All questions
Question 1
An issuer is being audited under PCAOB standards. The auditor receives a journal entry listing and transforms it to identify entries posted outside normal business hours; the auditor finds the time stamp field was converted to the auditor's local time zone, changing the apparent posting time. Based on the audit findings, how should the data be adjusted before drawing conclusions from the analytics?
- Convert all time stamps to dates only, because time-of-day analysis is inherently unreliable.
- Re-transform the data using the company's system time zone (or retain the original time stamp field), document the time zone assumption, and re-run the after-hours analysis on the corrected field. (correct answer)
- Keep the converted time stamps and adjust the definition of 'after hours' to match the auditor's local time.
- Use inquiry alone to determine whether journal entries were posted after hours and discontinue the analytics.
Explanation: PCAOB AS 2315 requires accurate data in analytics like identifying after-hours journal entries, addressing transformation errors such as time zone conversions. The key fact is the time stamp conversion to the auditor's local time, altering posting times. Choice B is correct as re-transforming with original time zones and documenting assumptions ensures integrity per AS 1105. Choice A is incorrect as converting to dates loses precision; Choice C is incorrect because adjusting definitions does not correct data; Choice D is incorrect as inquiry alone is insufficient. Auditors should framework by retaining original fields and validating assumptions. This approach is transferable to time-sensitive data analytics.
Question 2
You are the auditor of a nonissuer in a financial statement audit. Management provided a full-year sales report exported from the enterprise system to a spreadsheet, but you notice duplicate invoice numbers and several invoices dated in the current year that are included in prior-year revenue after management "sorted and filtered" the file. Which procedure should be applied to validate the data transformation before using it for substantive revenue testing?
- Rely on management's representation that the spreadsheet export is complete and accurate because it was generated from the enterprise system
- Reperform the export and transformation from the source system (or obtain a direct system-generated report), and agree record counts and key fields (e.g., invoice number, date, amount) to the transformed file, investigating exceptions (correct answer)
- Perform only analytical procedures on monthly revenue trends because duplicates would not affect overall reasonableness at the annual level
- Apply PCAOB requirements for testing automated controls over report generation because any spreadsheet used in an audit must be treated as a system report
Explanation: AU-C 500 requires auditors to evaluate the reliability of information used as audit evidence, including data transformations performed by management. The presence of duplicate invoice numbers and incorrectly dated transactions indicates that management's sorting and filtering compromised data integrity. The correct approach requires reperforming the export and transformation process, then agreeing record counts and key fields to verify completeness and accuracy. Option A incorrectly relies on management representations without corroboration, violating professional skepticism requirements. Option C inappropriately dismisses specific data integrity issues that could materially affect revenue testing. Option D incorrectly applies PCAOB standards to a nonissuer audit and mischaracterizes spreadsheet data as requiring automated control testing. The professional judgment framework requires auditors to validate any data transformation before relying on it for substantive procedures, especially when initial review reveals anomalies.
Question 3
You are the auditor of a nonissuer in an audit. To test payroll expense, you receive two data files: a payroll register from the payroll service organization and a general ledger detail export from the client. You convert both files to a common format and notice that several employee IDs in the payroll register do not exist in the client's HR listing used for authorization. Which factor is critical in assessing the reliability of the transformed data for audit purposes?
- Whether the transformed files are in the same spreadsheet format and sorted consistently by employee ID
- Whether the auditor can trace a sample of transformed records back to the original source files and evaluate the completeness and accuracy of the population, including investigating unmatched employee IDs (correct answer)
- Whether management asserts that the payroll service organization performs its own quality checks on payroll processing
- Whether the auditor delays the investigation of unmatched IDs until the final overall review stage to avoid disrupting fieldwork
Explanation: AU-C 500 requires auditors to evaluate whether information is sufficiently reliable for audit purposes, including assessing completeness and accuracy of transformed data. The presence of unmatched employee IDs between the payroll register and HR listing raises significant concerns about unauthorized payroll transactions or data integrity issues. The critical factor is the auditor's ability to trace transformed records back to original sources and investigate exceptions, not merely formatting consistency. Option A focuses on superficial formatting rather than substantive data validation. Option C inappropriately relies on third-party quality checks without direct validation of the specific data used in the audit. Option D incorrectly defers investigation of potential unauthorized transactions, which could indicate fraud or error requiring immediate attention. The professional framework requires auditors to validate data transformations by testing the completeness and accuracy of the population, especially when discrepancies suggest potential control deficiencies.
