All questions
Question 1
In an audit of a nonissuer retailer, data analytics over user access logs and journal entries show that one accounting supervisor posted 63 manual journal entries to revenue accounts during the last week of the year, and the same user also has the ability to create and approve new customer accounts in the system. The entity's documented controls state these duties should be segregated. What is the most appropriate audit response to the identified anomaly?
- Treat the analytics as conclusive evidence of fraud and withdraw from the engagement without performing additional procedures.
- Evaluate whether the segregation-of-duties control is operating effectively, assess the implications for risk of material misstatement due to fraud, and perform targeted substantive procedures on the related journal entries and revenue transactions. (correct answer)
- Rely on management's explanation that the supervisor was helping during year-end close and perform no additional testing because the entries were approved in the system.
- Communicate the issue only to the accounts payable manager because the anomaly involves user access rather than financial reporting.
Explanation: AU-C 240 requires auditors to respond to segregation of duties violations identified through analytics, particularly when they involve revenue manipulation capabilities. The analytics reveal a critical control breakdown: one supervisor posted 63 manual revenue entries during year-end while also possessing customer creation/approval abilities, directly violating documented segregation requirements. The appropriate response involves evaluating control effectiveness, assessing fraud risk implications, and performing targeted substantive procedures on the specific journal entries and related revenue transactions. Option A inappropriately assumes fraud without investigation, Option C ignores clear control violations based on inadequate management explanations, and Option D incorrectly limits communication to operational personnel rather than those charged with governance. When data analytics identify individuals with incompatible system access who execute unusual transaction patterns during financial reporting periods, professional standards require comprehensive investigation of both control implications and transaction validity.
Question 2
In an audit of an issuer, the auditor performs trend analysis on revenue by week and product line and notes a consistent pattern of revenue spikes in the final two days of each quarter, concentrated in one product line, with an increase in credit memos in the first week of the subsequent quarter. Management explains this is due to "end-of-quarter customer incentives" but provides no updated contract terms. How should the auditor adjust the audit plan given the analytics findings?
- Increase focus on cutoff and variable consideration for the affected product line by testing shipping terms, contract modifications, subsequent credit memos, and evaluating whether revenue recognition is appropriate under the issuer's policies. (correct answer)
- Rely on the trend analysis as sufficient substantive evidence of proper revenue recognition because it uses complete data and shows a repeatable pattern.
- Reduce substantive revenue testing because the trend pattern indicates stable operations and predictable quarter-end sales activity.
- Address the matter only through management representation letters because incentives are a business decision and not an audit concern.
Explanation: AS 2301 requires auditors to evaluate revenue recognition risks when analytics identify unusual patterns, particularly when combined with management incentives and subsequent adjustments. The trend analysis reveals quarter-end revenue spikes concentrated in one product line followed by credit memos—a pattern suggesting potential channel stuffing or premature revenue recognition to meet quarterly targets. The appropriate response is to increase focus on cutoff testing and variable consideration, examining shipping terms, contract modifications, and subsequent credit memos to determine whether revenue was recognized appropriately. Option B incorrectly treats analytics as sufficient substantive evidence without corroboration, Option C inappropriately reduces testing despite fraud risk indicators, and Option D fails to recognize that revenue recognition is a critical audit matter requiring substantive procedures. When analytics identify revenue patterns coinciding with reporting periods and management cannot provide updated contract terms supporting the transactions, auditors must design targeted procedures addressing the specific risks identified.
Question 3
In an audit of a nonissuer service company, the auditor's anomaly detection over payroll identifies 22 employees with direct deposit accounts that match a vendor bank account used for facilities maintenance payments, and 7 of those employees have no timekeeping records for the last two pay periods. Management says it is a "bank routing coincidence" and asks the auditor not to pursue it due to privacy concerns. Which action should the auditor take based on the data analytics results?
- Accept management's request and document the limitation as an immaterial scope restriction because payroll privacy overrides audit needs.
- Perform additional procedures to resolve the anomaly (e.g., validate employee existence, review payroll master file changes, inspect authorization and timekeeping support, and consider fraud implications), and if access is restricted, evaluate whether it constitutes a scope limitation affecting the audit opinion. (correct answer)
- Conclude the anomaly is invalid because data analytics can produce false positives, and proceed with standard payroll sampling only.
- Report the issue directly to the Public Company Accounting Oversight Board because payroll anomalies require regulator notification.
