0% found this document useful (0 votes)
120 views6 pages

CIA Part 2 Internal Audit Insights

The document outlines key concepts related to internal auditing, including the importance of reliable information, methods for gathering feedback, and the COSO internal control framework. It discusses the selection process for audit staff, risk assessment methods, and the significance of effective communication between auditors and management. Additionally, it emphasizes the need for proper documentation and evidence in audits, as well as the responsibilities of auditors in various scenarios.

Uploaded by

Rahul Menon
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
120 views6 pages

CIA Part 2 Internal Audit Insights

The document outlines key concepts related to internal auditing, including the importance of reliable information, methods for gathering feedback, and the COSO internal control framework. It discusses the selection process for audit staff, risk assessment methods, and the significance of effective communication between auditors and management. Additionally, it emphasizes the need for proper documentation and evidence in audits, as well as the responsibilities of auditors in various scenarios.

Uploaded by

Rahul Menon
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

CIA Part 2 Notes

Information means output which is reporting

Data means input

If controls are effective, then output (information) is reliable.

Reliability means free from bias and comes from a credible source. If controls are adequate and
effective, then we can rely on the information (output) because it is free from bias.

In scope questions, ask myself if the answers presented will add any helpful information to the audit
being addressed.

The three methods of gathering feedback include observing, analyzing, and questioning.

The selection process for an internal audit staff person begins with an accurate position description,
followed by determining the desired skills, knowledge and abilities for the successful candidate;
composing interview questions that will determine if the applicant has the desired skills and experience;
and finally interviewing applicants.

Appropriate use of computer simulation is for testing changes, such as impact of alternative purchasing
policies on investment in inventory, a “what if” type of evaluation.

The CAE selects the auditee and the scope of the audit.

The operational managers of the area being audit should participate in the discussions of draft versions
of observations and recommendations.

The COSO internal control framework consists of five interrelated components:

1. Control environment
a. Ex: Competence of accounting personnel (the staff)
2. Risk assessment
a. Ex. Complexity of accounting transactions (The produce of the work)
3. Control activities
a. Ex. Segregation of duties (the work duties)
4. Information and communication
5. Monitoring

Gross margin = GM
1. Sales – COGS = Sales net
2. Sales net/Sales = GM
The following preprocess controls provides assurance about validity transactions:
- Verification of the requestor: the identity of the requestor should be verified.
- Authentication of information: Information should be authenticated before transfer.
- Exception processing: Information that is not authenticated is an exception that should be
identified for additional processing.

Decryption may need to occur after information is received, but encryption is what occurs when
information is encoded for transfer.

The best type of graphic for comparing the sizes of various departmental budgets as part of the overall
company budget is a pie chart. The pie chart is suitable for showing proportion and relationships. The
pie chart is a graphical picture of information in which each portion of data is represented as a pie-
shaped part of a circle. This will give the proportionate sizes of the various departmental budgets
compared to each other.

An auditor used a mean-per-unit sampling plan to estimate the average cost of repairing photocopy
machines. The sample size was 50 and the population size was 2,000. The mean of the sample was $75.
The standard deviation was $14 and the standard error of the mean was $2. The confidence interval at a
95% confidence level (Z = 2) is $71 to $79.

The mean plus and minus two standard errors represent the confidence interval. In this case:

• $75 - ($2 × 2) = $71; this represents the lower limit of the confidence interval.
• $75 + ($2 × 2) = $79; this represents the upper limit of the confidence interval.

An online information service is interactive.

If there is a material finding and management is asking to hold off on the final communication due to
missing information, then the CAE should inform the audit committee of the outcome of earlier
meetings with management and the options being considered for recording the inventory adjustment

The Standards prescribe informing the board of management's decision on significant audit findings.

The Standards prescribe highlighting significant audit findings and recommendations and reporting on
the approved audit work schedule.

The auditor does not yet know if the inventory issue is actually a problem which can adversely affect the
organization.

