wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Unit 3.2: Processes to Develop a Risk-Based Audit Plan.

Total questions: 75

Worksheet time: 3hrs 30mins

Name
Class
Date
1.
Which of the following is best defined as the possibility that an internal auditor will fail to detect a material misstatement that causes financial statements or internal reports to be misstated or misleading?
a)
Detection risk.
b)
An event could occur affecting the achievement of objectives.
c)
Management will, either knowingly or unknowingly, make decisions that increase the potential liability of the organization.
d)
Financial statements or internal records will contain material misstatements.
2.
A CAE may use risk analysis in preparing work schedules. Which of the following is considered in performing a risk analysis?
a)
Issues relating to organizational governance.
b)
Skills available on the internal audit staff.
c)
Forecasted results of future engagements.
d)
Minor operating changes.
3.
Which internal audit planning tool is general in nature and is used to ensure adequate engagement coverage over time?
a)
The audit engagement work program.
b)
The internal audit function’s budget.
c)
The internal audit function’s charter.
d)
The internal audit function's charter.
4.
An internal auditor at a manufacturing company is developing a risk-based audit plan. The company has recently integrated the Internet of Things (IoT) technology into its production processes. What should the auditor prioritize when assessing risks related to this new technology?
a)
Evaluate the financial effects of the IoT investment on the company’s budget.
b)
Assess the effectiveness of the IoT devices in improving production efficiency.
c)
Review the cybersecurity measures in place to protect data generated by IoT devices.
d)
Conduct a survey among employees to determine their satisfaction with the new technology.
5.
An internal auditor should prioritize the annual audit schedule. Which factor should primarily influence the prioritization of audit engagements?
a)
The personal preferences of the audit team.
b)
The length of time since the last audit.
c)
The number of complaints received about each area.
d)
The assessed level of risk in each area.
6.
The internal audit function’s audit plan is based on all of the following except
a)
The audit universe.
b)
The cost of the engagement.
c)
Input from senior management and the board.
d)
Assessed risk and exposures.
7.
An organization with a strong ethical culture is undergoing a rapid expansion. How should the internal audit plan adapt to this change?
a)
Increase audits for financial reporting only.
b)
Focus on operational audits in new locations.
c)
Prioritize audits on the integration of the ethical culture across new units.
d)
Delay audits until the expansion is complete.
8.
An internal auditor at a manufacturing company is developing a risk-based audit plan. The company has recently expanded its production facilities overseas, introducing new compliance and regulatory challenges. What should be the auditor’s first step in developing this audit plan?
a)
Review new audit reports to identify recurring issues.
b)
Consult with the board and senior management to understand strategic objectives and risks.
c)
Prioritize audits based on the availability of internal audit resources.
d)
Focus on areas with the highest financial effects on the organization.
9.
During a review of risk management practices, an internal auditor finds that key controls have not been updated in response to new regulations. What should be the auditor’s recommended course of action?
a)
Advise management to develop a compliance training program.
b)
Recommend immediate updating of the key controls.
c)
Suggest addressing controls for the new regulations during the next audit if they are not enforced.
d)
Propose hiring external consultants to conduct a full review.
10.
An inventory management system is a primary risk to consider in the audit of the effectiveness of the inventory control system. What is a primary risk to consider in this engagement?
a)
Potential for inventory theft or loss.
b)
Fluctuations in market demand.
c)
Changes in supplier pricing.
d)
Employee turnover in the sales department.
11.
The internal auditing activity of Rivers Financial Group is developing a plan for the current year. Which of the following should not be emphasized in the audit plan?
a)
All control systems.
b)
Areas where inherent risk is very high.
c)
Control systems on which the organization is most reliant.
d)
Unacceptable current risks that require management action.
12.
An organization has no formal risk management framework. In developing a risk-based plan to determine the priorities of the internal audit function, the chief audit executive (CAE) should
a)
Use the same risk-based plan developed for other clients.
b)
Not establish a risk-based plan because one is not necessary.
c)
Consult with senior management and the board and use the best judgment of risks.
d)
Limit the scope of the engagement.
13.
