The CA Hub
All CA Inter P5 chapters

CA Inter P5 ยท Chapter 3

Risk Assessment and Internal Control MCQs with Answers

13 multiple-choice questions on Risk Assessment and Internal Control for CA Inter P5 Auditing and Ethics. Try each one before revealing the answer and explanation.

Practise this chapter interactively
  1. Question 1

    The internal audit department of Kirat Foods Ltd. has tested inventory controls, and the statutory auditor decides to use this work under SA 610. Which statement is correct?

    • A) The external auditor retains sole responsibility for the audit opinion, which is not reduced by the use of the internal auditors' work
    • B) The external auditor must refer to the internal auditors' work in the auditor's report
    • C) Responsibility for the opinion is shared in proportion to the work done by the internal auditors
    • D) The external auditor may use the work without evaluating the objectivity or competence of the internal audit function
    Show answer & explanation

    Answer: A) The external auditor retains sole responsibility for the audit opinion, which is not reduced by the use of the internal auditors' work

    SA 610 makes clear that the external auditor has sole responsibility for the audit opinion, and this is not reduced by using the internal audit function's work. The auditor must first evaluate the function's objectivity, competence and systematic and disciplined approach. The auditor's report does not refer to the internal auditors' work.

  2. Question 2

    Audit risk is a function of:

    • A) Inherent risk and business risk only
    • B) Engagement risk and the auditor's fee
    • C) Control risk and sampling risk only
    • D) The risks of material misstatement and detection risk
    Show answer & explanation

    Answer: D) The risks of material misstatement and detection risk

    Audit risk is the risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated. It is a function of the risks of material misstatement (made up of inherent risk and control risk) and detection risk. Business risk is broader and only some of it gives rise to risks of material misstatement.

  3. Question 3

    The auditor of Prakash Chemicals Ltd. has assessed the risk of material misstatement for inventory valuation as high. The auditor should therefore:

    • A) Accept a higher detection risk because the inherent risk is already known
    • B) Accept a lower detection risk and obtain more persuasive audit evidence from substantive procedures
    • C) Lower materiality to zero for inventory and test every item without considering risk
    • D) Reduce substantive procedures and rely on management's representations
    Show answer & explanation

    Answer: B) Accept a lower detection risk and obtain more persuasive audit evidence from substantive procedures

    Detection risk varies inversely with the assessed risk of material misstatement for a given level of audit risk. A high assessed risk requires a lower acceptable detection risk, which means more persuasive evidence through changes in the nature, timing and extent of substantive procedures, for example larger samples or procedures closer to the year-end.

  4. Question 4

    Which of the following is NOT one of the risk assessment procedures listed in SA 315?

    • A) Observation and inspection
    • B) External confirmation of trade receivable balances
    • C) Inquiries of management and other appropriate individuals within the entity
    • D) Analytical procedures
    Show answer & explanation

    Answer: B) External confirmation of trade receivable balances

    SA 315 states that risk assessment procedures include inquiries of management and others, analytical procedures, and observation and inspection. External confirmation under SA 505 is generally used as a further audit procedure (substantive test) responding to assessed risks rather than as a risk assessment procedure.

  5. Question 5

    The auditor of Saanvi Realty Ltd. has identified revenue recognition on long-term contracts as a significant risk and plans to respond using only substantive procedures. Under SA 330, those procedures must:

    • A) Include tests of details
    • B) Be performed only at an interim date
    • C) Be limited to inquiries of the project managers
    • D) Consist only of substantive analytical procedures
    Show answer & explanation

    Answer: A) Include tests of details

    SA 330 requires that when the approach to a significant risk consists only of substantive procedures, those procedures shall include tests of details. Substantive analytical procedures alone are not considered sufficient for a significant risk, and inquiry alone never provides sufficient appropriate evidence.

  6. Question 6

    Which of the following is NOT a component of internal control described in SA 315?

    • A) The information system and communication
    • B) The control environment
    • C) The entity's risk assessment process
    • D) The external audit function
    Show answer & explanation

    Answer: D) The external audit function

    SA 315 describes the components of the entity's system of internal control as the control environment, the entity's risk assessment process, the information system (including related business processes) and communication, control activities, and monitoring of controls. The external auditor is independent of the entity and is not part of its internal control.

  7. Question 7

    At Ishaan Logistics Ltd., the stores keeper and the security guard together removed goods from the warehouse and prepared matching false gate passes. The controls were well designed but failed. This is an example of which inherent limitation of internal control?

    • A) Controls designed only for routine transactions
    • B) Collusion among two or more people
    • C) The cost of a control exceeding its benefit
    • D) Management override of controls
    Show answer & explanation

    Answer: B) Collusion among two or more people

    Internal controls, however well designed, can be circumvented when two or more people collude, because segregation of duties relies on one person checking another. Here the stores keeper and guard acted together, defeating the control. Management override involves management, which is not the case.

