Compliance and Auditing Internal Controls 2 — Questions and Answers
Question 1: What is an 'IT general control' (ITGC) in the context of SOX compliance?
- A policy for general computer use
- Controls that apply broadly across IT systems to ensure overall IT integrity (Correct answer)
- A firewall configuration standard
- General guidelines for IT purchasing
Correct answer: Controls that apply broadly across IT systems to ensure overall IT integrity
IT General Controls (ITGCs) are controls that apply to all IT systems and infrastructure and are foundational to supporting the reliability of application controls and financial reporting.
Question 2: What is the purpose of a 'management review control' in financial reporting?
- To allow management to override audit findings
- To provide oversight through management's review and approval of financial results and reports (Correct answer)
- To review employee performance
- To assess the external auditor's work
Correct answer: To provide oversight through management's review and approval of financial results and reports
Management review controls involve senior management reviewing and approving financial information to detect and correct material misstatements before reports are finalized.
Question 3: Which principle requires that all financial transactions be supported by adequate documentation?
- Dual control
- Documented evidence (Correct answer)
- Audit trail integrity
- Record retention
Correct answer: Documented evidence
The documented evidence principle requires that every financial transaction have adequate supporting documentation to provide a verifiable record of what occurred and why.
Question 4: What is a 'user access review' (UAR) in IT compliance?
- A review of user satisfaction with IT systems
- A periodic review of user accounts and access rights to ensure they remain appropriate (Correct answer)
- An assessment of user training completion
- A review of IT help desk tickets
Correct answer: A periodic review of user accounts and access rights to ensure they remain appropriate
A User Access Review is a periodic process where managers confirm that employees' system access rights are appropriate for their current job roles and that terminated employees' access has been revoked.
Question 5: What does 'dual control' mean in banking and financial compliance?
- Using two different accounting systems
- Requiring two authorized individuals to complete a critical transaction (Correct answer)
- Having two layers of management approval
- Using two separate bank accounts
Correct answer: Requiring two authorized individuals to complete a critical transaction
Dual control (also called two-man rule or dual custody) requires two authorized individuals to be present and participate simultaneously in completing a sensitive or high-value transaction.
Question 6: What is the primary purpose of a bank reconciliation as an internal control?
- To prepare the annual financial statements
- To verify that the company's cash records match the bank's records and identify discrepancies (Correct answer)
- To calculate interest earned on deposits
- To authorize wire transfers
Correct answer: To verify that the company's cash records match the bank's records and identify discrepancies
Bank reconciliation is a control that compares the company's internal cash records with the bank statement to identify timing differences, errors, or unauthorized transactions.
What is an 'IT general control' (ITGC) in the context of SOX compliance?