ITGCs General
Interviewing
Risk Assessment
ITGC Domains
Aura for Interns
100

These are the 4 ITGC Domains

What are:

Access to Programs and Data 

Change Management 

Program Development 

Computer Operations 

100

What are the follow up items from an interview commonly referred to and how quickly should you send them out?

What are action items and what is immediately following the interview?

100

This is the risk that audit procedures will fail to detect material misstatement.

What is audit risk?

100

Batch Jobs are monitored for failure daily.

What is Computer Operations?

100

Best Practice is to replicate this often

What is every 15 minutes?

200

These are the different layers of an IT environment.

What are Network, Operating System, Application, and Database layers?

200

Name two of the 5 ways an interview can be held.

What are:

- Face-to-Face

- WebEx

- Video Call

- Phone

- Email

200

These two risk make up the risk of material misstatement.

What is Inherent Risk and Control Risk?

200

Requests for New Access must be approved by IT and user's supervisor

What is Access to Programs and Data?

200

A full blue circle indicates this status for an EGA.

What is Prepared?
300

The controls restricting developers from accessing production code would be included in this domain 

What is Program Changes?

300

These are the 3 phases of effective interviewing.

What are:

Prepare for the Interview 

Conduct the Interview

Take Action

300

When the risk of material misstatement is higher, the audit procedures should be _________.

What is increased?

300

New system developments are designed using the Business Requirements Document.

What is Program Development?

300

This is where you go to find all of the EGAs assigned to you

What is the Dashboard view?

400

Of the following domains, this domain is considered more risky: Access to Programs and Data or Computer Operations

Why? 

What is Access to Programs and Data?

In general Access to Programs and Data will contain higher risk controls. Access to Programs and Data often relate to restricted access of financial data or appropriate segregation of duties. While back ups and job scheduling, and the help desk function are important activities they are typically farther from the financial data. 

400

During the interview "Joe" thought this actor was cute in the Avengers Movie. (Note: Remembering key interviewing details is important)

Who is Chadwick Boseman?

400

These are the audit teams that are responsible for considering risk.

What are all audit teams?

400

An IT Director reviews all changes to production code on a weekly basis 

What is Change Management?

400

This is the real time Aura version 

What is Aura Online?

500

This is the primary reason we test ITGCs

What is to ensure the continued operating effectiveness of application controls and automated accounting procedures?

500

These are examples of benefits of providing an agenda prior to the interview

What is:

- Everyone is more prepared

- To ensure you cover all relevant topics

- To refer to after the meeting

500

When comparing two entities who provide the same products or services, this will be a consideration in assessing risk.

What is Industry?

500

Daily back ups are performed for all systems 

What is Computer Operations?

500

This view in Aura is where you document test results of controls

What is Execute View?