All questions
Question 1
An issuer is audited under PCAOB standards. The company's IT governance assigns responsibility for cybersecurity and financial systems to separate leaders, and there is no formal process for escalating cybersecurity incidents to the audit committee. A recent ransomware event affected a file server used to store accounting support schedules, though systems were restored from backups. Which factor would most likely affect the auditor's assessment of IT controls?
- Whether incident response and escalation procedures include timely communication of events affecting financial reporting information to those charged with governance (correct answer)
- Whether the company's public relations team issued a statement within 24 hours of the ransomware event
- Whether the company maintains cyber insurance coverage with a low deductible
- Whether the company's backups were stored offsite, regardless of the lack of governance escalation
Explanation: PCAOB AS 2201 integrates IT governance in ICFR, including escalation of incidents affecting financial data. The key facts include separate leaders without formal escalation to the audit committee, and a ransomware event impacting accounting files. Option A most affects the assessment as escalation ensures governance oversight, aligning with COSO monitoring. Option B is irrelevant to ICFR, and Option C is incorrect as insurance does not replace controls, per AS 2201. Option D is partial without addressing governance gaps. A transferable framework is to assess incident procedures by tracing escalations to governance roles. Professional judgment should evaluate monitoring's role in risk mitigation.
Question 2
A nonissuer distribution company is undergoing a financial statement audit under AICPA standards. The company's IT governance policy requires approval of system changes by a change advisory board, but the board did not meet for three months during the busiest season and changes were implemented directly by IT operations. The auditor is assessing the reliability of automated controls over inventory valuation that depend on system configuration. Which factor would most likely affect the auditor's assessment of IT controls?
- Whether changes affecting inventory costing parameters were implemented without documented testing and approval during the period the board did not meet (correct answer)
- Whether the company's inventory turnover ratio improved compared to the prior year
- Whether the company plans to hire additional IT staff next year
- Whether the company uses an enterprise risk management framework for non-IT risks
Explanation: AICPA AU-C 315 requires assessing IT controls' reliability, including governance over changes affecting automated controls. The key facts involve a change advisory board not meeting for three months, allowing direct implementations impacting inventory valuation configurations. Option A most affects the assessment as unapproved changes undermine control reliability, aligning with COSO's control activities. Option B is irrelevant to IT controls, and Option C is incorrect as future hiring does not remediate past deficiencies, per AU-C 330. Option D is wrong because non-IT frameworks do not address system configuration risks. A transferable judgment framework is to evaluate governance lapses by tracing changes to approval evidence against automated control risks. Auditors should consider the period of exposure when assessing control effectiveness.
Question 3
An issuer is audited under PCAOB standards, including an audit of ICFR. The company uses a shared service center where IT developers have emergency access to production to resolve outages, and the company asserts that compensating controls exist. The auditor is assessing segregation of duties within IT as it relates to financial reporting systems. Which control should the auditor evaluate to address the risk of unauthorized changes to programs and data?
- A control requiring all emergency production access to be time-bound, approved by management independent of development, logged, and reviewed after the fact for appropriateness (correct answer)
- A control requiring developers to document their coding standards in a personal notebook
- A control where accounting reviews financial statements at quarter-end for reasonableness without considering IT access logs
- A control requiring the organization to obtain a general ISO certification as a substitute for testing access controls
Explanation: PCAOB AS 2201 emphasizes testing segregation of duties in IT, including controls over emergency access to production environments. The key facts include developers' emergency access at a shared service center, with asserted compensating controls for financial systems. Option A aligns with COBIT by requiring time-bound, approved, logged, and reviewed access to mitigate unauthorized change risks. Option B is incorrect as personal documentation lacks oversight, and Option C represents financial review without IT specificity, per AS 2201. Option D is flawed because ISO certification does not replace specific access testing, as per audit evidence standards. A transferable framework involves assessing compensating controls for segregation risks by verifying independence and monitoring effectiveness. Auditors should consider the precision of such controls in preventing or detecting errors timely.