A great deal of time can be saved by scanning documents into the computer rather than typing notes,
and scanning complete documents provides more evidence than notes. While noting the source of
evidence rather than scanning or copying the evidence itself might be a quicker technique, it would not
provide sufficient data for the workpapers; the reviewer of the workpapers could not verify the evidence
used by the auditor without going to find the data himself or herself.
The auditor completed work on a segment of the audit program. It was clear that a problem existed that
would require a modification of the organization's distribution procedures. The auditee agreed and has
implemented revised procedures. The internal auditor should indicate in the audit report that the
auditee determined and implemented corrective action.

Ranking methods used to prioritize risk


- absolute ranking.
- relative ranking.
- matrix ranking.

Absolute ranking ranks risk measurement scores and places them in order of magnitude. Relative ranking
groups risk measurement scores into natural categories and assigns relative values such as high,
medium, and low. Matrix ranking uses a risk matrix to compare risk by placing measured probability and
severity of risk in a matrix form.

Expected loss is a risk measurement method, not a risk prioritization method.

Reliable evidence is the best attainable information through the use of appropriate engagement
techniques. It is reasonably free from error and bias and faithfully represents that which it purports to
represent.

Circumstantial evidence proves an intermediate fact, or group of facts, from which still other facts can be
inferred. Evidence that still needs another evidence to prove its right

corroborative evidence Is supplementary to other evidence already gathered and which tends to
strengthen or confirm. While corroborative evidence may be reliable, much reliable evidence is primary
rather than supplementary. If you accuse your neighbor of denting the door of your car, a corresponding
dent in her bumper could be corroborating evidence. Something that can prove what you are saying is
right.

physical evidence Is obtained by observing people, property, and events. All physical evidence is not
necessarily reliable; in fact, the quality of reliability is more often associated with documentary evidence.

The design of analytical procedures to be used in an audit requires imagination on the part of the
internal auditor. There must be thought, and imagination used by the internal auditor in designing
analytical procedures.

The cross-reference of individual payroll timecards to personnel department records and reports allows
an auditor to conclude that individuals are bona fide employees. If personnel records exist for
employees for whom a timecard exists, the bona fide nature of employment is a reasonable conclusion.

You can use consultants with expertise in a specialize skill to


- conduct an audit of the organization which include that consultant’s skill
- and train IA staff to conduct audit in that consultant’s expertise

The objectives of internal accounting control as stated in AICPA Professional Standards, Volume 1 are:
a. Transactions are executed in accordance with management's general or specific authorization.
b. Transactions are recorded as necessary:
1. to permit preparation of financial statements in conformity with generally accepted
accounting principles or any other criteria applicable to such statements and
2. to maintain accountability for assets.
c. Access to assets is permitted only in accordance with management's authorization.
d. The recorded accountability for assets is compared with the existing assets at reasonable
intervals and appropriate action is taken with respect to any differences.

Discuss the deficiency with the branch manager before drafting the written audit report. If the auditor
and branch manager agree upon corrective action, include both the deficiency and corrective action in
the audit report is correct. This approach takes nothing away from the auditor, and it builds a problem-
solving partnership between the auditor and branch manager.

Top management should be made aware of significant deficiencies that have existed, even though they
may have been corrected by the time the audit report is issued.

Discussion prior to issuing the report helps insure that there have been no misunderstandings or
misinterpretations of fact and provides the branch manager the opportunity to clarify specific items.

Discussions prior to issuing the report helps insure that there have been no misunderstandings or
misinterpretations of fact and provide the branch manager the opportunity to clarify specific items.
Discussion after issuing the report may be required for follow-up.

According to the Standards, the correct listing of the information that must be included in a fraud report
is Observations, conclusions, opinions, recommendations, and action plans (corrective action).