Explanation: AU-C 240 requires auditors to investigate anomalies suggesting potential payroll fraud, and management's restriction of access may constitute a scope limitation affecting the audit opinion. The analytics identify highly suspicious patterns: 22 employees sharing bank accounts with a vendor and 7 lacking timekeeping records—classic ghost employee indicators requiring immediate investigation through employee existence validation, payroll master file change reviews, and authorization testing. Management's privacy excuse for restricting access raises additional red flags requiring evaluation of whether this constitutes a scope limitation. Option A inappropriately accepts access restrictions, Option C dismisses valid anomalies without investigation, and Option D incorrectly requires immediate external reporting. When payroll analytics identify patterns consistent with fictitious employees and management attempts to restrict investigation access, auditors must pursue resolution through additional procedures and evaluate opinion implications if access remains restricted.
Question 4
In an audit of a nonissuer distributor, the auditor's outlier identification flags 31 customer returns processed in the first two weeks after year-end that reference sales invoices dated in the last two days of the year, with return reasons coded as "shipping error" and with unusually high unit prices compared to the customer's prior purchases. Management states the returns are "normal" and proposes no adjustment. Based on the data analysis, which conclusion is most appropriate?
- The outliers suggest increased risk related to revenue cutoff and returns/reserves, and the auditor should perform additional procedures such as testing subsequent returns, inspecting shipping documentation, and evaluating the adequacy of return reserves. (correct answer)
- The auditor should ignore the returns because they occurred after year-end and therefore cannot affect the current-year financial statements.
- The auditor should treat the outliers as a deficiency in the revenue policy only and avoid substantive testing because it would duplicate analytics.
- The auditor should communicate the matter only to the sales manager because returns are operational and not relevant to financial reporting.
Explanation: AU-C 560 requires auditors to evaluate subsequent events that provide evidence about conditions existing at year-end, particularly when analytics identify unusual return patterns. The outlier analysis reveals 31 returns in early January for sales recorded in the final two days, coded as "shipping errors" with unusually high prices—classic indicators of channel stuffing or fictitious sales requiring investigation of revenue cutoff and return reserves. The appropriate response involves testing subsequent returns, inspecting shipping documentation for the flagged sales, and evaluating return reserve adequacy. Option B incorrectly ignores subsequent events providing audit evidence, Option C limits response to policy evaluation without substantive testing, and Option D inappropriately restricts communication to operational management. When analytics identify concentrated subsequent returns of year-end sales with unusual characteristics, auditors must perform procedures to determine whether revenue was appropriately recognized and whether adequate reserves exist for expected returns.
Question 5
You are auditing an issuer and management uses predictive analytics to estimate the allowance for credit losses. Your independent expectation model (based on aging, write-off history, and macroeconomic factors) predicts an allowance of $18.5 million, while management recorded $12.0 million; the variance is concentrated in a newly expanded customer segment and affects the allowance, bad debt expense, and disclosures. Which factor would most likely influence the auditor's interpretation of the data analytics?
- Whether the auditor's model and management's model use consistent definitions of default and segmentation, and whether the underlying data inputs are complete and accurate. (correct answer)
- Whether the variance is less than performance materiality, because any amount below performance materiality is automatically acceptable without further evaluation.
- Whether the auditor can rely on the predictive model as a substitute for testing subsequent cash receipts and write-offs.
- Whether PCAOB standards prohibit any use of auditor-developed expectations for estimates on issuer audits.
Explanation: This question tests the auditor's evaluation of accounting estimates under AS 2501 for issuers, focusing on factors influencing analytics interpretation. The key facts include the variance between auditor and management models, concentration in a new segment, and impacts on allowance and expenses. Choice A is correct as AS 2501 requires assessing model consistency, data quality, and inputs to interpret variances reliably. Choice B is incorrect because variances below performance materiality still require evaluation per AS 2501 if indicative of bias; choice C is wrong as models supplement, not substitute, substantive testing under AS 2305; choice D is incorrect as PCAOB standards allow auditor-developed expectations per AS 2501. A transferable framework is to compare independent expectations with recorded estimates and investigate differences by validating assumptions and data. Professional judgment involves considering qualitative factors like segmentation changes when interpreting analytics outputs.