Question 4
A nonissuer manufacturing company is undergoing a financial statement audit under AICPA standards. During the year, management implemented a new enterprise resource planning (ERP) system that automatically posts sales invoices from the order-entry module to the general ledger, and the legacy system is now read-only for reference. The auditor identifies a risk that unauthorized users could create or modify customer master data and sales prices, resulting in misstated revenue. Which control should the auditor evaluate to address the risk of unauthorized access?
- Management's quarterly analytical review of revenue trends by product line, with follow-up on unusual fluctuations
- Role-based access provisioning with documented approvals, periodic user access recertifications, and timely removal of terminated users from the ERP (correct answer)
- A post-implementation review that occurs only after the first annual financial statements are issued
- Adoption of a general cybersecurity maturity model not incorporated into audit evidence for access control testing
Explanation: The COSO framework emphasizes the importance of control activities, including information technology general controls (ITGCs) such as logical access controls to mitigate risks in financial reporting systems. In this scenario, the key facts involve the implementation of a new ERP system with automated posting of sales invoices and the identified risk of unauthorized modifications to customer master data and sales prices, which could lead to revenue misstatements. Option B aligns with authoritative guidance from COBIT, which recommends role-based access controls, approvals, recertifications, and timely user terminations to prevent unauthorized access and ensure data integrity. Option A is incorrect because it represents a monitoring control rather than a preventive access control, and Option C is flawed as post-implementation reviews should occur timely, not delayed until after annual statements, per audit standards like AU-C 315. Option D is inappropriate because a general cybersecurity model without integration into audit evidence does not directly address access control testing, as per PCAOB AS 2201. A transferable professional judgment framework involves assessing the design and operation of access controls by evaluating provisioning processes against the principle of least privilege. Auditors should also consider the precision of controls in mitigating specific risks, balancing preventive and detective measures for effective risk response.
Question 5
A nonissuer construction company is undergoing a financial statement audit under AICPA standards. The company implemented a new job-costing system that allocates overhead to projects using standard rates maintained in a configuration table. The auditor identifies a risk that unauthorized changes to standard rates could materially affect cost of revenues. Which control should the auditor evaluate to address the risk of unauthorized access?
- Role-based access restricting who can change standard rates, with documented approvals for rate changes and periodic review of users with configuration access (correct answer)
- A control requiring project managers to approve timecards, without addressing who can change overhead rates
- A control requiring the IT department to perform an annual inventory count observation
- A control requiring adoption of a general enterprise architecture framework as a substitute for access controls
Explanation: AICPA AU-C 315 requires access controls to prevent unauthorized changes in systems affecting financial statements. The key facts involve a new job-costing system with configurable overhead rates, risking cost of revenues misstatements. Option A aligns with COBIT by restricting and reviewing access to configurations. Option B addresses timecards but not rates, and Option C is irrelevant to IT, per AU-C 330. Option D substitutes without evidence. A transferable decision rule is to evaluate access by verifying restrictions against modification risks. Auditors should balance preventive controls with periodic reviews.
Question 6
An issuer is audited under PCAOB standards. The auditor identifies that the company lacks a formal process to review and approve changes to key reports used in controls over financial reporting, including a cash reconciliation report generated from the ERP. Management asserts the report is unchanged from prior years. Which audit response is most appropriate to address the risk related to IT general controls over report changes?
- Test report logic and parameters, and evaluate change management controls over report modifications to support reliance on the report used in the control (correct answer)
- Rely on management's assertion that the report is unchanged because it has been used historically
- Limit testing to inquiry of the report owner because inspection of report configuration is outside the scope of an ICFR audit
- Obtain a SOC 2 report from the ERP vendor as a substitute for testing report change controls at the company
Explanation: PCAOB AS 2201 requires testing ITGCs over changes to reports used in ICFR controls. The key facts include lacking formal processes for report changes, with management asserting stability for the cash reconciliation report. Option A aligns with AS 2201 by testing logic, parameters, and change controls to support reliance. Option B is incorrect as assertions require corroboration, and Option C violates evidence needs in AS 2301. Option D is wrong as SOC 2 covers vendor controls, not company-specific. A transferable framework is to validate report integrity by inspecting configurations against change risks. Professional judgment should assess the impact on dependent manual controls.
