Accounting Information Systems, 2e (Kay/Ovlia)
Chapter 10 Fraud and Internal Control
Objective 1
1) Motive and opportunity without means still results in fraud.
2) Corruption involves theft of assets for personal gain.
3) Fraudulent financial reporting includes misstating financial statements to meet earnings
targets.
4) Not even the strongest system of controls can eliminate all risk of organizations being
defrauded by employees who are sufficiently motivated to find loopholes.
5) ________ includes illegal acts such as bribery, kickbacks, money laundering, and rigging
bids.
6) ________ focuses on managing when revenues and expenses are recorded in order to
favorably reflect a company’s financial performance in a legal manner.
7) ________ should be assessed periodically by the organization to identify specific potential
schemes and events that the organization needs to mitigate.
8) ________ techniques should be established to uncover fraud events when preventive measures
fail or unmitigated risks are realized.
9) What percentage of occupational fraud is committed by the accounting department?
A) 10%
B) 29%
C) 12%
D) 21%
10) What percentage of occupational fraud is committed by upper management?
A) 19%
B) 33%
C) 29%
D) 12%
11) How long does the typical fraud last before being detected?
A) Six months
B) One year
C) Two years
D) Three years
12) What percentage of fraud cases were inadequate internal controls cited as a primary
contributing factor?
A) 48%
B) 29%
C) 35%
D) 42%
13) Earnings management focuses on managing when revenues and expenses are recorded in
order to favorably reflect a company’s financial performance in a(n) ________.
A) illegal manner
B) legal manner
C) questionable manner
D) vague manner
14) List the three fraud and abuse categories. Provide examples.
15) What three things must a perpetrator have to commit fraud? Include a brief description of
each.
16) List and describe the principles for establishing an environment to effectively manage fraud
risk.
1) The accounting profession is self-regulated.
2) The SOX legislation basically requires management of privately held companies must assess
and report on the effectiveness of internal controls for financial reporting using a recognized
framework.
3) SOX emphasizes a strong system of internal control as a way of avoiding Enron-sized
accounting frauds.
4) SOX section 302 requires each annual report of a publicly traded company to contain an
internal control report stating the management’s responsibility to establish and maintain an
adequate system of internal control for financial reporting.
5) SOX section 404 requires requires each annual report of a publicly traded company to contain
an internal control report to contain a assessment of the effectiveness of the company’s internal
control structure and procedures.
6) SOX section 906 requires corporate management to certify reports filed with the SEC.
7) The Sarbanes-Oxley Act of 2002, which would become known as SOX, created the ________
to oversee and regulate public companies and their auditors.
8) A(n) ________ over financial reporting requires the auditor to conduct tests of controls to
obtain evidence that internal control over financial reporting has operated effectively.
9) In a(n) ________, the auditor performs tests of controls and substantive procedures.
10) A(n) ________, as required by Auditing Standard No. 5, integrates an audit of internal
control with an audit of financial statements.
11) When investigating fraud, ________ enables auditors to extract, analyze, and interpret
evidence to detect unusual patterns and irregularities.
12) A(n) ________ in internal control over financial reporting is defined as a deficiency as such
that there is a reasonable possibility that a material misstatement of financial statements will not
be prevented or detected in a timely basis.
13) Which organization was created by the Sarbanes-Oxley Act of 2002?
A) Public Company Accounting Oversight Board (PCAOB)
B) Institute of Management Accountants (IMA)
C) Security and Exchange Commission (SEC)
D) Committee of Sponsoring Organizations of the Treadway Commission (COSO)
14) Which SOX section requires the chief executive officer and the chief financial officer to
disclose to the auditors and the audit committee of the board of directors all significant
deficiencies in internal controls, which could adversely affect the ability to record, process,
summarize, and report financial data and any material weaknesses in internal controls?
A) Section 806. Protection for Employees of Publicly Traded Companies Who Provide Evidence
of Fraud
B) Section 404. Management Assessment of Internal Controls
C) Section 906. Corporate Responsibility for Financial Reports
D) Section 302. Corporate Responsibility for Financial Reports
15) Which SOX section requires the public accounting firm that audits the financial statements
of the company to issue an attestation report regarding the effectiveness of the company’s
internal controls?
