Why are internal controls relevant to an audit?
They are relevant throughout all audit stages, especially planning and execution, to ensure financial reporting reliability, operational efficiency, and compliance.
Must auditors understand internal controls if relying solely on substantive procedures?
Yes, auditors must understand controls even if using only a substantive approach.
Who is responsible for designing and maintaining internal controls?
Management, with oversight from governance.
What are the five components?
Control environment, risk assessment process, information system & communication, control activities, monitoring process.
What is the purpose of the control environment?
Sets the tone at the top; includes values, ethics, integrity, and accountability.
What is the risk assessment process?
Identifies and manages risks that could affect financial reporting.
What are control activities?
Policies and procedures to prevent or detect errors/fraud.
What is the monitoring process?
Ongoing or periodic evaluations of internal controls to ensure effectiveness.
What does information system and communication involve?
How financial data is recorded, processed, communicated, and corrected.
What is COSO?
Most widely used internal control framework (1992); includes control environment, risk assessment, control activities, info & communication, monitoring.
What is CoCo?
Developed by CPA Canada’s predecessor (1995) to improve governance and decision-making.
What is COBIT?
Developed by ISACA (1996) for IT governance; focuses on IT controls and alignment with business objectives.
What are the key objectives of internal controls?
Effectiveness and efficiency of operations, reliability of financial reporting, compliance with laws and regulations.
What is the difference between direct and indirect controls?
Direct controls address risks at the assertion level; indirect controls support other controls and usually operate at the entity level.
Which components are usually considered indirect controls?
Control environment, risk assessment process, monitoring controls.
Why are indirect controls important?
They help reduce overall audit risk but are not precise enough alone to detect misstatements.
Which components are generally considered direct controls?
Information system & communication, control activities.
What does the control environment reflect?
Tone at the top, culture, integrity, ethics, governance, assignment of authority, and accountability.
Why is it critical?
Weaknesses here can undermine other internal control components.
Types of direct controls in IT?
Manual controls, automated controls, IT-dependent manual controls.
Categories of ITGCs?
Access to programs/data, program changes/development, computer operations, business continuity.
How do control objectives relate to assertions?
Ensure completeness, existence, cutoff, accuracy, classification of transactions.
How do auditors gain understanding of internal controls?
Through inquiries, manuals, prior-year files, internal audit reports, walkthroughs.
How should understanding be documented?
Using flowcharts, narratives, checklists, or a combination, showing key controls and processes.