16
15) Which one of the following is an example of a general authorization?
A) The highest credit limit allowed for accounts receivable is $50,000.
B) ABC Company has a credit limit of $25,000.
C) Each supervisory wage rate must be approved by the executive manager.
D) Grocery supervisors approve each transaction reversal over five dollars.
16) Which one of the following is an example of a specific authorization?
A) The computer systems automatically reorder inventory when quantities fall below the
economic order quantity.
B) The highest credit limit allowed for accounts receivable customers is $100,000.
C) Each sales transaction that exceeds the credit limit of a customer must be approved by the
controller.
D) Grocery sales clerks may approve returns of goods less than ten dollars in value.
17) The chart of accounts is an important control because it provides the framework for
determining the information presented to management and other financial statement users. What
type of errors is the chart of accounts helpful in preventing? It helps prevent errors of
A) occurrence.
B) completeness.
C) accuracy.
D) classification.
18) An important type of protective measure for safeguarding assets and records is
A) adequate segregation of duties among personnel.
B) proper authorization of transactions.
C) the use of physical precautions.
D) adequate documentation.
17
19) An essential characteristic of the persons performing internal check procedures is
A) independence from the original data preparer.
B) a thorough knowledge of accounting.
C) an analytical and inquisitive mind.
D) competence in data entry skills.
20) A major control available in a small company, which might not be feasible in a large
company, is
A) a wider segregation of duties.
B) use of sequentially numbered documents.
C) fewer transactions to process.
D) the owner-manager’s personal interest and close relationship with the personnel.
21) Effective internal control in a small company that has an insufficient number of employees to
permit proper division of responsibilities can best be enhanced by
A) employment of temporary personnel to aid in the segregation of duties.
B) direct participation by the owner of the business in the record-keeping activities of the
business.
C) engaging a public accountant to perform monthly “write-up” work.
D) delegation of full, clear-cut responsibility to each employee for the functions assigned to
each.
18
22) A) The COSO internal control framework consists of five components. Describe each of
these components.
B) Custody of assets and reconciliation should be separated to contribute to strong internal
control. List the general categories of activities that should be separated.
19
23) A) Discuss what is meant by the term “control environment” and identify four control
environment subcomponents that the auditor should consider.
B) List the steps that management follows in assessing risks relevant to the preparation of
financial statements in conformity with an applicable financial reporting framework.
C) How does the auditor obtain knowledge about management’s risk assessment process?
D) Explain how management’s risk assessment process differs from the auditor’s risk assessment
process.
E) What is the relationship between management’s risk assessment process and audit evidence?
24) A) List the three types of general computer control systems.
B) Adequate segregation of duties is an important control procedure. Describe the specific
functions that should be separated for segregation of duties to prevent both intentional and
unintentional misstatements that are of significance to auditors.
C) Adequate documents and records are important for effective internal control. Five principles
dictate the proper design and use of documents and records. One principle is that documents and
records should be prenumbered consecutively to facilitate control over missing documents, and
to aid in locating documents when they are needed at a later date. Discuss each of the other four
principles of adequate documents and records.
21
25) Dimple Leather is a chain of retail stores that sells leather clothing and accessories across
Canada. Each store has point of sale equipment that is linked to a local server. At night, local
accounting information is transmitted to the head office computer and any updates to prices or
other adjustments are transferred to the local office.
Required:
Define the control environment. List the components of the control environment. For each
component, provide an example of a control that might exist at Dimple Leather.
22
26) Porterville, Ontario, is the home of the largest leather tanning operation in Canada. Hides
from various animals are stretched and treated, then cut into shapes for shipment to wholesalers.
Computer assisted operations are important in maintaining temperature, humidity, and proper
mix proportions in chemical solutions used for the tanning process. Computer assistance has
helped improve the quality of the tanning process, as well as provide a safer environment for
employees. Computer operations and backup is supported by the warehouse manager, Joe.
Individual hides are tagged with a bar code and tracked for quality control purposes. The
HomeTown Tanning Company uses a centralized microcomputer based system for its
manufacturing and accounting operations. The two owners of the company are active in the
business, and approve all new hardware and software acquisitions.
The controller is responsible for network upgrades as well as maintaining passwords and user
identification codes on the network. Accounting transactions are entered by accounting staff,
although the controller has the ability to review and correct transactions.
Required:
List the six categories of functions that need to be separated from each other. Does HomeTown
Tanning have these functions separated? For any functions that are not separated, indicate the
potential impact upon controls and upon the audit.
23
9.3 Define information technology governance. Describe the attributes of good IT governance
1) Jenny is the information technology support manager at CMH. Jenny is considered to be a
super-user at CMH since she can circumvent normal controls. In order to address the risk of
super-users, management should
A) remove the super-user.
B) establish effective compensating controls.
