Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

final kiem noi bo

Total questions: 100

Worksheet time: 50mins

Name
Class
Date
1.

Which of the following is the best reason for the CAE to consider the organization's strategic plan in developing the annual internal audit plan?

a)

To emphasize the importance of the internal audit function to the organization.

b)

To ensure that the internal audit plan will be approved by senior management

c)

To make recommendations to improve the strategic plan

d)

To ensure that the internal audit plan supports the overall business objectives

2.

Which of the following is the premier certification sponsored by the IIA?

a)

Certification in Control Self-Assessment

b)

Certified Internal Auditor

c)

Certification in Risk Management Assessment

d)

Certified Information Systems Auditor

3.

Which of the following is not a potential value driver for implementing ERM?

a)

Financial results will improve in the short run

b)

There will be fewer surprises from year to year

c)

There will be better information available to make risk decisions.

d)

An organization's risk appetite can be aligned with strategic planning

4.

Which competency is described as the ability to inspire trust through consistent competence and integrity

a)

Credibility

b)

Competence

c)

Courage

d)

Communication

5.

Which of the following is NOT a risk response strategy for a positive risk?

a)

Exploiting

b)

Enhancing

c)

Transferring

d)

Acceptance

6.

How does COSO ERM define 'risk'?

a)

A random event that has no influence on business outcomes

b)

The possibility that events will occur and affect the achievement of strategy and objectives

c)

The unavoidable circumstances that must be ignored

d)

A financial event that is predictable and manageable

7.

While planning an internal audit, the internal auditor obtains knowledge about the auditee to, among other things

a)

Develop an understanding of the auditee's objectives and risks

b)

Develop an attitude of professional skepticism about management's assertions

c)

Make constructive suggestions to management concerning internal control improvements.

d)

Evaluate whether misstatements in the auditee's performance reports should be communicated to senior management and the audit committee.

8.

Who is responsible for implementing ERM?

a)

The chief financial officer

b)

The chief audit executive

c)

The chief compliance officer

d)

Management throughout the organization

9.

Assurance, Insight, and Objectivity comprise

a)

The mission of internal auditing

b)

The three lines of defense model

c)

The value proposition

d)

The objectives of internal auditing

10.

Internal auditing is designed to add value through which of the following activities?

a)

Assurance and consulting activities aimed at improving operations

b)

Only identifying non-compliance issues

c)

Conducting market research

d)

Monitoring employee performance reviews

11.

Who is responsible for establishing the strategic objectives of an organization?

a)

The board of directors.

b)

Consensus among all levels of management.

c)

Senior management.

d)

The board and senior management jointly

12.

The competency 'Courage' is essential for internal auditors because it involves:

a)

The ability to connect with stakeholders

b)

Inspiring trust through competence and integrity

c)

The personal fortitude to remain independent and objective, and to stand by the results of engagements

d)

Communicating results in multiple forms

13.

AVF Company's new CFO has asked the company's CAE to meet with him to discuss the role of the internal audit function. The CAE should inform the CFO that the overall responsibility of internal audit is to

a)

Review the integrity of financial and operating information and the methods used to accumulate and report information

b)

Determine whether the company's system of internal controls provides reasonable assurance that information is effectively and efficiently communicated to management

c)

Serve as an independent assurance and consulting activity designed to add value and improve the company's operations

d)

Assess the company's methods for safeguarding its assets and, as appropriate, verify the existence of the assets

14.

Which of the following exemplifies a risk exploitation strategy?

a)

Implementing robust security measures to mitigate cyber threats.

b)

Collaborating with competitors to share market insights.

c)

Diversifying investments to reduce financial risk.

d)

Purchasing insurance to transfer risk to a third party

15.

Which of the following is one of the 5 Cs essential to success as an internal auditor?

a)

(1) Courage.

b)

(2) Collaboration.

c)

(3) Candidness.

d)

(4) Competence

16.

After business risks have been identified, they should be assessed in terms of their inherent

a)

Impact and likelihood

b)

Likelihood and probability

c)

Significance and severity

d)

Significance and control effectiveness

17.