Question 6
During an audit of an issuer, internal control assessment analytics identify that 18% of purchase orders were approved after the goods receipt date, and 6% of invoices were paid without a three-way match exception being documented as resolved; these rates increased significantly in the last quarter. Management states the enterprise resource planning (ERP) system "sometimes timestamps incorrectly" but provides no system change logs. Which action should the auditor take based on the data analytics results?
- Increase control risk to maximum for all cycles and eliminate any reliance on controls for the entire audit because any exception rate indicates ineffective controls.
- Treat the analytics as substantive evidence that purchases and payables are fairly stated and reduce accounts payable and expense testing.
- Investigate the nature and cause of the exceptions (including validating system timestamps and examining exception resolution), evaluate whether the control is designed and operating effectively, and modify the audit approach (controls reliance vs. substantive testing) based on the results. (correct answer)
- Communicate the matter only to the Securities and Exchange Commission because internal control exceptions in an issuer require immediate external reporting.
Explanation: AS 2201 requires auditors to investigate control exceptions identified through analytics to determine their nature, cause, and audit implications. The analytics reveal significant control breakdowns: 18% of purchase orders approved after receipt and 6% of invoices paid without documented three-way match resolution, with deterioration in the last quarter—patterns requiring investigation of system timestamps, exception resolution processes, and control effectiveness evaluation. The appropriate response involves validating the data, examining specific exceptions, and modifying the audit approach based on whether controls can be relied upon. Option A incorrectly abandons all control reliance based on exceptions in one area, Option B inappropriately treats control testing as substantive evidence, and Option D prematurely requires external reporting without investigation. When control assessment analytics identify exception patterns that management attributes to system issues without supporting evidence, auditors must perform additional procedures to validate the data and determine appropriate audit strategy modifications.
Question 7
You are the auditor of a nonissuer in an audit engagement. As part of an anomaly detection routine over the full population of cash disbursements, your data analytics identify 27 payments just below the $25,000 dual-approval threshold, all initiated by the same user ID in the last three business days of the fiscal year, and 9 of those payments were to new vendors created within 24 hours of payment. Which action should the auditor take based on the data analytics results?
- Conclude the disbursements are fairly stated because the analytics covered the full population and no further procedures are necessary.
- Perform targeted follow-up procedures on the flagged items, including inspecting supporting documentation, evaluating vendor setup controls, and expanding testing if results indicate potential fraud risk. (correct answer)
- Immediately communicate the suspected fraud to the Securities and Exchange Commission because the pattern indicates management override.
- Defer any investigation until after issuing the audit report because the transactions are individually below the approval threshold and likely immaterial.
Explanation: AU-C 240 requires auditors to maintain professional skepticism and respond appropriately when data analytics identify potential fraud indicators, including transactions structured to circumvent controls. The analytics reveal three red flags: 27 payments just below the dual-approval threshold, concentration by a single user in the last three days of the year, and 9 payments to vendors created within 24 hours—classic indicators of potential disbursement fraud or management override. The correct response requires targeted follow-up procedures including inspecting supporting documentation and evaluating vendor setup controls, as these anomalies represent specific risks requiring investigation. Option A incorrectly assumes analytics alone provide sufficient evidence without corroboration, Option C prematurely escalates to external reporting without investigation, and Option D inappropriately defers investigation of potential fraud indicators. When data analytics identify patterns consistent with fraud risk factors, professional standards require immediate investigation through targeted substantive procedures to determine whether misstatement has occurred.
Question 8
During an audit of an issuer, internal control assessment analytics show that 12% of system-generated credit limit overrides were approved by the same individual who entered the sales order, despite the control requiring independent approval; the override rate is highest for a new sales office, and subsequent cash receipts show slower collections for those customers. Which action should the auditor take based on the data analytics results?
- Conclude the control is effective because the system records an approval field, and treat the slower collections as a business issue unrelated to auditing.
- Evaluate the design and operating effectiveness of the credit override control at the new sales office, consider implications for the allowance for credit losses and revenue recognition, and determine whether a control deficiency exists that affects the audit approach. (correct answer)
- Rely exclusively on the analytics to quantify the allowance for credit losses and eliminate confirmations and subsequent receipt testing.
- Issue an adverse opinion on the financial statements because any control exception rate above 10% requires an adverse opinion for an issuer.
