Auditing: A Risk Based Approach to Conducting a Quality Audit, 10e
Solutions for Chapter 3
True/False Questions
3-1 T
3-2 T
3-4 F
3-6 T
3-8 T
3-10 T
3-12 T
3-14 T
3-16 T
3-18 F
3-20 F
Multiple Choice Questions
3-22 B
3-24 B
3-26 B
3-28 B
3-30 B
3-32 D
3-34 C
3-32 A
3-2
3-33 D
3-35 C
3-37 D
3-39 D
3-40 A
Review and Short Case Questions
3-41
Internal control over financial reporting provides many benefits to an organization, including
providing reasonable assurance regarding the reliability of their financial information and
3-42
Internal control is used to mitigate the risks to achieving objectives. For financial reporting, an
3-43
COSO defines internal control as:
a process, effected by an entity’s board of directors, management, and other personnel,
designed to provide reasonable assurance regarding the achievement of objectives in the
Important elements of the definition recognize that internal control is:
A process consisting of ongoing tasks and activities.
Effected by people and is not just about policy manuals, forms, and procedures. People
at every level of the organization, ranging from shipping clerks to the internal auditor to
the chief financial officer, chief executive officer and the board of directors, impact
internal control.
3-3
Geared toward the achievement of multiple objectives. The definition highlights that
3-44
COSO identifies the five components of internal control that support an organization in
achieving its objectives, which include:
1. Risk Assessment involves the process for identifying and assessing the risks that may
2. Control Environment is the set of standards, processes and structures that provides the
3. Control Activities are the actions that have been established by policies and
4. Information and Communication recognizes that information is necessary for an
organization to carry out its internal control responsibilities. Information can come from
5. Monitoring is necessary to determine whether the controls, including all five
components, are present and continuing to function effectively.
3-45
Some components of internal control operate across an entity and are referred to as entity-wide
controls. Entity-wide controls affect multiple processes, transactions, accounts, and assertions.
The following are typically considered entity-wide controls:
Controls related to the control environment
Controls over management override
3-4
In contrast, other controls such as control activities, typically affect only certain processes,
transactions, accounts, and assertions. These types of controls are sometimes referred to as
transaction controls, and they are not expected to have a pervasive effect throughout the
organization. They include controls over transactions related to:
Business processes
3-46
CONTROL ENVIRONMENT
1. The organization demonstrates a commitment to
integrity and ethical values.
2. The board of directors demonstrates independence of
3. Management establishes, with board oversight,
4. The organization demonstrates a commitment to
5. The organization holds individuals accountable for
3-47
NOTE: If the instructor is interested in providing the students with many examples of the
principles, the instructor may want to have the students read COSO’s Internal Control over
External Financial Reporting: A Compendium of Approaches and Examples that was published
in 2013.
1. The organization demonstrates a commitment to integrity and ethical values. Examples
2. The board of directors demonstrates independence of management and exercises
oversight of the development and performance of internal control. Examples include: an
3. Management establishes, with board oversight, structures, reporting lines, and
appropriate authorities and responsibilities in the pursuit of objectives. Examples include:
3-5
4. The organization demonstrates a commitment to attract, develop, and retain competent
individuals in alignment with objectives. Examples include: a contingency plan for
5. The organization holds individuals accountable for their internal control
responsibilities in the pursuit of objectives. Examples include: an internal quarterly
3-48
The control environment is the foundation for all other components of internal control. It starts
with the leadership of the organization, including the board of directors, the audit committee, and
3-49
The nature of compensation affects human behavior. Management needs knowledge of an
organization’s compensation scheme to determine if there might be motivation to misstate
financial data in order to meet performance goals, and thus to generate added bonuses or stock
3-6
Management and the board should be sensitive to, and adjust as appropriate, pressures that could
3-50
RISK ASSESSMENT
6. The organization specifies objectives with sufficient
clarity to enable the identification and assessment of
risks relating to objectives.
7. The organization identifies risks to the achievement
9. The organization identifies and assesses changes that
could significantly impact the system of internal control.
3-51
NOTE: If the instructor is interested in providing the students with many examples of the
principles, the instructor may want to have the students read COSO’s Internal Control over
External Financial Reporting: A Compendium of Approaches and Examples that was published
in 2013.
6. The organization specifies objectives with sufficient clarity to enable the identification
and assessment of risks relating to objectives. Examples include: an organization
7. The organization identifies risks to the achievement of its objectives across the entity
and analyzes risks as a basis for determining how the risks should be managed. Examples
8. The organization considers the potential for fraud in assessing risks to the achievement
9. The organization identifies and assesses changes that could significantly impact the
system of internal control. Examples include: the identification and analysis of key
3-7
3-52
CONTROL ACTIVITIES
10. The organization selects and develops control
activities that contribute to the mitigation of risks to the
achievement of objectives to acceptable levels.
