wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Control Frameworks Quiz

Total questions: 56

Worksheet time: 28mins

Name
Class
Date
1.

What is the purpose of internal controls according to the text?

a)

Enhancing operations and achieving better results

b)

Reducing the value for stakeholders

c)

Creating complexities in modern business environments

d)

Increasing risks for stakeholders

2.

Which organization developed the ISO 17799 standard?

a)

The Information Technology Infrastructure Library

b)

Capability Maturity Model Integration

c)

The Committee of Sponsoring Organizations

d)

The International Organization for Standardization

3.

What is the purpose of the COSO Framework according to the text?

a)

Encouraging e-commerce activities

b)

Promoting fraud and risk management

c)

Enhancing global trade and cultural diversity

d)

Improving financial reporting and focusing on governance, ethics, and internal controls

4.

Which component of the COSO Framework focuses on identifying, quantifying, and managing organizational risks?

a)

Control Activities

b)

Information and Communication

c)

Control Environment

d)

Risk Assessment

5.

What is the purpose of the ITIL framework?

a)

Enhancing customer satisfaction and reducing fraud

b)

Improving financial performance and reducing operational risks

c)

Aligning IT activities with business goals and managing IT-related risks

d)

Defining organizational structure and standard management procedures for IT operations

6.

Which organization administers the CMMI process improvement appraisal program?

a)

The Committee of Sponsoring Organizations

b)

The Institute of Internal Auditors

c)

The International Organization for Standardization

d)

Carnegie Mellon University

7.

What is the focus of the COBIT framework?

a)

Aligning IT activities with business goals and managing IT-related risks

b)

Defining organizational structure and skill requirements for IT operations

c)

Improving financial reporting and governance

d)

Enhancing internal controls and fraud prevention

8.

What is the purpose of the Global Technology Audit Guides (GTAGs)?

a)

Enhancing project management and performance improvement

b)

Developing voluntary standards for innovation

c)

Facilitating communication between stakeholders

d)

Providing essential IT management, control, and security information

9.

Which risk category typically arises from intentional and opportunistic actions by service providers?

a)

Financial Risks

b)

Operational Risks

c)

Composite Risks

d)

Strategic Risks

10.

What is the purpose of monitoring activities in internal control?

a)

Determining whether each component of internal control is present and functioning

b)

Identifying and testing control activities

c)

Assessing organizational risks

d)

Improving communication within the organization

11.

These frameworks help organize and prioritize internal controls, which are practices that add value and reduce risks for stakeholders.

a)

internal control framework

b)

external control framework

c)

cobit

d)

iso

12.

are voluntarily adopted by businesses to enhance their operations and achieve better results. They provide structure and guidance for managing the complexities of modern business environments.

Introduction


a)

control frameworks

b)

internal control framework

c)

external control framework

d)

cobit

13.

what year that coso widespread financial fraud led to the creation of a commission chaired by James C. Treadway.

a)

1990

b)

1890

c)

1980

d)

1985

14.

what year the COSO initiative was formed, backed by five professional associations and industry representatives

a)

1980

b)

1890

c)

1990

d)

1985

15.

aimed to improve financial reporting by focusing on governance, ethics, and internal controls, with an emphasis on risk management and fraud prevention

a)

Control Objectives for Information and Related Technology

b)

The Information Technology Infrastructure Library

c)

The International Organization for Standardization 17799

d)

Committee of Sponsoring Organizations

16.

statement 1: ICF was released in 1992, revised in 2013. it also contains 17 principles for effective internal control

statement 2: provides a structured approach for organizations to design, implement, and assess internal controls, which are processes, policies, and procedures aimed at achieving business objectives, managing risks, and ensuring compliance with laws and regulations


a)

both statement are true

b)

both statement are false

c)

statement 1 is true, statement 2 is false

d)

statement 1 is false, statement 2 is true

17.

