WorksheetsKTNB Chap 5+6
Total questions: 53
Worksheet time: 27mins
How does a control manage a specific risk?
It reduces the likelihood of the event giving rise to the risk.
It reduces the impact of the event giving rise to the risk.
It reduces either likelihood or impact or both.
It prevents the occurrence of the event
According to the risk factors approach (linking business processes and risks is through the development of basic risk factors used to evaluate risks across processes),which of the following are internal factors?
(I) Internal control effectiveness
(II) Significant changes in operations, processes, personnel, or technology within the company
(III) Legal/regulatory/external requirements
(IV) Complexity
(I) and (II)
(I) and (II) and (IV)
(II) and (III) and (IV)
Which of the following symbols in a process map will most likely contain a question?
Rectangle.
Diamond.
Arrow.
Oval
What risk response option are being applied by the organization: “The risk impact or likelihood is reduced by transferring or otherwise sharing a portion of the risk. Common techniques include purchasing insurance products, engaging in hedging transactions, or outsourcing an activity”
Acceptance
Avoidance
Pursuit
Reduction
Sharing
In a risk by process matrix, a process that helps to manage a risk indirectly would be shown to have:
A key link.
A secondary link.
An indirect link.
No link at all.
A company has recently outsourced its payroll process to a third-party service provider. An audit team was scheduled to audit payroll controls in the annual audit plan prepared prior to the outsourcing.
What action should the audit team take, considering the outsourcing decision?
Cancel the engagement, because the processing is being performed outside the organization.
Review only the controls over payments to the third-party provider based on the contract.
Review only the company's controls over data sent to and received from the third-party service provider.
Review the controls over payroll processing in both the company and the third-party service provider.
Use the chart to answer question.
If a risk appears in the bottom right of quadrant II in the above risk control map, it means that:
There is an appropriate balance between risk and control.
The controls may be excessive relative to the risk.
The controls may be inadequate relative to the risk.
There is not enough information to make a judgment
The set of connected activities linker with each other for purpose of achieving an objective?
Business process
Managing process
Risk management process
What risk response option are being applied by the organization: “No action is taken to decrease risk impact or likelihood. The organization is willing to accept the risk at the current level rather than spend valuable resources deploying one of the other risk response options”
Acceptance
Avoidance
Pursuit
Reduction
Sharing
What is a business process?
How management plans to achieve the organization's objectives.
The set of connected activities linked with each other for the purpose of achieving an objective or goal.
A group of interacting, interrelated, or interdependent elements forming a complex whole.
A finite endeavor (having specific start and completion dates) undertaken to create a unique product or service that brings about beneficial change or added value.
According to the risk factors approach (linking business processes and risks is through the development of basic risk factors used to evaluate risks across processes), which of the following are external factors?
(i) Market Visibility
(ii) Size of process/operation
(iii) Legal/regulatory/external requirements
(iv) Internal control stability
(I) and (III)
(I) and (II) and (IV)
(II) and (III) and (IV)
What risk response option are being applied by the organization: “A decision is made to exit or divest of the activities giving rise to the risk. For example, exiting a product line, deciding not to expand to a new geographical market, or selling a division”
Acceptance
Avoidance
Pursuit
Reduction
Sharing
Begins by looking at all processes directly at the activity level, and then aggregates the identified processes across the organization.
Top-Down Approach
Bottom-Up Approach
None of the above
Refers to how management plans to achieve the organization's objectives.
Objectives
Strategy
None of the above
What risk response option are being applied by the organization: “Exploit the risk if taking such a risk is advantageous to the organization or is necessary to achieve a particular business objective”
Acceptance
Avoidance
Pursuit
Reduction
Sharing
Which of the following are business processes?
I. Strategic planning.
II. Review and write-off of delinquent loans.
III. Safeguarding of assets.
IV. Remittance of payroll taxes to the respective tax authorities.
I and III.
II and IV.
I, II, and IV.
I, II, III, and IV
Begins at the entity level with the organization's objectives, and then identifies the key processes critical to the success of each of the organization's objectives
Top-Down Approach
Bottom-Up Approach
None of the above
In assessing organizational risk in a manufacturing organization, which of the following would have the greatest long-range impact on the organization?
Advertising budget.
Production scheduling.
Inventory policy.
