Accounting Information Systems, 8e—Test Bank, Chapter 15
11. Describe the components of a disaster recovery plan.
12. What is a mirrored data center?
13. What is a recovery operations center? What is its purpose?
14. Why is inadequate documentation a chronic problem?
15. What is program fraud?
16. The distributed data processing approach carries some control implications of which accountants
should be aware. Discuss two.
17. __________________________ are intentional mistakes while __________________________ are
unintentional mistakes.
18. Explain the relationship between internal controls and substantive testing.
19. Discuss the interrelationship of tests of controls, audit objectives, exposures, and existing controls.
20. Distinguish between errors and irregularities. Which do you think concern the auditors the most?
Accounting Information Systems, 8e—Test Bank, Chapter 15
21. Describe two tests that an auditor would perform to ensure that the disaster recovery plan is adequate.
22. Distinguish between inherent risk and control risk. How do internal controls and detection risk fit in?
23. Contrast internal and external auditing.
24. What are the components of audit risk?
25. How do the tests of controls affect substantive tests?
26. What is an auditor looking for when testing computer center controls?
27. Define and contrast attestation services and assurance services.
28. What is IT Governance?
29. Why should the tasks of systems development and maintenance be segregated from operations?
30. Why should new systems development activities be segregated from the program change
(maintenance) function.
31. Name three forms of computer fraud.
32. Name three types of program fraud.
33. Define operational fraud.
34. Define database management fraud.
35. What is scavenging?
36. As a form of computer fraud, what is eavesdropping?
37. Briefly explain the core competency theory.
38. What are commodity IT assets?
39. Briefly outline transaction cost economics as it relates to IT outsourcing.
40. Briefly explain how a SAS 70 report is used in assessing internal controls of outsourced facilities.
ESSAY
1. Discuss the key features of Section 404 of the Sarbanes-Oxley Act.
2. Section 404 requires management to make a statement identifying the control framework used to
conduct their assessment of internal controls. Discuss the options in selecting a control framework.
3. Explain how general controls impact transaction integrity and the financial reporting process.
4. Prior to SOX, external auditors were required to be familiar with the client organization’s internal
controls, but not test them. Explain.
5. Does a qualified opinion on management’s assessment of internal controls over the financial reporting
system necessitate a qualified opinion on the financial statements? Explain.
6. The PCAOB’s standard No. 2 specifically requires auditors to understand transaction flows in
designing their test of controls. What steps does this entail?
7. What fraud detection responsibilities (if any) are imposed on auditors by the Sarbanes-Oxley Act?
8. Describe how a Corporate Computer Services Function can overcome some of the problems associated
with distributed data processing.
9. Discuss the advantages and disadvantages of the second site backup options.
10. Internal control in a computerized environment can be divided into two broad categories. What are
they? Explain each.
11. Auditors examine the physical environment of the computer center as part of their audit. Many
characteristics of computer centers are of interest to auditors. What are they? Discuss.
12. Explain why certain duties that are deemed incompatible in a manual system may be combined in an
automated environment? Give an example.
13. Compare and contrast the following disaster recovery options: empty shell, recovery operations center,
and internally provided backup. Rank them from most risky to least risky, as well as most costly to
least costly.
14. What is a disaster recovery plan? What are the key features?
15. Computer fraud is easiest at the data collection stage. Why?
16. Explain the outsourcing risk of failure to perform.
17. Explain vendor exploitation.
18. Explain why reduced security is an outsourcing risk.
19. Explain how IT outsourcing can lead to loss of strategic advantage.
20. Explain the role of a SAS 70 report in reviewing internal controls.