) Monitoring
91) An audit committee is required by
A) the AICPA.
B) the Securities and Exchange Commission.
C) generally accepted accounting principles.
D) both the New York Stock Exchange and the Sarbanes-Oxley Act of 2002.
92) Which of the following are examples of risks that are relevant to the financial reporting
process?
A) Changes in the operating environment
B) Changes in personnel
C) Changes in the information system
D) All of these answers are correct.
93) The three types of functions that normally should be segregated to promote internal control
are
A) recording transactions, authorizing transactions, and approval.
B) authorizing transactions, approving transactions, and custody of assets.
C) authorizing transactions, recording transactions, and custody of assets.
D) authorizing transactions, inputting data, and outputting data.
94) A computer-produced document that is intended for resubmission into the system, such as
the part of the utility bill that the customer returns with payment, is a(n)
A) invoice.
B) dual-submit document.
C) turnaround document.
D) automated input document.
95) The marking of a form or document to direct or restrict its further processing is called
A) an endorsement.
B) a restriction.
C) blocking.
D) a cancellation.
96) Identifying transaction documents to prevent their further or repeated use after they have
performed their function is known as
A) cancellation.
B) restriction.
C) blocking.
D) endorsement.
97) The general term for any type of control total or count applied to a number of transaction
documents is
A) amount control total.
B) line control total.
C) hash total.
D) batch control total.
98) Totals of homogeneous amounts for a group of transactions or records, usually expressed in
dollars or quantities, is known as a(n)
A) batch control total.
B) hash total.
C) amount control total.
D) line total.
99) The reentry of transaction data with machine comparison of the initial entry to the second
entry to detect errors is called
A) batch balancing.
B) key verification.
C) validity checking.
D) a run-to-run comparison.
100) A repetition of processing and an accompanying comparison of individual results for
equality is called
A) redundant processing.
B) matching.
C) run-to-run comparison.
D) readback.