If the business objective is 'Ship all orders no later than 48 hours after receiving them,' what should the audit engagement objective be?

a)

Reviewing sales data for accuracy

b)

Determining whether orders are actually being shipped within 48 hours of receipt

c)

Ensuring financial statements comply with GAAP

d)

Assessing the adequacy of OSHA training procedures

18.

Independent outside auditors provide financial reporting assurance services primarily for

a)

The benefit of third parties

b)

Management

c)

Board of directors

d)

The CEO

19.

Which of the following would be considered a first line of defense in the Three Lines of Defense model

a)

An accounts payable supervisor conducting a weekly review to ensure all payments were issued by the required payment date

b)

A divisional compliance and ethics officer conducting a review of employee training records to ensure that all marketing and sales staff have completed the required FCPA training

c)

The external audit team observes the counting of inventory on December 31

d)

An internal audit team conducting an engagement to provide assurance on the company's Sarbanes-Oxley compliance with internal controls over financial reporting

20.

Growing the organization's market share, by acquiring complementary businesses, is a specific business objective of which of the following

a)

Reporting objective

b)

Operations objective

c)

Strategic objective

d)

Compliance objective

21.

What risk response option is being applied by the organization when the organization acknowledges a risk but chooses not to take specific actions to mitigate or transfer it?

a)

Avoidance

b)

Exploitation

c)

Acceptance

d)

Transfer

22.

Internal auditors provide their financial reporting assurance services primarily for the benefit of: (Select all correct answers)

a)

Third parties

b)

Management

c)

Board of directors

d)

Employees

23.

Which of the following roles should internal audit avoid to maintain its independence?

a)

Reviewing risk mitigation measures

b)

Setting the risk appetite for the organization

c)

Supporting risk analysis

d)

Coordinating ERM activities

24.

What is a key responsibility of the internal audit function in relation to management?

a)

Dictating corporate strategies and objectives

b)

Monitoring employee attendance and punctuality

c)

Facilitating social events for company employees

d)

Providing independent evaluations and recommendations to improve internal controls and risk management

25.

Which of the following best characterizes a risk avoidance strategy?

a)

Accepting all risks without mitigation measures.

b)

Transferring risks to external parties.

c)

Implementing measures to minimize the impact of identified risks.

d)

Choosing not to engage in activities that carry certain risks.

26.

Which of the following is mandatory guidance within the IPPF

a)

Implementation guidance

b)

Supplemental guidance

c)

The value proposition

d)

The core principles

27.

Which of the following represents a risk reduction strategy?

a)

Increasing investment in high-risk ventures

b)

Transferring all liabilities to a third party

c)

Implementing safety protocols to minimize workplace accidents

d)

Ignoring potential risks and proceeding with business as usual

28.

Roles the internal audit function should not undertake?

a)

Evaluating risk management processes

b)

Giving assurance on the risk management processes

c)

Making decisions on risk responses

d)

Reviewing the management of key risks

29.

What is the focus of 'Communication' as a key competency for internal auditors?

a)

Having the courage to remain independent

b)

Understanding the needs of stakeholders

c)

Instituting methods of relaying information and listening to individuals

d)

Providing advisory services that add value

30.

What are the major components of governance?

a)

1. Strategic direction

b)

2. Oversight

c)

3. Regulations

d)

4. Ethics

31.

Which of the following are key roles of the internal audit function? (Select all that apply)

a)

Conducting external financial audits

b)

Providing independent assurance on risk management and internal control

c)

Evaluating the effectiveness of compliance programs

d)

Managing day-to-day operational decisions

32.

What is the primary focus of the 'Strategy and Business Objectives' component in the COSO ERM Framework?

a)

Establishing financial reports

b)

Aligning risk management with the entity's strategy

c)

Managing employee performance

d)

Developing organizational policies

33.

Ship all orders no later than 48 hours after receiving the orders, is a specific business objective of which of the following?

a)

Reporting objective

b)

Operations objective

c)

Strategic objective

d)

Compliance objective

34.

The internal audit function should not:

a)

Assess the organization's governance and risk management processes

b)

Provide advice about how to improve the organization's governance and risk management processes.

c)

Oversee the organization's governance and risk management processes.

d)

Coordinate its governance and risk management-related activities with those of the independent outside auditor.

35.

