FAC Finance and Accounting Auditing & Risk Review 2 — Questions and Answers
Question 1: Which type of audit opinion is issued when financial statements contain a material misstatement that is pervasive to the overall financial statements?
- Qualified opinion
- Adverse opinion (Correct answer)
- Disclaimer of opinion
- Unmodified opinion
Correct answer: Adverse opinion
An adverse opinion is issued when material misstatements are both material and pervasive, meaning the financial statements do not present fairly in conformity with GAAP.
Question 2: In enterprise risk management (ERM), the COSO framework identifies how many interrelated components?
- 5
- 6
- 8 (Correct answer)
- 10
Correct answer: 8
The original COSO ERM framework identifies eight interrelated components: internal environment, objective setting, event identification, risk assessment, risk response, control activities, information & communication, and monitoring.
Question 3: A company's board audit committee is reviewing a situation where the external auditor also provides tax consulting services. This creates which type of threat to auditor independence?
- Advocacy threat
- Self-review threat
- Self-interest threat (Correct answer)
- Familiarity threat
Correct answer: Self-interest threat
Providing additional paid services creates a self-interest threat because the auditor may benefit financially from retaining the client relationship.
Question 4: When assessing inherent risk during an audit, which factor would MOST increase the assessed level?
- Strong internal controls over financial reporting
- Complex transactions involving significant estimates (Correct answer)
- Stable industry with low regulatory oversight
- Long-tenured management with no turnover
Correct answer: Complex transactions involving significant estimates
Complex transactions requiring significant management estimates increase inherent risk because they are more susceptible to material misstatement before considering controls.
Question 5: Under the Sarbanes-Oxley Act (SOX) Section 404, management must assess the effectiveness of internal control over financial reporting (ICFR) as of which date?
- The date the auditor's report is issued
- The end of the most recent fiscal year (Correct answer)
- The date the audit engagement begins
- Any date chosen by management
Correct answer: The end of the most recent fiscal year
SOX Section 404 requires management's assessment of ICFR effectiveness to be as of the end of the company's most recent fiscal year.
Question 6: In a risk-based audit approach, which sequence correctly reflects the audit planning process?
- Perform substantive tests → assess risk → understand internal controls
- Understand entity → assess risk → design audit procedures (Correct answer)
- Design audit procedures → identify risks → perform tests of controls
- Gather evidence → assess risk → issue opinion
Correct answer: Understand entity → assess risk → design audit procedures
The risk-based audit approach flows from understanding the entity and its environment, to assessing risks of material misstatement, to designing appropriate audit procedures.
Question 7: Which internal control activity is BEST described as comparing actual financial results with budgeted amounts and investigating significant variances?
- Segregation of duties
- Physical safeguards
- Performance reviews (Correct answer)
- Information processing controls
Correct answer: Performance reviews
Performance reviews involve comparing actual results to budgets, forecasts, or prior periods to identify unexpected variances that may indicate errors or fraud.
Which type of audit opinion is issued when financial statements contain a material misstatement that is pervasive to the overall financial statements?