102. ______________________________ is the possibility that an event will occur.
103. ______________________________ is a deliberate act or untruth intended to obtain unfair or unlawful
gain.
104. ______________________________ are those events that would have a negative impact on organization
objectives.
105. ______________________________ are events that would have a positive impact on objectives.
106. The ______________________________ states that “a fundamental aspect of management’s stewardship
responsibility is to provide shareholders with reasonable assurance that the business is adequately controlled.”
107. The section of Sarbanes Oxley that establishes an independent board to oversee public company audits is
______________________________.
108. The section of Sarbanes Oxley that has received the most press as companies and their auditors have
struggled to comply with its requirements is ______________________________.
109. The section of Sarbanes Oxley that prohibits audit firms from providing a wide array of nonaudit services
to audit clients is ______________________________.
110. The section of Sarbanes Oxley that requires a company’s CEO and CFO to certify quarterly and annual
reports is ______________________________.
111. The section of Sarbanes Oxley that requires each annual report filed with the SEC to include an internal
control report is ______________________________.
112. The section of Sarbanes Oxley that requires financial analysts to properly disclose in research reports any
conflicts of interest they might hold with the companies they recommend is
______________________________.
113. The section of Sarbanes Oxley that authorizes the SEC to censure or deny any person the privilege of
appearing or practicing before the SEC if that person is deemed to be unqualified, have acted in an unethical
manner, or have aided and abetted in the violation of federal securities laws is
______________________________.
114. The section of Sarbanes Oxley that makes it a felony to knowingly destroy, alter, or create records and or
documents with the intent to impede, obstruct, or influence an ongoing or contemplated federal investigation
and offers legal protection to whistle-blowers is ______________________________.
115. The section of Sarbanes Oxley that sets forth criminal penalties applicable to CEOs and CFOs of up to $5
million and up to 20 years imprisonment if they knowingly or willfully certify false or misleading periodic
reports is ______________________________.
116. The section of Sarbanes Oxley that provides for fines and imprisonment of up to 20 years for individuals
who corruptly alter, destroy, mutilate, or conceal documents with the intent to impair the document’s integrity or
availability for use in an official proceeding, or to otherwise obstruct, influence or impede any official
proceeding is ______________________________.
117. ______________________________ provides guidance on how an organization’s IT might affect any of
COSO’s five components of internal control. This standard guides auditors in understanding the impact of IT on
internal control and assessing IT-related control risks.
118. PCAOB Auditing Standard No. 5 uses ______________________________ in its description of the
conduct of an integrated audit under SOX 404.
119. The ______________________________ framework suggests that organizations and auditors should
continue to use COSO as a basis for internal control.
120. COSO’s ______________________________ is the entity’s identification and analysis of relevant risks to
the achievement of its objectives, forming a basis for determining how the risks should be managed.
121. COSO’s ______________________________ sets the tone of the organization, influencing the control
consciousness of its people.
122. COSO’s ______________________________ are the policies and procedures that help ensure that
management directives are carried out.
123. Establishing a viable internal control system is the responsibility of ______________________________.
124. COSO’s ______________________________ is a process that assesses the quality of internal control
performance over time.
125. ______________________________ is a series of actions or operations leading to a particular and usually
desirable result.
126. ______________________________ is a process¾effected by an entity’s board of directors, management,
and other personnel¾designed to provide reasonable assurance regarding the achievement of objectives such as:
effectiveness and efficiency of operations, reliability of reporting, and compliance with applicable laws and
regulations.
127. COSO’s ______________________________ is the foundation for all other components of internal
control, providing discipline and structure.
128. ______________________________ includes crime in which the computer is the target of the crime or the
means used to commit the crime.
129. A computer crime technique called ______________________________ involves the systematic theft of
very small amounts usually by rounding to the nearest cent in financial transactions such as the calculation of
interest on savings accounts.
130. A computer abuse technique called ______________________________ involves a program that
replicates itself on disks, in memory, and across networks.
131. A computer abuse technique called ______________________________ involves a programmer’s
inserting special code or passwords in a computer program that will allow the programmer to bypass the
security features of the program.
132. A(n) ______________________________ is a computer abuse technique in which unauthorized code is
inserted in a program, which, when activated, could cause a disaster such as shutting down a system or
destroying data.
133. A(n) ______________________________ is a program that secretly takes over another Internet -attached
computer and then uses that computer to launch attacks that can’t be traced to the creator.