Which principle is essential for internal auditors to maintain during their engagements?

a)

Independence and objectivity

b)

Profit maximization

c)

Direct involvement in management decisions

d)

Exclusive focus on financial statements

36.

Which of the following is not a goal of corporate governance

a)

Complying with society's legal and regulatory rules

b)

Providing an overall benefit to society

c)

Maximizing executive compensation

d)

Reporting fully and truthfully to stakeholders

37.

What risk response option is being applied by the organization: "Action is taken to reduce the risk impact, likelihood, or both. This involves a myriad of everyday business decisions, such as implementing controls"

a)

Acceptance

b)

Avoidance

c)

Pursuit

d)

Reduction

e)

Sharing

38.

Which of the following are components of the definition of internal auditing?

a)

Independence and objectivity

b)

A systematic and disciplined approach

c)

Helping the organization accomplish its objectives

d)

All of the answers

39.

Comply with Occupational Safety and Health Administration (OSHA) regulations, is a specific business objective of which of the following?

a)

Reporting

b)

Compliance

c)

Operations

d)

Strategic

40.

Governance should help ensure that the objectives of an entity's stakeholders are met. Stakeholders include

a)

Employees and Customers

b)

Regulators and Suppliers

c)

Suppliers, Regulators and Customers

d)

Employees, Suppliers, Regulators and Customers

41.

What does "ERM" stand for in the COSO ERM Framework?

a)

External Risk Management

b)

Enterprise Risk Management

c)

Employee Risk Management

d)

Environmental Risk Management

42.

What risk response option is being applied by the organization: "Discontinuing a specific business activity or exiting a particular market"

a)

Acceptance

b)

Reduction

c)

Avoidance

d)

Exploitation

43.

What is the main objective of the internal audit function within an organization?

a)

Managing external stakeholder relationships

b)

Monitoring employee productivity

c)

Ensuring compliance with legal requirements and internal policies

d)

Conducting market research for product development

44.

Who is ultimately responsible for identifying new or emerging key risk areas that should be covered by the organization's governance process?

a)

The board of directors.

b)

Risk owners.

c)

Senior management.

d)

The internal audit function

45.

What is one of the main focuses of internal auditing according to its definition?

a)

Focusing solely on financial reporting

b)

Evaluating and improving the effectiveness of risk management, control, and governance processes

c)

Ensuring the organization achieves maximum profits

d)

Overseeing external audits

46.

Which of the following best illustrates a risk acceptance strategy?

a)

Investing in comprehensive insurance coverage to mitigate potential losses

b)

Implementing strict quality control measures to prevent product defects

c)

Accepting potential risks without taking specific actions to mitigate them

d)

Collaborating with suppliers to share supply chain risks

47.

According to COSO ERM, which of the following is not an inherent challenge that arises as part of establishing strategy and business objectives?

a)

Ensuring culture is clearly articulated by the board.

b)

Possibility of strategy not aligning

c)

Implications from the strategy chosen

d)

Risk to achieving the strategy

48.

When assessing the risk associated with an activity, an internal auditor should

a)

Determine how the risk should best be managed.

b)

Provide assurance on the management of the risk.

c)

Update the risk management process based on risk exposures.

d)

Design controls to mitigate the identified risks.

49.

What is residual risk?

a)

Impact of risk.

b)

Risk that is under control

c)

Underlying risk in the environment

d)

Risk that is not managed.

50.

What does "Competence" refer to as a key competency for internal auditors

a)

The skills and knowledge required to provide assurance and advisory services that add value

b)

The ability to stand by the results of engagements conducted

c)

Understanding the needs of each stakeholder individually

d)

Inspiring trust based on consistent integrity

51.

Which of the following is not an example of a risk sharing strategy?

a)

Outsourcing a noncore, high-risk area

b)

Hedging against interest rate fluctuations

c)

Selling a nonstrategic business unit

d)

Buying an insurance policy to protect against adverse weather

52.

What is a core role of internal audit in ERM?

a)

Implementing risk mitigation strategies

b)

Providing assurance on risk management processes

c)

Setting the organization's risk appetite

d)

Making decisions on risk responses

53.