Explanation: AS 2201 requires evaluation of control deficiencies identified through analytics, particularly when they correlate with adverse business outcomes like deteriorating collections. The analytics reveal that 12% of credit overrides bypass independent approval requirements, concentrated in a new sales office with slower subsequent collections—indicating both a control deficiency and potential financial statement impact on credit loss allowances and revenue recognition. The appropriate response involves evaluating control design and operating effectiveness, assessing implications for allowances and revenue, and determining whether deficiencies affect the audit approach. Option A incorrectly assumes system fields prove control effectiveness, Option C inappropriately substitutes analytics for required audit procedures, and Option D misapplies control deficiency evaluation standards. When control analytics identify approval violations that correlate with collection deterioration, auditors must evaluate both the control deficiency severity and its financial statement implications through targeted testing procedures.
Question 9
You are auditing an issuer and perform trend analysis on gross margin by customer segment. Analytics show a 480 basis point gross margin increase in one segment despite stable list prices and rising input costs, and the segment also has a higher frequency of manual cost-of-sales journal entries posted after month-end close. Management attributes the margin increase to "operational efficiencies" but cannot provide supporting analysis. How should the auditor adjust the audit plan given the analytics findings?
- Design additional procedures over cost of sales and inventory/standard cost updates for the segment, including testing manual entries for support and authorization, evaluating cutoff, and considering whether controls over journal entries are operating effectively. (correct answer)
- Conclude the segment is low risk because higher margin suggests improved performance, and reduce substantive testing for the segment.
- Treat the trend analysis as sufficient evidence and issue the audit report without further work because the analytics are based on complete data.
- Request that management restate the financial statements immediately because unusual gross margin trends require mandatory restatement.
Explanation: AS 2110 requires auditors to investigate unusual analytical relationships, particularly when gross margin improvements contradict economic conditions and coincide with manual journal entry patterns. The analytics reveal a 480 basis point margin increase despite stable prices and rising costs, combined with increased manual cost-of-sales entries after month-end—indicators of potential earnings management requiring targeted procedures over cost accounting and journal entry support. The appropriate response includes testing manual entries for authorization and support, evaluating cutoff procedures, and assessing journal entry controls effectiveness. Option B incorrectly assumes higher margins indicate lower risk, Option C inappropriately relies solely on analytics without corroboration, and Option D prematurely requires restatement without investigation. When trend analytics identify margin improvements that defy business logic and correlate with manual adjustment patterns, auditors must design procedures specifically addressing the potential for inappropriate cost deferrals or classification errors.
Question 10
You are auditing an issuer and run anomaly detection on journal entries. Analytics identify a cluster of manual entries posted on the last day of the year by a senior finance user, with descriptions referencing "reclass" and "true-up," and entries frequently posted to revenue and accrued liabilities without standard support; this affects revenue, liabilities, and the risk of management override. What is the most appropriate audit response to the identified anomaly?
- Select the flagged journal entries for detailed testing, obtain and evaluate support, assess the business purpose, and consider whether to expand journal entry testing and fraud procedures. (correct answer)
- Conclude the entries are appropriate because they were posted by a senior user and therefore must have been reviewed.
- Communicate the results only to the internal audit director because journal entry issues are an internal audit responsibility in issuer audits.
- Treat the analytics as a control test and reduce substantive testing of revenue and liabilities without further corroboration.
Explanation: This question tests responding to journal entry anomalies under AS 2401 for fraud risks in issuer audits. The key facts include year-end postings by a senior user to revenue and liabilities without support, indicating override risk. Choice A aligns with AS 2401 by requiring testing, evaluation, and potential expansion of procedures. Choice B is incorrect as senior involvement increases, not decreases, risk per AS 2401; choice C is wrong because auditors communicate to governance per AS 1301, not just internal audit; choice D is incorrect as analytics are risk assessment tools, not control tests, under AS 2110. A decision rule is to prioritize anomalies with fraud indicators for detailed testing and consider broader implications. Professional judgment involves escalating testing scope based on the anomaly's characteristics and context.
Question 11
In an audit of an issuer, your predictive analytics comparing budget-to-actual operating expenses indicates that IT consulting expense should be approximately $9.0 million based on headcount and project milestones, but actual expense is $14.2 million; vendor master data shows 30% of the spend is paid to a newly added vendor with a similar name to an existing vendor. The area impacts operating expenses, related-party considerations, and procurement controls. Which action should the auditor take based on the data analytics results?
