Skip to content

CMA Intermediate · Corporate Accounting and Auditing · Audit Risk, Internal Control, Internal Check and Internal Audit

Per SA 315, how does an entity respond to the risks arising from the use of IT or from manual elements in its internal control?

The entity responds by establishing effective controls suited to the characteristics of its information system. SA 315 notes that the extent and nature of risks vary with that system, so controls must be designed accordingly rather than removing manual elements or relying on the auditor.

  1. ABy abandoning all manual elements
  2. BBy establishing effective controls in light of the characteristics of its information systemCorrect
  3. CBy transferring the risk to the statutory auditor
  4. DBy relying solely on the external auditor's tests

Explanation

SA 315 states that the extent and nature of risks to internal control vary with the characteristics of the information system, and the entity responds by establishing effective controls in light of those characteristics. It does not require abandoning manual elements or shifting the risk to the auditor.

Did you get it right without looking?

One question tells you little. A timed set on Audit Risk, Internal Control, Internal Check and Internal Audit shows your real accuracy, how long you take and where you lose marks.

More Audit Risk, Internal Control, Internal Check and Internal Audit questions