Vocabulary
COSO Framework
Control Deficiencies
Planning the Audit
Other
100

What is, "the method by which an entity's board of directors, management, and other personnel provide reasonable assurance about the achievement of objectives in the following categories:  (1) reliability of financial reporting, (2) effectiveness and efficiency of operations, and (3) compliance with applicable laws and regulations."

Internal Control

100

How many components of the COSO Framework are there?

5

100

What is a Control Deficiency?

A deficiency in internal control exists when the design or operation of a control does not allow management or employees, in the normal course of performing their assigned functions, to prevent, or detect and correct, misstatements on a timely basis.

100

Who has the responsibility to design and maintain a system of internal control that provides reasonable assurance that assets and records are properly safeguarded, and that the entity’s information system generates information that is reliable for decision making.

Management

100

Which Auditing Standard requires public company auditors to test and report on the design and effectiveness  ofmost public companies' internal control over financial reporting?

Auditing Standard 5 (AS5)

200

What does ICFR stand for?

Internal Control over Financial Reporting

200

How many principles underly the components of the COSO Framework of Internal Control?

17

200

Which two dimensions of the control deficiency must the auditor consider?

Likelihood and Magnitude

200

Which of the following should be considered when planning an audit of ICFR?

a. The role of assessment and the risk of fraud.
b. Scaling the audit
c. Using the work of others
d. All of the above

D. All of the above

200

Name a tool available to the auditor for documenting the understanding of internal control.


The entity's procedures manuals and organizational charts. 

Internal control questionnaire

Flowcharts

Narrative description

300

What is the process of correcting a material weakness as part of management's assessment of the effectiveness of ICFR?

Remediation

300

Which of the following best describes what Monitoring of Controls is intended to assess?

a. When controsl fail
b. Every fradulent action committed in an entity.
c. The quality of internal control performance over time.
d. The level of risk that is acceptable for the auditor.

c. The quality of internal control performance over time.

300

The auditor's disclosure about the material weakness(es) should include what information?

The nature of the material weakness(es) and it's impact on the entity's financial reporting and its ICFR.

300

Which of the following is a step in the evaluation process by management of ICFR? 

a. Measure internal weaknesses.
b. Evaluate evidence about the operating effectiveness of ICFR.
c. Evaluate the flexibility of the internal controls.
d. None of the above.

b. Evaluate evidence about the operating effectiveness of ICFR.

300

Which section of SOX requires management of a publicaly traded company to issue a report that accepts responsbility for establishing and maintaining adequate ICFR?

Section 404

400

What kind of procedure is being done when a transition is traced by an auditor from origination through the entity's information system until it is reflected in the entity's financial reporting?

A Walkthrough.

400

Which of the component of the COSO Framework of Internal Control sets teh tone of the organization? (This component is also considered the foundation for implementing the entity's system of internal control.)

Control Environment

400

Which of the following is a deficiency, or a combination of deficiencies, in internal control that is less severe than a material weakness yet important enough to merit attention by those charged with governance?

a. Design Deficiency
b. Material Weakness
c. Significance Deficiency
d. Performance Deficiency

c. Significance Deficiency

400

What elements of the auditor's report are required?

*Identifies management's conclusion on the effectiveness of the entity's ICFR.

*States that the assessment on which management's conclusion is based is the responsibility of management.

*Defines ICFR

*Indicates that PCAOB requires the auditor plan and perform the auditor to obtain reasonable assurance about whether effective ICFR was maintained in all material respects. 

*Explains in general terms what an audit of ICFR entails

*Explicitly addresses the fact that even effective Internal Controls cannot guarantee that misstatements will be prevented or detected and corrected. 

*Report concludes with the auditor's opinion on whether the company maintained, in all material respects, effective ICFR as of the period end.

400

Which strategy is when the auditor decides to rely on the entity's controls, test those controls, and reduce the direct tests of the financial statement accounts?

Reliance Strategy

500

The risk that a misstatement that could occur in an assertion about an account or disclosure and that could be material, either individually or when aggregated with other misstatements, will not be prevented, or detected and corrected, on a timely basis by the entity’s internal control.

Control Risk

500
Name three of the COSO Framework components.

Control Environment
Entity's Risk Assessment
Control Activities
Information and Communication
Monitoring Activities

500

Which of the following is a deficiency, or combination of deficiencies, in internal control, such that there is a reasonable possibility that a material misstatement of the entity’s financial statements will not be prevented, or detected and corrected, on a timely basis?

a. Design Deficiency
b. Material Weakness
c. Significance Deficiency
d. Performance Deficiency

b. Material Weakness

500

What are the five steps an auditor must perform in an Audit of ICFR?

1. Plan (plan the audit of ICFR)
2. Identify (Identify controls to test)
3. Scope (Evaluate the design and test the operating effectiveness of selected controls)
4. Evaluate (Evaluate identified control deficiencies)
5. Report (Form an opinion on the effectiveness of ICFR)

500

Which strategy is when the auditor’s decides not to rely on the entity’s controls and to audit the related financial statement accounts by relying more on substantive procedures.

Substantive Strategy