C) update the background check on the super-user on a yearly basis.
D) ensure that the super-user is familiar with the code of conduct of the company.
2) Bravo Design had IMB consulting design a custom software to record the job costs and sales
in progress. What acquisition process did Bravo design follow?
A) In-house development
B) Systems acquisition
C) Turnkey software development
D) Outsourcing
24
9.4 Describe what the auditor does to obtain an understanding of internal controls
1) When the auditor attempts to determine the operation of the accounting system by tracing one
or a few transactions through the accounting system, this is referred to as
A) tracing.
B) vouching.
C) tests of controls.
D) a walk-through.
2) Once an understanding of internal controls is obtained that is sufficient for audit planning,
then the auditor must first assess
A) whether a lower level of control risk could be supported.
B) whether the financial statements are auditable.
C) the level of control risk supported by the understanding obtained.
D) the level of control risk to use.
3) Control risk is a measure of the auditor’s expectation that internal controls will
A) prevent material misstatements from occurring.
B) detect and correct material misstatements.
C) either prevent material misstatements or detect and correct them.
D) neither prevent material misstatements nor detect and correct them.
4) When planning the audit, the auditor’s decision on the appropriate assessed level of control
risk to use is
A) an economic issue, trading off the costs of testing controls against the cost of testing balances.
B) calculated by using the audit risk model.
C) calculated by using a standard formula.
D) determined by using actuarial tables.
5) The procedures to test effectiveness of control policies and procedures in support of a reduced
assessed control risk are called
A) tests of details of balances.
B) tests of controls.
C) analytical procedures.
D) a walk-through.
6) Narratives, flowcharts, and internal control questionnaires are three commonly used methods
of
A) documenting the auditor’s understanding of internal controls.
B) testing internal controls.
C) designing the audit manual and procedures.
D) documenting the auditor’s understanding of client’s organizational structure.
7) Paul is in the process of performing procedures to obtain the necessary understanding of the
client’s internal controls. As part of this process, Paul received from the client completed
narratives, flowcharts and internal control questionnaires. Paul can use this information from the
client
A) if the entity level controls and tone at the top were found to be effective.
B) if there has not been any significant change in the internal controls since the prior year.
C) as long as any subsequent reliance on controls is adequately substantiated with testing.
D) since it was prepared by management who are unbiased.
8) When a compensating control exists, a weakness in the system
A) is no longer a concern because the potential for misstatement has been sufficiently reduced.
B) is reduced but not removed; therefore, it is still of concern to the auditor.
C) could cause a material loss, so it must be tested using substantive procedures.
D) is magnified and must be removed from the sampling process and examined in its entirety.
26
9) When the auditor identifies opportunities for the client to make operational improvements in
the internal control system, it will be communicated to the client’s audit committee in the
A) management letter.
B) reportable conditions letter.
C) engagement letter.
D) audit report.
10) A secondary objective of the auditor’s study and evaluation of internal control is that the
study and evaluation provide
A) a basis for constructive suggestions concerning improvements in internal control.
B) a basis for reliance on the accounting system.
C) an assurance that the records and documents have been maintained in accordance with
existing company policies and procedures.
D) an indication that management and employees are trustworthy.
11) Each key control that the auditor intends to rely on must be supported by sufficient
A) tests of details of balances.
B) tests of controls.
C) analytical review procedures.
D) reperformance procedures.
12) A procedure that would most likely be used by an auditor in performing tests of control
procedures that involve segregation of functions and that leave no transaction trail is
A) inspection.
B) observation.
C) reperformance.
D) reconciliation.
13) Ideally, tests of controls should be applied to controls
A) at the balance sheet date.
B) at each quarterly interim period.
C) for the entire period under audit.
D) at the beginning of the fiscal period.
14) After considering a client’s internal controls, an auditor has concluded that it is well designed
and is functioning as intended. Under these circumstances, the auditor would most likely
A) perform tests of controls to the extent outlined in the audit program.
B) determine the control procedures that should prevent or detect errors and irregularities.
C) use a combined audit approach that includes tests of controls and substantive tests.
D) determine whether transactions are recorded to permit preparation of financial statements in
accordance with generally accepted accounting principles.
15) A) Step one in the auditor’s study and evaluation of internal control is obtain understanding
of internal control for audit planning purposes. List each of the remaining steps.
B) Once the auditor has an understanding of internal control, two assessments are made. List
each assessment that must be made prior to testing controls.
C) Describe five common procedures an auditor can use to obtain an understanding of internal
control design.
16) You have just finished documenting your understanding of cycle controls at an audit
engagement.
Required:
A) Explain how you will identify the controls that will be tested.
B) What process will you follow for weakness in internal controls?
9.5 Identify important risks and controls in small businesses
1)
A)
B)
C)
D)