Saturday, August 8, 2026

CIA Part 1Comprehensive mocktest Aug 8




 CIA Part 1Comprehensive mocktest Aug 8

GMSi Gmsisuccess <gmsi2022cia@gmail.com>

cia part 1 compreh mocktest 8aug

GMSi Gmsisuccess <gmsi2022cia@gmail.com>Sat, Aug 8, 2026 at 9:18 AM
To: GMSi Gmsisuccess <gmsi2022cia@gmail.com>

A. Foundations of Internal Auditing

1. Which of the following BEST describes the primary purpose of internal auditing?

A. To prepare accurate financial statements
B. To provide independent, objective assurance and advisory services designed to add value and improve operations
C. To detect every instance of fraud
D. To guarantee that organizational objectives will be achieved

Answer: B


2. Which of the following is NOT normally an objective of internal auditing?

A. Evaluating governance processes
B. Assessing risk management
C. Improving control processes
D. Guaranteeing that management will never make an error

Answer: D


3. The internal audit activity creates value primarily by:

A. Replacing management's responsibilities
B. Providing assurance and insight regarding governance, risk management, and control
C. Taking responsibility for operational decisions
D. Eliminating all organizational risks

Answer: B


4. Which statement about internal auditors is MOST appropriate?

A. Internal auditors own the organization's risks.
B. Internal auditors are responsible for establishing management controls.
C. Internal auditors evaluate and provide assurance regarding governance, risk management, and controls.
D. Internal auditors must approve every significant management decision.

Answer: C

5. EITHER/OR

The internal audit activity primarily provides:

A. Assurance OR advisory services
B. Assurance and/or advisory services
C. Management services OR accounting services only
D. Audit opinions OR statutory certifications only

Answer: B


6. Which of the following would create the GREATEST threat to internal audit independence?

A. The chief audit executive reports functionally to the audit committee.
B. The internal audit department participates in risk assessment discussions.
C. The chief audit executive is responsible for operating a business process being audited.
D. Internal auditors communicate audit findings to senior management.

Answer: C


7. An internal auditor previously managed the payroll function. The auditor is now assigned to audit payroll. Which is the BEST approach?

A. Accept the assignment without modification.
B. Disclose the potential impairment and consider an appropriate safeguard.
C. Cancel the entire internal audit activity.
D. Allow the auditor to audit payroll because prior experience automatically guarantees objectivity

Answer: B


8. ASSERTION–REASON

Assertion: Internal auditors should maintain objectivity during audit engagements.

Reason: Objectivity requires an unbiased mental attitude that allows auditors to perform engagements without compromising professional judgment.

A. Both Assertion and Reason are true, and Reason correctly explains Assertion.
B. Both are true, but Reason does not explain Assertion.
C. Assertion is true, Reason is false.
D. Assertion is false, Reason is true.

Answer: A


9. Which of the following is the BEST example of an internal audit advisory service?

A. Designing and operating management's controls
B. Making an operational decision for management
C. Advising management on control considerations during implementation of a new system
D. Assuming responsibility for the organization's risk management process

Answer: C


10. NEITHER/NOR

Which of the following should internal auditors normally do?

A. Neither evaluate controls nor communicate deficiencies
B. Evaluate controls and communicate significant deficiencies
C. Assume management's responsibility for controls
D. Guarantee that controls will eliminate all risk

Answer: B


B. Ethics & Professionalism

11. Which principle requires internal auditors to be honest and truthful?

A. CompetencyB. IntegrityC. ConfidentialityD. Objectivity

Answer: B


12. An internal auditor discovers confidential customer information during an engagement. The auditor should:

A. Share it with friends because the information is interesting.
B. Use the information for personal investment decisions.
C. Protect the information and use it only for legitimate professional purposes.
D. Publish it after completing the audit.

Answer: C


13. Which of the following is MOST likely to violate the principle of confidentiality?

A. Reporting relevant information to authorized management
B. Discussing confidential client information with an unauthorized third party
C. Using information necessary to perform an audit
D. Protecting audit documentation

Answer: B


14. An auditor receives an expensive gift from the manager of an audited department. What is the PRIMARY concern?

A. CompetencyB. ObjectivityC. CommunicationD. Audit documentation

Answer: B


15. Which of the following is NOT consistent with professional competence?

A. Applying appropriate knowledge and skills
B. Continuing professional development
C. Performing work without possessing the necessary knowledge
D. Maintaining professional proficiency

Answer: C


16. EXCEPT

Internal auditors should demonstrate professional behavior by doing all of the following EXCEPT:

A. Exercising professional judgment
B. Maintaining confidentiality
C. Acting with integrity
D. Suppressing unfavorable audit findings to protect management

Answer: D


17. ASSERTION–REASON

Assertion: Internal auditors should disclose material facts known to them when withholding such facts could distort reporting.