- Investigate the new vendor and the nature of services by inspecting contracts and invoices, evaluating vendor onboarding controls, and considering whether related-party or fraud risks require expanded procedures. (correct answer)
- Conclude the variance is acceptable because budgets are not part of the financial statements and therefore cannot affect the audit.
- Assume the predictive model is definitive and propose an adjusting entry to reduce expense to $9.0 million without obtaining supporting evidence.
- Communicate the issue only to the vendor's account manager because procurement matters are outside the scope of the financial statement audit.
Explanation: This question addresses responding to predictive analytics variances under AS 2301 in issuer audits. The key facts include the budget-to-actual gap, new vendor similarity, and impacts on expenses and controls. Choice A is correct per AS 2301, requiring investigation and evaluation of risks. Choice B is incorrect as budgets inform risk assessment per AS 2110; choice C is wrong because models require corroboration under AS 2305; choice D is incorrect as procurement affects financial statements per AS 2401. A framework is to trace variances to underlying data and assess control implications. Judgment involves considering patterns like vendor anomalies in risk responses.
Question 12
A data analytic of the company's payroll register flags five active employees who have not taken any sick or vacation leave for the entire 12-month period under audit. The company has a 'use-it-or-lose-it' vacation policy.
While this could be a legitimate situation, an auditor interpreting this output should consider it a potential indicator of what type of fraud scheme?
- The existence of ghost employees. (correct answer)
- An improper accrual of vacation liabilities.
- Employees being forced to work without taking time off.
- Overpayment of wages through incorrect pay rates.
Explanation: One common red flag for 'ghost' employees (fictitious employees in the payroll system) is a lack of normal activity, such as taking paid time off, changing benefits, or receiving promotions. A real employee is highly likely to use at least some vacation time over a full year, especially under a 'use-it-or-lose-it' policy. The absence of this activity for multiple employees warrants investigation into their actual existence.
Question 13
An auditor uses a data analytic tool to review the travel and entertainment (T&E) expense reimbursement file. The tool is programmed to flag transactions with certain attributes for further review. The output includes a list of all expense reports that were submitted and approved on a weekend.
When interpreting this output, what is the auditor's most appropriate initial conclusion?
- These transactions are definitive evidence of fraudulent employee reimbursements.
- The data analytic's parameters are flawed, as legitimate business activities can occur on weekends.
- The flagged transactions indicate a higher risk and require further investigation to determine their business purpose. (correct answer)
- Management should be immediately instructed to reverse these T&E expense entries.
Explanation: The correct interpretation is that transactions occurring at unusual times (like weekends) represent a potential indicator of fraud or error and thus a higher risk. The auditor's professional responsibility is to apply skepticism and perform further procedures, such as examining supporting documentation, to determine the legitimacy and business purpose of these transactions. The output itself is not definitive proof of fraud.
Question 14
In performing substantive analytical procedures for revenue, an auditor develops a regression model. The model uses monthly marketing expenditures and website traffic data to predict monthly sales. The model's output shows an R-squared value of 0.85 and a p-value for the marketing expenditure variable of 0.25.
How should the auditor interpret the p-value of 0.25 for the marketing expenditure variable?
- Marketing expenditures explain 25% of the variation in the company's sales.
- The relationship between marketing expenditures and sales is not statistically significant in the model. (correct answer)
- There is a 25% probability that the marketing expenditure data used in the model is erroneous.
- The overall regression model is unreliable for predicting sales and should be discarded.
Explanation: The p-value tests the null hypothesis that a variable has no correlation with the dependent variable. A high p-value (typically > 0.05) indicates that the null hypothesis cannot be rejected. Therefore, a p-value of 0.25 suggests that marketing expenditure is not a statistically significant predictor of sales within this specific model, even though the overall model (as indicated by the high R-squared) may be useful.
Question 15
An auditor applies Benford's Law analysis to the cash disbursement transaction file for the fiscal year. The output shows that the leading digit '1' appears significantly less frequently than expected, while the leading digits '8' and '9' appear significantly more frequently than expected.
This output would most likely lead the auditor to suspect a risk of:
- Numerous random data entry errors in the payment processing system.
- Payments being systematically structured to fall just below an internal control authorization threshold. (correct answer)
- Duplicate payments being issued to the same vendors for the same invoices.
- Failure to record all cash disbursements that occurred during the year.