Question 4
An issuer is being audited under PCAOB standards. The auditor plans to use a system-generated accounts receivable aging to test valuation, but the client exports the aging to a spreadsheet and manually adds a column for 'expected credit loss %' before providing it to the auditor. Which procedure should be applied to validate the data transformation and manual modification before using it as audit evidence?
- Use the spreadsheet as provided because it is derived from a system report, and manual additions do not affect the aging buckets.
- Obtain the aging directly from the system (or a read-only report), compare it to the provided spreadsheet for completeness and accuracy, and test the logic and inputs for the manually added expected loss column. (correct answer)
- Request management representation that the added expected loss percentages are reasonable and treat that as sufficient evidence.
- Perform only a high-level analytical procedure on the allowance account and omit detailed testing of the aging.
Explanation: PCAOB AS 1105 requires auditors to evaluate the reliability of data from client systems, especially when manual modifications are added to transformed data for testing valuation assertions. The key fact is that the client manually added an expected credit loss percentage column to the exported aging spreadsheet, raising risks of manipulation or error. Choice B aligns with standards by obtaining the aging directly from the system, comparing for completeness, and testing manual additions, ensuring accurate audit evidence. Choice A is incorrect as using the spreadsheet without validation violates AS 2301's requirements for data reliability; Choice C is incorrect because management representation alone is not sufficient per AS 2805; Choice D is incorrect as omitting detailed testing reduces assurance on valuation per AS 2501. A transferable framework involves sourcing data from read-only reports and testing modifications through logic and input verification. This decision rule helps auditors maintain integrity in using transformed and modified data across engagements.
Question 5
An issuer is being audited under PCAOB standards. The auditor obtains a payroll report exported to a text file and then imports it into audit software to run analytics for duplicate direct-deposit accounts; after import, the auditor notices that some negative adjustments are displayed as positive amounts. What action should the auditor take to ensure data integrity before concluding on the payroll analytics results?
- Treat the sign changes as immaterial because the analytics are only a risk assessment procedure and do not affect substantive testing.
- Re-perform the import using the correct field definitions, then agree a sample of adjusted amounts to the original payroll extract and reconcile total net pay per the transformed file to the original report. (correct answer)
- Request management to certify in writing that the transformed file is complete and accurate, and file the certification as sufficient audit evidence.
- Discontinue using transformed data and instead rely exclusively on inquiry and observation for payroll testing.
Explanation: PCAOB standards, such as AS 2301, emphasize the need for auditors to ensure the reliability of data used in audit procedures, including analytics for identifying duplicates in payroll. The key facts here are that negative adjustments appear as positive after import, indicating a data integrity issue in the transformation process. Choice B is correct because re-performing the import with correct field definitions, agreeing samples to the original extract, and reconciling totals ensures the data's accuracy and completeness as per AS 1105. Choice A is incorrect as treating sign changes as immaterial ignores the requirement to validate data reliability before relying on analytics under AS 2315; Choice C is incorrect because management certification alone does not constitute sufficient audit evidence per AS 1105; Choice D is incorrect as discontinuing transformed data limits the audit scope unnecessarily when validation is feasible. A decision rule for auditors is to identify anomalies in transformed data and respond by reprocessing and validating against source documents. This framework promotes robust evidence gathering by prioritizing data integrity in technology-assisted audits.
Question 6
An issuer is being audited under PCAOB standards. The auditor obtains a capitalized software cost listing and transforms it to test capitalization criteria by project phase; the auditor learns project phase codes were updated mid-year and the transformed file applies only the new codes, misclassifying earlier costs. What action should the auditor take to ensure data integrity for testing capitalization by phase?