The chief audit executive (CAE) performs a risk assessment before developing the annual audit plan. Which of the following is most likely to increase the assessment of identified risks?
a)
An immaterial, unanticipated drop in cash flow after plant closings.
b)
A request from senior management to review the strategic plan.
c)
An unexpected, significant increase in receivables not related to an increase in sales.
d)
A critical activity had not been subject to a compliance audit during the past year.
14.
Risk management is critical to the sound governance of which of the following?
a)
Financial activities of the organization.
b)
Manufacturing activities of the organization.
c)
All organizational activities that produce more than 10% of revenue.
d)
All organizational activities, regardless of revenue.
15.
An internal auditor at a financial institution is evaluating the effectiveness of the organization’s control systems. Which of the following should be a key consideration during this evaluation?
a)
The cost of implementing the controls.
b)
The relationship of controls with organizational objectives.
c)
The popularity of the controls among employees.
d)
The historical performance of the financial institution.
16.
A CAE is reviewing a request from the board to conduct an audit on a newly implemented blockchain system. The CAE must decide whether to include this request in the annual audit plan. Which factors should be considered when making this decision?
a)
The blockchain system’s alignment with the internal audit charter and potential resource constraints.
b)
The novelty of blockchain technology and its potential to attract regulatory interest.
c)
The preferences of the internal auditors regarding the audit of new technologies.
d)
The potential for the blockchain system to enhance the organization’s public image.
17.
An internal auditor is reviewing the engagement plan for an advisory service to be offered to a department within the organization. What is a key consideration to ensure this engagement is beneficial?
a)
The engagement requires minimal resources.
b)
The benefits of the engagement exceed its costs.
c)
The engagement focuses only on compliance issues.
d)
The engagement is requested by a senior manager.
18.
The internal audit function at a financial institution is assessing the effectiveness of the organization’s risk management process. Which of the following should be the audit’s focus area to ensure comprehensive coverage?
a)
The organization’s asset liquidity.
b)
The organization’s code of conduct.
c)
The organization’s compliance with environmental regulations.
d)
The organization’s IT security measures.
19.
In preparing the internal audit plan, the CAE needs to consider requests from the board and senior management. What is a critical factor the CAE must assess regarding these requests?
a)
The popularity of the request among employees.
b)
Whether the request involves financial reporting.
c)
The ease of scheduling the requested audit.
d)
The consistency of the request with the internal audit charter.
20.
An internal auditor at a technology organization is assessing the effects of emerging technologies on the organization’s risk profile. Which of the following should be the primary focus of the auditor’s assessment?
a)
Evaluating the risk reduction potential of new technologies.
b)
Identifying and managing risks associated with new technologies.
c)
Assessing the market demand for new technological products.
d)
Reviewing the organization’s historical technology investments.
21.
An internal auditor is auditing the control systems of an organization that has recently undergone significant organizational changes. Which factor should the auditor consider most critical in this situation?
a)
The organization’s strategic objectives and risk profile of the organization.
b)
The most recent findings of the organization.
c)
The financial performance of the organization post changes.
d)
The feedback from employees about the changes.
22.
The internal audit function of a large retail chain is evaluating its audit universe. Which factor should be considered most critical when prioritizing engagements?
a)
The availability of internal audit staff.
b)
The organization’s risk profile and strategic objectives.
c)
The recent implementation of new marketing directions.
d)
The preferences of the board of directors.
23.
During a risk-based audit plan, the chief audit executive (CAE) of a healthcare organization is assigned to a risk-based audit plan. What is the most critical factor the CAE should consider?
a)
The organization’s budgetary constraints for the upcoming year.
b)
Input from patients and community stakeholders.
c)
The results of the organization’s risk management and strategic objectives.
d)
The scheduling preferences of the internal audit team.
24.
An internal auditor at a healthcare organization observes that the organization lacks a formal risk management framework. What action should the auditor take next to address this issue?
a)
Recommend the immediate implementation of the COSO ERM framework.
b)
Perform an independent risk assessment before consulting management.
c)
In the absence of a framework, increase audit engagements.
d)
Consult with senior management to understand their current risk management practices before recommending a framework.
25.