Question 7
An issuer is audited under PCAOB standards. Management identified a deficiency where terminated employees' access to the financial reporting system was not removed timely, but management argues it is not a material weakness because no unauthorized activity was detected. The auditor is evaluating the severity of the deficiency in ICFR. Which factor would most likely affect the auditor's assessment of IT controls?
- The likelihood and magnitude of potential misstatement given the level of access retained by terminated users and the period of continued access (correct answer)
- Whether the company's HR department has a documented employee handbook
- Whether management intends to purchase a new identity management tool next year
- Whether the deficiency was discovered by internal audit rather than by external audit
Explanation: PCAOB AS 2201 evaluates ICFR deficiencies by likelihood and magnitude of misstatement, not just detection. The key facts include untimely access removal for terminated employees, argued as non-material despite no activity. Option A most affects the assessment as continued access heightens risks, aligning with COSO. Option B is irrelevant, and Option C is future-oriented, per AS 2201. Option D does not impact severity. A transferable framework is to classify deficiencies by potential impact, considering exposure periods. Professional judgment should disregard absence of errors if risks persist.
Question 8
A nonissuer technology company is undergoing a financial statement audit under AICPA standards. The company uses a source code repository and automated deployment tools to push changes to its billing application, which feeds revenue transactions into the general ledger. The auditor notes that developers can approve their own pull requests and deployments. Which control should the auditor evaluate to address the risk of unauthorized changes to programs affecting financial reporting?
- Segregation of duties in the deployment process, including independent code review/approval, restricted production deployment rights, and audit logs of deployments (correct answer)
- A control requiring developers to document new features in release notes without independent approval
- A control requiring finance to perform a high-level monthly revenue trend analysis only
- A control requiring adoption of a general quality management standard that does not provide evidence over specific deployments
Explanation: AICPA AU-C 330 requires controls over program changes to mitigate unauthorized modifications affecting financial reporting. The key facts involve developers approving their own deployments to the billing application feeding the GL. Option A aligns with COBIT by enforcing segregation, reviews, and logs to prevent unauthorized changes. Option B lacks independence, and Option C is incorrect as trend analysis is monitoring, not preventive, per AU-C 315. Option D is inadequate without specific evidence. A transferable decision rule is to evaluate deployment controls by verifying segregation against change risks. Auditors should consider logging for detective effectiveness.
Question 9
An auditor is reviewing the IT environment of a new client. The auditor discovers that the company's network administrator is also responsible for programming changes to the accounts payable system and has unrestricted access to the live production data.
This situation represents a significant weakness primarily in which area of IT general controls?
- Program development and acquisition.
- Computer operations.
- Segregation of duties and access controls. (correct answer)
- Business continuity planning.
Explanation: The scenario describes a classic violation of segregation of duties. The network administrator has conflicting responsibilities: programming (authorization and development) and unrestricted access to production data (custody/operations). This combination creates a significant risk that unauthorized and potentially fraudulent changes could be made to systems and data without detection. This falls squarely under segregation of duties and access controls.
Question 10
While performing an audit, an auditor uses generalized audit software to compare the client's current production version of the payroll program with an authorized version from the beginning of the year. The comparison reveals several lines of code that were modified during the year but are not documented in the change request logs.
This finding is most indicative of a failure in which category of IT general controls?
- Logical access controls.
- Program change controls. (correct answer)
- Data conversion controls.
- Computer operations controls.
