Download as docx, pdf, or txt
Download as docx, pdf, or txt
You are on page 1of 1

Review Questions

3. They are application controls and general controls. General controls are not application
specific, but apply to all systems. Application controls ensure validity, completeness, and
accuracy of financial transactions.
Discussion Questions
1. The key features of section 302 in SOX is that the CEO has to certify the financial statements
and other information in the organizations quarterly and annual reports. Management also has to
certify internal controls over the financial reporting.
2. The key features of section 404 is that management has to assess effectiveness of their internal
controls and financial reporting. The following points must be covered: flow of transactions,
assessing both design and operating effectiveness, assess potential fraud, evaluate adequacy of
controls, and finally evaluate entity-wide controls that correspond to COSO.
6. General controls are not application-specific because they apply to all systems. They have an
effect on transaction integrity. General controls are there to support the environment in which
application controls are there to function.
8. The data collection stage is the most common way to commit computer fraud. Very few
computer skills are needed by the one committing fraud. Its also important to commit computer
fraud, that there needs to be poorly designed controls. The person committing fraud just needs to
know how the system works to commit fraud.
13. The attest function is the individual auditors responsibility to have a fair presentation of the
clients financial statements. An assurance service is there for the clients organization to
improve operational efficiency and effectiveness.

You might also like