"Connectivity" as a competency for internal auditors involves:

a)

Understanding the needs of stakeholders individually while considering the whole organization

b)

Relaying information in various forms

c)

Ensuring accuracy in financial statements

d)

Demonstrating courage in the face of challenges

54.

Within the context of internal auditing, assurance services are best defined as

a)

Professional activities that measure and communicate financial and business data

b)

Advisory services intended to add value and improve an organization's operations

c)

Objective examinations of evidence for the purpose of providing independent assessments

d)

Objective evaluations of compliance with policies, plans, procedures, laws, and regulations

55.

How does ERM influence the internal audit function's approach to assurance?

a)

It restricts internal audit to focus only on financial risks

b)

It provides a framework for internal audit to prioritize high-risk areas and optimize resources

c)

It eliminates the need for internal audit involvement in risk management

d)

It requires internal audit to set the organization's risk appetite

56.

Management has careful evaluated the likelihood and impact of events on its foreign operations. In the event 3% variation in exchange rate, the impact is estimated at $10 million without any action taken by management and $6 million if the company purchases a hedge instrument. The impact of the residual risk of changes in foreign currency exchange on achieving company's business objectives is:

a)

$10 M

b)

$16 M

c)

$6 M

d)

$4 M

57.

Which of the following best describes the role of the internal audit function within an organization?

a)

Conducting independent evaluations to ensure compliance with laws, regulations, and internal policies

b)

Providing external stakeholders with financial reports and disclosures

c)

Assisting in the recruitment and training of new employees

d)

Overseeing marketing strategies and sales operations

58.

The COSO ERM Framework emphasizes integrating risk management with what?

a)

Legal Compliance

b)

The organization's strategy and decision-making process

c)

Operational Procedures

d)

Technological Innovation

59.

Which of the following would be considered a second line of defense in the Three Lines of Defense model?

a)

An accounts payable supervisor conducting a weekly review to ensure all payments were issued by the required payment date.

b)

A divisional compliance and ethics officer conducting a review of employee training records to ensure that all marketing and sales staff have completed the required FCPA training

c)

A shift supervisor inspecting a sample of finished goods to ensure quality standards are met.

d)

An internal audit team conducting an engagement to provide assurance on the company's Sarbanes-Oxley compliance with internal controls over financial reporting

60.

Who is responsible for the 3rd Line of Defense in the Three Lines of Defense Model?

a)

Internal Audit

b)

Financial Controller

c)

External Assurance Providers

d)

Senior Management

61.

Record only valid sales transactions is a specific business objective of which of the following?

a)

Reporting objective

b)

Operations objective

c)

Strategic objective

d)

Compliance objective

62.

Who is responsible for overseeing the effectiveness of the entire Three Lines of Defense Model?

a)

Senior Management

b)

Governing Body/Board/Audit Committee

c)

Internal Audit

d)

External Assurance Providers

63.

Which of the following best describes a risk-sharing strategy?

a)

Transferring all risks to a third-party insurer

b)

Provide assurance on the management of the risk

c)

Allocating risks among different parties to reduce individual exposure

d)

Ignoring risks and hoping for the best outcome

64.

Internal auditing follows a specific approach. What is it?

a)

A systematic and disciplined approach, particularly through the engagement process

b)

A spontaneous and ad-hoc method for identifying risks

c)

A flexible and unstructured methodology based on department needs

d)

A focus on external auditing standards

65.

Which of the following best describes an internal auditor's purpose in reviewing the organization's existing governance, risk management, and control processes?

a)

To help determine the nature, timing, and extent of tests necessary to achieve engagement objectives

b)

To ensure that weaknesses in the internal control system are corrected.

c)

To provide reasonable assurance that the processes will enable the organization's objectives and goals to be met efficiently and economically.

d)

To determine whether the processes ensure that the accounting records are correct and that financial statements are fairly stated

66.

Which of the following best describes the role of the "COSO ERM Components"?

a)

They are guidelines for external audits.

b)

They represent the structural elements needed to manage risks effectively.

c)

They are tools for financial reporting.

d)

They focus solely on compliance with laws and regulations.

67.

According to the COSO ERM Framework, which of the following is part of the organization's core elements that ERM aligns with?

a)

Organizational Structure

b)

Mission, Vision, and Core Values

c)

IT Systems

d)

Profit and Loss Statements

68.