All of the following potential explanations could explain the increase in gross margin, which is calculated
as revenue less cost of goods sold:
1. The company has developed a new manufacturing process that is much more efficient. This
would increase the number of products that could be produced and sold and therefore could
increase revenue.
2. Sales price per unit has increased. All else remaining equal, a higher sales price means more
revenue.
3. Inventory is overstated. If inventory is overstated, cost of goods sold would decrease, resulting
in a higher gross margin.

The risk assessment component of the internal control system logically follows the establishment of the
control environment. Once the control environment of the internal control system is in place,
management can assess the risks to achieving its objectives.
Appropriate starting point for a compliance evaluation of software licensing requirement would be to
determine if software installation is controlled centrally or distributed through the organization. The
logical starting point is to determine the point(s) of control.

While assisting the external auditor, the internal auditor should be supervised by the external auditor.
An external audit team sometimes finds it efficient to utilize a client's internal auditor personnel. On
such occasions, the internal auditors should work under the supervision of the external audit team.
However, the responsibility for audit decisions remains with the external auditors.

In a comprehensive audit of a not-for-profit activity, an internal auditor would be primarily concerned


with the extent of achievement of the organization's mission. Not-for-profit organizations are funded to
accomplish a specific goal or mission. Compliance, although rightfully included in a comprehensive
audit, is not the primary issue in an audit of not-for-profit entities.

A list of the key core competencies and specialties of each audit staff member would not be helpful in
assisting the internal audit manager in planning the annual audit staff schedule for effective use of time.
Although a list of the key core competencies and specialties of each audit staff member would help
assign staff members to audits that best utilize their competencies, it does not address the
management of time resources. What would be helpful are
- A listing of all upcoming planned vacations for each staff member
- A listing of all audits on the current audit plan
- A Gantt chart that divides each audit on the audit plan into sequential activities with estimated
start and completion times

The effectiveness of outsourcing the IT audit function would not be a consideration of the chief audit
executive when determining the internal audit resource requirements for the annual internal audit
plan. Resource management involves consideration of the following:

- Staffing plans
- Financial budgets
- The knowledge, skills, and other competencies of the internal audit staff
- The knowledge, skills, and other competencies required to perform the engagements
- The number and quality of auditors required

Outsourcing the IT audit function may be necessary if the internal audit department does not have the
knowledge, skills, and other competencies required to perform IT audit engagements.

Proper valuation of inventory and review of control systems against established criteria are both part
of an internal control system.

Observing inventory transactions would not likely identify material thefts.


A reasonable objective of an audit to audit a forecast model would be to verify that for varying input
values the model gives results consistent with revenue behavior. Pretty much testing that input and
output are consistent.

All of the items listed are important pieces of evidence that might be included in the workpapers.

- Minutes of the board of directors or key committees can be used, for example, to show that a
particular project was approved and authorized by the board.
- Schedules prepared by a department can be used, for example, as a starting point to test the
validity of that document.
- Policy or procedure manuals can be important documents to show what the correct practices
are for a segment of the organization. This is especially important when it concerns controls.

Just because the client says they’ll adjust something doesn’t mean its valid. Its not valid until it can be
confirmed.

If there is not a proper segregation of duty, then the internal controls are inadequate even if cash
account is properly reconciled and no cash shortage were detected.

Precision is the range within the estimate of the population characteristic is expected to fall.

The auditors may not be in the best position to determine whether the trading is fraudulent and
certainly are not in a position to report the information to government officials. The CAE should
discontinue audit work associated with the insider trading. Report the preliminary findings to the
chairperson of the audit committee and recommend an investigation.

The environmental manager proposes a minimal approach that will safely manage waste as well as keep
the company in compliance with applicable regulations. The auditor prefers an approach that would
correct the deficiencies but also enhance operations, believing that the company has an obligation to go
beyond compliance. The auditor should accept the proposed corrective action. It is management's
responsibility to determine policy and set performance goals; the auditor is not necessarily in a position
to insist on actions that may be perceived as extraordinary by operations management.

Marketing director oversees product distribution.