which of the following is not included in the five key components

a)
  1. CONTROL ENVIRONMENT

b)

RISK MANAGEMENT

c)

CONTROL ACTIVITIES

d)
  1. INFORMATION AND COMMUNICATION

e)

MONITORING ACTIVITIES

18.
  • It identify, assess, and manage risks across an organization and

  • provides a comprehensive strategy for organizations to understand and mitigate risks that could impact their ability to achieve their objectives.

a)

Enterprise Risk Management (ERM) Framework

b)

COSO FRAMEWORK

c)

CONTROL FRAMEWORK

d)

NONE FO THE ABOVE

19.

also known as the workplace environment

a)

Control Environment

b)

Risk assessment

c)

Control activities

d)

Monitoring activities

20.

the following is an examples of unethical behavior IN CONTROL ENVIRONMENT which is NOT?

a)
  1. prioritizing profits over customer satisfaction

b)
  1. using high-pressure sales tactics

c)
  1. engaging in kickbacks or bribery

d)

Violations of ethical standards

21.

statement 1: Violations of ethical standards can lead to significant financial penalties and damage to a company's reputation.

statement 2: Auditors must remain vigilant for signs of ethical behavior and ensure compliance with laws and regulations

a)

both statements are true

b)

both statements are false

c)

statement 1 is true, statement 2 is false

d)

statement 1 is false, statement 2 is true

22.

This refers to management practices that may appear to fulfill necessary tasks on the surface, but lack true execution.

a)

form over substance

b)

control environment

c)

ethical behavior

d)

substance over form

23.

are used to determine if an organization’s values, systems, policies, and processes would enable or dissuade fraud and encourage proper conduct

a)

Entity level controls

b)

organization level control

c)

low level control

d)

high level control

24.

external auditors are encouraged to remember that a person’s behavior is determined by the person and his or her environment. There are a number of different and competing forces that combine to result in the situation the individual encounters

a)

true

b)

false

25.

The second component of the COSO framework relates to the identification, quantification, analysis, and management of organizational risks

a)

risk management

b)

risk assessment

c)

monitoring activity

d)

control activity

26.

This is the risk that the organization’s processes are not effectively obtaining, managing, and disposing their assets, that the organization is not performing effectively and efficiently in meeting customer needs, is not creating value or is diluting value by suffering the degradation of financial, physical, and information assets

a)

business

b)

process risk

c)

both

d)

none of the above

27.

is a process improvement appraisal program administered and marketed by Carnegie Mellon University.

a)

Capability Maturity Model Intergration

b)

Information Technology Infrastructure Library

c)

International Organization for Standardization

d)

Control Objectives for Information and Related Technologies

28.

defines the organizational structure and skill requirements of an IT organization and standard management procedures and practices to manage an IToperation

a)

Capability Maturity Model Intergration

b)

Information Technology Infrastructure Library

c)

International Organization for Standardization

d)

Control Objectives for Information and Related Technologies

29.

provides a comprehensive set of controls and guidelines that help organizations align their IT activities with business goals

a)

Capability Maturity Model Intergration

b)

Information Technology Infrastructure Library

c)

International Organization for Standardization

d)

Control Objectives for Information and Related Technologies

30.

is an independent, nongovernmental organization. Through its 162 national standards groups, it brings together experts to share knowledge and develop voluntary standards that support innovation and provide solutions to global and business challenges

a)

Capability Maturity Model Intergration

b)

Information Technology Infrastructure Library

c)

International Organization for Standardization

d)

Control Objectives for Information and Related Technologies

31.

the following are included in the Critical managerial and accounting/financial activities which is NOT?

a)

Establishing IT direction

b)

Project management

c)

Purchases

d)

Training end users

e)

software development

32.

are a collection of guides published by the Institute of Internal Auditors (IIA) that provide essential IT management, control, and security information.

a)

Global Technology Audit Guides

b)

World Technology Audit Guide

c)

