Font size
WorksheetsInternal Auditing MCQs
Total questions: 68
Worksheet time: 1hrs 8mins
Which of the following are components of the definition of internal auditing?
Independence and objectivity
A systematic and disciplined approach
Helping the organization accomplish its objectives
All of the answers
Assurance, Insight, and Objectivity comprise
The mission of internal auditing
The three lines of defense model
The value proposition
The objectives of internal auditing
Independent outside auditors provide financial reporting assurance services primarily for
The benefit of third parties
Management
Board of directors
The CEO
AVF Company's new CFO has asked the company's CAE to meet with him to discuss the role of the internal ausit functions. The CAE should inform the CFO that the overall responsibility of internal audit is to
Review the integrity of financial and operating information and the methods used to accumulate and report information
Determine whether the company's system of internal controls provides reasonable assurance that information is effectively and efficiently communicated to management
Serve as an independent assurance and consulting activity designed to add value and improve the company's operations
Assess the company's method for safeguarding its assets and, as appropriate, verify the existence of the assets
Which of the following statements is NOT TRUE about business objectives
Business objectives represent targets of performance
Establishing meaningful business objectives is a key component of the management process
Establishing meaningful business objectives is a prerequisite to effective internal control
Business objectives are managment's means of employing resources and assigning responsibilities
Within the context of internal auditing, assurance services are best defined as
Professional activities that measure and communicate finalcial and business data
Advisory servies intended to add value and improve an organization's operations
Objective examinations of evidence for the purpose of providing independent assessments
Objective evaluations of compliance with policies, plans, procedures, laws, and regulations
Which of the following is mandatory guidance within the IPPF
Implementation guidance
Supplemental guidance
The value proposition
The core principles
While planning an internal audit, the internal auditor obtains knowledge about the auditee to, among other things
Develop an understanding of the auditee's objectives and risks
Develop an attitude of professional skepticism about managemnet's assertions
Make constructive suggestions to management concerning internal control improvements
Evaluate whether misstatements in the auditee's performance reports shouls be communicateed to senior management and the audit committee
Which of the following is the premier certification sponsored by the IIA
Certification in Control Self-Assessment
Certified Internal Auditor
Certification in Risk Management Assessment
Certified Information Systems Auditor
Which of the folloeing is the ultimate position of a carrer internal auditor?
CEO
CFO
CRO
CAE
Growing the organization's market share, by acquiring complementary businesses, is a specific business object of which od the following
Reporting objective
Operations objective
Stratergic objective
Compliance objective
Ship all orders no later than 48 hours after receiving the orders, is a specific business of which of the following?
Reporting objective
Oprerations objective
Strategic objective
Compliance objective
Record only valid sales transactions is a specific business objective of which of the following?
Reporting objective
Operations objective
Strategic objective
Compliance objective
Which of the following best describes an internal auditor's purpose in reiewing the organization's existing governance, risk management, and control processes?
To help determine the nature, timing, and extent of tests necessart to achieve engagement objectives
To ensure that weaknesses in the internal control system are corrected
To provide reasonable assurance thta the processes will wnable the organization's objective and goals to be met efficiently and economically
To determine whether the processes ensure that the accounting records are correct and that financial statements are fairly stated
Which of the following is not an appropriate governance role for an organization's broad of directors
Evaluating and approving strategic objectives
Influencing the organization's risk-taking philosophy
Providing assurance directly to third parties that the organization's governance processes are effective
Establishing broad boundaries of conduct, outsides of which the organization should
Who is reposible for establishing the strategic objectives of an organization?
The board of directors
Consensus among all levels of management
Senior managerment
The board and senior management jointly
Who is ultimately responsible for identifying new or emerging key risk areas that should be covered by the organization's governance process?
The board of directors
Risk owners
Senior management
The internal aufit function
The internal audit function should not:
Assess the organization's governance and risk management processes
Provide advice about how to improve that organization's governance and risk managenment processes.
Oversee the organization's governance and risk management processes
Coordinate its governance and risk management-related activities with those of independent outside auditor.
