Accounting Information Systems, 11e (Bodnar/Hopwood)
Chapter 14 Auditing Information Technology
1) Auditing activities undertaken during substantive testing of account balances can be described
as “auditing through the computer.”
2) The external auditor serves the firm’s stockbrokers, the government, and the general public.
3) Total audit cost is increased significantly when some audit resources are directed at reviewing
and verifying the internal controls that exist in a system.
4) With the advances in technology today, the “around-the-computer” approach to auditing is no
longer widely used.
5) Application controls are related to specific computer application systems.
6) Basic auditing standards may be altered by the technology employed in the system to be
audited.
7) Using information technology in auditing reduces the time spent on clerical tasks and may
improve the overall morale and productivity of auditors.
8) ITF is the one universal auditing approach used in information system audits.
9) The test data technique requires minimal computer expertise and is usually inexpensive to
implement.
10) ITF does not involve the input of test data into the master files of the computer system being
audited.
11) ITF is a powerful information system audit technology.
12) Parallel simulation processes test data through real programs.
13) Parallel simulation is appropriate where transactions are sufficiently important to require a
100 percent audit.
14) GAS has a long history of usage because public accounting firms developed it in the 1960s.
15) Some embedded audit routines use automated collection language (ACL) to embed specially
programmed modules as in-line code with regular programs.
16) Embedded audit routines are more easily added to a program as a modification rather than
being added as a program is developed.
17) Snapshot technology is generally incorporated into extended records for later review by
auditors.
18) A trace can produce thousands of output records if an excessive number of transactions are
tagged.
19) The degree of independence that auditors can maintain while developing embedded audit
routines will depend largely on the level of technical expertise that they possess.
20) One type of tracing is to verify a hash total of the object code of software to detect
modifications to the software.
21) Specific documentation showing the nature of application controls in a system is known as
control flowcharting.
22) Most information system audits follow a four-phase structure, which is followed by analysis
and reporting of results.
23) An audit program is a detailed list of the audit procedures to be applied on a particular audit.
24) An information systems application audit focuses almost exclusively on the testing of
processing controls.
25) Development standards are major general controls in computerized systems.
26) Project management controls are concerned with the maintenance of application programs.
27) One very common program change control is to periodically compare actual copies of object
code with duplicate copies retained in the past.
28) Information system development audits are more common to large organizations because
they often have a formal development process.
29) An audit of an organization’s computer service center is normally undertaken before any
information system application audit.
30) PCAOB has encouraged a risk-based approach to testing the effectiveness of internal
controls as they relate to financial audits.
31) Audits of computer service centers do not require as high a degree of technical expertise as
do audits of computerized applications.
32) Risk-based auditing provides assurances relating to the effectiveness of an organization’s
enterprise risk management process.
33) In RBA, the subject of the audit is how well the management prevents fraud.
34) IT governance has the objective of enhancing and ensuring the efficient application of IT
resources as a critical success factor.
35) COBIT is an IT governance framework that is critical in ensuring proper control and
governance over information and the system that creates, stores, manipulates, and retrieves that
information.
36) COBIT contains 34 IT processes and organizes them into 8 domains.
37) Each COBIT IT process should have its own navigation diagram.
38) Maturity models are used to evaluate an organization’s relative level of achievement of IT
governance on a scale from 1-10.
39) CISA, CISM, and CGEIT are professional certifications in system security.
40) ________ auditors commonly undertake audits that are reviewed and relied upon by
________ auditors.
41) When batch processing was the dominant method used in computerized data processing, the
________ approach provided an adequate audit.
42) A clear and obvious benefit is obtained from the ________ analysis capability provided by
information technology.
43) The ________ ________ technique may be used to verify input transaction validation
routines.
44) Test data used in ITF are identified by special ________ and must be excluded from normal
system outputs.
45) Using an integrated-test-facility approach, ________ testing is appropriate to ________, real-
time processing technology.
46) Auditors with little computer expertise can use ________ to perform audit-related data
processing functions.
47) A comprehensive ________ ________ can be established by collecting, in an extended
record, supplementary data concerning processing not normally collected.