11. The organization selects and develops general
12. The organization deploys control activities as
3-53
NOTE: If the instructor is interested in providing the students with many examples of the
principles, the instructor may want to have the students read COSO’s Internal Control over
External Financial Reporting: A Compendium of Approaches and Examples that was published
in 2013.
10. The organization selects and develops control activities that contribute to the
11. The organization selects and develops general control activities over technology to
support the achievement of objectives. Examples include: development of control
12. The organization deploys control activities as manifested in policies that establish
what is expected and in relevant procedures to effect the policies. Examples include: a
3-54
Three types of transactions having a significant effect on the quality of data in the general ledger
include transactions related to:
Business processes
Accounting estimates
3-8
Adjusting, closing, and unusual journal entries
Control activities related to business transaction processing include verifications such as
Controls over adjusting, closing, and other unusual journal transactions include:
Documented support for all entries
3-55
Important considerations in security management related to user access include:
Access to any data item is limited to those with a need to know.
The ability to change, modify, or delete a data item is restricted to those with the
authorization to make such changes.
3-56
For automated application controls to work properly, an organization needs to have effective
general computer controls (sometimes referred to as technology general controls or information
technology general controls). General computer controls are pervasive control activities that
affect multiple types of information technology systems. They are relevant for mainframe
3-57
a. A walkthrough is process whereby management (or the auditor) will follow a transaction
from origination through the organization’s processes until it is reflected in the organization’s
financial records. This process includes a combination of inquiry, observation, inspection of
b. Elements of ineffective internal control include:
1. No credit checks are made of contract clients.
3. Weak control is exerted over cash transactions.
5. Forms are not prenumbered or accounted for.
7. The control over slow or delinquent payments is very poor.
9. There are no running control totals to prevent contract services from exceeding
the contract ceilings.
10. No controls are in effect to assure that all work was billed.
c. Elements of effective internal control include:
1. A cash log is maintained even though it is not used effectively.
3. Monthly analyses of cost percentages of revenue items are performed, although
they could be performed more effectively.
5. Periodic analyses are performed of unpaid bills.
7. Unusual variations between costs and revenues are investigated on a monthly
basis.
3-10
3-58
(A)
Authorized price list for all products should be kept in computer tables that must be referenced
for all orders. If the price charged a customer differs (either by a small percentage or by any
amount) from the authorized list, the order would be rejected for processing pending a review
and approval of the transaction by the marketing manager.
(B)
Total payroll on a weekly basis should be compared with the number of employees and previous
week’s payroll.
Batch control procedures should be established to prevent duplicate processing.
Edit tests could be implemented to compare the hours worked for a specific time period to
determine whether an employee had already been paid for the current period.
(C)
(D)
Access controls should limit the ability to change the files. In this particular situation, the
individual tried to change a product master file. A printout of all changes should be developed as
changes are made and sent to the individuals responsible for making the changes. The report
would provide evidence of the unauthorized change should the access control procedures fail to
operate effectively.
(E)
Edit tests could be used to determine the validity of a product number during data entry. The
computer edit program should verify part numbers and billing prices. If matches are not achieved
(F)
Use of self-checking digit would have prevented the error.
3-11
Further tests could be performed by comparing some other information furnished by the
customer such as shipping name or address with the data contained in the customer address file
for the customer identifier.
(G)
Segregation of duties is intended to prevent the individual billing or posting of accounts
receivable from receiving cash remittances. The initial segregation can develop accountability
3-12
3-59
Transaction
Authorization Required
Rationale
(A) Write-off of
accounts receivable.
Credit manager or president
of a small company.
Someone independent of cash receipts and accounts receivable
should have the authority to write-off old receivables so that
someone with cash couldn’t divert cash and cover it up through
write-offs.
In a small company, the president should have knowledge of
the credit risks assumed by the organization.
(B) Acquisition of
New Company
Board of Directors
This represents a major corporate strategic direction and use of
shareholder’s investment. The Board of Directors is designated
to see that such transactions are carried out in the best interests
of existing shareholders.
(E) Purchases from
New Customer
Purchasing Agent, with
review by supervisory
personnel or functional
management.
All orders for goods should come from the purchasing agents.
Before adding someone new to the list of authorized vendors,
the company may want to examine the vendor’s reputation for
quality and timeliness.
Transaction
Authorization Required
Rationale
(F) Temporary
investments of
funds.
Treasurer, subject to overall
policies developed by board
of directors and senior
management.
Investing funds is the treasurer’s function. However, some
organizations have specific policies that prohibit investments in
common stock. The rationale is to minimize potential risk of
temporary funds needed for short-term business purposes.
responsibility to ensure that
development is consistent with the overall operations of the
3-14
3-60
a. Deficiency
b. Potential
Misstatements
c. Possible Other Controls
(A) The payroll
person has complete
access to the system
and is responsible
could have a
fictitious employee
paid.