Which of the following would not be considered a first line of defense in the Three Lines of Defense model
A divisional controller conducts a peer review of compliance with financial control stadards
An accounts payable cleck reviews supporting documentd before processing an invoice for payment
An accouting supervisor conducts a monthly review to ensure all reconciliations were completed properly
A production line worker inspects finidhed goods to ensure that company's quality standards are met
Which of the following would be considered a second line of defense in the Three Lines of Defense model?
An accounts payable supervisor conducting a weekly review to ensure all payments were issued by the required payment date
A divisional compliance and ethics offices conducting a review of employee training records to ensure that all marketing anf sales staff have completed the required FCPA training
A shift supervisor inspecting a sample of finishes goods to wnsure quality standards are met
An internak audit team conducting an engagement to provide assurance on the company's Sarbanes-Oxley complianxe with internal controls over financial reporting
What are the major components of governance?
1. Strategic direction
2. Oversight
3. Regulations
4. Ethics
1 and 2 only
1,2 and 4 only
2 and 4 only
3 and 4 only
Governance should help ensure that the objectives of an entity's stakeholders are met. Stakeholders include
Employees and Customers
Regulators and Suppliers
Suppliers, Regulations and Customers
Employees, Suppliers, Regulators and Customers
Which of the following is not a goal of corporate governance?
Complying with society's legal and regulatory rules
Providing an overal benefit to society
Reporting fully and truthfully to stakeholders
Maximizing executive compensation
The internal audit activity most directly contributes to an organization's governance process by
Identifying significant exposures to risk
Evaluating the design of ethics-ralated activities
Evaluating the efffectiveness of internal control over financial reporting
Promoting continuous improvement controls
According to COSO ERM, which of the following is not an inherent challenge that arises as part of establishing strategy and business objectives?
Ensuring culture is clearly articulated by the board
Possiblity of strategy not aligning
Implications from the strategy chosen
Risk to achieving the strategy
Who has primary resposiblity for the monitoring component of internal control?
The organization's independent outside auditor
The organization's internal audit function
The organization's management
The organization's board of directors
Which of the following is not an example of a risk sharing strategy?
Outsourcing a noncore, high-risk area
Hedging against interest rate fluctuations
Selling a nonstrategy business unit
Buying an insurance policy to protect against adverse weather
After business risks have been identified, they should be assessed in terms of their inherent
Impact and likehood
Likehood and probability
Significance and severity
Significance and control effectiveness
Which of the following risk management activities is out of sequence in terms of timing?
Identify, assess, and prioritize risks
Develop risk responses/ treatments
Determine key organizational objectives
Monitor the effectiveness of risk responses/ treatments
Who is responsible for implementing ERM?
The chief financial officer
The chief audit executive
The chief compliance officer
Management throughout the organization
Which of the following is not a potential value driver for implementing ERM?
Financial results will improve in the short run
There will be fewer surprises from year to year
There will be better information available to make risk decisions.
An organization's risk appetite can be aligned with strategic planning
Which of the following is the best reason for the CAE to consider the organization's strategic plan in developing the annual internal audit plan?
To emphasize the importance of the internal audit function to the organization
To ensure that the internal audit plan will be approved by senior management
To make recommendations to improve the strategic plan
To ensure that the internal audit plan supports the overall business objectives
Which of the following is not a goal of corporate governance?
Complying with the society's legal and regulatory rules
Providing an overall benefit to society
Earning a profit.
Reporting fully and truthfully to stakeholders
What risk response option are being applied by the organization: “Action is taken to reduce the risk impact, likelihood, or both. This involves a myriad of everyday business decisions, such as implementing controls"
Acceptance
Avoidance
Pursuit
Reduction
Sharing
COSO's Internal Control Framework consists of five internal control components and 17 principles for achieving effective internal control. Which of the following is/are (a) principle(s)?
I. The organization demonstrates a commitment to integrity and ethical values.
II. A level of assurance that is supported by generally accepted auditing procedures and judgments.
III. A body of guiding principles that form a template against which organizations can evaluate a multitude of business practices.