During an advisory engagement, you notice that the organization’s risk management process is not fully integrated across all departments. What should be your first course of action?
a)
Document the observation and proceed with the current scope.
b)
Expand the engagement scope to include a full risk management audit.
c)
Discuss the observation with management to understand the underlying reasons.
d)
Recommend immediate changes in the organization’s risk management process.
26.
As a chief audit executive (CAE), you are preparing the annual internal audit plan for a healthcare organization. Given the industry-specific risks, which engagement should be prioritized in a risk-based audit plan?
a)
Auditing the cafeteria’s inventory management system.
b)
Reviewing compliance with patient data privacy regulations.
c)
Assessing the hospital’s parking facility revenue controls.
d)
Verifying the accuracy of gift shop sales records.
27.
An internal auditor at XYZ Corporation notices that the frequency of financial surprises has increased at senior management levels. Which action should the auditor prioritize to address this issue?
a)
Perform an independent evaluation of the organization’s risk management framework.
b)
Focus on auditing low-risk areas to confirm their risks have not changed.
c)
Focus on auditing low-risk areas to confirm their risks have not changed.
d)
Recommend the implementation of a new IT system to improve financial reporting.
28.
What is the purpose of establishing an internal audit plan?
a)
To update the audit universe.
b)
To ensure adequate coverage of areas with the greatest exposure to risks.
c)
To identify areas of audits with lower risks.
d)
To identify, document, and analyze the means by which management mitigates the risks.
29.
Risk assessment is a systematic process for assessing and integrating professional judgment about probable adverse conditions or events. Which of the following statements reflects the appropriate action for the chief audit executive to take?
a)
The chief audit executive should generally assign engagement priorities to activities with higher risks.
b)
The chief audit executive should restrict the number of sources of information used in the risk assessment process.
c)
Work schedule priorities should be established to lead the chief audit executive in the risk assessment process.
d)
The risk assessment process should be conducted at least every 3 to 5 years.
30.
When developing the internal audit plan, the chief audit executive must consider the expectations of the following: Department managers Stakeholders Human resource managers.
a)
1 only.
b)
2 only.
c)
3 only.
d)
2 and 3.
31.
Which of the following is not considered in a risk analysis?
a)
Skills available on the internal audit staff.
b)
Issues relating to organizational governance.
c)
The length of time since the last audit.
d)
The results of prior engagements.
32.
Which of the following represents the appropriate internal audit action in response to the risk assessment process? The low-risk areas may be delegated to the internal audit function, but the high-risk areas should be performed by the internal audit function. The high-risk areas should be integrated into an audit work schedule along with the high-priority requests of senior management and the audit committee. The risk analysis should be used in determining an annual audit work schedule. Thus, the risk analysis should be performed only on an annual basis.
a)
1 only.
b)
2 only.
c)
3 only.
d)
1 and 3 only.
33.
Considering that auditing factors, including criteria derived from both traditional methods and contemporary approaches such as data analytics, integrated auditing, and remote auditing techniques, will adequately weigh, which audit engagements should the chief audit executive pursue?
a)
1 and 2 only.
b)
1 and 3 only.
c)
2 and 3 only.
d)
1, 2, and 3 only.
34.
The chief audit executive of an organization has developed a plan that includes a detailed schedule of engagements to be performed during the coming year, an estimate of the time required for each engagement, and the approximate starting date of each engagement. The scheduling of specific engagements was based upon the time elapsed since the last engagement in each department. The plan is inadequate because it fails to
a)
Cite authoritative support for such a plan.
b)
Consider factors such as risk and effectiveness of risk management processes.
c)
State whether all internal audit function resources have been committed to the plan.
d)
Seek senior management approval of the plan.
35.
Management has just implemented a policy that every department must downsize its immediate cutting 10% of each department’s staff and budget. The chief audit executive has reacted to the organization’s recent plans for downsizing (reducing the size of staff across the board) by notifying the internal audit function staff and budgets that the CAE will re-prioritize internal audit resources so that the CAE will reduce the immediate engagement risk coverage by 10%. Which of the following statements actually are true regarding the chief audit executive’s action and potential internal audit supervisors’ action is true?
a)
The chief audit executive’s action should result in approximately the same amount of risk coverage as the previous engagement work schedule but reduced by 10%.
b)
Individual internal audit supervisors can attain 90% of the previously defined engagement coverage by uniformly cutting engagement procedures by 10%.
c)
The chief audit executive should have re-prioritized risks and eliminated specific engagements rather than cutting 10% across the board.
d)
All of the answers are correct.