- Use only the post-update period data because it reflects the current coding and is more relevant.
- Incorporate both old and new phase codes using a documented crosswalk, validate the crosswalk to project documentation, and reclassify the full-year dataset before selecting items for testing. (correct answer)
- Convert all phase codes to alphabetical order so the analytics can be performed consistently.
- Rely on management's summary of capitalized costs by phase and discontinue use of the detailed listing.
Explanation: PCAOB AS 2501 requires complete and accurate data for testing capitalization criteria, addressing mid-year code updates. The key fact is applying only new codes, misclassifying earlier costs. Choice B is appropriate as incorporating both via crosswalk and validating ensures integrity per AS 1105. Choice A is incorrect as using post-update only incompletes the year; Choice C is incorrect because alphabetical conversion does not resolve; Choice D is incorrect as relying on summaries lacks detail. Auditors should framework with crosswalks and reclassification for code changes. This transfers to phased project testing.
Question 7
You are performing an issuer financial statement audit. To test journal entries, you request a complete general ledger dump; management provides a file that excludes entries posted by the CFO, stating those entries are "confidential." You plan to transform the file for analytics to identify unusual entries. What action should the auditor take to ensure data integrity?
- Proceed with analytics on the provided file because excluding confidential entries is acceptable if management approves
- Treat the exclusion as a scope limitation and obtain a complete population (including CFO-posted entries) or modify the audit opinion if sufficient appropriate evidence cannot be obtained (correct answer)
- Replace the missing entries by projecting from prior-year CFO activity and include the projection in the analytics population
- Rely on management's written representation that the excluded entries are not material and therefore do not affect the completeness of the data
Explanation: AS 2110 and AS 2301 establish requirements for testing journal entries as part of the auditor's response to fraud risks, requiring access to the complete population of journal entries. The exclusion of CFO-posted entries represents a scope limitation that prevents the auditor from obtaining sufficient appropriate audit evidence about potential management override of controls. The auditor must either obtain the complete population or modify the audit opinion if management refuses to provide access. Option A incorrectly proceeds with an incomplete population, potentially missing fraudulent entries. Option C attempts to substitute missing data with projections, which cannot replace actual journal entry testing. Option D inappropriately relies on management representations about materiality when testing for management override, which by nature could involve any amount. The professional judgment framework requires treating any limitation on access to journal entries as a significant scope limitation requiring resolution or opinion modification.
Question 8
You are performing an issuer audit. Management provides a system-generated inventory movement report, but to perform data analytics you must convert item codes to a standardized format because the company changed its item master midyear. After mapping old codes to new codes, your analytics indicate negative quantities on hand for several items near year-end. What is the most appropriate method for validating data accuracy before concluding on the existence assertion for inventory?
- Assume the negative quantities are an expected artifact of code mapping and exclude those items from the analysis
- Validate the mapping by testing the code-conversion logic (e.g., inspect the mapping table, reperform the conversion on a sample, and agree converted items to source transactions), and investigate negative quantities through source documents and physical inventory procedures as needed (correct answer)
- Rely solely on inquiry of management about the item master change because PCAOB standards allow inquiry as sufficient evidence for analytics-based procedures
- Use the mapped file without validation because the report is system-generated and therefore presumed accurate under PCAOB standards
Explanation: AS 1105 requires auditors to evaluate the reliability of information used as audit evidence, particularly when data transformations involve mapping or conversion logic. The appearance of negative inventory quantities after code mapping indicates potential errors in the conversion process that must be investigated before drawing conclusions about the existence assertion. The appropriate response involves validating the mapping logic through inspection of mapping tables, reperformance of conversions, and investigation of anomalies through source documents and physical procedures. Option A incorrectly dismisses negative quantities without investigation, potentially missing material misstatements. Option C inappropriately relies solely on inquiry for a substantive analytical procedure under PCAOB standards. Option D mischaracterizes PCAOB standards regarding system-generated reports, which still require validation when transformations are applied. The decision framework requires auditors to validate any data transformation that produces unexpected results before using the data to support audit conclusions.
