Podcast
Questions and Answers
What does PALACE stand for?
What does PALACE stand for?
Password Authorisation Levels Access Control Enforcement
Which of the following are NOT e-Commerce controls: (Select all that apply)
Which of the following are NOT e-Commerce controls: (Select all that apply)
Which of the following are considered "Business Continuity Controls"?
Which of the following are considered "Business Continuity Controls"?
What is the primary control activity for completeness of inventory transactions?
What is the primary control activity for completeness of inventory transactions?
Signup and view all the answers
The audit team should review the system's life cycle and the overall process during the implementation of software.
The audit team should review the system's life cycle and the overall process during the implementation of software.
Signup and view all the answers
What does "SCRUM" stand for?
What does "SCRUM" stand for?
Signup and view all the answers
What is the main concern of the auditor when examining the occurrence of inventory transactions?
What is the main concern of the auditor when examining the occurrence of inventory transactions?
Signup and view all the answers
What are the two primary concerns auditors have when examining the completeness of inventory transactions?
What are the two primary concerns auditors have when examining the completeness of inventory transactions?
Signup and view all the answers
What is the purpose of the control "No movement of stock without authorisation and a document"?
What is the purpose of the control "No movement of stock without authorisation and a document"?
Signup and view all the answers
Which of the following is NOT a risk related to the purchase cycle?
Which of the following is NOT a risk related to the purchase cycle?
Signup and view all the answers
What is the purpose of performing a "re-performance" test during an audit?
What is the purpose of performing a "re-performance" test during an audit?
Signup and view all the answers
What is the primary concern of the auditor during the "matching" test?
What is the primary concern of the auditor during the "matching" test?
Signup and view all the answers
Which of the following is NOT a risk related to the revenue cycle?
Which of the following is NOT a risk related to the revenue cycle?
Signup and view all the answers
The validity of revenue transactions is tested by making sure all customers are properly identified and authenticated before sales are made.
The validity of revenue transactions is tested by making sure all customers are properly identified and authenticated before sales are made.
Signup and view all the answers
How is the "completeness" of revenue transactions tested?
How is the "completeness" of revenue transactions tested?
Signup and view all the answers
The effectiveness of IT systems can be directly assessed by auditors through the use of CAATs.
The effectiveness of IT systems can be directly assessed by auditors through the use of CAATs.
Signup and view all the answers
List three primary areas of concern for auditors examining the "accuracy" of the revenue cycle?
List three primary areas of concern for auditors examining the "accuracy" of the revenue cycle?
Signup and view all the answers
What is the primary purpose of "cut-off" testing on the revenue cycle?
What is the primary purpose of "cut-off" testing on the revenue cycle?
Signup and view all the answers
What is the purpose of "classification" testing on the revenue cycle?
What is the purpose of "classification" testing on the revenue cycle?
Signup and view all the answers
What is the purpose of "completeness" testing of the revenue cycle?
What is the purpose of "completeness" testing of the revenue cycle?
Signup and view all the answers
What is the purpose of the "Existence and Rights/Obligations" assertion for accounts receivable?
What is the purpose of the "Existence and Rights/Obligations" assertion for accounts receivable?
Signup and view all the answers
What is the purpose of "Valuation" testing on accounts receivable?
What is the purpose of "Valuation" testing on accounts receivable?
Signup and view all the answers
How should an auditor test the "existence" and "rights/obligations" assertions of accounts receivable?
How should an auditor test the "existence" and "rights/obligations" assertions of accounts receivable?
Signup and view all the answers
What is the purpose of performing "re-performance" testing on the purchases cycle?
What is the purpose of performing "re-performance" testing on the purchases cycle?
Signup and view all the answers
What is the primary purpose of "matching" testing in the purchases cycle?
What is the primary purpose of "matching" testing in the purchases cycle?
Signup and view all the answers
List three key areas where an auditor would focus to test the occurrence assertion of purchases?
List three key areas where an auditor would focus to test the occurrence assertion of purchases?
Signup and view all the answers
What is the main purpose of "cut-off" testing for purchases?
What is the main purpose of "cut-off" testing for purchases?
Signup and view all the answers
What is the primary focus of the "completeness" assertion for purchases?
What is the primary focus of the "completeness" assertion for purchases?
Signup and view all the answers
What is the main purpose of "accuracy" testing in the purchases cycle?
What is the main purpose of "accuracy" testing in the purchases cycle?
Signup and view all the answers
What is the purpose of "cut-off" testing for payments?
What is the purpose of "cut-off" testing for payments?
Signup and view all the answers
What is the purpose of "completeness" testing in the payments cycle?
What is the purpose of "completeness" testing in the payments cycle?
Signup and view all the answers
What is the purpose of "accuracy" testing for payments?
What is the purpose of "accuracy" testing for payments?
Signup and view all the answers
What is the main concern when auditors examine the "classification" of purchases?
What is the main concern when auditors examine the "classification" of purchases?
Signup and view all the answers
What is the primary responsibility of an auditor during an inventory count?
What is the primary responsibility of an auditor during an inventory count?
Signup and view all the answers
Besides physically inspecting the inventory, what are three other key activities an auditor should perform during an inventory count?
Besides physically inspecting the inventory, what are three other key activities an auditor should perform during an inventory count?
Signup and view all the answers
What is the main purpose of "rights and obligations" testing for inventory?
What is the main purpose of "rights and obligations" testing for inventory?
Signup and view all the answers
What is the purpose of "completeness" testing for inventory?