36.
The work of the internal audit function includes evaluating and contributing to the improvement of risk management systems. The negative effect of certain criteria to occur Measured in terms of impact Measured in terms of likelihood.
a)
1 only.
b)
1 and 2 only.
c)
2 and 3 only.
d)
1, 2, and 3 only.
37.
An approved audit plan for the internal audit function is an essential part of
a)
Scheduling support for the external audit.
b)
Establishing standards for employee performance.
c)
Providing senior management with information about the quality of the internal audit function’s performance.
d)
Planning for the internal audit function.
38.
A chief audit executive (CAE) uses a risk assessment model to establish the annual audit plan. Which of the following would be an appropriate action by the CAE? Maintain ongoing dialogue with management and the audit committee Ensure that the schedule of audit priorities remains unchanged Employ only quantitative methods to determine risk weightings Revise the risk assessment and audit priorities as warranted.
a)
1 only.
b)
1 and 2 only.
c)
1 and 4 only.
d)
3 and 4 only.
39.
Which of the following represent(s) appropriate internal audit action in response to the risk assessment process? The high-priority requests of senior management and the audit committee should be given little weight with regard to the audit work schedule. Engagements for the low-risk areas may be delegated to the external auditor, but engagements for the high-risk areas should be performed by the internal audit function. The chief audit executive should develop a risk-based plan, making adjustments as necessary in response to organizational changes. The risk analysis should be used in determining an annual audit work schedule, implying risk analysis is performed only on an annual basis.
a)
1 only.
b)
2 only.
c)
3 only.
d)
2 and 4 only.
40.
The internal audit function’s plan of engagements is based on which of the following?
a)
Risk Assessment Undertaken at least annually Input of The board and senior management.
b)
Risk Assessment Undertaken at least annually Input of The board and senior management.
c)
Risk Assessment Undertaken at least semi-annually Input of The board and senior management.
d)
Risk Assessment Undertaken at least semi-annually Input of The board and senior management.
41.
The internal audit function is effectively managed when
a)
Senior management creates its operating budget.
b)
The organization’s human resources department hires the internal audit function’s associates.
c)
Trends and emerging issues are considered.
d)
The board establishes policies and procedures for the internal audit function.
42.
Which of the following parties is (are) primarily responsible for resource management in an internal auditing engagement? The chief audit executive Senior management.
a)
1 and 2.
b)
1 only.
c)
2 only.
d)
1 and 3.
43.
The internal audit function has recently experienced the departure of two internal auditors who cannot be immediately replaced due to budget constraints. Which of the following is the least desirable option for efficiently completing future engagements given this reduction in resources?
a)
Using self-assessment questionnaires to address audit objectives.
b)
Employing information technology in audit planning, sampling, and documentation.
c)
Eliminating advisory engagements from the engagement work schedule.
d)
Filling vacancies with personnel from operating departments that are not being audited.
44.
According to The IIA’s Three Lines Model,
a)
Management has first line and second line roles. Describing the governing body as a "line" is logical, but The IIA elected not to use this convention to avoid confusion.
b)
First line roles include support functions.
c)
Second line roles involve delivery of products to clients.
d)
Third line roles are performed primarily by external auditors.
45.
Which of the following is not considered in preparing a risk analysis?
a)
Issues relating to organizational governance.
b)
Skills available on the internal audit staff.
c)
Results of prior engagements.
d)
Major operating changes.
46.
Risk modeling or risk analysis is often used in conjunction with development of long-range engagement work schedules. The key input in the evaluation of risk is:
a)
Previous engagement results.
b)
Management concerns and preferences.
c)
Specific requirements of professional standards.
d)
Judgment of the internal auditors.
47.