Question 9
You are performing an attestation engagement (examination) for a nonissuer on management's assertion about compliance with a debt covenant that requires a minimum fixed-charge coverage ratio. Management provides a spreadsheet calculating the ratio using data exported from the general ledger and then manually reclassifies certain expenses as "nonrecurring." You note the reclassification entries are not supported by documentation and were not posted to the ledger. Which factor is critical in assessing the reliability of the transformed data used in the covenant calculation?
- Whether the spreadsheet uses consistent formulas across periods, regardless of whether reclassifications are supported
- Whether management has approved the reclassifications, since approval alone establishes that the data is suitable for the assertion
- Whether the auditor can obtain evidence supporting the manual reclassifications and reconcile the covenant calculation to underlying accounting records, including evaluating whether adjustments are in accordance with the covenant definition (correct answer)
- Whether the auditor performs the validation after issuing the examination report, because covenant calculations can be corrected in subsequent periods
Explanation: AT-C 315 requires the practitioner to obtain sufficient appropriate evidence to support the examination opinion on management's assertion about covenant compliance. Manual reclassifications without supporting documentation raise significant concerns about whether the covenant calculation accurately reflects the terms of the debt agreement. The critical factor is obtaining evidence that supports the reclassifications and ensures they align with the covenant definition, not merely management approval or spreadsheet consistency. Option A focuses on formula consistency rather than substantive support for adjustments. Option B incorrectly suggests management approval alone establishes suitability without documentary support. Option D inappropriately defers validation until after report issuance, violating the requirement to obtain sufficient evidence before expressing an opinion. The professional framework requires practitioners to validate all adjustments affecting compliance calculations, particularly unsupported manual entries that could materially affect the assertion.
Question 10
An auditor is using a data file of all sales invoices for the year to perform substantive analytical procedures. To test the completeness of the data file, which of the following procedures would be most effective?
- Compare the total number of records in the data file to the last sales invoice number issued during the year, assuming invoices are sequentially numbered. (correct answer)
- Select a sample of invoices from the data file and trace them to the corresponding shipping documents.
- Recompute the sales total from the data file and compare it to the general ledger sales account balance.
- Use data analytics to identify any duplicate invoice numbers within the data file.
Explanation: The correct answer is A. To test for completeness of the sales invoice data file, the auditor needs to verify that all invoices that should have been recorded are included. Comparing the record count to the sequence of prenumbered documents is a classic procedure to identify missing items. Choice B tests for existence/occurrence, not completeness. Choice C is a reconciliation that tests accuracy at an aggregate level but wouldn't detect omitted invoices if other errors offset them. Choice D tests for duplicates, which is the opposite of completeness.
Question 11
While preparing a client-provided accounts receivable aging report for analysis, an auditor notes that customer names are inconsistently entered (e.g., "ABC Corp.", "ABC Corporation", "ABC Co."). What is the most appropriate initial step for the auditor to take to transform this data for effective analysis?
- Request a new report from the client with standardized customer names.
- Use data cleansing techniques to standardize the customer names into a single, consistent format. (correct answer)
- Exclude all records with inconsistent customer names from the analysis.
- Send confirmations to a sample of customers regardless of the name inconsistency.
Explanation: The correct answer is B. This is a common data preparation or 'cleansing' task. To properly analyze data by customer, the names must be consistent. Auditors use data analysis tools to perform these standardization routines. Choice A is less efficient and may not be feasible for the client. Choice C would result in an incomplete analysis. Choice D is a substantive procedure that would be performed after preparing the data, and the inconsistencies would still make it difficult to select a representative sample by customer.
Question 12
An auditor is validating the accuracy of a payroll data extract provided by a client. The extract includes employee name, hours worked, and pay rate. Which procedure would provide the most persuasive evidence regarding the accuracy of the pay rates in the extract?
- Vouching a sample of pay rates from the data extract to the employees' official human resources files. (correct answer)
- Comparing the total payroll expense calculated from the extract to the amount recorded in the general ledger.