What is the purpose of "completeness" testing for inventory?
Signup and view all the answers
What is the purpose of "valuation" testing in the inventory cycle?
What is the purpose of "valuation" testing in the inventory cycle?
Signup and view all the answers
How does an auditor test the accuracy of an inventory valuation?
How does an auditor test the accuracy of an inventory valuation?
Signup and view all the answers
How does an auditor test the "classification" assertion of inventory?
How does an auditor test the "classification" assertion of inventory?
Signup and view all the answers
What is a key control to be in place to prevent unauthorized movement of inventory?
What is a key control to be in place to prevent unauthorized movement of inventory?
Signup and view all the answers
Why are strong internal controls crucial for ensuring the accuracy of inventory records?
Why are strong internal controls crucial for ensuring the accuracy of inventory records?
Signup and view all the answers
What is the primary concern when auditors examine the "completeness" of inventory transactions?
What is the primary concern when auditors examine the "completeness" of inventory transactions?
Signup and view all the answers
Besides physical inspection of inventory, what are three key aspects of testing the accuracy of inventory transactions?
Besides physical inspection of inventory, what are three key aspects of testing the accuracy of inventory transactions?
Signup and view all the answers
Study Notes
Week 5 - IT Controls
- System maintenance controls prevent unauthorized changes to programs, data, terminals and files. Standards for program changes, requests, forms, testing, and documentation are used.
- Organizational and management controls establish a framework for computer activities, including responsibility levels, staff practices, division of duties, virus controls, and supervision. IT departments should be separate, and transactions shouldn't be authorized by IT staff. Training on systems and databases is essential.
- Access controls restrict physical access to IT infrastructure (servers, data centers, network equipment) to authorized personnel based on roles (segregation of duties). VPNs secure remote user access, and logon IDs are used for authorization, logging unauthorized attempts.
- Computer operating controls schedule processing using correct programs and data files, ensuring procedures are applied consistently. Hardware checks and duty divisions are included.
- System development controls use software from reputable companies, process data, require training, and ensure new system conversions are correctly performed with post-implementation reviews and backups.
Access Controls
- Only authorized personnel can access physical IT infrastructure.
- Access is granted based on the role/segregation of duties.
- VPNs ensure secure remote user access.
- Authorization of users through logon IDs.
- A log of unauthorized attempts is maintained.
Computer Operating Controls
- Controls include scheduling processing and using the correct programs and data files.
- Procedures are applied correctly and consistently.
- Hardware checks and division of duties are part of the operating procedures.
System Development Controls
- Software must come from reputable companies.
- Conversion controls ensure data transfer with balancing of old and new files, backup of the new system, and implementation review. Required training is provided.
Business Continuity Controls
- List of files and data to be recovered.
Week 7 - Revenue and Receipts Cycle
- Revenue Process Risks: Early revenue recognition, holding books open past the accounting period, including false sales, problems with related party transactions, overstating receivables, and other income.
- Key Controls: Adequate segregation of duties, proper authorization of sales, adequate records of receiving, authorising, processing, dispatching, invoicing, and recording. Documents are sequentially prenumbered and monthly statements and reconciliations are performed.
- Inherent Risks: Nature of business and other industry-related factors.
Week 8 - Purchases Cycle
- Inspect (Documents), Observe (Actions), Inquire (Missing Documents), Re-Perform (Numbers and Calculations), Test, Matching (Documents): Purchase requisitions, purchase orders, receiving of goods (GRNs), recording of purchases, payment preparation, recording of payments.
- Test of Controls: All documents are sequentially prenumbered and inspections/signatures confirm procedures.
- Inherent Risks: Management bias and incentive to misstate expenses, complexity of expenditures, inadequate controls, incorrect cut-offs, and understating accounts payable.
Week 9 - Inventory Cycle
- Planning (Order), Receipt, Issue, Inventory Adjustment Forms, Inventory Records: Key processes and documents related to inventory management.
- Inherent Risks: Volume and complexity of manufacturing, changes in staff and systems, net realisable value (NRV).
Inventory Controls (Week 9/10)
- Inventory is located at multiple sites with 'Goods in Transit'.
- Staff are trained to do the inventory tasks accurately and correctly with controls to prevent obsolete or damaged goods.
- Controls to ensure no double-counting and omission of inventory, and procedures exist to account for inclusion of the same inventory more than once, to prevent damage, loss, or theft of stock. Segregation of duties and reconciliation procedures are essential.
- Controls for the efficient production planning and scheduling of the inventory tasks.
ISA 501 (Week 9/10)
- Before Inventory Count: Contact with the client and previous auditor, review of procedures, verification of locations where inventory is stored. Third party arrangements must be made.
- During Inventory Count: Inquire on segregation of duties, team numbers, no movement, and no production is scheduled. Inspecting count sheets verifies completeness, sequences, and descriptions of goods. Verify inventory is allocated to counting teams, ensuring it's all included, avoiding duplication in the count and identifying those that shouldn't be valued (e.g., damaged, obsolete stock).
- Testing of Controls: Cut-off, inspection of documents (e.g., GRNs, GDNs, purchase invoices), verifying sequential pre-numbering and supplier invoices/payroll. Inventory is also checked for correct classification, condition (obsolete, slow-moving, excess), and net realisable value (NRV).
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Related Documents
Description
This quiz covers essential IT controls for maintaining system integrity and security. Topics include system maintenance, organizational controls, access restrictions, and operational procedures. Understanding these controls is crucial for effective IT management and risk mitigation.