Chapter 7 Solutions Auditing Information Technology-Based Processes
Turner/Accounting Information Systems, 2e
Solutions Manual
Chapter 7
Concept Check
1. b
2. b
3. d
4. c
9. d
10. a
11. a
12. c
13. c
14. d
15. c
Discussion Questions
22. (SO 1) What are assurance services? What value do assurance services provide?
23. (SO 2) Differentiate between a compliance audit and an operational audit. A
compliance audit is a form of assurance service that involves accumulating and
Chapter 7 Solutions Auditing Information Technology-Based Processes
24. (SO 2) Which type of audit is most likely to be performed by government auditors?
Which type of audit is most likely to be performed by internal auditors?
Governmental auditors are most likely to perform compliance audits, and internal
auditors are most likely to perform operational audits.
25. (SO 2) Identify the three areas of an auditor’s work that are significantly impacted by
the presence of IT accounting systems. The IT environment plays a key role in how
26. (SO 3) Describe the three causes of information risk. Information risk is caused by:
Remote information; for instance, when the source of information is removed
27. (SO 3) Explain how an audit trail might get “lost” within a computerized system.
Loss of an audit trail occurs when there is a lack of physical evidence to view in
28. (SO 3) Explain how the presence of IT processes can improve the quality of
information that management uses for decision making. IT processes tend to
provide information in a timely and efficient manner. This enhances management’s
ability to make effective decisions, which is the essence of quality of information.
29. (SO 4) Distinguish among the focuses of the GAAS standards of fieldwork and
standards of reporting. The standards of fieldwork provide general guidelines for
30. (SO 4) Which professional standard-setting organization provides guidance on the
conduct of an IT audit? The Information Systems Audit and Control Association
(ISACA) is responsible for issuing Information Systems Auditing Standards (ISASs),
which provide guidelines for conducting an IT audit.
31. (SO 5) If management is responsible for its own financial statements, why are
auditors important? Auditors are important because they are responsible for
Chapter 7 Solutions Auditing Information Technology-Based Processes
32. (SO 6) List the techniques used for gathering evidence. The techniques used for
gathering evidence include the following:
physically examining or inspecting assets or supporting documentation
33. (SO 6) During which phase of an audit would an auditor consider risk assessment
and materiality? Risk assessment and materiality are considered during the
planning phase of an audit.
34. (SO 7) Distinguish between auditing through the computer and auditing with the
computer. When are auditors required to audit through the computer as opposed to
auditing around the computer? Auditing through the computer involves directly
35. (SO 8) Explain why it is customary to complete the testing of general controls before
testing application controls. Since general controls are the automated controls that
36. (SO 8) Identify four important aspects of administrative control in an IT environment.
Four important aspects of administrative control include:
37. (SO 8) Explain why Benford’s Law is useful to auditors in the detection of fraud.
Benford’s Law recognizes nonuniform patterns in the frequency of numbers
38. (SO 8) Think about a place you have worked where computers were present. What
are some physical and environmental controls that you have observed in the
workplace? Provide at least two examples of each from your personal experience.
Student’s responses are likely to vary greatly. Examples of physical controls may
Chapter 7 Solutions Auditing Information Technology-Based Processes
include card keys and configuration tables, as well as other physical security
features such as locked doors, etc. Environmental controls may include temperature
and humidity controls, fire, flood, earthquake controls, or measures to ensure a
consistent power supply.
39. (SO 8) Batch totals and hash totals are common input controls. Considering the fact
that hash totals can be used with batch processing, differentiate between these two
40. (SO 8) The test data method and an integrated test facility are similar in that they are
both tests of applications controls and they both rely on the use of test data. Explain
the difference between these two audit techniques. The test data method tests the
41. (SO 9) Explain the necessity for performing substantive testing even for audit clients
with strong internal controls and sophisticated IT systems. Since substantive testing
42. (SO 9) What kinds of audit tools are used to perform routine tests on electronic data
files taken from databases? List the types of tests that can be performed with these
tools. CPA firms use generalized audit software (GAS) or data analysis software
(DAS) to perform audit tests on electronic data files taken from commonly used
database systems. These tools help auditors perform routine testing in an efficient
manner. The types of tests that can be performed using GAS or DAS include:
mathematical and statistical calculations
43. (SO 10) Which of the four types of audit reports is the most favorable for an audit
client? Which is the least favorable? An unqualified audit report is the most
favorable because it expresses reasonable assurance that the underlying financial
statements are fairly stated in all material respects. On the other hand, an adverse
Chapter 7 Solutions Auditing Information Technology-Based Processes
misstatements in the underlying financial statements.
44. (SO 10) Why is it so important to obtain a letter of representations from an audit
client? The letter of representations is so important because it is management’s
45. (SO 11) How can auditors evaluate internal controls when their clients use IT
outsourcing? When a company uses IT outsourcing, auditors must still evaluate
46. (SO 12) An auditor’s characteristic of professional skepticism is most closely
associated with which ethical principle of the AICPA Code of Professional Conduct?
