Auditing, 12e (Arens)
Chapter 9 Internal Controls and Control Risk
9.1 State the three primary objectives of effective internal control
1) A system of internal control consists of policies and procedures designed to provide
management with
A) reasonable assurance that the company achieves its objectives.
B) assurance that fraud will be prevented.
C) reasonable assurance that fraud will be detected.
D) assurance that the firm’s resources will be used in the optimal way.
2) Management’s objectives with respect to internal control include
A) having reasonable assurance that the financial statements are in accordance with IFRS or
ASPE.
B) ensuring that all policies and procedures are clearly documented to reduce employee training
costs.
C) preventing fraud and illegal activities at all costs.
D) providing reasonable assurance that the goals and objectives important to the entity have been
met.
3) Management safeguards assets by
A) having the internal auditors conduct periodic counts of physical assets.
B) controlling access and by comparison of physical items to records.
C) requiring the external auditors to do surprise audits.
D) having management sign a management representation letter.
4) Carrie is the manager of the Bay Street Pharmacy. Carrie is considering implementing a
security tag system to reduce the losses related to stolen goods at their store. The system Carrie is
looking at currently costs $60,000 and is expected to be effective for 5 years. In order to justify
the implementation of the security tag system, average theft per year should be at least
A) $1,000.
B) $12,000.
C) $60,000.
D) theft should be prevented at all costs.
5) Which one of the following controls would be of concern to management, but not to the
auditor? Controls over the
A) collection of accounts receivable amounts.
B) entry of payroll wage rates into the computer systems.
C) distribution of promotional information to present and potential clients.
D) cost of inventory items as recorded in the perpetual inventory system.
6) To comply with the second examination standard, the auditor need not be concerned with all
areas of internal control that apply to management. The auditor’s primary concerns are with the
system’s ability to
A) maintain reliable control systems pertaining to financial transactions.
B) promote efficiency and encourage adherence to policy.
C) prevent and detect financial statement fraud and error.
D) provide reliable data and safeguard assets.
7) The accuracy of the results of the accounting system (account balances) is heavily dependent
upon the
A) knowledge and skills of the auditor.
B) adequacy of the entity level controls.
C) accuracy of the inputs and processing (transactions).
D) training provided to the personnel.
8) The auditor may identify some risks that cannot be effectively tested by substantive tests
alone, for example, when there are paperless transactions (perhaps using EDI – electronic data
interchange). Then the auditor is required, to address those risks, to
A) assess the design effectiveness of relevant controls, and test them
B) obtain an understanding of the controls and test them if reliance is intended
C) obtain an understanding of the controls and assess their design effectiveness
D) test the controls that address the paperless aspects of the transactions
9) Internal controls can never be regarded as completely effective. Even if systems personnel
could design an ideal system, its effectiveness depends on the
A) adequacy of the computer system.
B) proper implementation by management.
C) ability of the internal audit staff to maintain it.
D) competency and dependability of the people using it.
10) It is important for the public accountant to consider the competence of the audit clients’
employees because their competence bears directly and importantly upon the
A) cost/benefit relationship of internal controls.
B) achievement of the objectives of the system of internal control.
C) comparison of recorded accountability with assets.
D) timing of the tests to be performed.
11) Which of the following best describes the inherent limitations that should be recognized by
an auditor when considering the potential effectiveness of an accounting system?
A) Procedures whose effectiveness depends on segregation of duties can be circumvented by
collusion.
B) The competence and integrity of client personnel provides an environment conducive to
accounting control and provides assurance that effective control will be achieved.
C) Procedures designed to assure the execution and recording of transactions in accordance with
proper authorizations are effective against irregularities perpetrated by management.
D) The benefits expected to be derived from effective accounting system usually do not exceed
the costs of such control.
12) An act of two or more employees to work together to misstate records is called
A) malfeasance.
B) collusion.
C) defalcation.
D) felony.