The chief audit executive of a manufacturer is updating the long-range engagement work schedule. Several possible engagements can be assigned to a given time slot. Information on potential monetary exposure and key internal controls has been gathered. Based on percent and risk, select the assignment of greatest merit.
a)
Precious metals inventory – carrying amount, $1,000,000; separately stored, access not restricted.
b)
Branch office petty cash – ledger amount, $50,000; 10 branch offices, equal amounts; replenishment of accounts requires three separate approvals.
c)
Sales force travel expenses – budget, $1,000,000; 50 sales people; all expenditures over $25 must be receipted.
d)
Expendable tools inventory – carrying amount, $500,000; issued by tool crib attendant upon receipt of authorization form.
48.
Which of the following comments is (are) true regarding the assessment of risk associated with two projects that are competing for limited internal audit resources? Industry knowledge should be used to identify the project with the higher priority. Activities with higher financial budgets always should be considered higher risk than those with lower financial budgets. Activities that are requested by the board always should be considered higher risk than those requested by management. Senior management’s evaluations of the risk associated with each project must be considered.
a)
1 and 2 only.
b)
2 and 3 only.
c)
1 and 3 only.
d)
1 and 4 only.
49.
Which of the following actions by the internal audit function is (are) appropriate in response to a risk assessment? Although input of senior management and the board should be obtained, the chief audit executive does not need to consider it when developing the internal audit function’s plan of engagements. The high-risk areas should be integrated into an audit plan along with the high-priority requests of management and the audit committee. The risk analysis should be used in determining an annual audit plan. Thus, it should be performed only on an annual basis.
a)
1 only.
b)
2 only.
c)
1 and 3 only.
d)
1 and 2 only.
50.
The internal auditors of Smother Corp. are considering lower-risk audits as a part of their audit plan. They should
a)
Include the lower-risk audits to give them coverage and confirm that their risks have not changed.
b)
Not include the lower-risk audits in the audit plan since they are not risky.
c)
Include only half of the lower-risk audits to see if the risks have changed.
d)
Include the lower-risk audits only with senior management approval.
51.
The chief audit executive for the next budget year and limited resources. In deciding whether to schedule the purchasing or the personnel department for an engagement, which of the following is the least important factor?
a)
Major changes in operations have occurred in one of the departments.
b)
The internal audit staff has recently added an individual with expertise in one of the areas.
c)
More opportunities to achieve operating benefits are available in one of the departments than in the other.
d)
Updated assessed risk is significantly greater in one department than the other.
52.
Which of the following factors is least likely to be considered in determining the audit work schedule?
a)
Engagement work programs.
b)
The effectiveness of risk management and control processes.
c)
The effectiveness of risk management and control processes.
d)
Issues relating to organizational governance.
53.
During discussions with senior management, the chief audit executive identified several strategic business issues to consider in preparing the annual audit work schedule. Which of the following is most important to ensure the assessment’s independence?
a)
A monthly budgeting process will be implemented.
b)
An international marketing campaign will be started to develop product recognition and also to leverage the new organization-based advertising department.
c)
Joint-venture candidates will be sought to provide manufacturing and sourcing capabilities in European and Asian markets.
d)
Human resources data will be established to ensure consistent administration of policies and to improve data retention.
54.
The chief audit executive for an organization has just completed a risk assessment process, identified the areas with the highest risks, and assigned an engagement priority to each. Which of the following conclusions most logically follow(s) from such a risk assessment items should be quantified as to risk in the rank order of quantifiable monetary exposure to the organization. The risk priorities should be in order of major control deficiencies. The risk assessment process, though quantified, is the result of professional judgments about both exposures and probability of occurrences.
a)
1 only.
b)
1 and 2 only.
c)
2 and 3 only.
d)
1, 2, and 3 only.
55.
Which of the following comments is (are) true regarding the assessment of risk associated with two projects that are competing for limited internal audit resources? Activities that are requested by the board always should be considered higher risk than those requested by management. Activities with higher financial budgets always should be considered higher risk than those with lower financial budgets. The risk is the highest risk assessment process.
a)
1 only.
b)
1 and 2 only.
c)
2 and 3 only.
d)
1 and 3 only.
56.
The internal auditor is considering making a risk analysis as a basis for determining the activities of the organization where engagements should be performed. Which one of the following statements is true regarding risk analysis?
a)
The extent to which internal auditor judgments are required in an activity could serve as a risk factor in assisting the internal auditor in making a comparative risk analysis.
b)
The highest risk assessment should always be assigned to the activity with the greatest potential loss.
c)
The extent to which internal auditor judgments are required in an activity could serve as a risk factor in assisting the internal auditor in making a comparative risk analysis.
d)
The concept of risk analysis is not limited to quantitative measures.