The payroll person could:
(1) add fictitious
individuals to the payroll
Without the addition of a personnel department
to act as a check on the payroll operations, there
are no strong mitigating controls. Some that
could be considered:
(3) Wage expense per job or functional area
could be compared to budget and any excess
expenses promptly investigated.
(4) The payroll bank reconciliation should be
periodically reconciled by someone independent
3-15
(B) The person
handling cash
receipts is in a
position to cover up
The person handling cash
can take cash receipts and
cover it up through the
bank reconciliation.
Have someone independent of the cash
processing function prepare the monthly bank
reconciliations.
(D) There is no major
problem in this situation
There are no apparent problems as
long as the system is
Shipments should be reconciled with orders.
accuracy of the cash
drawer. There is no
evidence that the
waitress slips are
prenumbered or
employee could pocket the cash.
Items could be billed at incorrect
amounts and not detected because there
is no independent review of the tickets.
Prenumbering could be added to the tickets. The
owner could account for all the prenumbered
tickets at the end of each day.
3-16
Any indication of sales to customers beyond
the pre-approved credit limit should be
investigated.
3-17
3-61
a. Potential application control procedures for the order-taking process at Sports Life World
might include:
Self-checking digits for all part numbers (optional because some of the other controls
procedures listed below might compensate for not having this control).
item. The order taker can also verify the product description and the price with the
customer. This verification process is sufficient to eliminate the need for the self-
checking digit.
Internet ordering whereby the customer clicks on the item for sale and the sale price, adds
it to the cart, and then checks out. The key controls include the master part number,
Oral verification of products ordered using part number and description. This could
effectively replace the self-checking digits and expedite the ordering process.
Edit tests that might be embedded in the software include a valid product code, pre-
established credit limits, and oral verification of products ordered.
b. Similar controls would be used for on-line ordering via the Internet. However, the access
to information such as inventory on hand, shipping date, and so forth would be done through the
computer software and would not use the intermediary on the phone. Instead of using self-
c. Potential Misstatements
Control Deficiency
Types of Potential Misstatements
Self-Checking Digit
Incorrect products might be shipped. However, as noted,
this control may be offset by other controls, e.g. oral
verification.
Well Designed Screen
Format
Information is missing or orders not processed.
No Customer Address
File
Bill to the wrong address.
Grant credit inappropriately.
No computerized prices
Customers could be billed at incorrect prices.
Inconsistent billing across agents taking the orders.
Reference to Quantities
on Hand
Increased backorders.
Billing for items not shipped.
Automatic Computation
of Order
Orders are computed incorrectly. There is also a potential
legal problem if there is a systematic mispricing of orders.
Credit Verification
Ship goods to customers who do not have credit. Likelihood
of collectability is lower.
Require approved credit
card.
Increase in uncollectible accounts.
Oral Verification
Increase the likelihood that (a) incorrect products are
shipped, or (b) they are shipped at wrong prices, or (c) there
are fictitious invoices.
Note: Most of the deficiencies will be detected by strong monitoring controls, especially a
review of all customer inquiries/complaints by a department separate from the billing
department. Such departments normally keep logs of activities.
3-62
INFORMATION AND
COMMUNICATION
parties regarding matters affecting the functioning of
internal control.
13. The organization obtains or generates and uses
relevant, quality information to support the functioning
of internal control.
14. The organization internally communicates
15. The organization communicates with external
3-19
3-63
NOTE: If the instructor is interested in providing the students with many examples of the
principles, the instructor may want to have the students read COSO’s Internal Control over
External Financial Reporting: A Compendium of Approaches and Examples that was published
in 2013.
13. The organization obtains or generates and uses relevant, quality information to
support the functioning of internal control. Examples include: a periodic survey of its
14. The organization internally communicates information, including objectives and
responsibilities for internal control, necessary to support the functioning of internal
15. The organization communicates with external parties regarding matters affecting the
3-64
MONITORING
16. The organization selects, develops, and performs
17. The organization evaluates and communicates
internal control deficiencies in a timely manner to those
3-65
NOTE: If the instructor is interested in providing the students with many examples of the
principles, the instructor may want to have the students read COSO’s Internal Control over
3-20
16. The organization selects, develops, and performs ongoing and/or separate evaluations
to ascertain whether the components of internal control are present and functioning.
Examples include: software to automate the review of all payment transactions and
17. The organization evaluates and communicates internal control deficiencies in a timely
manner to those parties responsible for taking corrective action, including senior
3-66
a. A convenience store such as 7-Eleven:
Monitoring Control: comparison of daily, weekly, and monthly sales with:
o past results for the store
b. A chain restaurant such as Olive Garden:
Monitoring Control: comparison of daily, weekly, and monthly sales with:
o past results for the store
c. Manufacturing division making rubberized containers:
Monitoring Control: comparison of daily, weekly, and monthly sales
with:
o past results
o industry trends
o gross margin