- Analyzing the pay rates in the extract for any outliers or unusual values.
- Recalculating the gross pay for a sample of employees using the hours and rates in the extract.
Explanation: The correct answer is A. To validate the accuracy of a specific data point (pay rate), the most persuasive evidence comes from comparing it to the authoritative source document or record, which in this case is the official HR file containing the authorized pay rate. Choice B is a high-level reconciliation. Choice C is an analytical procedure that may identify potential errors but does not confirm accuracy. Choice D tests the mathematical calculation but does not validate the accuracy of the pay rate data itself.
Question 13
An auditor is analyzing an inventory data file that contains fields for 'purchase_date' and 'sale_date'. To identify slow-moving inventory, the auditor needs to calculate the number of days each inventory item was held. Which data transformation step is necessary to perform this analysis?
- Filtering the data to show only items with a 'sale_date' in the current fiscal year.
- Creating a new calculated field by subtracting the 'purchase_date' from the 'sale_date'. (correct answer)
- Sorting the data by 'purchase_date' in ascending order.
- Joining the inventory file with the sales invoice file using the item number as a key.
Explanation: The correct answer is B. The objective is to calculate the holding period. This requires creating a new data point (a calculated field) derived from existing fields. Subtracting the purchase date from the sale date achieves this. Choices A, C, and D are other common data analysis techniques, but they do not accomplish the specific transformation of calculating the number of days an item was held.
Question 14
An auditor wants to perform a three-way match to test the occurrence of revenue transactions. The auditor has obtained separate data files for sales orders, shipping documents, and sales invoices. Which data transformation technique is essential to perform this test?
- Stratifying the sales invoice file by dollar amount.
- Joining the three files using a common field, such as sales order number. (correct answer)
- Summarizing the shipping document file by date.
- Filtering the sales order file for orders that have not been fulfilled.
Explanation: The correct answer is B. A three-way match involves linking records from three different datasets to ensure they all relate to the same valid transaction. The data transformation technique used to link datasets is called 'joining'. The auditor would join the files on a common key (like a sales order number or customer PO number) to verify that for every invoice, there is a related shipment and an authorized customer order. Choices A, C, and D are other data analysis procedures, but they are not the technique used for a three-way match.
Question 15
An auditor is considering two sources for a data file of employee wages to be used in substantive analytical procedures: (1) a spreadsheet manually prepared by the payroll clerk, and (2) a system-generated report from the payroll module, over which IT general controls are effective. Which of the following statements is correct regarding the reliability of this information?
- The spreadsheet is more reliable because the payroll clerk can add explanatory comments.
- Both sources are equally reliable if the totals reconcile to the general ledger.
- The system-generated report is generally considered more reliable due to the lower risk of manual error and manipulation. (correct answer)
- The reliability of either source is irrelevant if the auditor plans to perform tests of details on a sample.
Explanation: The correct answer is C. A fundamental principle of audit evidence is that evidence is more reliable when it is obtained from a source with effective controls. A system-generated report from an application with effective IT general controls is less susceptible to human error or intentional manipulation than a manually prepared spreadsheet. Choice A is incorrect; comments do not increase reliability. Choice B is incorrect; a macro-level reconciliation does not guarantee the integrity of the detailed data. Choice D is incorrect; the reliability of the population from which a sample is drawn is always a critical consideration.
Question 16
While preparing a fixed asset register data file for analysis, an auditor discovers that the 'in-service_date' field is missing for a significant number of assets. The auditor's objective is to recalculate depreciation for all assets. What is the most appropriate course of action?
- Assume a default 'in-service_date' of the first day of the fiscal year for all assets with missing dates.
- Remove the records with missing dates from the population before calculating depreciation.
- Discuss the missing data with management and request supporting documentation to populate the dates. (correct answer)
- Proceed with the depreciation calculation, noting a scope limitation in the audit report.