57.
The chief audit executive set up a computerized spreadsheet to facilitate the risk assessment process involving a number of different divisions in the organization. The spreadsheet included the following factors: Presence on divisional management to meet profit goals Complexity of operations. Competence of divisional personnel. The monetary amount of subjectively influenced accounts in the division, such as accounts in which management’s judgment can affect the expense, e.g., postretirement benefits The CAE used a group meeting of internal audit supervisors to reach a consensus on the competence of divisional personnel. Other factors were assessed as high, medium or low by either the CAE or an internal audit supervisor who had performed an engagement at the division. The CAE assigned a weight ranging from 0.5 to 1.0 to each factor and then computed a composite risk score. Which statement is true?
a)
The risk analysis is not appropriate because it mixes both quantitative and qualitative factors, thereby making expected value calculations impossible.
b)
Assessing factors at discrete levels such as high, medium, and low is inappropriate for the risk assessment process because the ratings are not quantifiable.
c)
The weighting is subjective and should have been determined through a process such as multiple-regression analysis.
d)
Using a subjective group consensus to assess personnel competence is appropriate.
58.
When a risk assessment process has been used to construct an audit engagement schedule, which of the following should receive attention first?
a)
The external auditors have requested assistance for their upcoming annual audit.
b)
A new accounts payable system is currently undergoing testing by the information technology department.
c)
Management has requested an investigation of possible lapping in receivables.
d)
The existing accounts payable system has not been audited over the past year.
59.
Which of the following is considered the least important in deciding whether existing internal audit resources should be moved from an ongoing compliance engagement to a divisional-level engagement requested by management?
a)
A financial audit of the divisional performed by the external auditor a year ago.
b)
The potential for fraud associated with the ongoing engagement.
c)
The potential for fraud associated with the ongoing engagement.
d)
The significant regulatory fines associated with the ongoing engagement.
60.
Which of the following represents the best based on the relative extent of uncertainty of those events and their impact on achievement of long-term organizational objectives?
a)
Assessment of the risk levels for future events.
b)
Assessment of inherent and control risks and their impact on the extent of financial misstatements.
c)
Assessment of the risk levels of current and future events, the effect on achievement of the organization's objectives, and the root causes identified using data analytics.
d)
Assessment of the risk levels of current and future events, their impact on the organization’s mission, and the potential for elimination of existing or possible risk factors.
61.
What is the chief audit executive’s most logical definition of risk of loss to be used in selecting a department for review?
a)
Amount of risk exposure times the probability of loss.
b)
Amount of annual costs in a department.
c)
Probability of loss.
d)
Amount of assets in a department.
62.
Which department most likely needs a pure operational (nonfinancial) engagement?
a)
Production A.
b)
Production C.
c)
Purchasing.
d)
Marketing.
63.
The chief audit executive is considering engagement assignments for inclusion in the work schedule for the upcoming year. The following activities have not been evaluated recently, and there are no known reasons that they should be given immediate attention. If resources are scarce, which project should be given priority?
a)
Cash and credit policy.
b)
Cash management and credit policy.
c)
Employee time reporting and forecasting.
d)
Budget preparation and forecasts.
64.
Which of the following is a valid reason for an internal auditing engagement involving a payroll department to receive priority over a purchasing department engagement?
a)
The director of the payroll department requested that the payroll department engagement be performed first.
b)
The purchasing department engagement will require more time to perform.
c)
The payroll department’s relative risk and exposure are greater.
d)
The purchasing department recently restructured its major operations.
65.
An organization manufactures mirror frames. Scrap is adequately accounted for at the point of generation. The scrap is sorted and sold frequently to the organization’s regular buyer at a price negotiated between the scrap manager and the buyer. A risk exposure caused by these procedures is that
a)
Excessive scrap has been generated.
b)
The price received for scrap may be inadequate.
c)
The production of scrap indicates inefficiencies in production.
d)
Nothing suggests excessive scrap generation.