134. A(n) ______________________________ is a tool designed to assist you in evaluating the potential
effectiveness of controls in a business process by matching control goals with relevant control plans.
135. ______________________________ are business process objectives that an internal control system is
designed to achieve.
136. The control goal called ensure ______________________________ is a measure of success in meting one
or more goals for the operations process.
137. The control goal called ensure ______________________________ is a measure of the productivity of
resources applied to achieve a set of goals.
138. The control goal that seeks to protect an organization’s resources from loss, destruction, disclosure,
copying, sale, or other misuse of an organization’s resources is called ensure
139. The control goal of ensure ______________________________ strives to prevent fictitious items from
entering an information system.
140. A(n) ______________________________ item is an object or event that is not authorized, never occurred,
or is otherwise not genuine.
141. The control goal that is concerned with the correctness of the transaction data that are entered into a system
is called ensure ______________________________.
142. A missing data field on a source document or computer screen is an example of an error that could
undermine the achievement of the control goal of ensure ______________________________.
143. The control goal of ensure ______________________________ provides assurance that all valid objects
or events which were entered into the computer are in turn reflected in their respective master data once and
only once.
144. The control goal of ensure ______________________________ provides assurance that objects or events
which were entered into the computer are in reflected correctly in their respective master data.
145. The control goal of ensure ______________________________ requires that all valid objects or events are
captured and entered into the computer once and only once.
146. Information-processing policies and procedures that assist in accomplishing control goals are known as
______________________________.
147. A(n) ______________________________ relates to a specific AIS process, such as billing or cash
receipts.
148. ______________________________ are applied to all IT service activities.
149. ______________________________ are automated business process controls contained within computer
programs.
150. Control plans that relate to a multitude of goals and processes are called
______________________________.
151. ______________________________ is software designed specifically to damage or disrupt computer
systems.
152. A(n) ______________________________ is program code that can attach itself to other programs or
macros thereby infecting those programs and macros.
153. Three terms used in the chapter to refer to when a control plan is exercised are
______________________________, ______________________________, and corrective control plans.
154. A(n) ______________________________ control plan is designed to discover problems that have
occurred.
155. A(n) ______________________________ control plan is designed to rectify problems that have occurred.
156. Below is a list of sources of information and guidance on internal controls. The second list contains
descriptions or information provided by these sources.
Required:
On the blank line to the left of each numbered item, place the capital letter of the source that best matches that
description. HINT: Some letters may be used more than once. Conversely, some letters may not apply at all.
Sources
of
Informati
on and
Guidance
on
Internal
Controls
A.
B.
C.
D.
E.
F.
G
1.
A fundamental aspect of management’s stewardship responsibility is to provide shareholders with reasonable assurance
that the business is adequately controlled.
2.
This was developed to help management identify, assess and manage risk.
3.
This addressed four categories of management objectives: strategic, operations, reporting and compliance.
4.
This prohibits a CPA firm that audits a public company to engage in certain nonaudit services with the same client.
5.
Provides guidance for conducting an integrated audit of financial statements under Sarbanes-Oxley Act Section 404.
6.
This provides guidance on how an organization’s IT might affect any of COSO’s five components of internal control.
7.
This requires each annual report filed with the SEC to include an internal control report.
8.
Reduced the requirements laid out in Sarbanes-Oxley Act Section 404.
9.
States that COSO is a suitable framework for an assessment of internal control.
10.
The definition of internal control in this document has been adopted throughout the world.
Descriptions
Answer
1
B
3
A
4
D
5
C
6
F
7
E
8
C
9
C
10
G
157. Below is a list of control goals followed by a list of short scenarios describing system failures (i.e., control
goals not met) and/or instances of successful control plans (i.e., plans that helped to achieve control goals).
Required:
On the blank line to the left of each numbered scenario, place the capital letter of the control goal that best
matches the situation described. HINT: Some letters may be used more than once. Conversely, some letters
may not apply at all.
Control
Goals
A.
Ensure effectiveness of operations.
E.
Ensure input accuracy.
B.
Ensure efficient employment of resources.
F.
Ensure input completeness.
C.
Ensure security of resources.
G.
Ensure update accuracy.
D.
Ensure input validity.
H.
Ensure update completeness.
1.
A batch of documents sent by the mail room to the accounts receivable department were lost in the intercompany mail
and never recorded.