13) Three conditions for fraud are referred to as the “fraud triangle.” One of the sides of this
triangle is incentives or pressures. The other two sides are
A) opportunities, a desire to meet debt repayment obligations.
B) opportunities, attitudes or rationalizations.
C) attitudes or rationalizations, the need to maintain stock prices.
D) the need to maintain stock prices and meet debt repayment obligations.
14) Fraud risk factors are examples of factors that increase the risk of fraud. Which of the
following is an example of a management “incentives or pressures” risk factor?
A) Customer demand for a new product line was significantly less than expected.
B) Management and the auditors disagree upon how to value a large contract in progress.
C) There is only one board member who understands financial statements, and she has suffered a
heart attack.
D) There has been significant turnover in the accounting department in the last year.
15) Fraud risk factors are examples of factors that increase the risk of fraud. Which of the
following is an example of a management “opportunities” risk factor?
A) The company has lost a major account and income is falling.
B) Two major competitors have gone bankrupt as margins decline in the industry.
C) The chief executive officer owns forty percent of the outstanding share capital.
D) New accounting standards provide three different methods for valuing financial instruments.
16) Which of the following is a factor that relates to “incentives or pressures” to commit
fraudulent financial reporting?
A) Significant accounting estimates involving subjective judgments
B) Excessive pressure for management to meet debt covenant requirements
C) Management’s practice of making overly achievable forecasts
D) High turnover of accounting, internal audit and information technology staff
17) Which of the following is a factor that relates to “attitudes or rationalization” to commit
fraudulent financial reporting?
A) Significant accounting estimates involving subjective judgments
B) Excessive pressure for management to meet debt repayment requirements
C) Management’s practice of making overly aggressive forecasts
D) High turnover of accounting, internal audit and information technology staff
18) A) Describe the three broad objectives of management when designing an effective system
of internal control.
B) Describe the aspect of internal control with which auditors are primarily concerned with for a
financial statement audit.
19) A) Describe the three basic concepts (assumptions) underlying the study of internal control
and assessment of control risk.
B) Describe the inherent limitations of internal control.
20) Joan is the owner of a small manufacturing company. In prior years, your firm has conducted
a review engagement of the company. However, this year, Joan obtained a loan from the federal
business development bank, and is required to have an audit of her financial statements. When
you started asking about controls and procedures at the company, Joan got pretty upset.
“All you need to be concerned about is the numbers! Why are you asking all of these questions?
It takes too much time away from my staff to answer these questions! Just check the numbers
and let us get on with our work!”
You calmed her down a bit, and reminded her about the general discussion that occurred with the
engagement letter. You invited her for coffee to briefly explain the following items:
1. Why auditors are concerned about internal controls
2. Why auditors are required to be concerned about internal controls
3. What you need to do to understand internal controls
4. What you will do once you have documented your understanding of internal controls
Required:
Explain what you would say to Joan.
21) You, PA, have been assigned as in charge auditor of a long-time audit client of your firm,
Mikla Tool Inc. (MTI). MTI is owned by George Mikla, an experienced machinist. George
established the business over 20 years ago, and it has grown into a $10 million a year business,
with an excellent reputation for high quality machined parts. MTI has regular clients in the
automobile parts sector and in the health care sector. The company has recently begun producing
parts for environmentally friendly products, such as recycling containers. This is due to the
business’ versatility in dealing with a variety of metals as well as plastics using both manually
controlled and machine controlled (computerized) equipment. The following description is based
upon your review of prior files, and planning discussions with personnel at MTI.
Equipment suppliers have helped MTI develop efficient operations, by providing sample
programs for standard operations and by providing training to employees. One of the suppliers
unfortunately sent sample programs that had been infected by a virus. George’s daughter,
Tiffany, had to cleanse the servers and each of the machines using her copy of the anti-virus
software. When contacted, the supplier did not know that the software was infected, and
apologized profusely!
