ICAEW ARF ยท Chapter 4
Internal control systems and IT controls MCQs with Answers
12 multiple-choice questions on Internal control systems and IT controls for ICAEW ARF Assurance and Risk Fundamentals. Try each one before revealing the answer and explanation.
Practise this chapter interactivelyQuestion 1
Which of the following is NOT a component of an entity's system of internal control?
- A) The control environment
- B) The entity's risk assessment process
- C) The external auditor's substantive procedures
- D) Control activities
Show answer & explanation
Answer: C) The external auditor's substantive procedures
The components of internal control are the control environment, the entity's risk assessment process, its process to monitor internal control, the information system and communication, and control activities. The external auditor's procedures are part of the audit, not part of the entity's own internal control.
Question 2
Which of the following forms part of the control environment?
- A) The attitude of those charged with governance towards internal control
- B) Monthly bank reconciliations
- C) Passwords restricting access to the sales ledger
- D) Sequential numbering of sales invoices
Show answer & explanation
Answer: A) The attitude of those charged with governance towards internal control
The control environment includes the governance and management functions and their attitudes, awareness and actions concerning internal control, including commitment to integrity and ethical values. Bank reconciliations, passwords and sequential numbering are specific control activities that operate within that environment.
Question 3
Which of the following is a detective control rather than a preventive control?
- A) Authorisation of purchase orders before they are sent to suppliers
- B) Monthly reconciliation of purchase ledger balances to supplier statements
- C) Restricting physical access to the inventory store
- D) Checking a customer's credit limit before accepting an order
Show answer & explanation
Answer: B) Monthly reconciliation of purchase ledger balances to supplier statements
A detective control identifies errors or irregularities after they have happened, so that they can be corrected. Reconciling supplier statements reveals differences already recorded in the ledger. Authorising orders, restricting access and credit checks all operate before the transaction or event, so they are preventive.
Question 4
Which of the following combinations of duties shows the most serious lack of segregation of duties?
- A) One employee prepares sales invoices and another posts them to the receivables ledger
- B) One employee orders goods and another checks them on delivery
- C) One employee both receives customer cheques and maintains the receivables ledger
- D) One employee prepares the payroll and the finance director authorises the payment
Show answer & explanation
Answer: C) One employee both receives customer cheques and maintains the receivables ledger
Good segregation separates custody of assets from recording of the related transactions. An employee who handles cheques and maintains the receivables ledger could steal receipts and conceal it by manipulating customer accounts, for example by teeming and lading. The other combinations involve two different people at the key stages.
Question 5
Which of the following is an IT general control?
- A) Regular back-up of data, with copies stored securely off-site
- B) Check digit verification on customer account codes
- C) Batch totals agreed before and after processing
- D) A range check that rejects weekly hours above a set maximum
Show answer & explanation
Answer: A) Regular back-up of data, with copies stored securely off-site
General IT controls apply to the whole IT environment, for example back-ups, access security, program development and change controls. Check digits, batch totals and range checks are application controls, which relate to the input, processing and output of a particular application.
Question 6
A computerised sales system performs a sequence check on sales invoice numbers. What is the main purpose of this control?
- A) To ensure that invoices are calculated at the correct prices
- B) To ensure that sales are only made to customers who are creditworthy
- C) To identify missing or duplicated invoice numbers, supporting the completeness of recorded sales
- D) To ensure that invoices are posted to the correct customer accounts
Show answer & explanation
Answer: C) To identify missing or duplicated invoice numbers, supporting the completeness of recorded sales
A sequence check looks for gaps and duplicates in a numbered sequence, so it helps ensure that every invoice raised is recorded once only. Pricing accuracy relies on controls over price lists, credit risk is controlled by credit checks, and correct posting is supported by controls such as check digits on account codes.
Question 7
Two cheque signatories, each required to approve every payment, agree together to sign payments to a fictitious supplier they have set up. Which inherent limitation of internal control does this illustrate?
- A) Collusion
- B) Management override
- C) Human error
- D) Controls designed for routine transactions only
Show answer & explanation
Answer: A) Collusion
The control of two signatories relies on each acting independently. When two or more people agree to act together to circumvent the control, it is collusion, which internal control cannot fully prevent. Management override occurs when a manager instructs others to bypass controls, and human error involves mistakes rather than deliberate fraud.
Question 8
Which of the following is a test of control?
- A) Inspecting a sample of purchase invoices for evidence of approval by the purchasing manager
- B) Agreeing a sample of payables ledger balances to supplier statements
- C) Recalculating the year-end accrual for electricity
- D) Comparing this year's wages expense with last year's
Show answer & explanation
Answer: A) Inspecting a sample of purchase invoices for evidence of approval by the purchasing manager
Tests of control obtain evidence about whether controls operated effectively during the period, such as looking for evidence that invoices were approved. Agreeing balances to supplier statements, recalculating accruals and comparing wages year on year are substantive procedures that seek evidence directly about the amounts.
Question 9
How should an auditor communicate significant deficiencies in internal control identified during an audit?
- A) Orally to the accounts clerk responsible for the relevant area
- B) In the opinion section of the auditor's report
- C) In writing to those charged with governance on a timely basis
- D) Only when the shareholders ask about internal control at the annual general meeting
Show answer & explanation
Answer: C) In writing to those charged with governance on a timely basis
Auditing standards require significant deficiencies to be communicated in writing to those charged with governance on a timely basis. Other deficiencies may be reported to management at an appropriate level. Control weaknesses do not by themselves modify the auditor's opinion, which concerns the financial statements.
Question 10
Which of the following would NOT normally be included in an auditor's report to management on internal control deficiencies?
- A) A description of each deficiency found
- B) An explanation of the possible effects of each deficiency
- C) A recommendation for improving each control
- D) A statement that the auditor has identified all of the deficiencies in the company's internal control
Show answer & explanation
Answer: D) A statement that the auditor has identified all of the deficiencies in the company's internal control
A report on deficiencies normally sets out each deficiency, its possible consequences and a recommendation. It also explains that the audit was not designed to identify all deficiencies, because the auditor considers controls only to the extent needed to design audit procedures. Claiming to have found all deficiencies would be misleading.
Question 11
Which of the following controls best prevents unauthorised changes being made to a company's accounting software?
- A) Program changes are tested and approved by users and IT management before being moved into the live environment
- B) Data input is checked using validity and range checks
- C) Hash totals are calculated on batches of payroll data
- D) The cash book is reconciled to the bank statement each month
Show answer & explanation
Answer: A) Program changes are tested and approved by users and IT management before being moved into the live environment
Program change controls are general IT controls designed to ensure that only authorised, tested changes are made to live programs. Validity checks, range checks and hash totals are application controls over data rather than programs. A bank reconciliation is a manual detective control over cash.
Question 12
What is the main purpose of a walk-through test?
- A) To confirm the auditor's understanding of the system by following a transaction through it from start to finish
- B) To provide substantive evidence for the year-end balance
- C) To test whether a control operated effectively throughout the year
- D) To select a statistical sample of transactions for testing
Show answer & explanation
Answer: A) To confirm the auditor's understanding of the system by following a transaction through it from start to finish
In a walk-through test the auditor traces one or a few transactions through the system to confirm that it operates as documented, for example in flowcharts or narrative notes. It is not enough to show that controls worked throughout the period, which requires tests of control on a sample, and it does not provide substantive evidence on balances.