2.
A flaw in the processing logic of a computer program resulted in cash received from customers being added to their
accounts receivable balances rather than subtracted.
3.
A mail room clerk fabricated a phony document for a friend to make it look like the friend had paid his account
receivable balance. The phony document got recorded.
4.
An accounts receivable clerk made a copy of the company’s accounts receivable master data and sold this customer
information to a competing company.
5.
Customer checks received in the mail room are batched and sent to the cashier several times a day so that they can be
deposited as fast as possible.
6.
In a manual bookkeeping system, an accounts receivable clerk failed to post an entire page of transactions from the cash
receipts journal to the accounts receivable subsidiary ledger.
7.
In a manual bookkeeping system, cash receipts recorded correctly in the cash receipts journal but some were
inadvertently posted to the wrong customer accounts.
8.
In keying remittance advices into his computer terminal, an accounts receivable clerk entered a receipt of $200 as
$2,000.
9.
The cost of the people and computers needed to process incoming checks is less than the benefit obtained from the
incoming funds.
10.
The company’s accounts receivable system was infiltrated by a hacker.
1
F
6
H
2
G
7
G
3
D
8
E
4
C
9
B
5
A
10
C
Answers
158. Figure TB-7.1 depicts the objective setting process shown in Chapter 7 but with all labels removed.
Required:
Complete Figure TB-7.1 by inserting the following labels where they belong in the model:
Box Title
Box Description
A.
Related objectives
E.
e.g., to be in the top
quartile of product sales
for retailers of our
products
B.
Strategy
F.
e.g., to be the leading
producer of household
products in the regions in
which we operate
C.
Mission, vision, purpose
G.
·
increase production of x by 15%
·
hire 180 qualified new staff
·
maintain product quality
D.
Strategic objectives
H.
e.g., expand production of
our top-five selling retail
products to meet increased
demand
159. Listed below are 13 specific fraud examples taken from some well-known fraud cases: MiniScribe, ZZZZ
Best Carpet Cleaning, Lesley Fay, and Equity Funding.
Required:
For each fraud example, enter a letter corresponding to which information control goal was initially
violated¾Validity, Completeness, or Accuracy. Some examples might involve more than one violation.
160. The CFO of Exeter Corporation is very uncomfortable with its current risk exposure related to the
possibility of business disruptions. Specifically, Exeter is heavily involved with e-business and its internal
information systems are tightly interlinked with its key customers’ systems. The CFO has estimated that every
hour of system downtime will cost the company about $5,000 in sales. The CFO and CIO have further
estimated that if the system were to fail, the average downtime would be about 2 hours per incident. They have
anticipated (assume with 100% annual probability) that Exeter will likely experience 10 downtime incidents in
a given year due to internal computer system problems, and another 10 incidents per year due to external
problems; specifically system failures with the Internet service provider (ISP). Currently, Exeter pays an
annualized cost of $25,000 for redundant computer and communication systems, and another $25,000 for
Internet service provider (ISP) support just to keep total expected number of incidents to 20 per year.
Required:
a.
b.
161. Listed below are 8 descriptions of sections of the Sarbanes-Oxley Act of 2002 (SOX) followed by the
names of 8 sections of SOX.
Required:
On the blank line next to the numbered section description enter a letter of the corresponding section name.
a.
$5,000 ´ 2 hours = $10,000 per incident. $10,000 per incident ´ 20 incidents ´ 100% probability = $200,000 for expected gross risk.
1.
Section makes it a felony to knowingly destroy, alter, or create records or documents with the intent to impede,
obstruct, or influence an ongoing or contemplated federal investigation and provides legal protection for whistle
blowers.
2.
Section prohibits a CPA firm that audits a public company to engage in certain nonaudit services with the same client.
3.
Corporate federal income tax returns should be signed by the CEO.
4.
Section requires each annual report filed with the SEC to include an internal control report.
5.
Section that requires the company’s CEO and CFO to certify quarterly and annual report.
6.
Section requires financial analysts to properly disclose in research reports any conflicts of interest they might hold with
the companies they recommend.
7.
Section establishes an independent board to oversee public company audits.
8.
Section authorizes the General Accounting Office (GAO) to study the consolidation of public accounting firms since
1989 and offer solutions to any recognized problems.
1.
g
5.
c
2.
b
6.
e
3.
h
7.
a
d
f
Answers