Organizational Technology Guide

d)

none of the above

33.

consist of ongoing, separate or a combination of evaluations used to determine whether each of the five components of internal control is present and functioning.

a)

monitoring activities

b)

control activities

c)

risk assessment

d)

information and communication

34.

arise when a client loses its ability to implement a process due to longterm outsourcing, potentially resulting in a lack of back-office operational capabilities, both material and intellectual

a)

Composite risks

b)

Strategic Risks

c)

Operational Risks

d)

risk of outsourcing

35.

occur when work processes break down or are repeated incorrectly, often due to misunderstandings or insufficient capabilities, leading to delays, increased costs, and reduced quality.

a)

composite risk

b)

strategic risk

c)

Operational Risks

d)

outsourcing risk

36.

risks typically arise from intentional and opportunistic actions undertaken by service providers or their staff

a)

composite risk

b)

operational risk

c)

strategic risk

d)

outsourcing risk

37.

occurs between individuals

a)

Interpersonal or face-to-face communication

b)

Group-level communications

c)

Organizational level communications

d)

external communication

38.

occur within and among teams, units, and interest groups.

a)

Interpersonal or face-to-face communication

b)

Group-level communications

c)

Organizational-level communication

d)

external communication

39.

focus on company vision and mission, policies, and new initiatives

a)

Organizational-level communication

b)

external communication

c)

Group-level communication

d)

Interpersonal or face to face communication

40.

which communication disseminates messages throughout the organization, facilitating clear directives from senior management

a)

internal

b)

external

c)

Group-level

d)

Organizationallevel

41.

which communication involves receiving external information and providing responses to external parties' requirements and expectations

a)

inetrnal

b)

external

c)

Group-level

d)

Organizational-level

42.

component of the COSO IC/IF model focuses on information flow within an organization, aiming for clear, consistent, timely, and purposeful directives from top management to measure performance.

a)

risk assessment

b)

information and communication

c)

control activity

d)

monitoring activity

43.

which control activities that act before the error or omission can occur

a)

Preventive

b)

Directive

c)

Compensating

d)

Detective

44.

which control activities that identify error after occurence

a)

Preventive

b)

Directive

c)

Detective

d)

Compensating

45.

which control activity that temporary controls to redirect actions

a)

Preventive

b)

Directive

c)

Detective

d)

Compensating

46.

which one of the control activity that put in place when a control is not where it is expected

a)

Preventive

b)

Directive

c)

Detective

d)

Compensating

47.

actions established through policies and procedures that mitigate the likelihood and/or impact of risks

a)

monitoring

b)

control

c)

regulation

d)

rules

48.

rewards received should be commensurate with the effort exerted and the outcome achieved

a)

Rewarding

b)

Evaluated

c)

Time-bound

d)

none of the above

49.

Excitable, ethical, engaging, ecological, and enjoyable

a)

Rewarding

b)

Evaluated

c)

Time-bound

d)

none of the above

50.

Timed, timely, time-specific, trackable, and tangible

a)

rewarding

b)

evaluated

c)

Time-bound

d)

none of the above

51.

Realistic and resourced

a)

rewarding

b)

evaluated

c)

time-bound

d)

relevant

52.

Appropriate, assignable, ambitious, aspirational, attainable, agreed, actionable, and aligned.

a)

achievable

b)

relevant

c)

rewarding

d)

time- bound

53.

Meaningful, motivational, and manageable.

a)

measurable

b)

relevant

c)

rewarding

d)

achievable

54.

Significant, simple, stretching, and sufficiently detailed.

a)

specific

b)

measurable

c)

relevant

d)

achievable

55.

which of the following is not included in political

a)

Regulations and legislation risk

b)

Public policy risk

c)

Instability risk

d)

Data integrity

56.

which of the following is not part of social risk

a)

Demographics risk

b)

Privacy risk

c)

CSR

d)

Mobility

e)

Instability risk