Professional skepticism is most closely associated with the principle of Objectivity
Brief Exercises
47. (SO 2) Why is it necessary for a CPA to be prohibited from having financial or
personal connections with a client? Provide an example of how a financial
connection to a company would impair an auditor’s objectivity. Provide an example
of how a personal relationship might impair an auditor’s objectivity. An auditor
should not have any financial or personal connections with a client company
48. (SO 3) From an internal control perspective, discuss the advantages and
disadvantages of using IT-based accounting systems. The advantages of using IT-
based accounting systems are the improvements in internal control due to the
Chapter 7 Solutions Auditing Information Technology-Based Processes
49. (SO 4) Explain why standards of fieldwork for GAAS are not particularly helpful to an
auditor who is trying to determine the types of testing to be used on an audit
50. (SO 5) Ping and Pong are assigned to perform the audit of Paddle Company. During
the audit, it was discovered that the amount of sales reported on Paddle’s income
statement was understated because one week’s sales transactions were not
recorded due to a computer glitch. Ping claims that this problem represents a
violation of the management assertion regarding existence, because the reported
account balance was not real. Pong argues that the completeness assertion was
violated, because relevant data was omitted from the records. Which auditor is
correct? Explain your answer. The completeness assertion is concerned with
51. (SO 6) One of the most important tasks of the planning phase is for the auditor to
gain an understanding of internal controls. How does this differ from the tasks
performed during the tests of controls phase? During the planning phase of an audit,
52. (SO 8) How is it possible that a review of computer logs can be used to test for both
internal access controls and external access controls? Other than reviewing the
computer logs, identify and describe two types of audit procedures performed to test
internal access controls, and two types of audit procedures performed to test
external access controls. Internal access controls can be evaluated by reviewing
Chapter 7 Solutions Auditing Information Technology-Based Processes
53. (SO 9) Explain why continuous auditing is growing in popularity. Identify and
describe a computer-assisted audit technique useful for continuous auditing.
Continuous auditing has increased in popularity due to the increase in e-commerce.
54. (SO 11) Distinguish between the various service organization controls (SOC)
reporting options available to auditors who evaluate cloud computing service
providers. The SOC 1 report addresses internal controls over financial reporting. A
SOC 1Type I report contains management’s assessment and the auditor’s opinion
Problems
55. (SO 4) Given is a list of standard-setting bodies and a description of their purpose.
Match each standard-setting body with its purpose.
I. c.
56. (SO 8) Identify whether audit tests are used to evaluate internal access controls (I),
external access controls (E), or both (B).
Authenticity tests (B)
Penetration tests (E)
Chapter 7 Solutions Auditing Information Technology-Based Processes
57. (SO 9) Refer to the notes payable audit program excerpt presented in Exhibit 7-3. If
an auditor had a copy of his client’s data file for its notes receivable, how could a
general audit software or data analysis software package be used to assist with
these audit tests? GAS and DAS could assist auditors in testing notes payable by
58. (SO 11) In order to preserve auditor independence, the Sarbanes-Oxley Act of 2002
restricts the types of nonaudit services that auditors can perform for their public-
company audit clients. The list includes nine types of services that are prohibited
because they are deemed to impair an auditor’s independence. Included in the list
are the following:
financial information systems design and implementation
internal audit outsourcing
Describe how an auditor’s independence could be impaired if she performed IT
design and implementation functions for her audit client. Likewise, how could an
auditor’s involvement with internal audit outsourcing impair her independence with
respect to auditing the same company? Both of these scenarios would place the
governmental accounting, not-for-profit accounting, education, and
entrepreneurship. Some specialty areas include forensic accounting, environmental
accounting, and showbiz accounting.
click on the IT Audit Basics tab to find articles covering topics concerning the audit
process. Locate an article on each of the following topics and answer the related
question:
Chapter 7 Solutions Auditing Information Technology-Based Processes
a. Identify and briefly describe the four categories of CAATs used to support
IT auditing. The four categories include
1
:
data analysis software, including GAS and DAS
Network security evaluation software/utilities
61. (SO 8) Locate the stock tables for the two major stock exchanges in any issue of
the Wall Street Journal. Beginning from any point within the table, prepare a list of
the first digits of the daily volume for 100 stocks. Determine whether the listed
data conform to Benford’s Law.
62. (SO 12) Perform an Internet search to determine the nature of Xerox Corporation’s
management fraud scheme and to find out what happened to the company after the
problems were discovered. Xerox’s fraud involved earnings management or
manipulation of the financial statements in order to boost earnings. This occurred at
Xerox to the tune of hundreds of millions of dollars and involved various accounting
Cases
63. Internal Controls and CAATs for a Wholesale client.
a. What tests of controls would be effective in helping Draker determine whether
Palitt’s vendor database was susceptible to fraud? The following tests of
controls could be used:
Verify that the database is physically secure and that programs and
data files are password protected to prevent unauthorized access.
Chapter 7 Solutions Auditing Information Technology-Based Processes
Since this situation involves an internal breach of authority, access
logs should be reviewed for activity at unusual times (non-business
hours).
Make sure that system programmers do not have access to database
operations so that there is no opportunity to alter source code and the
related operational data.
b. What computer-assisted audit technique would be effective in helping Draker
determine whether Palitts vendor database had actually been falsified?
Draker could use GAS or DAS to perform audit testing on electronic data files
taken from Lea’s database system. Several types of audit tests commonly
performed by GAS or DAS systems could be used in this case, including data
queries, stratification and comparison of data items, and selection of items of
interest. In addition, the following tests can be performed to test the propriety
of inputs to the system:
Financial control totals can be used to determine whether total dollar
amounts or item counts are consistent with journal entry amounts.
This can detect whether additions have been made during processing.
64. Issues with the client representation letter.
a. Would it be appropriate for Pannor to reopen the audit testing phases in
order to expand procedures, in light of the lack of representative evidence
from management? Why or why not? No, Pannor should not expand
testing procedures. The purpose of the client’s representations letter is for
Chapter 7 Solutions Auditing Information Technology-Based Processes
b. Will Pannor’s firm still be able to issue an unqualified audit report if it does
not receive the representations letter? Research the standard wording to
be included in an unqualified audit report, as well as the typical wording
included in a client representations letter. Base your answer on your