Explanation: A common pattern that violates Benford's Law is the avoidance of certain leading digits. If a company has a policy requiring a higher level of approval for payments of, for example, $10,000 or more, individuals might create multiple payments for $9,999 or $8,500. This would lead to a lower frequency of payments starting with '1' and a higher frequency starting with '8' or '9', suggesting an attempt to circumvent controls.
Question 16
An auditor uses a data analytic tool to perform a sequence check on all sales invoice numbers generated during the year. The tool's output report lists 42 numerical gaps in the sales invoice sequence.
The interpretation of this finding most directly suggests a risk that which financial statement assertion for revenue has not been met?
- Occurrence
- Accuracy
- Cutoff
- Completeness (correct answer)
Explanation: Gaps in a pre-numbered sequence of documents, such as sales invoices, suggest that some transactions may not have been recorded. This directly relates to the completeness assertion, which states that all transactions and events that should have been recorded have been recorded. The auditor would need to investigate these gaps to ensure that they do not represent unrecorded sales.
Question 17
A data analytic on the accounts payable file identifies 75 payments with matching vendor names, invoice dates, and invoice amounts. The audit team selects a sample of 20 of these items for investigation. For 19 of the items, they find that they represent legitimate separate purchases from the same vendor on the same day. One item is confirmed to be an actual duplicate payment.
What is the most reasonable interpretation of these findings?
- The data analytic tool is not functioning correctly and cannot be relied upon.
- The presence of one duplicate payment indicates a material weakness in internal controls.
- The analytic's parameters were likely too broad, resulting in many false positives that are not control deficiencies. (correct answer)
- The entire population of 75 flagged items must be investigated before concluding on the effectiveness of controls.
Explanation: Data analytics often produce 'false positives,' which are exceptions that are not actual errors or misstatements. The investigation shows that the vast majority of flagged items were legitimate. This suggests the criteria for identifying duplicates (vendor, date, amount) were too broad and should be refined (e.g., by adding invoice number). The risk of material misstatement from this issue appears low based on the sample.
Question 18
An auditor creates a data visualization that plots sales revenue by day for the entire fiscal year. The visualization clearly shows a recurring pattern: a large, sharp spike in recorded revenue on the last day of each of the four fiscal quarters. Revenue on other days is relatively stable.
This observed pattern should cause the auditor to increase professional skepticism and design additional procedures related to:
- The accuracy of sales commission calculations for the sales team.
- Revenue recognition and the proper cutoff of sales transactions. (correct answer)
- The collectibility of the accounts receivable generated by these sales.
- The effectiveness of the company's marketing and promotional campaigns.
Explanation: A significant spike in sales on the last day of a reporting period is a classic red flag for aggressive or fraudulent revenue recognition practices. It suggests that management may be improperly accelerating revenue into the current period or holding the books open past the cutoff date. This requires the auditor to design detailed cutoff tests and other procedures to validate the occurrence and timing of these sales.
Question 19
An auditor uses a clustering algorithm on the vendor master file change log. The output identifies a distinct group of activities performed by a single accounts payable clerk. The cluster consists of repeated changes to vendor electronic payment instructions followed within 24 hours by large payments to those vendors.
The interpretation of this cluster of activities should lead the auditor to suspect a potential risk of:
- Unrecorded liabilities due to delayed invoice processing.
- Systemic errors in the electronic funds transfer (EFT) system.
- Fraudulent disbursements being diverted to an employee. (correct answer)
- Violations of vendor data privacy regulations.
Explanation: This pattern is highly indicative of a classic fraud scheme. An employee with access to change vendor payment details could alter a vendor's bank account to their own, process a legitimate payment to that vendor, and then change the details back. The clustering of these specific actions by one person points to deliberate manipulation rather than a system error or other issue.
Question 20
During journal entry testing, a data analytic flags five large, non-standard entries that increased revenue. The transaction log shows the entries were created and approved by the same user ID, which belongs to the head of the shipping department.
Interpreting this output suggests a significant deficiency or material weakness related to:
- The accounting policies for revenue recognition.
- The documentation standards for non-standard journal entries.
- The physical security over inventory in the shipping department.
- Segregation of duties and logical access controls. (correct answer)
Explanation: A fundamental principle of internal control is segregation of duties. An individual from an operational department like shipping should not have the ability to create and approve journal entries, especially those impacting revenue. This finding indicates a severe breakdown in logical access controls (who can access what in the system) and segregation of duties, creating an opportunity for fraud or error.