IV. The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
I only
I and IV only
II and IV only
I, II, III, and IV
When assessing the risk associated with an activity, an internal auditor should:
Determine how the risk should best be managed
Provide assurance on the management of the risk
Update the risk management process based on risk exposures
Design controls to mitigate the identified risks
Internal auditors provide their financial reporting assurance services primarily for the benefit of: (Select all correct answers)
Third parties
Management
Board of directors
Employees
An effective system of internal controls is most likely to detect a fraud perpetrated by a:
Group of employees in collusion
Single employee
Group of managers in collusion
Single manager
Enterprise risk management
Guarantees achievement of business objectives
Requires establishment of risk and control activities by internal auditors
Includes selection of best risk response for the organization
Involves the identification of events with negative impacts on business objectives.
What is residual risk?
Impact of risk.
Risk that is under control
Risk that is under control
Risk that is not managed.
Which of the following best describes an internal auditor’s purpose in reviewing the organization’s existing governance, risk management, and control processes?
To help determine the nature, timing, and extent of tests necessary to achieve engagement objectives.
To ensure that weaknesses in the internal control system are corrected.
To provide reasonable assurance that the processes will enable the organization’s objectives and goals to be met efficiently and economically
To determine whether the processes ensure that the accounting records are correct and that financial statements are fairly stated
Which of the following is a preventive control?
credit check before approving a sale on account
bank reconciliation
physical inventory count
comparing the accounts receivable subsidiary
The bank reconciliation uncovered a transposition error in the books. This is an example of a
detective control
preventive control
corrective control
feedforward control
Reasonable assurance, as it pertains to internal control, means that:
The objectives of internal control vary depending on the method of data processing used
A well-designed system of internal controls will prevent or detect all errors and fraud
Inherent limitations of internal control preclude a system of internal control from providing absolute assurance that objectives will be achieved
Management cannot override controls, and employees cannot circumvent controls through collusion
Which of the following best exemplifies a control activity referred to as independent verification?
Reconciliation of bank accounts by someone who does not handle cash or record cash transactions
Identification badges and security codes used to restrict entry to the production facility
Accounting records and documents that provide a trail of sales and cash receipt transactions
Separating the physical custody of inventory from inventory accounting
The risk assessment component of internal control involves the:
Independent outside auditor’s assessment of residual risk.
Internal audit function’s assessment of control deficiencies.
Organization’s identification and analysis of the risks that threaten the achievement of its objectives.
Organization’s monitoring of financial information for potential material misstatements.
Which of the following is not an element of the internal control environment?
management philosophy and operating style
organizational structure of the firm
well-designed documents and records
the functioning of the board of directors and the audit committee
Which of the following is not an internal control procedure?
authorization
management's operating style
independent verification
physical control
Which of the following is NOT a risk response strategy for a positive risk?
Exploiting
Enhancing
Transferring
Acceptance
According to COSO, the difference between inherent risk and residual risk is management's?
inability to reduce the inherent risk
actions to reduce the inherent risk
inability to share the residual risk
actions to reduce the residual risk
Management has careful evaluated the likelihood and impact of events on its foreign operations. In the event 3% variation in exchange rate, the impact is estimated at $10 million without any action taken by management and $6 million if the company purchases a hedge instrument. The impact of the residual risk of changes in foreign currency exchange on achieving company's business objectives is:
$10 M
$16 M
$6 M
$4 M
According to COSO ERM, which of the following is not an inherent challenge that arises as part of establishing strategy and business objectives?
Ensuring culture is clearly articulated by the board.
Possibility of strategy not aligning.
Implications from the strategy chosen.
Risk to achieving the strategy
Which of the following is one of the 5 Cs essential to success as an internal auditor?
(1) Courage.
(2) Collaboration.
(3) Candidness.
(4) Competence
(1) and (2) only
(1) and (4) only
(3) and (4) only
(1), (2), (3) and (4)
Governance should help ensure that the objectives of an entity's stakeholders are met. Stakeholders include
1. Employees
2. Regulators
3. Suppliers
4. Customers
(1) and (4) only
(2) and (3) only
(2), (3) and (4) only
(1), (2), (3) and (4)
Which of the following is not a goal of corporate governance
Complying with society's legal and regulatory rules
Providing an overall benefit to society
Maximizing executive compensation
Reporting fully and truthfully to stakeholders
The internal audit activity most directly contributes to an organization's governance process by
Identifying significant exposures to risk
Evaluating the effectiveness of internal control over financial reporting
Evaluating the design of ethics-related activities
Promoting continuous improvement of controls
Who is responsible for implementing ERM?