Product quality
A major upgrade to an important information system would most likely represent a high
External risk factor.
Internal risk factor.
Other risk factor.
Likelihood of future systems problems
Internal auditors often prepare process maps and reference portions of these maps to narrative descriptions of certain activities. This is an appropriate procedure to:
Determine the ability of the activities to produce reliable information.
Obtain the understanding necessary to test the process.
Document that the process meets internal audit standards.
Determine whether the process meets established management objectives.
After business risks have been identified, they should be assessed in terms of their inherent:
Impact and likelihood.
Likelihood and probability.
Significance and severity.
Significance and control effectiveness.
Use the chart to answer question.
Which of the following circumstances would concern the internal auditor the most?
A risk in the lower left corner of quadrant I.
A risk in the lower right corner of quadrant II.
A risk in the upper left corner of quadrant III.
A risk in the upper right corner of quadrant IV
What an entity desires to achieve. When referring to what an organization wants to achieve, these are called business objectives, and may be classified as strategic, operations, reporting, and compliance?
Objectives
Strategy
None of the above
What types of risk response options are there?
Acceptance
Avoidance
Pursuit
Reduction
All of the above
According to the risk factors approach (linking business processes and risks is through the development of basic risk factors used to evaluate risks across processes),which of the following are other factors?
Significant changes in operations, processes, personnel, or technology
Size of process/operation
Prior audit results
Use the chart to answer question.
If a risk appears in the middle of quadrant IV in the above risk control map, it means that:
There is an appropriate balance between risk and control.
The controls may be excessive relative to the risk.
The controls may be inadequate relative to the risk
There is not enough information to make a judgment.
The process plays a direct and key role in managing the risk
A key link.
A secondary link.
An indirect link.
No link at all.
Which of the following is true regarding business process outsourcing?
Outsourcing a core, high-risk business process reduces the overall operational risk.
Outsourced processes should not be included in the internal audit universe.
The independent outside auditor is required to review all significant outsourced business processes.
Management's controls to ensure the outsourcing provider meets contractual performance requirements should be tested by the internal audit function.
What risk response option are being applied by the organization: “Action is taken to reduce the risk impact, likelihood, or both. This involves a myriad of everyday business decisions, such as implementing controls”
Acceptance
Avoidance
Pursuit
Reduction
Sharing
Which flowcharting symbol indicates the start or end of a process?
Arrow.
Diamond
Oval.
Rectangle.
Who has primary responsibility for the monitoring component of internal control?
a. The organization's independent outside auditor.
b. The organization's internal audit function.
c. The organization's management.
d. The organization's board of directors.
Reasonable assurance, as it pertains to internal control, means that:
a. The objectives of internal control vary depending on the method of data processing used.
b. A well-designed system of internal controls will prevent or detect all errors and fraud.
c. Inherent limitations of internal control preclude a system of internal control from providing absolute assurance that objectives will be achieved.
d. Management cannot override controls, and employees cannot circumvent controls through collusion.
operational level within an organization. The COSO framework uses the terms "Entity-Level Control", "Process-Level Control" and "Transaction-Level Control" to generally describe these controls.
The control activities “Controls over management override” is classified as?
A. Entity-Level Control
B. Process-Level Control
C. Transaction-Level Control
When assessing the risk associated with an activity, an internal auditor should:
a. Determine how the risk should best be managed.
b. Provide assurance on the management of the risk.
c. Update the risk management process based on risk exposures.
d. Design controls to mitigate the identified risks.
Who has primary responsibility for the control activities component of internal control?
a. The organization's independent outside auditor.
b. The organization's internal audit function.
c. The organization's management.
d. The organization's board of directors
Which of the following best describes an internal auditor's purpose in reviewing the organization's existing governance, risk management, and control processes?
a. To help determine the nature, timing, and extent of tests necessary to achieve engagement objectives.
b. To ensure that weaknesses in the internal control system are corrected.
c. To provide reasonable assurance that the processes will enable the organization's objectives and goals to be met efficiently and economically.
d. To determine whether the processes ensure that the accounting records are correct and that financial statements are fairly stated.
An effective system of internal controls is most likely to detect a fraud perpetrated by a:
a. Group of employees in collusion.
b. Single employee.
c. Group of managers in collusion.
d. Single manager.