48) All embedded audit routine techniques require a(n) ________ level of technical expertise to
set up, and at least a(n) ________ level of knowledge to use them effectively.
49) In ________ checking, an auditor manually processes test or real program data through the
logic of a program.
50) ________ can be effectively used in conjunction with a test data technique.
51) Application controls are divided into ________ general areas.
52) The primary audit technique used in an information systems development audit is the review
and testing of related ________.
53) Documentation governing the design, development, and implementation of application
systems is known as systems ________ ________.
54) An audit of the computer service center is undertaken before any application audits to ensure
the ________ ________ of the environment in which the application will function.
55) ________ is an IT governance professional certification for individuals who manage, design,
oversee, and assess an enterprise’s information security program.
56) An organization’s current status compared to benchmarks and international standards, as well
as an organization’s strategy for improvement, is called a(n) ________ model.
57) ________ is an open standard which provides “good practices” across a domain and process
framework and presents activities in a manageable and logical structure.
58) In RBA, the subject of the audit is how well the management manages ________.
59) RBA provides assurances relating to the effectiveness of an organization’s ________
________ ________ processes.
60) “Auditing with the computer”
A) is only performed by external auditors.
B) involves activities related to compliance testing.
C) is only performed by internal auditors.
D) involves activities related to substantive testing of account balances.
61) “Auditing through the computer” refers to
A) substantive tests.
B) compliance tests.
C) transaction tests.
D) application control tests.
62) An interim audit
A) consists only of substantive testing of account balances.
B) has the objective of verifying financial statement figures to render a professional opinion of
the financial statements.
C) has the objective of establishing the degree to which the internal control system can be relied
upon.
D) None of these answers is correct.
63) Confirming the existence, assessing the effectiveness, and checking the continuity of the
operation of the internal controls upon which reliance is placed is called
A) compliance testing.
B) financial statement auditing.
C) auditing “around-the-computer.”
D) substantive testing.
64) A financial statement audit
A) consists only of compliance testing of account balances.
B) has the objective of verifying financial statement figures to render a professional opinion of
the financial statements.
C) has the objective of establishing the degree to which the internal control system can be relied
upon.
D) None of these answers is correct.
65) External auditors typically conduct compliance testing because
A) the main goal of a financial statement audit is to ensure that internal controls are operating
effectively.
B) compliance tests yield more reliable evidence than substantive tests.
C) compliance tests determine how much reliance can be placed on the internal controls in
substantive tests.
D) compliance testing can be conducted solely by the internal auditors.
66) The comparison of input to output is known as auditing
A) around-the-computer.
B) through the computer.
C) with the computer.
D) without the computer.
67) The verification of controls in a computer system is known as auditing
A) around-the-computer.
B) through the computer.
C) with the computer.
D) without the computer.
68) The use of information technology to perform audit work is known as auditing
A) around-the-computer.
B) through the computer.
C) without the computer.
D) with the computer.
69) Information system audits to verify compliance with internal controls are performed by
A) internal auditors only.
B) external auditors only.
C) outside third-party consultants only.
D) both internal and external auditors.
70) Information technology is used to perform some audit work that otherwise would be done
manually. The use of information technology by auditors is
A) essential.
B) mandatory under AICPA Statements of Auditing Standards.
C) optional.
D) at the sole discretion of the manager in charge of the audit.
71) An external auditor conducts an information systems audit using the professional standards
promulgated by the
A) Institute of Internal Auditors.
B) American Institute of Certified Public Accountants.
C) Institute of Management Accountants.
D) Information Systems Audit and Control Association.
72) An internal auditor conducts an information systems audit using the professional standards
promulgated by the
A) Institute of Internal Auditors.
B) American Institute of Certified Public Accountants.
C) Institute of Management Accountants.
D) Information Systems Audit and Control Association.
73) Which of the following is a possible benefit of using information systems technology in the
conduct of an audit?
A) Increased independence from information systems personnel
B) Elimination of most manual calculations, footing, and cross-footing
C) Standardization of audit working papers and correspondence
D) All of these answers are correct.
74) The first (and oldest) technique used to audit through the computer is
A) the integrated test facility.
B) parallel simulation.
C) the test data approach.
D) generalized audit procedures.