A) Section 806. Protection for Employees of Publicly Traded Companies Who Provide Evidence
of Fraud
B) Section 404. Management Assessment of Internal Controls
C) Section 906. Corporate Responsibility for Financial Reports
D) Section 302. Corporate Responsibility for Financial Reports
16) Which audit type requires the auditor to conduct tests of controls to obtain evidence that
internal control over financial reporting has operated effectively?
A) Audit of financial reporting control
B) Audit of financial statements
C) Audit of internal control
D) IT audit
17) What is SOX?
18) What does Auditing Standard No. 5, an Audit of Internal Control Over Financial Reporting
That Is Integrated with an Audit of Financial Statements, require the auditor to understand about
IT?
1) Internal control is designed to provide reasonable assurance regarding the achievement of
objectives in effectiveness and efficiency of operations, reliability of financial reporting, and
compliance with applicable laws and regulations.
2) The internal control category control environment includes identifying, analyzing, and
managing risks affecting the ability to report financial data properly.
3) For internal control to be effective, an organization needs stated ________ and ________ for
internal controls.
4) For internal control to be effective, an organization needs ________ with internal controls.
5) The COSO ________ provides a blueprint for implementing an internal control system to
assist in ensuring the reliability of financial statements and compliance with Sarbanes-Oxley
legislation.
6) In control activities, ________ divide authorization, recording, and asset custody among
different individuals.
7) In control activities, ________ ensure appropriate information processing, authorization, and
data integrity.
8) Which of the following is NOT the purpose of internal controls?
A) Compliance with laws and regulations
B) Effectiveness and efficiency of operations
C) Public examine of private data
D) Reliability of financial reporting
9) Which COSO Internal Control-Integrated Framework essential component of an effective
internal control system involves identifying, analyzing, and managing risks that affect a
company’s ability to record, process, summarize, and report financial data properly?
A) Risk Assessment
B) Control Environment
C) Control Activities
D) Monitoring
10) In the COSO Internal Control-Integrated Framework, risk assessment objectives include all
of the following EXCEPT
A) Identification and analysis of financial reporting risks
B) Importance of financial reporting objectives
C) Assessment of fraud risk
D) Risks of financial controls
11) In the COSO Internal Control-Integrated Framework, control activities do NOT include
A) Independent reconciliations of assets and accounting records
B) Physical controls
C) Segregation of duties
D) Management controls
12) Which COSO Internal Control-Integrated Framework essential component of an effective
internal control system includes the accounting system for identifying, recording, processing, and
reporting transactions and financial data?
A) Monitoring
B) Information and Communication
C) Control Activities
D) Control Environment
13) Which COSO Internal Control-Integrated Framework essential component of an effective
internal control system involves assessing internal controls as well as the process for taking
corrective action?
A) Control Environment
B) Risk Assessment
C) Monitoring
D) Control Activities
14) What are the objectives of internal control?
15) What is internal control and what is its purpose?
16) What are the five major categories of internal control?
17) What factors are part of the control environment?
18) List and describe the control activities for mitigating financial, operational, and compliance
controls risks.
19) Internal control is a set of policies, procedures, and activities to achieve an enterprise’s
objectives that are related to what?
20) For internal control to be effective what two things does an enterprise need?
1) Increasingly the expectation is that the auditor and the IT professional learn more about the
other’s field.
2) Internal controls for the accounting system are incomplete without IT controls.
3) Application controls ensure completeness and accuracy of transaction processing,
authorization, and validity.
4) Input controls ensure data is processed properly.
5) Processing controls ensure reports and other output are distributed properly.
6) IT general controls have a pervasive effect on all internal controls.
7) ________ controls include IT governance at top management levels where strategic business
objectives are set and policies are established.
8) ________ controls are embedded within business process applications.
9) ________ controls support application controls to provide a reliable operating environment.
10) Which level in the company corresponds to the Entity-Level IT Controls?
A) Top management
B) Information management
C) Business processes
D) IT services
11) Which of the following is NOT part of the audit committee’s responsibilities?
A) The organization’s compliance with legal and regulatory requirements
B) The integrity of the organization’s financial statements and reports
C) The organization’s policies regarding ethical conduct
D) The organization’s ability to process data efficiently and effectively
12) Which general IT control includes control over SDLC phases for software upgrades and
modifications?
A) Program development controls
B) Access security controls
C) Computer operations controls
D) Program change controls