COSO's Internal Control Framework consists of five internal control components and 17 principles for achieving effective internal control. Which of the following is/are (a) principle (s)?
I. The organization demonstrates a commitment to integrity and ethical values.
II. A level of assurance that is supported by generally accepted auditing procedures and judgments.
III. A body of guiding principles that form a template against which organizations can evaluate a multitude of business practices
IV. The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
a. I only.
b. I and IV only.
c. II and IV only.
d. I, II, III, and IV
Appropriate internal control for a multinational corporation's branch office that has a department responsible for the transfer of money requires that:
a. The individual who initiates wire transfers does not reconcile the bank statement.
b. The branch manager must receive all wire transfers.
c. Foreign currency rates must be computed separately by two different employees.
d. Corporate management approves the hiring of employees in this department.
The requirement that purchases be made from suppliers on an approved vendor list is an example of a:
a. Preventive control.
b. Detective control.
c. Compensating control.
d. Monitoring control
An adequate system of internal controls is most likely to detect an irregularity perpetrated by a:
a. Group of employees in collusion.
b. Single employee.
c. Group of managers in collusion.
d. Single manager
"Internal control is not the responsibility of everyone in an organization. Only the board of directors, management and internal auditors are responsible for internal control". Is this statement true or false?
A. True
B. False
Who is primarily responsible for the system of internal control system?
A. Management (CEO)
B. Board of Directors
C. Internal Auditor
COSO's Internal Control Framework consists of five internal control components and 17 principles for achieving effective internal control.
The principle "The organization specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives" supports which component of internal control?
A. Control Environment
B. Risk Assessment
C. Control Activities
D. Information and Communication
E. Monitoring Activities
An internal auditor plans to conduct an audit of the adequacy of controls over investments in new financial instruments. Which of the following would not be required as part of such an engagement?
a. Determine whether policies exist that describe the risks the treasurer may take and the types of instruments in which the treasurer may invest.
b. Determine the extent of management oversight over investments in sophisticated instruments.
c. Determine whether the treasurer is getting higher or lower rates of return on investments than treasurers in comparable organizations.
d. Determine the nature of monitoring activities related to the investment portfolio
27. COSO's Internal Control Framework consists of five internal control components and 17 principles for achieving effective internal control.
The principle " The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels " supports which component of internal control?
A. Control Environment
B. Risk Assessment
C. Control Activities
D. Information and Communication
E. Monitoring Activities
Which of the following best exemplifies a control activity referred to as independent verification?
a. Reconciliation of bank accounts by someone who does not handle cash or record cash transactions.
b. Identification badges and security codes used to restrict entry to the production facility.
c. Accounting records and documents that provide a trail of sales and cash receipt transactions.
d. Separating the physical custody of inventory from inventory accounting.
What is residual risk?
a. Impact of risk.
b. Risk that is under control.
c. Risk that is not managed.
d. Underlying risk in the environment.
Who is responsible for overseeing management, provides direction regarding internal control, and ultimately has responsibility for overseeing the system of internal controls.
A. Management (CEO)
B. Board of Directors
C. Internal Auditor
The risk assessment component of internal control involves the:
a. Independent outside auditor's assessment of residual risk.
b. Internal audit function's assessment of control deficiencies.
c. Organization's identification and analysis of the risks that threaten the achievement of its objectives.
d. Organization's monitoring of financial information for potential material misstatements.
All controls are designed to mitigate risk either at the enterprise level or at the operational level within an organization. The COSO framework uses the terms "Entity-Level Control", "Process-Level Control" and "Transaction-Level Control" to generally describe these controls.
The control activities “Authorizations.” is classified as?
A. Entity-Level Control
B. Process-Level Control
C. Transaction-Level Control
The control that would most likely ensure that payroll checks are written only for authorized amounts is to:
a. Conduct periodic floor verification of employees on the payroll.
b. Require the return of undelivered checks to the cashier.
c. Require supervisory approval of employee time cards.
d. Periodically witness the distribution of payroll checks
All controls are designed to mitigate risk either at the enterprise level or at the operational level within an organization. The COSO framework uses the terms "Entity-Level Control", "Process-Level Control" and "Transaction-Level Control" to generally describe these controls.
The control activities “Physical verifications of assets (such as inventory counts).” is classified as?
A. Entity-Level Control
B. Process-Level Control
C. Transaction-Level Control