The company’s four CAD/CAM terminals and printers are connected to the company’s central
local area network. The local area network is maintained by Toni Lee, the owner of a computer
shop conveniently located three blocks away. All computer equipment, software and supplies are
now purchased from Mr. Lee, who is responsible for attaching and maintaining equipment,
upgrading software, and maintaining user profiles on the network. To reduce the amount of Mr.
Lee’s work as network administrator, he has set up passwords by function.
There is one user identification code (userid) and password for accounting (shared by Tiffany,
George and the accounting clerk, Isabel). The plant supervisors share another userid that is used
for production control and to initiate the timekeeping system every morning. A separate userid
and password allowing for only enquiry into the job costing system has also been set up, and can
be used by all employees.
A standard routine has been set up to back up the accounting systems. Either Tiffany or the
accounting clerk inserts one of seven tape cartridges into the system at the end of the day (they
are labelled with the day of the week), so that the company has a full set of accounting
backups for the week. Tiffany keeps these in her office. These are particularly important, since
during the last office move, two years ago, the original software for the accounting system was
misplaced.
The network has two central servers, eleven user stations, and five printers. The user stations are
set up as follows: four CAD/CAM, two time keeping, two production planning and control, two
accounting and one for George.
A good working relationship is extremely important for satisfying some of the company’s larger
customers. MTI has paid for computer equipment for each of the supervisors, so that they have
fully functioning computers at home. If a rush job requires weekend work, then these senior
personnel can work at home to get the necessary quoting or design work completed. Since the ‘at
home’ systems are identical to the office systems Mr. Lee simply copied across the MTI systems
to the home computers. Files can be easily taken home and then brought back to the office using
thumb drives. It is understood that when times are slower, a day off can be taken to compensate
for this weekend work.
It is almost ten years ago that Tiffany arranged for the implementation of the network, and the
purchase of the standard integrated accounting packages (general ledger, order entry/accounts
receivable, purchases/payable and payroll), and for the purchase of the job costing and time
keeping systems. A variety of reports are printed daily, weekly, or monthly from the job costing
system which are used for monitoring employee hours, the status of the jobs, the costs
accumulated for particular jobs, and the work in progress inventory.
The weekly report of hours from the job costing system is approved by the production
supervisors, and is used as an input source for hours worked into the payroll system. The
accounting clerk enters the hours into the accounting system, so that weekly payroll cheques and
reports can be produced. The accounting clerk handles most data entry.
Tiffany is really pleased with their accounting clerk, Isabel, who has been with the company for
three years. She insists that fate had a hand in getting Isabel working for MTI. Isabel had been
‘pounding the pavement,’ having recently immigrated, and had no Canadian business experience.
Her accounting skills were rudimentary, but she quickly learned the accounting software, and has
reorganized the filing systems. Tiffany considers her as indispensable. When Isabel goes on
holiday, many things just don’t get done! Tiffany can do the payroll in a pinch, but accounts
payable and cash disbursements are always done by Isabel. If she’s away, suppliers are simply
told to wait, or Tiffany issues a manual cheque for recording later. Isabel is very good at clearing
queries from suppliers, and ensuring that new suppliers are set up properly. The purchasing
supervisor and his staff rely on Isabel, for she checks the account allocation of purchases and
makes any necessary corrections.
Tiffany or George are signing officers, although Tiffany realizes that she checks supporting
materials more thoroughly than George, who usually just queries Isabel verbally about larger
purchases.
In the past, MTI’s audit has been entirely substantive. However, your partner has decided that
with MTI’s growth, it is time for the company to consider adding additional internal controls.
Accordingly, he has asked you to draft a management letter, to be addressed to George and
Tiffany.
Required:
A) Prepare a draft management letter, clearly identifying the weaknesses (W), impact or
implications of the weaknesses (I), and recommendations for improvement (R).
[The following is a theory question that does not require examples from the case, although
examples could be used.]
B) Explain how the control environment and general IT (information technology) controls are
related. Describe the impact of the control environment and of general IT controls upon different
types of application controls and upon the audit process.