Which of the following is a key purpose of internal auditing?

a)

Focusing solely on financial reporting

b)

Helping the organization accomplish its objectives

c)

Monitoring only compliance with laws

d)

Maximizing external auditor reliance

69.

Which of the following is the ultimate position of a career internal auditor?

a)

CEO

b)

CFO

c)

CRO

d)

CAE

70.

According to COSO, the difference between inherent risk and residual risk is management's?

a)

inability to reduce the inherent risk

b)

actions to reduce the inherent risk

c)

inability to share the residual risk

d)

actions to reduce the residual risk

71.

Which of the following statements is not true about business objectives

a)

Business objectives represent targets of performance

b)

Establishing meaningful business objectives is a key component of the management process

c)

Establishing meaningful business objectives is a prerequisite to effective internal control

d)

Business objectives are management's means of employing resources and assigning responsibilities

72.

One key benefit of implementing the COSO ERM Framework is:

a)

Guaranteeing higher profits

b)

Aligning risk appetite with strategic decision-making

c)

Eliminating all organizational risks

d)

Reducing the need for external auditors

73.

According to COSO ERM, which of the following is not an inherent challenge that arises as part of establishing strategy and business objectives?

a)

Ensuring culture is clearly articulated by the board.

b)

Possibility of strategy not aligning.

c)

Implications from the strategy chosen.

d)

Risk to achieving the strategy

74.

A company requires two levels of approval for significant financial transactions when an automated system check is not feasible. This is an example of:

a)

detective control

b)

preventive control

c)

corrective control

d)

compensating control

75.

The internal audit function is expected to:

a)

Design and implement internal controls to prevent fraud.

b)

Make arrests of employees suspected of committing fraud.

c)

Provide independent assessments of the effectiveness of fraud controls.

d)

Approve budget allocations for fraud prevention initiatives.

76.

The bank reconciliation uncovered a transposition error in the books. This is an example of a

a)

detective control

b)

preventive control

c)

corrective control

d)

feedforward control

77.

Which of the following is not an internal control procedure?

a)

authorization

b)

management's operating style

c)

independent verification

d)

physical control

78.

Reasonable assurance, as it pertains to internal control, means that:

a)

The objectives of internal control vary depending on the method of data processing used

b)

A well-designed system of internal controls will prevent or detect all errors and fraud

c)

Inherent limitations of internal control preclude a system of internal control from providing absolute assurance that objectives will be achieved

d)

Management cannot override controls, and employees cannot circumvent controls through collusion

79.

A well-designed purchase order is an example of a?

a)

detective control

b)

preventive control

c)

corrective control

d)

feedforward control

80.

Who has primary responsibility for the monitoring component of internal control?

a)

The organization's independent outside auditor.

b)

The organization's internal audit function.

c)

The organization's management.

d)

The organization's board of directors

81.

The risk assessment component of internal control involves the:

a)

Independent outside auditor's assessment of residual risk.

b)

Internal audit function's assessment of control deficiencies.

c)

Organization's identification and analysis of the risks that threaten the achievement of its objectives.

d)

Organization's monitoring of financial information for potential material misstatements.

82.

An effective system of internal controls is most likely to detect a fraud perpetrated by a:

a)

Group of employees in collusion

b)

Single employee

c)

Group of managers in collusion

d)

Single manager

83.

Which of the following is a responsibility of management in the context of fraud risk management?

a)

Setting the tone at the top and providing oversight.

b)

Retaining outside counsel and experts.

c)

Implementing the system of internal controls.

d)

Monitoring reports about fraud incidents.

84.

Which control type would be implemented after a problem has been detected to ensure it does not happen again?

a)

detective control

b)

preventive control

c)

corrective control

d)

compensating control

85.

What responsibility does the Board of Directors have in a fraud risk management program?

a)

Daily execution of fraud control activities.

b)

Implementing the overall fraud risk management program.

c)

A comprehensive understanding of key fraud risks.

d)

Participating in monitoring activities.

86.

Which of the following is not an element of the internal control environment?

a)

management philosophy and operating style

b)

organizational structure of the firm

c)

well-designed documents and records

d)

the functioning of the board of directors and the audit committee

87.

