Internal Control Flashcards

(32 cards)

1
Q

What are the objectives of internal control systems?

A

To ensure orderly and efficient operations, safeguard assets, prevent and detect fraud and error, maintain accuracy of records, and ensure compliance with laws/regulations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the limitations of internal controls?

A

Human error, collusion, management override, cost–benefit constraints.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the main components of the COSO internal control framework?

A

Control environment, Risk assessment, Control activities, Information & communication, Monitoring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the control environment?

A

The overall attitude, awareness, and actions of directors and management regarding internal controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are control activities?

A

Policies and procedures such as Segregation of duties, Organisation, Authorisation, Physical controls, Supervisory controls, Personnel controls, Arithmetic and accounting controls, Management controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is monitoring of controls?

A

Processes to assess the quality and effectiveness of internal control performance over time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the auditor’s responsibility regarding internal controls?

A

To obtain an understanding of internal controls relevant to the audit and assess risks of material misstatement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

When should auditors test controls?

A

When intending to rely on controls to reduce substantive testing, or when required by regulations (e.g. SOX for listed entities).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Give examples of tests of control.

A

Inspection of documents - eg look for signatures and matching and system settings,

observation of activities,

re-performance of controls in place to test effectiveness

, enquiry of staff.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the purpose of a management letter?

A

To communicate deficiencies in internal control to management and those charged with governance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What should a management letter include?

A

Deficiency identified, its implications, and recommendations for improvement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the difference between significant and material deficiencies?

A

Significant = important enough to merit attention by governance; Material = could result in a material misstatement in the FS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Explain why an auditor needs to obtain an understanding of the components of internal control relevant to the preparation of the financial statements.

A

To identify risks of material misstatement, plan the audit effectively, determine testing strategy, and assess control reliability (ISA 315).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Explain how auditors record systems of internal control including the use of narrative notes, flowcharts and questionnaires.

A

Narrative notes: detailed written description.

Flowcharts: visual summary showing flow of documents and controls.

Questionnaires: structured questions to confirm control design and operation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Evaluate internal control components, including deficiencies and significant deficiencies in internal control.

A

Deficiency: control missing or ineffective.

Significant deficiency: serious issue needing governance attention - reasonably likely to cause misstatement, previously resulted in actual errors, involves **senior management, **deficiency is pervasive, impacts compliance/regulatory requirements

Evaluate via walkthroughs, control testing, and assessing risk impact.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Describe computer systems controls including general IT controls and information processing controls.

A

General IT controls: restricted access, , recovery, change management.

Processing controls: input validation, accuracy, completeness, and authorisation.

17
Q

Explain, in a report to management, significant deficiencies within a system of internal control and provide control recommendations.

A

Format: Intro → Findings → Implications → Recommendations.

Example: Missing authorisation → leads to fraud risk → recommend approval limits and dual signatures.

18
Q

Discuss the need for auditors to communicate with those charged with governance.

A

Required by ISA 260—to report audit findings, significant risks, and independence issues; strengthens accountability and transparency.

19
Q

Discuss the factors to be taken into account when assessing the need for internal audit.

A

Size and complexity, level of control risk, management competence, and regulatory requirements. More risk = greater need.

20
Q

Discuss the elements of best practice in the structure and operations of internal audit.

A

Independence, direct access to the audit committee, clear charter, skilled staff, risk-based planning, and regular reporting.

21
Q

Compare and contrast the role of external and internal audit.

A

External: independent opinion on financial statements.

Internal: assesses internal control, risk, and operations.
Both improve governance, but internal is part of management structure.

22
Q

Discuss the scope of internal audit and the limitations of the internal audit function.

A

Scope covers risk, control, governance, and compliance. Limitations: lack of full independence, resource constraints, and reliance on management access.

23
Q

Explain outsourcing and the associated advantages and disadvantages of outsourcing the internal audit function.

A

Advantages: expertise, independence, flexibility (can scale up or downwards), no need for additional staffing
Disadvantages: loss of internal knowledge, confidentiality risks, dependency on external providers.

24
Q

Discuss the nature and purpose of internal audit assignments including value for money, IT, financial, regulatory compliance, fraud investigations and customer experience.

A

Each assignment assesses efficiency, control, and compliance in its area—helping management improve processes and reduce risk.

25
Discuss the nature and purpose of operational internal audit assignments.
Reviews efficiency, economy, and effectiveness of operations—ensures resources are used optimally and processes achieve objectives.
26
Describe the format and content of internal audit review reports and make appropriate recommendations to management and those charged with governance.
Recommendations should be actionable, prioritised, and time-bound.
27
Advantages and Disadvantages of each Documentation of Internal Control
Questionnaires A- Quick and Easy to prepare- juniors can prepare and understand them. Easy to determine control deficincies D- Can overstate controls that are present D- Lack of detail if questionnaire isn't company specific NARRATIVE NOTES are EXACT OPPOSITE OF QUESTIONNAIRES Flowcharts A- Easy to understand visually Standardised format makes review easy Highlights control deficiencies Good for complex Systems D- Can Oversimplify Controls Requires expertise- staff can make lots of mistakes Hard to change if system changes
28
What are the Corporate Governance Principles?
Board Composition Independence Training Accountability to shareholders Transparency Separation of chair/CEO Proper committees (audit, remuneration, nomination)
29
Issue with Board appointing friends as NED
independence issues do they have appropiate experience?
30
Appropiate Template in providing Recommendations
“Management should [ACTION] by [RESPONSIBLE PERSON], to ensure [CONTROL OBJECTIVE / RISK REDUCED].”
31
Steps an Auditor Should take to confirm flowcharts from last year
Review management letter's Review Recorded Deficencies Review prior year system notes Obtain client's current documentation Perform Walkthroughs Employee interviews
32
Control System Order
Order Authorise Execute Record Review