Common questions

Powered by AI

An efficient manufacturing process increases output and reduces costs, directly lowering the cost of goods sold and thus increasing the gross margin. Other factors affecting gross margin include an increase in sales price per unit, which will boost revenue if quantities sold remain stable, and potential inventory overstatements, which artificially reduce the cost of goods sold by misrepresenting inventory levels .

Working collaboratively with operational managers to address discrepancies results in a problem-solving partnership, facilitating corrective action implementation and improving process ownership. It ensures managerial buy-in and minimizes resistance, enhancing the effectiveness of corrective measures. This approach supports building mutual understanding, averting potential misunderstandings, and encourages proactive engagement with audit findings, ultimately strengthening organizational processes and control environments .

In not-for-profit organizations, the internal auditor focuses primarily on the extent of achievement of the organizational mission, as these entities aim to fulfill specific goals rather than generate profits. Unlike for-profit audits that focus on financial performance, not-for-profit audits emphasize mission effectiveness, resource allocation alignment, and compliance with donor-imposed restrictions. This requires a deep understanding of program objectives and community impact, alongside financial considerations .

Absolute ranking involves ordering risk measurement scores by magnitude, providing a straightforward hierarchy of risks from highest to lowest. This method is useful for prioritizing risks when decisions must be made based on clear numerical thresholds. Relative ranking groups risks into categories (high, medium, low) and assigns relative values, enabling a more nuanced assessment that can adapt to changing circumstances and allow for trade-offs between categories. Absolute ranking is advantageous for pinpoint accuracy, while relative ranking offers flexibility and ease of communication among stakeholders .

Fraud reports must include observations, conclusions, opinions, recommendations, and action plans (corrective actions). Observations provide facts detected during the audit. Conclusions interpret the findings, while opinions offer expert assessments of their implications. Recommendations guide remediation efforts to address identified issues. Action plans ensure accountability and track corrective action progress. Together, these components ensure comprehensive understanding, promote responsive management engagement, and support enhancements to prevent future occurrences, thus maintaining the credibility and effectiveness of fraud investigations .

Physical evidence is obtained by direct observation and can include tangible proofs such as property or events. Unlike documentary evidence, its reliability can be questionable as it may be subject to interpretation and environmental factors affecting the observation. It requires corroboration from other evidence types to strengthen its credibility. Challenges include ensuring accuracy in recording observations and preventing bias from affecting the interpretation of the physical evidence .

The mean-per-unit sampling plan estimates average costs by determining the mean of a sample and applying it to the population. Its reliability hinges on sample size relevance and accurate representation of the population. While mean-per-unit sampling can produce confidence intervals offering statistical assurance (e.g., a 95% confidence level at $71 to $79), errors may arise from assumptions about sample conformity to the overall population. An incorrect sample may mislead audit conclusions, necessitating careful design and validation of sampling technique .

The control environment is a foundational component in the COSO internal control framework, influencing the organizational culture and the way controls are perceived and implemented. It includes the competence of accounting personnel, ethical values, and the operating style of management. A strong control environment sets the tone for the organization and provides the necessary structure and discipline. It influences other components by determining the level of risk assessment needed, the effectiveness of control activities, the adequacy of information and communication, and the thoroughness of monitoring mechanisms .

An internal audit manager needs timely and efficient resource allocation, which requires a complete understanding of staff availability and audit timelines. Information such as planned staff vacations, current audit plans, and a Gantt chart detailing activities with projected timelines is more critical for managing time resources effectively than understanding individual staff competencies, which serves a different purpose of skill alignment. Ensuring availability and alignment with the audit calendar minimizes disruptions and optimizes resource utilization .

When material findings are present and management wishes to delay communication, the CAE should promptly inform the audit committee of earlier discussions with management and the potential consequences of not addressing the findings. The Standards prescribe that significant audit findings must be highlighted and reported to the board. The CAE must assess the risks of delaying communication, including potential impacts on decision-making and regulatory compliance, while ensuring transparency to uphold the integrity and purpose of the audit process .

You might also like