What is not a typical role of the internal audit function regarding fraud?

a)

Conducting audits to identify weaknesses in fraud prevention measures.

b)

Providing assurance that controls to mitigate fraud risks are effective.

c)

Leading all company-wide fraud prevention training sessions.

d)

Monitoring the organization's whistleblower hotline and reporting to management.

88.

Which of the following is not a duty of the Board of Directors regarding fraud oversight?

a)

Directing the internal audit function and independent auditors.

b)

A comprehensive understanding of fraud-related policies and procedures.

c)

Conducting investigations of fraud incidents themselves.

d)

Receiving and monitoring reports on fraud incidents.

89.

What should employees do as part of their role in fraud risk management?

a)

Investigate suspicious activities on their own.

b)

Retain outside counsel when fraud is suspected.

c)

Have a basic understanding of fraud and red flags.

d)

Provide assurance to the board about fraud risks.

90.

COSO's Internal Control Framework consists of five internal control components and 17 principles for achieving effective internal control. Which of the following is/are (a) principle(s)?

a)

I. The organization demonstrates a commitment to integrity and ethical values.

b)

II. A level of assurance that is supported by generally accepted auditing procedures and judgments.

c)

III. A body of guiding principles that form a template against which organizations can evaluate a multitude of business practices.

d)

IV. The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.

91.

The internal audit function's responsibilities with respect to fraud are limited to:

a)

The organization's operational and compliance activities only because financial reporting matters are the responsibility of the independent outside auditor

b)

Monitoring any calls received through the organization's whistleblower hotline but not necessarily conducting a follow-up investigation

c)

Being aware of fraud indicators, including those relating to financial reporting fraud, but not necessarily possessing the expertise of a fraud investigation specialist

d)

Ensuring that all employees have received adequate fraud awareness training

92.

Which of the following is a preventive control?

a)

credit check before approving a sale on account

b)

bank reconciliation

c)

physical inventory count

d)

comparing the accounts receivable subsidiary

93.

Which of the following describes a detective control?

a)

Regularly reviewing financial transactions to identify errors or anomalies

b)

Implementing measures to prevent unauthorized access to sensitive data

c)

Providing training to employees on cybersecurity best practices

d)

Conducting background checks on prospective employees before hiring

94.

Which of the following best exemplifies a control activity referred to as independent verification?

a)

Reconciliation of bank accounts by someone who does not handle cash or record cash transactions

b)

Identification badges and security codes used to restrict entry to the production facility

c)

Accounting records and documents that provide a trail of sales and cash receipt transactions

d)

Separating the physical custody of inventory from inventory accounting

95.

The requirement that purchases be made from suppliers on an approved vendor list is an example of a:

a)

detective control

b)

preventive control

c)

corrective control

d)

compensating control

96.

Which rationale is least likely to be used by a fraud perpetrator?

a)

I deserve this after all the extra work I've done.

b)

This is a temporary fix to my financial situation.

c)

I want to prove how clever I am by beating the system.

d)

I need to help my family with this money.

97.

Which of the following is a key responsibility of the internal audit function in managing fraud risk?

a)

Reviewing and approving all changes to employee pay rates.

b)

Conducting full forensic investigations of all suspected fraud incidents.

c)

Reporting any identified fraud risks to senior management and the board.

d)

Training external auditors on the organization's internal controls.

98.

What is one of the key roles of the internal audit function in managing fraud risk?

a)

Developing fraud-related policies and incentive plans.

b)

Conducting day-to-day fraud detection activities.

c)

Providing independent assurance to the board and management.

d)

Establishing a system of monitoring and reporting.

99.

What fraud schemes were reported to be most common in the ACFE's 2016 Report to the Nations?

a)

Corruption

b)

Fraudulent billing.

c)

Misappropriation of assets by employees.

d)

Inappropriately reporting revenues in published financial results.

100.

A payroll clerk increased the hourly pay rate of a friend and shared the resulting overpayment with the friend. Which of the following controls would have best served to prevent this fraud?

a)

Requiring that all changes to pay records be recorded on a standard form

b)

Periodically reconciling pay rates per personnel records with those of the payroll system

c)

Limiting the ability to make changes in payroll system personnel information