CPA Exam — AUDAssessing Risk and Developing a Planned ResponseHard

During the risk assessment phase, an auditor identifies that a client, a manufacturing company, has a highly decentralized organizational structure with autonomous business units. Each unit manages its own procurement and inventory, but the financial reporting is consolidated centrally. This structure would most likely increase the auditor's assessment of control risk related to:

  1. AThe effectiveness of segregation of duties within individual business units.
  2. BThe valuation of property, plant, and equipment.
  3. CThe completeness of revenue for each business unit.
  4. DEntity-level controls over financial reporting.
Show answer & explanation

Correct answer: D. Entity-level controls over financial reporting.

A highly decentralized structure with autonomous units can make it challenging to implement and monitor consistent, effective entity-level controls (e.g., control environment, risk assessment, monitoring activities) across the entire organization, particularly for consolidated financial reporting. This increases control risk at the entity level.

Why the other options are wrong

  • A. Segregation of duties within individual units is a control activity at the transaction level. While potentially impacted, the primary risk from a decentralized structure is the overarching effectiveness of entity-wide controls, not just individual control activities.
  • B. While property, plant, and equipment valuation can be complex, the scenario's focus on a decentralized structure with autonomous units more directly impacts entity-level oversight and consistency than a specific asset valuation.
  • C. Completeness of revenue for individual units is a transaction-level assertion. The decentralized structure primarily impacts the consistency and oversight of controls for consolidated reporting, which is a higher-level concern.

Entity-Level Controls (Decentralized)

Entity-level controls are controls that operate across the entire entity and affect multiple processes and assertions. A decentralized structure can challenge their consistent application and effectiveness.

  • Include controls related to the control environment, risk assessment, and monitoring.
  • Crucial for overall financial reporting reliability.
  • Consistency and communication are harder in decentralized organizations.

Memory trick: Decentralized means 'ENTITY' controls are 'RISKY'.

More Assessing Risk and Developing a Planned Response questions