9.2 Explain the five components of the COSO internal control framework and relate these to the
audit process
1) The essence of an effectively controlled organization lies in the
A) effectiveness of its auditor.
B) effectiveness of its internal auditor.
C) attitude of its employees.
D) attitude of its management.
2) The control environment consists of actions, policies and procedures that
A) reflect the overall attitudes of top management, the directors and the owners of an entity
about control and its importance.
B) govern access to particular applications, such as how employees use passwords to change
master file payroll rates.
C) are recorded on the web site, for example, access policies to data.
D) help implement the ethical attitudes at the organization, such as a computer usage policy.
3) The board of directors is essential for effective corporate governance because it has ultimate
responsibility to
A) make sure management implements proper internal control and financial reporting processes.
B) assist management in the preparation of the financial statements.
C) test internal controls and ensure they are working properly.
D) provide a report to the auditor confirming that internal controls are working properly.
4) To help with corporate governance and a positive “tone at the top,” the board of directors and
its committees, such as the audit committee, should
A) rubber stamp the financial statements once per year.
B) consist of all members of executive management.
C) follow the policies and procedures approved by management.
D) take an active role in overseeing the company.
5) A well-designed organizational structure at an entity
A) has operations and programming personnel tasks combined.
B) clearly defines authority and responsibility assignments.
C) requires that wage rates are recorded and tracked by the human resources department.
D) has the internal audit department report to the Chief Financial Officer.
6) The methods that management uses to supervise the entity’s activities are called
A) personnel practices.
B) management control methods.
C) methods of assigning authority and responsibility.
D) management’s operating style.
7) External auditor Mary Smith may not rely on the work of internal auditor Ray Jones unless
A) Jones is certified (CA, CGA or CMA).
B) Jones is independent of the client.
C) Jones is supervised by Smith.
D) Smith obtains evidence that supports the competence, integrity, and objectivity of Jones.
8) The first step for management in the risk assessment process is to identify factors that may
increase risk, for example failure to meet prior objectives. Then, management will
A) assess the likelihood of the risk occurring.
B) make sure that procedures are developed to eliminate the risk.
C) estimate the significance of that risk.
D) develop specific actions to reduce the risk to an acceptable level.
9) Management assesses risks as a part of designing and operating internal controls to minimize
fraud and errors. Auditors assess risks to
A) decide the evidence needed in the audit.
B) fully implement the audit risk model.
C) enable them to assess the completeness of internal controls.
D) make sure that the company will continue to operate over the next year.
10) FiddleWare Limited uses purchased packaged application software to handle the processing
of its transactions. An important control that management should implement with respect to
information systems is the
A) use of a formal systems development methodology.
B) evaluation of potential new systems against organizational objectives.
C) use of appropriate checkpoints and milestones during development.
D) tracking of routine program maintenance changes.
11) An example of general computer control systems that provide reasonable assurance of
authorization of application systems is
A) operations and information systems support.
B) systems, acquisition, development and maintenance controls.
C) organization and management controls.
D) application system control procedures.
12) Which of the following duties would indicate a weakness in internal controls? The
A) accounting function is under the controller.
B) custodianship of cash is the responsibility of the treasurer’s function.
C) internal auditor reports to the board of directors.
D) custodianship of buildings and equipment is the responsibility of the controller’s function.
13) The operational responsibility and the recording of transactions are normally kept separate
A) to centralize activities in order to be more cost efficient.
B) to ensure unbiased information is recorded.
C) because operational personnel rarely has the necessary accounting skills to record
transactions.
D) to avoid confusion of responsibilities and duplication of efforts.
14) Why is it important to separate systems development (or acquisition) and program
maintenance activities from accounting?
A) Accounting personnel have the expertise to evaluate program changes that have been
implemented.
B) Custody of media is important to help ensure ongoing operations.
C) This allows accounting to reconcile transaction totals to transaction details.
D) Lack of separation could result in unauthorized changes to programs and systems.