Reason: Ethical professional conduct requires auditors to communicate information fairly and not knowingly participate in misleading reporting.

A. Both are true, and Reason explains Assertion.B. Both are true, but Reason does not explain Assertion.C. Assertion is true, Reason is false.
D. Both are false.

Answer: A


18. An internal auditor lacks sufficient knowledge to audit a highly specialized cybersecurity system. What should the auditor MOST appropriately do?

A. Perform the engagement regardless of competence.
B. Obtain appropriate assistance or expertise.
C. Ignore cybersecurity risks.
D. Ask management to perform the audit instead.

Answer: B


19. Which situation BEST represents a conflict of interest?

A. An auditor reviews a process in which the auditor has a significant personal financial interest.
B. An auditor communicates findings to the audit committee.
C. An auditor performs a risk assessment.
D. An auditor reviews supporting documentation.

Answer: A


20. EITHER/OR

If an auditor's objectivity is impaired, the auditor should:

A. Ignore the impairment OR conceal it
B. Disclose the impairment and apply appropriate safeguards OR avoid the assignment
C. Continue auditing OR change the audit results
D. Accept management's explanation OR delete the working papers

Answer: B


C. Governance

21. Which of the following BEST describes organizational governance?

A. The system by which an organization is directed, overseen, and held accountableB. The process of recording journal entries
C. The preparation of tax returnsD. The process of approving employee leave

Answer: A


22. Which body normally provides the MOST direct oversight of the chief audit executive?

A. Accounts payable departmentB. Audit committee or equivalent governing bodyC. Sales departmentD. Human resources department

Answer: B


23. Which of the following is NOT normally a responsibility of the board?

A. Providing oversight of risk management
B. Overseeing organizational governance
C. Monitoring senior management's performance
D. Performing every operational control personally

Answer: D


24. CASE-BASED

The board of a company rarely receives information about major cybersecurity risks. Management believes cybersecurity is purely an IT issue.

Internal audit discovers that significant cyber risks could affect the organization's strategic objectives.

What should internal audit MOST appropriately recommend?

A. Ignore the issue because cybersecurity belongs only to IT.
B. Ensure significant cybersecurity risks are incorporated into organizational risk oversight and governance.
C. Transfer all cybersecurity responsibilities to internal audit.
D. Eliminate the cybersecurity department.

Answer: B


25. Which governance practice BEST promotes accountability?

A. Clearly defined roles and responsibilities
B. Unlimited management authority
C. No reporting requirements
D. Elimination of independent oversight

Answer: A


26. NEITHER/NOR

Effective governance normally requires:

A. Neither accountability nor transparency
B. Accountability and transparency
C. Elimination of risk assessment
D. Elimination of board oversight

Answer: B


27. Which of the following is the BEST example of effective governance?

A. Management makes decisions without oversight.
B. The board receives reliable information and oversees organizational performance and risk.
C. Internal audit approves operational transactions.
D. Employees determine the organization's risk appetite independently.

Answer: B


D. Risk Management

28. Risk is BEST described as:

A. The certainty that an objective will fail
B. The possibility of an event occurring that could affect achievement of objectives
C. A financial loss only
D. Fraud committed by employees

Answer: B


29. Which of the following BEST describes inherent risk?

A. Risk remaining after controls are applied
B. Risk existing before management takes action to modify it
C. Risk eliminated by internal audit
D. Risk resulting only from fraud

Answer: B


30. Which of the following BEST describes residual risk?

A. Risk before controls are implemented
B. Risk remaining after management's response to risk
C. Risk that can never occur
D. Risk identified only by external auditors

Answer: B


31. A company's risk appetite represents:

A. The amount and type of risk the organization is willing to accept in pursuit of its objectivesB. The amount of fraud management expects
C. The maximum audit feeD. The amount of risk internal audit must eliminate

Answer: A


32. EXCEPT

Management may respond to risk by:

A. Accepting the riskB. Avoiding the riskC. Reducing the riskD. Guaranteeing that the risk will never occur

Answer: D


33. ASSERTION–REASON

Assertion: Internal auditors should consider risk when developing the audit plan.

Reason: Internal audit resources are limited and should generally be directed toward areas with significant risks to organizational objectives.

