Define the CONtrol Objective for the risk of systems not being maintained once implemented.
To assess the effectiveness of processes around maintaining the systems in order to prolong their useful life.
Name the most effective control to prevent fraud around the conflicting tasks of processing invoices and processing payments.
Segregation of Duties
Ensuring access to systems is restricted to authorized individuals only is an important aspect of management's controls as a part of Change Management processes.
Agree / Disagree with rationale.
Disagree. Restricting access to authorized individuals falls under the Logical Access umbrella.
Which of the following best defines an internal auditor’s opinion expressed following an assurance engagement?
A. A summary of the significant engagement observations.
B. The internal auditor’s professional judgment about the situation that was reviewed.
C. Conclusions that must be included in the final engagement communication.
D. Recommendations for corrective action.
B. The internal auditor’s professional judgment about the situation that was reviewed.
ACL stands for
Audit Command Language
Identify the underlying risk addressed by the CONtrol objective: To ascertain that system amendments are justified and authorized.
Unwanted and/or unauthorized system changes are initiated.
Which of the following activities represents both an appropriate personnel department function and a deterrent to payroll fraud?
A. Distribution of paychecks.
B. Authorization of overtime.
C. Authorization of additions and deletions from the payroll.
D. Collection and retention of unclaimed paychecks.
C. Authorization of additions and deletions from the payroll.
Due to limited resources, ACME Inc has the same individual responsible for developing and implementing system changes. Name the next best control activity that can compensate for lack of sufficient Segregation of Duties.
Review of the Developer's activity log / trail
OR
Supervisor review of all changes implemented
Is this an appropriate OPINION in an internal auditing final communication of the results of an engagement to evaluate the organization’s branch operations:
"Statistical sampling was used to determine the extent of unauthorized purchases from the imprest fund."
Yes / No and Why?
No. This is a description of an audit procedure and not a conclusion.
What is the difference between CAATTs and CAATs?
CAATTs include all technologies for analysis, working paper management, and productivity management.
CAATs focus on data extraction, analysis, fraud detection, and continuous auditing.
Draft a CONtrol objective to address the risk of untested system changes being implemented in the production environment.
To evaluate whether system amendments are comprehensively and independently tested prior to being correctly applied in the production environment.
The internal audit activity’s responsibility for preventing fraud is to
Evaluate the system of internal control.
The change request ticketing system is the best source for selecting samples of system changes for testing whether changes are authorized, developed, tested, implemented, and monitored.
Agree / Disagree with rationale
Disagree. Selecting system-generated list of system code changes is the best source of complete population for testing change management controls.
Is this an appropriate OPINION in an internal auditing final communication of the results of an engagement to evaluate the organization’s branch operations:
"The engagement to review branch operations was conducted in accordance with the Standards."
Yes / No and Why?
No. Stating that the engagement to review branch operations was conducted in accordance with the Standards is not a conclusion, that is, an evaluation of the effects of the observations and recommendations on the activities reviewed.
CLASSIFY function in ACL can be used to summarize payment amount by Vendor Name and Invoice Date.
Agree / Disagree with rationale.
No. CLASSIFY function can only summarize by one field at a time and cannot summarize on a date/time field.
Name the two risks addressed by the CONtrol Objective: To evaluate whether only authorized and tested amendments are applied.
(1) Unauthorized changes are implemented; and
(2) Untested changes are implemented
In an organization with a separate division that is primarily responsible for the prevention of fraud, the internal audit activity is responsible for
A. Examining and evaluating the adequacy and effectiveness of that division’s actions taken to prevent fraud.
B. Establishing and maintaining that division’s system of internal control.
C. Planning that division’s fraud prevention activities.
D. Controlling that division’s fraud prevention activities.
A. Examining and evaluating the adequacy and effectiveness of that division’s actions taken to prevent fraud.
If a system is maintained by a third-party, there is no need to test changes to those systems by the organization's internal auditor.
Agree / Disagree with rationale.
Disagree. The internal auditor should either test the change management processes between own organization and the vendor OR review a third-party Service Organization Control (SOC) report.
Is this an appropriate OPINION in an internal auditing final communication of the results of an engagement to evaluate the organization’s branch operations:
"The vice-president of branch operations should require the timely review of the daily transaction report as a means of monitoring purchases from the imprest fund."
Yes / No and Why?
No. Stating that the vice-president of branch operations should require the timely review of the daily transaction report is a recommendation.
Tracing transactions through the system to determine whether procedures are being applied as prescribed is a good example of an analytical procedure.
Agree / Disagree with rationale.
No. Tracing transactions through the system is a test of controls directed toward the operating effectiveness of internal control, not an analytical procedure.
Define a CONtrol Objective to minimize the risk of poor documentation around system changes that would limit the ability of the IT function to maintain the system.
To evaluate how adequately system changes are documented so that they can be effectively maintained.
Which of the following fraudulent entries is most likely to be made to conceal the theft of an asset?
A. Debit expenses, and credit the asset.
B. Debit the asset, and credit another asset account.
C. Debit revenue, and credit the asset.
D. Debit another asset account, and credit the asset.
A. Debit expenses, and credit the asset.
Name the three system environments maintained as a part of effective change management processes.
Development environment
Testing environment
Production environment
Is this an appropriate OPINION in an internal auditing final communication of the results of an engagement to evaluate the organization’s branch operations:
"Except for the unauthorized purchases from the imprest fund, the system of internal controls over branch operations appears to be working well."
Yes / No and Why?
Yes. Conclusions (opinions) are the internal auditor’s evaluations of the effects of the observations and recommendations on the activities reviewed. They usually put the observations and recommendations in perspective based upon their overall implications.
Which combination of the following analytical data provides the strongest indication of the possibility of the fraud?
A. Percentage increase in sales and inventory turnover.
B. Gross margin percentage and change in sales returns.
C. Inventory turnover and change in sales returns.
D. Percentage increase in sales and gross margin percentage.
B. Grow margin % and change in sales returns.
Rapid increases in gross margin percentage are expected if sales are fictitious, that is, if sales are recorded without shipments and a consequent increase in cost of sales. The large increase in returns is also symptomatic of falsified sales.