  8. Question 8

    In Vritika Stores Pvt. Ltd., the cashier who receives cash from customers also posts entries to the customers' ledger accounts. This arrangement is weak because it:

    • A) Prevents the use of computerised accounting
    • B) Combines authorisation with execution of purchase orders
    • C) Violates the requirement that cash be banked daily
    • D) Combines custody of assets with recording of transactions, allowing misappropriation to be concealed
    Show answer & explanation

    Answer: D) Combines custody of assets with recording of transactions, allowing misappropriation to be concealed

    Effective segregation of duties separates authorisation, recording and custody of assets. A cashier who also maintains the customer ledger can misappropriate receipts and conceal it by manipulating ledger entries, for example through teeming and lading. The weakness lies in combining custody with recording.

  9. Question 9

    The auditor of Harshil Steel Ltd. tested a control over credit approvals last year and found it effective. The control mitigates a significant risk. There is no change in the control this year. Under SA 330, the auditor intending to rely on it:

    • A) May rely on last year's test without further work, as the control has not changed
    • B) May rely on last year's test until the third audit, as permitted for all unchanged controls
    • C) Need only inquire of management whether the control has changed
    • D) Must test the operating effectiveness of the control in the current period
    Show answer & explanation

    Answer: D) Must test the operating effectiveness of the control in the current period

    SA 330 allows the auditor to use evidence from previous audits about unchanged controls, testing them at least once in every third audit. However, where the auditor plans to rely on controls over a risk that has been determined to be significant, the controls shall be tested in the current period. Inquiry alone is insufficient to test operating effectiveness.

  10. Question 10

    Which of the following is a test of control rather than a substantive procedure?

    • A) Obtaining a balance confirmation from a supplier
    • B) Recomputing depreciation charged on a sample of assets
    • C) Inspecting a sample of purchase orders for the signature of the authorised purchase manager
    • D) Comparing the year-end payables balance with an expectation based on purchases
    Show answer & explanation

    Answer: C) Inspecting a sample of purchase orders for the signature of the authorised purchase manager

    Tests of controls evaluate whether controls operated effectively, for example by inspecting documents for evidence of authorisation. Supplier confirmations, recomputation of depreciation and analytical comparison of payables are substantive procedures designed to detect material misstatements at the assertion level.

  11. Question 11

    Which of the following is an application control in an IT environment?

    • A) An input check that rejects a sales order when the quantity field is left blank
    • B) A procedure requiring approval and testing before program changes are moved to production
    • C) Daily backup of data to an off-site data centre
    • D) A policy requiring users to change their passwords periodically
    Show answer & explanation

    Answer: A) An input check that rejects a sales order when the quantity field is left blank

    Application controls operate at the level of individual applications and transactions, such as input validation, edit checks and matching. Password policies, program change management and backups are general IT controls that support the continued functioning of application controls across systems.

  12. Question 12

    During the audit of Mehar Textiles Ltd., the auditor identifies a deficiency in internal control that, in the auditor's judgment, is a significant deficiency. Under SA 265, the auditor shall:

    • A) Communicate it only if management has not already rectified it before the year-end
    • B) Communicate it in writing to those charged with governance on a timely basis, and also communicate it to management at an appropriate level
    • C) Communicate it orally to the accountant and record the discussion in the working papers
    • D) Disclose it in the Opinion section of the auditor's report
    Show answer & explanation

    Answer: B) Communicate it in writing to those charged with governance on a timely basis, and also communicate it to management at an appropriate level

    SA 265 requires significant deficiencies to be communicated in writing to those charged with governance on a timely basis. They must also be communicated to management at an appropriate level, unless inappropriate in the circumstances. Other deficiencies of sufficient importance are communicated to management. Internal control deficiencies are not reported in the opinion paragraph under SA 265.

  13. Question 13

    An auditor uses the audit risk model AR = IR x CR x DR. Acceptable audit risk is 4%, inherent risk is assessed at 80% and control risk at 50%. What is the maximum acceptable detection risk?

    • A) 5%
    • B) 8%
    • C) 10%
    • D) 1.6%
    Show answer & explanation

    Answer: C) 10%

    DR = AR / (IR x CR) = 0.04 / (0.80 x 0.50) = 0.04 / 0.40 = 0.10, or 10%. 8% results from ignoring inherent risk (0.04/0.50), 5% from ignoring control risk (0.04/0.80), and 1.6% from multiplying instead of dividing (0.04 x 0.40). A lower acceptable detection risk would call for more substantive work.

Sponsored slot availableRun a CA academy or hiring firm? Put your name in front of students preparing for this exam.Advertise โ†’