Skip to content

CMA Intermediate · Corporate Accounting and Auditing · Audit Risk, Internal Control, Internal Check and Internal Audit

An auditor of a manufacturing company notes that the entity relies on a fully integrated ERP. Which of the following is NOT stated in SA 315 as a general benefit of IT to an entity's internal control?

The statement that IT eliminates management's need to respond to IT risks is not a benefit stated in SA 315. The standard says the entity responds to risks from IT or manual elements by establishing effective controls suited to its information system, while IT's benefits include accuracy, timeliness and segregation of duties.

  1. AEnhancing timeliness, availability and accuracy of information
  2. BReducing the risk that controls will be circumvented
  3. CEnhancing the ability to achieve effective segregation of duties through security controls in applications, databases and operating systems
  4. DEliminating the need for management to respond to risks arising from the use of ITCorrect

Explanation

SA 315 lists A, B and C among the benefits of IT. It also says the entity responds to risks arising from the use of IT by establishing effective controls suited to its information system, so IT does not remove the need for a management response. Option D is therefore not a stated benefit and is contrary to the standard.

Did you get it right without looking?

One question tells you little. A timed set on Audit Risk, Internal Control, Internal Check and Internal Audit shows your real accuracy, how long you take and where you lose marks.

More Audit Risk, Internal Control, Internal Check and Internal Audit questions