A. Both are true, and Reason correctly explains Assertion.
B. Both are true, but Reason does not explain Assertion.
C. Assertion is true, Reason is false.
D. Assertion is false, Reason is true.

Answer: A


34. CASE-BASED

A company has identified a major supply-chain risk. Management believes the probability is moderate but the potential financial impact is extremely high.

What should internal audit consider when assessing this risk?

A. Impact only
B. Likelihood only
C. Both likelihood and impact
D. Neither likelihood nor impact

Answer: C


35. Which of the following is the BEST example of risk avoidance?

A. Purchasing insuranceB. Installing additional controls
C. Discontinuing an activity that exposes the organization to unacceptable risk
D. Accepting the risk without action

Answer: C


E. Internal Control

36. The PRIMARY purpose of internal control is to:

A. Guarantee achievement of all objectivesB. Provide reasonable assurance regarding achievement of objectivesC. Eliminate all risks
D. Detect every fraud

Answer: B


37. Which of the following is NOT a typical internal control objective?

A. Effectiveness and efficiency of operations
B. Reliability of reporting
C. Compliance with applicable laws and regulations
D. Guaranteeing zero business risk

Answer: D


38. Which control is MOST likely preventive?

A. Bank reconciliation
B. Exception report
C. Password access restriction
D. Post-audit review

Answer: C


39. Which control is MOST likely detective?

A. Segregation of dutiesB. Authorization before purchase
C. Bank reconciliationD. Password requirement

Answer: C


40. EXCEPT

Which of the following can be considered control activities EXCEPT:

A. AuthorizationB. ReconciliationC. Physical safeguards
D. Elimination of all inherent limitations of control

Answer: D


41. A company requires one employee to prepare payments and another employee to approve them. This is primarily an example of:

A. Segregation of dutiesB. Risk acceptance
C. Risk avoidanceD. Monitoring

Answer: A


42. CASE-BASED

An employee can create a new vendor, approve invoices from that vendor, and authorize payment.

Which control weakness is MOST significant?

A. Excessive monitoring
B. Inadequate segregation of duties
C. Excessive authorization
D. Excessive documentation

Answer: B


43. Which of the following is an example of a corrective control?

A. Password requirementB. Approval before purchase
C. Automated backup restoration after data lossD. Segregation of duties

Answer: C


44. ASSERTION–REASON

Assertion: Internal controls provide reasonable rather than absolute assurance.

Reason: Human judgment, management override, collusion, and cost-benefit considerations can limit control effectiveness.

A. Both are true, and Reason correctly explains Assertion.
B. Both are true, but Reason does not explain Assertion.
C. Assertion is true, Reason is false.
D. Assertion is false, Reason is true.

Answer: A


45. NEITHER/NOR

Which statement is correct regarding internal controls?

A. Neither preventive nor detective controls are necessary.
B. Preventive and detective controls can complement each other.
C. Controls eliminate all risk.
D. Controls eliminate the need for management oversight.

Answer: B


F. Fraud Risks

46. Which of the following is NOT one of the classic elements of the fraud triangle?

A. Pressure/incentiveB. OpportunityC. RationalizationD. Guaranteed detection

Answer: D


47. CASE-BASED

A finance manager is under severe personal financial pressure and believes that manipulating expense reports is justified because "the company owes me anyway."

Which fraud triangle elements are MOST clearly present?

A. Pressure and rationalizationB. Opportunity only
C. Detection and monitoringD. Governance and compliance

Answer: A


48. An employee discovers that no one reviews manual journal entries. The employee realizes that fictitious entries can be recorded without detection.

This situation MOST directly represents:

A. RationalizationB. OpportunityC. PressureD. Risk avoidance

Answer: B


49. EXCEPT

Internal auditors may contribute to fraud risk management by:

A. Assessing fraud risksB. Evaluating controls designed to address fraud risks
C. Increasing awareness of fraud indicatorsD. Assuming complete responsibility for preventing all fraud

Answer: b


50. COMPREHENSIVE CASE-BASED

A rapidly growing company has weak segregation of duties. Senior management rarely reviews unusual transactions. Several employees complain that sales targets are unrealistic. An internal auditor notices that one sales manager frequently records large sales at month-end and reverses them early in the following month.

Which combination BEST represents the situation?