Explanation: The presence of undocumented changes to a production program is a direct failure of program change controls. The purpose of these controls is to ensure all changes are authorized, tested, documented, and approved before implementation. While weak logical access controls (A) may have been the enabling factor allowing the change, the core control failure is in the change management process itself. Data conversion controls (C) apply to new system implementations, and computer operations controls (D) relate to program execution, not modification.
Question 11
An auditor is assessing IT general controls at a client's data center. Which of the following would provide the most persuasive evidence regarding the operating effectiveness of physical access controls?
- Reviewing the company's written policy on data center access.
- Interviewing the data center manager about procedures for granting access.
- Observing employee and visitor access to the data center and inspecting the access log for proper authorization. (correct answer)
- Examining the invoice for the recently installed biometric scanner at the data center entrance.
Explanation: Audit evidence is most persuasive when it is obtained from multiple sources or is of different types. Combining direct observation of the control in operation with inspection of related documentation (the access log) provides strong evidence of operating effectiveness. Reviewing a policy (A) only addresses control design. Inquiry (B) is not sufficient on its own. Examining an invoice (D) proves a control was purchased but not that it is operating effectively.
Question 12
An auditor plans to use data analytics to perform substantive testing on a client's entire population of sales transactions. The reliability of the results of this data analytics procedure is most dependent on the effectiveness of the client's:
- Sales commission calculation policies.
- Substantive analytical procedures performed in prior years.
- Manual controls over shipping and receiving.
- IT general controls and controls over data completeness and accuracy. (correct answer)
Explanation: The principle of 'garbage in, garbage out' applies to data analytics. The results of any analysis are only as reliable as the underlying data. Therefore, the auditor must first gain assurance over the completeness and accuracy of the data population being analyzed. This assurance is derived from effective IT general controls and specific application controls over data integrity. A, B, and C are not directly related to the reliability of the electronic data population.
Question 13
An auditor is testing a client's control that requires department managers to perform a quarterly review of their employees' access rights to the financial reporting system. Which audit procedure would best test the operating effectiveness of this control?
- Inquiring of the IT director about the process for generating the user access lists.
- Selecting a sample of new employees hired during the year and ensuring they were granted appropriate initial access.
- Examining the system's log of access attempts that were denied.
- Selecting a sample of quarterly review forms and verifying evidence of the manager's review and the timely removal of inappropriate access. (correct answer)
Explanation: To test the operating effectiveness of the access review control, the auditor must examine evidence that the control was performed and that corrective actions were taken. This involves inspecting the signed review forms (evidence of performance) and then tracing any identified issues (e.g., employees who transferred or left) to ensure their access was promptly revoked. A, B, and C test other related controls but not the manager's quarterly review itself.
Question 14
An auditor discovered that the client's database administrator (DBA) has superuser access to the production accounting database and is also responsible for recording certain complex journal entries in the general ledger system. This IT general control weakness would most likely be classified as at least a significant deficiency because:
- It involves a third-party software package rather than an in-house developed system.
- The auditor identified the issue, not the client's internal audit function.
- The cost to remediate the control weakness is expected to be significant.
- It represents a fundamental breakdown in segregation of duties that could allow a material misstatement to occur and not be timely detected. (correct answer)
Explanation: The severity of a control deficiency is based on the magnitude of potential misstatement and the likelihood that it would not be detected. A severe lack of segregation of duties involving a privileged user (the DBA) who can both manipulate the underlying database and record transactions creates a reasonable possibility that a material misstatement could occur and be concealed. This meets the definition of a material weakness, and therefore at least a significant deficiency. The other choices are irrelevant to the classification of the deficiency's severity.
Question 15
An auditor has identified a significant deficiency in an entity's IT general controls related to program change management. What is the auditor's most likely conclusion concerning the testing of automated application controls that were not modified during the period under audit?
- The auditor cannot rely on any automated application controls and must adopt a fully substantive approach.
