Home › Certifications › CPA AUD › Internal controls
23 multiple-choice questions and 22 flashcards on Internal controls, about 6% of the CPA AUD bank. Every one carries a written rationale.
Internal controls is one of 6 chapters in CoStudy's CPA — Auditing & Attestation (AUD) [Core] bank, and it holds 23 of the bank's 410 multiple-choice questions — roughly 6% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
IT general controls typically include controls over:
Answer: C — Access, change management, and computer operations
A) That is an application/transaction-level control. B) Inventory counts are business-process controls. C) Correct — IT general controls (ITGCs) cover access, change management, computer operations, and program development — the environment supporting all applications. D) Fair-value valuation is a substantive matter.
A client's computer operations general controls include job scheduling and backup procedures. These controls are MOST directly intended to provide assurance that:
Answer: C — Data processing jobs run completely, in the correct sequence, and recoverable data exists if processing is disrupted
A) Manual journal entry authorization is a separate control activity unrelated to computer operations scheduling and backup. B) Revenue recognition policy compliance is an accounting matter, not a computer-operations general control objective. C) Correct — computer operations controls are designed to provide assurance that processing occurs completely and in proper sequence and that data can be recovered after disruption. D) Chart-of-accounts mapping relates to application configuration or master data controls, not computer operations scheduling and backup.
A control deficiency that is LESS SEVERE than a material weakness but merits attention by those charged with governance is a:
Answer: D — Significant deficiency in internal control
A) The lowest-level category does not require TCWG attention. B) 'Reportable condition' is legacy pre-2007 terminology. D) Correct — under AU-C 265 / AS 2201, a significant deficiency is less severe than a material weakness but important enough to merit governance attention. C) That is not a defined category.
Testing IT general controls over logical access is important to the auditor primarily because:
Answer: B — Weak access controls increase the risk that unauthorized users could initiate or alter transactions or data processed by otherwise reliable-looking application controls
A) Testing ITGCs does not eliminate the need to test application controls; they are complementary layers. B) Correct — inadequate access controls increase the risk that data or programs are altered inappropriately, undermining reliance on application controls even if those controls appear well designed. C) ITGC testing is relevant whenever the auditor intends to rely on IT-dependent controls, in both public and private company audits. D) Access control testing does not substitute for separate procedures addressing completeness of journal entries.
Under the COSO 2013 framework, the FIVE components of internal control are supported by:
Answer: A — Seventeen principles
C) There are more than five principles. B) There are not ten. A) Correct — COSO 2013 identifies 17 principles supporting the five components; each principle must be present and functioning. D) There are not fifty subprinciples in the framework.
Under SEC cyber-disclosure rules effective 2023, an issuer must disclose a material cybersecurity incident on:
Answer: A — Form 8-K generally within 4 business days
B) 10-K covers annual disclosures, not incident reporting. A) Correct — the SEC rule requires disclosure of a material cybersecurity incident on Form 8-K generally within 4 business days of determining materiality. C) 10-Q is not the trigger. D) S-1 is a registration filing, not a real-time incident report.
Which of the following is a required communication under AU-C 265 regardless of engagement scope?
Answer: C — Significant deficiencies and material weaknesses identified during the audit
A) Auditors are not required to communicate every trivial deficiency identified. B) Remediated items are still communicated if identified during the period under audit. C) Correct — AU-C 265 requires written communication of significant deficiencies and material weaknesses to management and those charged with governance, on a timely basis. D) The requirement is mandatory, not contingent on client request.
A reasonable possibility exists that a material misstatement will not be prevented or detected on a timely basis, and the potential magnitude could be material. This fact pattern MOST likely indicates a:
Answer: D — material weakness in internal control over financial reporting
A) A reasonable possibility of a material, undetected misstatement is precisely the threshold that elevates a deficiency to a material weakness. B) The fact pattern doesn't distinguish design from operating deficiencies; either could produce this result. C) Material weaknesses must be communicated to management and those charged with governance, not merely internal audit. D) Correct — AS 2201 / AU-C 265 define a material weakness as a deficiency (or combination) where there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis.
A control deficiency exists when a control is designed, implemented, or operated in a manner that:
Answer: A — does not allow management or employees to prevent or detect misstatements on a timely basis
A) Correct — AU-C 265 / AS 2201 define a control deficiency as one where the design or operation does not allow timely prevention or detection of misstatements. B) SEC referral is not part of the definition. C) An undocumented or unimplemented control describes one possible cause of a deficiency, not the general definition. D) Who identifies the deficiency (auditor vs. management) doesn't determine whether it exists.
An integrated audit under PCAOB AS 2201 is required when the client is a(n):
Answer: C — Accelerated or large accelerated SEC filer
A) Non-profits follow AICPA/GAGAS, not PCAOB. B) Non-issuer thresholds do not trigger PCAOB integrated audits. C) Correct — SOX §404(b) and AS 2201 require integrated audits for accelerated and large accelerated filers. D) Emerging growth companies are typically exempt from §404(b) auditor attestation.
4 cards from the 22 in this chapter.
Significant deficiency?
Less severe than a material weakness but important enough to merit attention from those charged with governance.
Why does weak change management undermine reliance on application controls?
Even a well-designed application control can't be relied upon if unauthorized, untested changes could have altered the program logic during the period.
AU-C 265 communication requirement?
Written communication of significant deficiencies and material weaknesses to management and those charged with governance, on a timely basis.
COSO internal control framework components?
Control environment, risk assessment, control activities, info & communication, monitoring.
These are a sample. The full Internal controls chapter runs 45 items with per-chapter progress tracking, on the web and in the iOS app.