A. Strong governance, low fraud risk, and effective controlsB. Fraud risk indicators involving pressure, opportunity, and potentially inappropriate revenue recognitionC. Only operational risk with no fraud implications
D. Neither governance nor control weaknesses

Answer b

Pl read…High-yield CIA Part 1 areas tested

  • Foundations: purpose, role, assurance/advisory, independence, objectivity
  • Ethics & Professionalism: integrity, objectivity, confidentiality, competency
  • Governance: board, audit committee, accountability, transparency
  • Risk Management: inherent risk, residual risk, appetite, response
  • Internal Control: preventive, detective, corrective, segregation of duties, reasonable assurance
  • Fraud: pressure/incentive, opportunity, rationalization, fraud indicators

CIA Part 1–style MCQs on Ethics & Professionalism….

1. Which principle requires an internal auditor to be honest and transparent in professional activities?

A. ConfidentialityB. ObjectivityC. IntegrityD. Competency

Answer: C. Integrity


2. An internal auditor discovers confidential information about a planned acquisition. What should the auditor do?

A. Share it with colleagues outside the engagement
B. Use it for personal investment purposes
C. Protect the information and use it only for legitimate professional purposes
D. Discuss it publicly after the audit

Answer: C. Protect the information and use it only for legitimate professional purposes


3. Which situation MOST likely impairs an internal auditor's objectivity?

A. Reviewing evidence obtained during an engagement
B. Attending professional training
C. Auditing a department that the auditor previously managed
D. Communicating findings to the audit committee

Answer: C. Auditing a department that the auditor previously managed


4. Which of the following is NOT consistent with professional competence?

A. Maintaining relevant knowledge and skills
B. Performing an engagement without adequate expertise
C. Obtaining assistance when specialized knowledge is required
D. Continuing professional development

Answer: B. Performing an engagement without adequate expertise

Which of the following BEST demonstrates professional competence?

A. Ignoring new professional requirements
B. Performing work without adequate knowledge
C. Maintaining and applying appropriate knowledge and skills
D. Accepting assignments regardless of expertise

Answer: C. Maintaining and applying appropriate knowledge and skills


5. An auditor is offered an expensive gift by the manager of the department being audited. What is the PRIMARY ethical concern?

A. ConfidentialityB. CompetencyC. ObjectivityD. Due professional care

Answer: C. Objectivity


6. ASSERTION–REASON

Assertion: Internal auditors should disclose significant impairments to independence or objectivity.

Reason: Undisclosed impairments may influence users' perception of the reliability and impartiality of audit work.

A. Assertion is false, but Reason is true
B. Both are false
C. Both are true, and Reason correctly explains Assertion
D. Assertion is true, but Reason is false

Answer: C


7. An internal auditor does not possess sufficient expertise to evaluate a highly technical cybersecurity system. What is the MOST appropriate action?

A. Obtain appropriate assistance or expertise
B. Complete the engagement without considering the limitation
C. Ignore the cybersecurity component
D. Transfer responsibility for the entire internal audit function to IT

Answer: A. Obtain appropriate assistance or expertise


8. EXCEPT

Internal auditors should:

A. Exercise professional judgment
B. Protect confidential information
C. Maintain objectivity
D. Deliberately omit unfavorable findings to protect senior management

Answer: D. Deliberately omit unfavorable findings to protect senior management


9. An internal auditor becomes aware of information that, if omitted, would make an audit report misleading. What should the auditor do?

A. Delete the information from the working papers
B. Report only information requested by management
C. Communicate the relevant information appropriately
D. Wait until the next audit cycle

Answer: C. Communicate the relevant information appropriately


10. CASE-BASED

An internal auditor is auditing a purchasing department. The department manager is a close personal friend of the auditor. During the engagement, the manager asks the auditor to ignore several control deficiencies.

What is the BEST course of action?

A. Ignore the deficiencies because the manager is a friend
B. Allow the manager to decide which findings are reported
C. Disclose the potential impairment and take appropriate action to safeguard objectivity
D. Cancel the entire internal audit activity

Answer: C. Disclose the potential impairment and take appropriate action to safeguard objectivity

CIA Part 1–style practice questions focused on fraud risks, fraud risk management, fraud indicators, the fraud triangle, controls, investigations, and the internal auditor's role.

1. Which of the following BEST describes the internal auditor's role regarding fraud?

A. Guarantee that fraud will never occur
B. Assume management's responsibility for fraud prevention
C. Assess fraud risks and evaluate controls designed to address those risks
D. Conduct criminal investigations in every suspected case

Answer: C


2. Which of the following is NOT an element of the traditional fraud triangle?

A. Pressure or incentiveB. OpportunityC. RationalizationD. Competency

Answer: D


3. An employee is experiencing severe financial difficulties and believes that stealing company funds is justified because the company underpays employees. Which fraud triangle elements are MOST evident?