- The auditor may be able to rely on the automated application controls after testing them at a point in time to verify their functionality. (correct answer)
- The auditor must test the automated application controls continuously throughout the entire audit period.
- The auditor should rely solely on management's representation that the controls were effective since they were not changed.
Explanation: Even with weak change controls, an automated control that has not changed since it was last tested may still be reliable. The auditor can use a 'benchmark' or 'baseline' strategy, which involves testing the control's functionality at a point in time. This is more efficient than testing its operation throughout the period (C). A is too extreme; if the control hasn't changed, it may be reliable. D is never appropriate as management representation alone is not sufficient audit evidence.
Question 16
A company outsources its payroll processing to a third-party service organization. The company's management has provided the auditor with the service organization's SOC 1, Type 2 report. The report includes an unmodified opinion from the service auditor, indicating that the service organization's controls are suitably designed and operating effectively.
What is the most appropriate conclusion for the company's auditor to draw from this report regarding the audit of payroll?
- The auditor does not need to perform any further procedures related to payroll because the SOC report provides sufficient appropriate evidence.
- The auditor can reduce the assessment of control risk for payroll assertions, assuming the user entity's own complementary controls are also effective. (correct answer)
- The auditor must visit the service organization's data center to perform direct tests of its IT general controls.
- The SOC 1 report is irrelevant to the audit of the company's financial statements and should be disregarded.
Explanation: A SOC 1, Type 2 report with an unmodified opinion provides evidence that allows the user auditor to place some reliance on the service organization's controls. This enables the auditor to reduce the assessed level of control risk for relevant assertions. However, the auditor must still evaluate and test the user entity's own controls (complementary user entity controls) related to the outsourced function. A is incorrect because user entity controls must still be considered. C is incorrect because the purpose of the SOC report is to avoid this. D is incorrect as the report is highly relevant.
Question 17
An issuer is undergoing an audit under PCAOB standards. During the year, the company experienced a cybersecurity incident involving compromised credentials for a privileged IT administrator account; management states that no financial data were altered. The auditor has identified deficiencies in privileged access management and is evaluating the impact on ICFR. Which factor would most likely affect the auditor's assessment of IT controls?
- Whether the incident involved a privileged account with access to applications and databases supporting financial reporting (correct answer)
- Whether the company's marketing website experienced any downtime during the incident
- Whether management plans to adopt a new cybersecurity framework in the next fiscal year
- Whether the incident was disclosed in a press release, regardless of its relevance to financial reporting systems
Explanation: PCAOB AS 2201 guides the evaluation of IT control deficiencies in ICFR, focusing on risks to financial reporting from cybersecurity incidents. The key facts include a compromised privileged account and deficiencies in access management, with no financial data alterations claimed. Option A most affects the assessment as privileged access to financial systems heightens misstatement risks, aligning with COSO's risk assessment principles. Option B is irrelevant as website downtime does not impact ICFR, and Option C is incorrect because future plans do not remediate current deficiencies, per AS 2201. Option D is wrong as press releases do not substitute for control evidence, emphasizing substance over disclosure in COBIT. A transferable judgment framework is to assess deficiency severity by likelihood and magnitude of misstatement from privileged access breaches. Auditors should apply professional skepticism, considering compensating controls when evaluating overall ICFR effectiveness.
Question 18
An issuer is being audited under PCAOB standards, including internal control over financial reporting (ICFR). The company uses a third-party cloud platform to host its financial reporting applications, and the IT governance structure includes an IT steering committee that approves system changes and prioritizes IT projects affecting financial reporting. The auditor plans to test IT governance as part of understanding and testing entity-level controls that support ICFR. What is the most appropriate audit procedure for testing IT governance?