Explanation: The correct answer is C. The 'in-service date' is a critical piece of data for accurately calculating depreciation. When data is missing, the first step is always to inquire of management and attempt to obtain the correct information from underlying records (e.g., purchase invoices). Making assumptions (Choice A) or excluding records (Choice B) would lead to known errors in the auditor's analysis. Concluding a scope limitation (Choice D) is premature until the auditor has exhausted efforts to obtain the data.
Question 17
To test for fictitious vendors, an auditor plans to match the vendor master file against a public database of registered businesses. The client provides the auditor with a spreadsheet of the vendor master file via email. To best ensure the authenticity of the data being used for the test, the auditor should:
- Trust the spreadsheet provided by the client as it comes from an internal source.
- Obtain a system-generated, read-only download of the vendor master file directly from the client's system, preferably with observation. (correct answer)
- Ask the client to provide a screenshot of the first few pages of the vendor master file to confirm its existence.
- Confirm a sample of vendor addresses from the spreadsheet through an online search.
Explanation: The correct answer is B. The authenticity of audit evidence is crucial. A spreadsheet provided via email can be easily manipulated. By obtaining the data directly from the source system (and observing the download process, if possible), the auditor gains much greater assurance that the data is complete and has not been altered before being provided. This reduces the risk that fictitious vendors were removed from the file before it was sent to the auditor. Choice A lacks professional skepticism. Choice C provides very weak evidence. Choice D tests the accuracy of addresses but not the authenticity or completeness of the entire vendor file.
Question 18
An auditor has a detailed data file of every purchase transaction for the year. To perform a high-level substantive analytical procedure comparing monthly purchase trends year-over-year, which data transformation must the auditor perform first?
- Aggregate the transaction data by month. (correct answer)
- Select a random sample of transactions for each month.
- Test the data for outliers and remove them from the file.
- Vouch a sample of large purchases to receiving reports.
Explanation: The correct answer is A. The source data is at the individual transaction level. The desired analysis is at the monthly level. Therefore, the auditor must first transform the data by summarizing, or aggregating, the detailed transactions into monthly totals. Once this is done, the monthly totals can be used in the analytical procedure. Choices B and D are tests of details, not analytical procedures. Choice C might be part of the analysis, but aggregation must happen first.
Question 19
An auditor uses a scripting language (e.g., SQL, Python) to perform several data transformation and cleansing steps on a large, client-provided dataset. Which of the following is the best way for the auditor to document the procedures performed on the data?
- Write a narrative memo describing the steps taken from memory after the analysis is complete.
- Save the final, cleaned dataset in the audit file, overwriting the original file.
- Include the well-commented script in the workpapers along with a summary of the steps performed. (correct answer)
- Prepare a flowchart showing the high-level flow of data from the client to the auditor's analysis.
Explanation: The correct answer is C. Audit documentation must be sufficient to enable an experienced auditor, having no previous connection with the engagement, to understand the procedures performed. The script itself is the most precise record of the transformations. Including the commented script makes it understandable, and a summary memo provides context. This makes the work transparent and reviewable. Choice A is unreliable. Choice B destroys the original data and makes it impossible to review the transformation steps. Choice D is good for an overview but lacks the necessary detail of the specific steps taken.
Question 20
A client's IT department provides an auditor with a large data file of purchase transactions. To ensure the file was not altered during transfer to the audit team, the IT department also provides a hash total for the file. What is the auditor's responsibility regarding this hash total?
- Independently recalculate the hash total on the received file and compare it to the total provided by the client. (correct answer)
- Document the client-provided hash total in the workpapers as sufficient evidence of data integrity.
- Request that the client's internal audit department verify the hash total.
- Compare the hash total to the total dollar value of purchases in the general ledger.
Explanation: The correct answer is A. A hash total acts as a unique digital fingerprint for a file. The only way to verify that the file has not been corrupted or altered is for the auditor to use software to calculate a new hash total on the file they received and compare it to the original hash total provided by the client. If they match, the auditor has evidence of the file's integrity. Choice B provides no assurance. Choice C is an improper delegation of an audit procedure. Choice D misunderstands what a hash total is; it is a calculated value based on the file's contents, not a sum of financial data.