100% CORRECT ANSWERS
What is the purpose of substantive tests? - Answer- To confirm the integrity of actual
processing.
What does compliance testing determine? - Answer- Whether controls are being applied
in compliance with policy.
What is the role of the audit charter in an organization? - Answer- To outline the overall
authority, scope, and responsibilities of the Audit Function.
What is the relationship between compliance testing results and substantive testing? -
Answer- The results of compliance testing influence the planning of substantive testing.
What type of sampling method is useful for compliance testing? - Answer- Attribute
sampling.
What is the focus of substantive testing? - Answer- Detailed testing of transactions and
procedures.
What does compliance testing verify? - Answer- Whether controls are implemented and
effective.
What is the significance of the audit charter in audit processes? - Answer- It ensures
that audit authority and responsibilities are clearly defined.
What is a substantive test in auditing? - Answer- Using a statistical sample to inventory
the tape library.
What type of test is performed when selecting a sample of programs to check if source
and object versions are the same? - Answer- A compliance test of program library
controls.
What does a compliance test determine? - Answer- If controls are operating as
designed and comply with management policies.
What is substantive testing? - Answer- Evidence gathering to evaluate the integrity of
individual transactions, data, or other information.
What role should an IS auditor take in a CSA program? - Answer- Program facilitator.
, What is essential for a successful CSA program? - Answer- Line managers must take
responsibility for control monitoring.
What is the primary advantage of CSA techniques? - Answer- It ascertains high-risk
areas that might need a detailed review later.
When is the best time to perform a CSA involving all concerned parties? - Answer-
During the preliminary survey.
What is one objective of a CSA program? - Answer- Enhancement of audit
responsibilities.
What type of sampling is used for compliance testing? - Answer- Attribute sampling.
What type of sampling is used for substantive testing? - Answer- Variable sampling.
What is the role of an IS auditor during a CSA workshop? - Answer- To guide clients in
assessing their risks and relevant controls.
What should the focus of a CSA program be? - Answer- On areas of high risk.
What is the objective of CSA concerning audit responsibilities? - Answer- To enhance
audit responsibilities, not replace them.
What is key to the success of a control self-assessment (CSA) program? - Answer-
Involvement of line managers
What is an objective of a control self-assessment (CSA) program? - Answer-
Concentration on areas of high risk
What is the advantage of CSA over a traditional audit? - Answer- Early identification of
risk
What is the purpose of control self-assessment (CSA)? - Answer- To enhance audit
responsibilities, not replace them.
What are the elements of Risk? - Answer- Probability and Impact.
How is Risk calculated? - Answer- Risk = Probability * Impact.
What is the formula for Risk involving asset value? - Answer- Risk = Asset Value *
Vulnerability * Threat.
What is Vulnerability? - Answer- A weakness or gap in protection efforts.