The chief financial officer
The chief audit executive
Management throughout the organization
The chief compliance officer
Which of the following is not a potential value driver for implementing ERM?
Financial results will improve in the short run.
The chief audit executive
There will be fewer surprises from year to year
An organization's risk appetite can be aligned with strategic planning
When assessing the risk associated with an activity, an internal auditor should
Determine how the risk should best be managed
Provide assurance on the management of the risk
Update the risk management process based on risk exposures
Design controls to mitigate the identified risks
Which of the following is an example of misappropriation of assets?
A small amount of petty cash is stolen.
A journal entry is modified to improve reported financial results.
A foreign official is bribed by the chief operating officer (COO) to facilitate approval of a new product.
A duplicate bill is sent to a customer in hopes that they will pay it twice.
Which of the following is not a typical “rationalization” of a fraud perpetrator?
It’s in the organization’s best interest.
The company owes me because I’m underpaid.
I want to get back at my boss (revenge).
I’m smarter than the rest of them
The Cressey Fraud Triangle does not include, as one of its vertices:
Pressure
Opportunity
Rationalization
Fraudster personality
Which of the following is not something all levels of employees should do?
Understand their role within the internal control framework.
Have a basic understanding of fraud and be aware of the red flag
Report suspicions of incidences of fraud.
Investigate suspicious activities that they believe may be fraudulent
From an organization's standpoint, because internal auditors are seen to be "internal control experts," they also are:
Fraud risk management process owners, and hence, the first and most important line of defense against fraudulent financial reporting or asset misappropriation.
The best resource for audit committees, management, and others to consult in-house when setting up anti-fraud programs and controls, even if they may not have any fraud investigation experience.
The best candidates to lead an investigation of a fraud incident involving the potential violation of laws and regulations.
The primary decision-maker in terms of determining punishment or other consequences for fraud perpetrators.
An organization that manufactures and sells computers is trying to boost sales between now and the end of the year. It decides to offer its sales representatives a bonus based on the number of units they deliver to customers before the end of the year. The price of all computers is determined by the vice president of sales and cannot be changed by sales representatives. Which of the following presents the greatest reason a sales representative may commit fraud with this incentive program?
Sales representative may sell units that have a lower margin than other units.
Customers have the right to return a laptop for up to 90 days after purchase.
The units delivered may be defective
The customers may not pay for the computers timely
A payroll clerk increased the hourly pay rate of a friend and shared the resulting overpayment with the friend. Which of the following controls would have best served to prevent this fraud? a. Requiring that all changes to pay records be recorded on a standard form. b. Limiting the ability to make changes in payroll system personnel information to authorized HR department supervisors. c. Periodically reconciling pay rates per personnel records with those of the payroll system. d. Monitoring payroll costs by department supervisors monthl
Requiring that all changes to pay records be recorded on a standard form
Limiting the ability to make changes in payroll system personnel information to authorized HR department supervisors
Periodically reconciling pay rates per personnel records with those of the payroll system.
Monitoring payroll costs by department supervisors monthly
The internal audit function's responsibilities with respect to fraud are limited to:
The organization's operational and compliance activities only because financial reporting matters are the responsibility of the independent outside auditor.
Monitoring any calls received through the organization's whistleblower hotline but not necessarily conducting a follow-up investigation.
Being aware of fraud indicators, including those relating to financial reporting fraud, but not necessarily possessing the expertise of a fraud investigation specialist.
Ensuring that all employees have received adequate fraud awareness training
Which of the following types of companies would most likely need the strongest anti-fraud controls? a. A manufacturer of popular athletic shoes. b. A grocery store. c. A bank. d. An internet-based electronics retailer
A manufacturer of popular athletic shoes.
A grocery store.
A bank
An internet-based electronics retailer