75) Which of the following procedures uses only auditor-prepared test transactions?
A) The test data approach
B) Integrated test facility
C) Parallel simulation
D) Embedded audit routines
76) The information systems auditing technique that uses special software to monitor the
execution of a program is called
A) embedded audit routines.
B) mapping.
C) a snapshot.
D) tracing.
77) The information systems auditing technique that uses software that has been specifically
designed to allow auditors to perform audit-related data processing functions is called
A) mapping.
B) tracing.
C) generalized audit software.
D) embedded audit routines.
78) Which of the following statements is an advantage to using the test data technique in
information systems auditing?
A) The test can be run only on a specific program at a specific point in time.
B) The test must be announced.
C) Test data is limited to certain combinations of processing conditions.
D) The technique is used for testing programs in which calculations such as interest or
depreciation are involved.
79) Which of the following statements is a disadvantage to using the integrated-test-facility (ITF)
approach in information systems auditing?
A) When carefully planned, the costs of using ITF are minimal.
B) No interruption of normal computer activity is involved in using ITF.
C) Fictitious data must be excluded from output reports.
D) ITF is used in large computer application systems that use real-time processing.
80) Which of the following should be developed when the related application system is
developed?
A) Test data approach
B) Integrated test facility
C) Parallel simulation approach
D) Artificial intelligence software
81) Which of the following processes real data through a test program?
A) Test data approach
B) Integrated test facility
C) Parallel simulation approach
D) Artificial intelligence software
82) An audit technique not requiring the use of the client’s computer facilities is
A) the use of snapshots.
B) the test data approach.
C) the integrated test facility.
D) parallel simulation.
83) An advantage of generalized audit software is that
A) it can select a sample of accounts receivable for confirmation and help the auditor prepare
confirmation requests.
B) the auditor avoids having to review systems documentation.
C) it eliminates the need for any coding by the auditor.
D) the client’s staff can use it to perform audit-related tasks.
84) Which of the following is correct regarding the ACL audit software package?
A) ACL can only be used in a mainframe environment.
B) ACL enables the field auditor to connect a PC to a client’s accounting system.
C) ACL is used primarily for administrative audit activities.
D) Most client files must be converted to the ACL language format before processing.
85) The technology that involves the modification of actual computer programs for audit
purposes is called
A) generalized audit software (GAS).
B) ACL.
C) embedded audit routines.
D) record extension.
86) Using embedded audit routine technology, an auditor may program a module so that the test
limits can be altered as desired. This approach has been termed
A) sample audit review file.
B) in-line coding.
C) system control audit review file.
D) off-line auditing.
87) The extended record technique provides a way to reconstruct an audit trail by
A) adding specific “dummy” test data processed by the system in the extended record for
examination by the auditor after processing is complete.
B) processing real data through a test program and comparing the simulated and regular output
after processing is complete.
C) capturing a detailed listing of the sequence of program statement executions in the extended
record that would not normally be saved.
D) tagging specific transactions and capturing intervening processing steps in the extended
record that would not normally be saved.
88) The snapshot technique involves capturing and dumping
A) selected transaction data.
B) the program code itself.
C) selected master file contents.
D) selected memory contents.
89) Which two information system auditing technologies are very similar?
A) Snapshot and extended records
B) ITF and ACL
C) Snapshot and ACL
D) Extended records and ITF
90) Which of the following information system auditing technologies produces a printed audit
trail of computer processing?
A) Extended records
B) Snapshot
C) Sample audit review file
D) System control audit review file
91) Tracing of a program’s execution provides
A) programmed edits for input data items.
B) test data for subsequent processing.
C) a detailed listing of the sequence of program statement execution.
D) a comprehensive audit trail which can be reviewed by auditors after processing ends.
92) Probably the oldest (and still widely used) information systems auditing technique is
A) test data.
B) review of systems documentation.
C) generalized audit software.
D) ACL.
93) The auditor performs a review of systems documentation
A) during the initial audit phase.
B) throughout the audit at the beginning of each audit phase.
C) during the intermediate phase, after becoming familiar with the basic approach to be taken.
D) during the final audit phase, giving the auditor a chance to first become familiar with all of
the company’s operations.