โ† All CFP Flashcard Decks

Auditing Principles & Procedures Flashcards

7 cards from real CFP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Auditing Principles & Procedures flashcards as text
  1. Which of the following represents a 'compensating control' in a fintech environment where full segregation of duties is not feasible?

    Answer: Enhanced supervisory review and detailed management monitoring reports

    A compensating control substitutes for a missing primary control; enhanced supervisory review can mitigate the segregation-of-duties risk when staffing prevents full separation.

  2. An auditor is evaluating a peer-to-peer lending platform's loan loss reserve. Which procedure is most relevant?

    Answer: Testing the reasonableness of the credit loss model assumptions against actual historical default rates

    Loan loss reserves involve significant management estimates; auditors must evaluate whether model assumptions are supported by historical loss experience and current economic conditions.

  3. What is the primary purpose of an 'engagement letter' at the start of a fintech audit?

    Answer: To define the terms, scope, responsibilities, and fee structure of the audit engagement

    The engagement letter is a contractual document that establishes mutual understanding of the audit's scope, objectives, each party's responsibilities, and the fee arrangement.

  4. During a fintech audit, the auditor identifies a transaction routed through a jurisdiction on the FATF blacklist. What should the auditor do first?

    Answer: Assess the risk and determine whether management has applied adequate AML scrutiny and documentation

    The auditor's first step is to evaluate whether management identified and properly documented the risk, not to act as a law enforcement agent.

  5. Which of the following is a key indicator of a significant deficiency in internal controls under PCAOB standards?

    Answer: A deficiency that is less severe than a material weakness but merits attention by those charged with governance

    PCAOB AS 2201 defines a significant deficiency as an ICFR deficiency, or combination of deficiencies, that is less severe than a material weakness yet important enough to warrant governance attention.

  6. A fintech company uses third-party cloud infrastructure for all financial data processing. Which audit report should the auditor obtain to assess controls at the cloud provider?

    Answer: A SOC 1 Type II report from the cloud provider

    A SOC 1 Type II report provides independent assurance that the service organization's controls relevant to user entities' financial reporting were operating effectively over a defined period.

  7. Which approach best describes 'continuous auditing' as applied in a fintech context?

    Answer: Using automated tools to monitor transactions and controls in near real-time throughout the year

    Continuous auditing leverages automation and data analytics to monitor controls and transactions on an ongoing basis, enabling timely detection of anomalies rather than year-end sampling.