Skip to content

CA Final · Advanced Auditing, Assurance and Professional Ethics · Materiality, Risk Assessment and Internal Control

Nova Retail Ltd has recently migrated to an automated billing system. The auditor is assessing risks under SA 315. Which statement about the entity's response to risks from IT use or manual elements is consistent with SA 315?

Under SA 315, risks to internal control vary with the nature and characteristics of the entity's information system, and the entity responds by establishing effective controls suited to those characteristics. IT reduces but does not eliminate risks, and neither manual nor automated elements are always safer.

  1. AThe entity responds by establishing effective controls in light of the characteristics of its information systemCorrect
  2. BIT eliminates the risk of controls being circumvented entirely, so no risk assessment is needed
  3. CThe extent of risks to internal control is the same regardless of the information system
  4. DManual elements always carry lower risk than automated elements

Explanation

SA 315 says the extent and nature of risks to internal control vary with the characteristics of the entity's information system, and the entity responds by establishing effective controls in light of those characteristics. IT only reduces the risk of circumvention; it does not eliminate it. The other options make absolute claims that the standard does not support.

Did you get it right without looking?

One question tells you little. A timed set on Materiality, Risk Assessment and Internal Control shows your real accuracy, how long you take and where you lose marks.

More Materiality, Risk Assessment and Internal Control questions