66.
Updating the audit universe is useful in developing the internal audit plan. The audit universe
a)
Consists of all possible audits.
b)
Reflects only past organizational strategies.
c)
May not overlap with the organization’s strategic plan.
d)
Is typically updated on a fixed, alternate-year schedule.
67.
The chief audit executive develops a risk-based plan after updating the audit universe. The item least likely to be part of the audit universe is
a)
Major programs.
b)
Cost, profit, and investment centers.
c)
A component of the organization’s strategic plan.
d)
The minutes from the last board of directors meeting.
68.
The internal audit function of a large organization has established its operating plan and budget for the coming year. The operating plan is restricted to the following categories: a prioritized listing of all engagements, staffing, a detailed expense budget, and the commencement date of each engagement. Which of the following best describes the major deficiency of this operating plan?
a)
Requests by management for special projects are not considered.
b)
Opportunities to achieve operational benefits are ignored.
c)
Measurability criteria and targeted dates of completion are not provided.
d)
Knowledge, skills, and other competencies required to perform work are not provided.
69.
At a meeting with engagement supervisors, the chief audit executive is allocating the engagement work schedule for next year’s plan. Which of the following methods will ensure that each supervisor receives an appropriate share of both the work schedule and internal audit function resources?
a)
The full list of scheduled engagements is published for the staff, and work assignments are made based on career interests and travel requirements.
b)
Review of external auditor’s internal control and audit reports during each engagement is done by a different accounting firm.
c)
Each supervisor is assigned to teach based on risk and skill analysis.
d)
Each supervisor is assigned to teach based on risk and skill analysis.
70.
The chief audit executive of a manufacturer is updating the long-range engagement work schedule. Several possible engagements can be assigned to a given time slot. Information on potential monetary exposure and key internal controls has been gathered. Based on percent and risk, select the assignment of greatest merit.
a)
Precious metals inventory – carrying amount, $10,000; separately stored, access restricted.
b)
Branch office petty cash – ledger amount, $75,000; 10 branch offices, equal amounts; replenishment of accounts requires three separate approvals.
c)
Sales force travel expenses – budget, $1,200,000; 50 sales people; all expenditures over $25 must be receipted.
d)
Expendable tools inventory – carrying amount, $1,100,000; stored with other inventory.
71.
In deciding whether to accept an advisory engagement, the Standards require the chief audit executive to consider the engagement’s potential to Add value Improve management of risks Develop internal audit competencies Improve the organization’s operations.
a)
1 only.
b)
1 and 2 only.
c)
1, 2, and 4 only.
d)
1, 2, 3, and 4.
72.
Which of the following is not a requirement of risk-based audit planning?
a)
The chief audit executive consults with external auditors.
b)
The risk-based plan considers the organization’s strategies and objectives.
c)
The risk-based plan is adjusted for changes in the organization’s business.
d)
To determine the priorities of the internal audit function, a risk-based plan must be established.
73.
Which of the following is not a characteristic of effective risk management?
a)
It provides absolute assurance that organizational objectives will be achieved.
b)
It is fully integrated into management at all levels.
c)
It assists in identifying key controls.
d)
It reduces unacceptable risks to tolerable levels.
74.
Which of the following represents an external risk factor?
a)
The organization’s CEO unexpectedly became ill and had to resign. The chairman of the board of directors stepped into the vacant role until a new CEO could be found.
b)
The company performed an outdated equipment used in the manufacturing process cost three times more than the amount budgeted.
c)
Additional safety regulations enacted by the government have caused a strain on the organization’s resources.
d)
Weak controls over cash accounts have resulted in employee theft.
75.
Refer to the internal audit function’s charter and the approved engagement plan that includes the area designated for evaluation in the current time period. The internal auditor should
a)
The written charter, approved by the board, defines the scope of internal audit activities.
b)
Management does not determine the scope of this type of assurance engagement. A scope limitation imposed by management might prevent the internal audit function from achieving its objectives.
c)
Other objectives may be established by management and the internal auditors. The internal audit function should always adhere to the professional standards set by the quality assurance department. It considers such standards in the development of the engagement program.
d)
The internal auditors must conduct the engagement and communicate any scope limitations to senior management and the board.