- Inspect steering committee charters, meeting minutes, and evidence of oversight of financial reporting systems, and corroborate through inquiry of members and follow-up on escalated issues (correct answer)
- Rely exclusively on management's representation letter that IT governance operated effectively throughout the year
- Test only year-end journal entries because IT governance does not affect ICFR when a cloud provider is used
- Obtain a penetration test report and treat it as sufficient evidence that IT governance controls are operating effectively
Explanation: PCAOB AS 2201 requires auditors to test entity-level controls, including IT governance, to assess their impact on internal control over financial reporting (ICFR). The key facts here include the use of a third-party cloud platform for financial applications and an IT steering committee overseeing changes and projects, necessitating evidence of effective governance. Option A aligns with AS 2201 by emphasizing inspection of charters, minutes, and corroboration through inquiry to verify oversight, ensuring governance supports ICFR. Option B is incorrect as reliance on management representations alone violates AS 2805's requirement for sufficient appropriate evidence, and Option C is wrong because IT governance affects ICFR even with cloud providers, per AS 2601. Option D is inadequate since penetration tests address vulnerabilities but not comprehensive governance, as noted in COBIT frameworks. A transferable decision rule is to evaluate governance by tracing oversight activities to risk mitigation, ensuring alignment with COSO's control environment component. Professional judgment should weigh the pervasiveness of governance controls in reducing detection risk for ICFR testing.
Question 19
An issuer is audited under PCAOB standards. Management identified multiple IT general control weaknesses over user access provisioning and periodic access reviews for the financial reporting system, and the auditor concludes the deficiencies are pervasive to ICFR. Management requests that the auditor still issue an unqualified opinion on ICFR because no misstatements were detected in the financial statements. What type of opinion should be issued considering the IT control weaknesses identified?
- Unqualified opinion on ICFR because substantive testing did not identify misstatements
- Disclaimer of opinion on ICFR because any IT control weakness requires a disclaimer
- Adverse opinion on ICFR if the deficiencies constitute one or more material weaknesses as of year-end (correct answer)
- Qualified opinion on the financial statements because IT deficiencies automatically require a financial statement qualification
Explanation: PCAOB AS 2201 requires an adverse opinion on ICFR if material weaknesses exist, regardless of detected misstatements. The key facts include pervasive ITGC weaknesses in access provisioning and reviews, identified by management and confirmed by the auditor. Option C aligns with AS 2201, mandating an adverse opinion for material weaknesses impacting ICFR reliability. Option A is incorrect as unqualified opinions require effective ICFR, and Option B is wrong because disclaimers are for scope limitations, not deficiencies, per AS 3101. Option D is flawed as IT weaknesses affect ICFR opinions, not necessarily financial statement qualifications, unless misstatements result. A transferable framework is to classify deficiencies by severity, considering pervasiveness and compensating controls. Auditors should apply judgment in evaluating whether weaknesses could lead to material misstatements.
Question 20
A nonissuer not-for-profit is undergoing a financial statement audit under AICPA standards. The entity uses spreadsheets to upload journal entries into the general ledger, and the upload utility accepts files placed in a shared folder. The auditor identifies a risk that journal entry files could be modified after preparer approval but before upload. Based on the circumstances, which IT control is most critical for ensuring data integrity?
- Restricting write access to the upload folder, using file versioning or hashing, and reconciling uploaded entries to an approved journal entry listing (correct answer)
- Requiring that all journal entry preparers attend annual training on financial reporting updates
- Performing a backup of the shared folder monthly without controlling access to it
- Implementing a general project management framework that does not address file integrity or access restrictions
Explanation: AICPA AU-C 315 emphasizes IT controls for data integrity in upload processes to prevent modifications. The key facts involve spreadsheet uploads via a shared folder, with risks of post-approval alterations to journal entries. Option A aligns with COBIT by restricting access, using hashing, and reconciling to ensure integrity. Option B is incorrect as training does not prevent modifications, and Option C lacks access controls, per AU-C 330. Option D is flawed because frameworks without specifics do not address risks. A transferable decision rule is to assess file integrity controls by verifying security and reconciliation against alteration risks. Auditors should evaluate automated protections for efficiency in high-volume processes.