A. Opportunity and detectionB. Governance and control
C. Pressure and rationalizationD. Competency and monitoring

Answer: C


4. An employee discovers that no one reviews cash disbursements. The employee realizes that fictitious payments could be made without detection. This represents:

A. RationalizationB. PressureC. OpportunityD. Fraud concealment

Answer: C


5. Which of the following is the BEST preventive control against employee fraud?

A. Investigation after fraud is discovered
B. Segregation of incompatible duties
C. Review of fraud losses after year-end
D. External reporting of detected fraud

Answer: B


6. Which situation is MOST likely to indicate fraudulent financial reporting?

A. Management consistently exceeds realistic earnings expectations by recording unsupported revenue near year-end
B. The company performs monthly bank reconciliations
C. Employees take annual leave regularly
D. Management strengthens approval procedures

Answer: A


7. EXCEPT

Fraud risk indicators may include all of the following EXCEPT:

A. Unusual transactions
B. Significant unexplained changes in financial results
C. Strong segregation of duties
D. Excessive management pressure to achieve unrealistic targets

Answer: C


8. Which of the following is the BEST example of asset misappropriation?

A. Deliberately overstating revenue
B. Concealing a regulatory violation
C. Stealing inventory for personal use
D. Manipulating accounting estimates

Answer: C


9. CASE-BASED

A purchasing employee creates a fictitious vendor controlled by a relative and approves invoices from that vendor. No independent review of new vendors is performed.

Which combination of fraud risk factors is MOST apparent?

A. Opportunity and conflict of interestB. Rationalization only
C. Pressure onlyD. Risk avoidance and monitoring

Answer: A


10. Which action would MOST effectively reduce the opportunity component of the fraud triangle?

A. Increasing employee bonusesB. Establishing effective segregation of duties and authorization controlsC. Reducing internal audit activities
D. Allowing employees unrestricted system access

Answer: B


11. ASSERTION–REASON

Assertion: Internal auditors should consider fraud risks when planning engagements.

Reason: Fraud can prevent an organization from achieving its objectives and may exploit weaknesses in governance, risk management, and control processes.

A. Both are true, and the Reason correctly explains the Assertion
B. Both are true, but the Reason does not explain the Assertion
C. Assertion is true, but Reason is false
D. Assertion is false, but Reason is true

Answer: A


12. An employee reports suspected fraud through an organization's whistleblower mechanism. What should management MOST appropriately ensure?

A. The employee is immediately dismissed
B. The allegation is ignored unless financial loss is already proven
C. The allegation is appropriately assessed and investigated according to established procedures
D. The suspected employee is immediately declared guilty

Answer: C


13. Which of the following is MOST likely to be a red flag for procurement fraud?

A. Competitive bidding with documented approvals
B. One supplier repeatedly receiving contracts despite significantly higher prices
C. Periodic supplier evaluations
D. Independent review of purchase orders

Answer: B


14. NEITHER/NOR

Which statement about fraud prevention is MOST appropriate?

A. Neither management nor the board has responsibility for fraud risk management
B. Management and the board have important responsibilities for establishing an environment that reduces fraud risk
C. Internal audit should own all fraud prevention controls
D. Fraud can be completely eliminated through internal controls

Answer: B


15. An internal auditor suspects that senior management may be involved in fraud. What is the MOST appropriate initial consideration?

A. Ignore the matter because senior management cannot commit fraud
B. Follow established escalation and investigation procedures and communicate with the appropriate level of governance
C. Confront the suspected executive publicly
D. Delete the audit evidence to avoid conflict

Answer: B


16. Which of the following BEST distinguishes fraud from error?

A. Fraud always involves a financial lossB. Fraud involves intentional deception, whereas an error is generally unintentionalC. Errors are committed only by employeesD. Fraud can occur only in financial reporting

Answer: B


17. CASE-BASED

A sales director knows that annual bonuses depend on achieving a revenue target. Near year-end, the director instructs employees to record sales before the goods are actually delivered, with the intention of reversing the entries next quarter.

What is the PRIMARY fraud concern?

A. Accidental accounting errorB. Fraudulent financial reporting through premature revenue recognitionC. Normal business judgment
D. Physical asset theft

Answer: B


18. Which of the following is the BEST example of management override?

A. An employee follows an established approval procedure
B. A manager bypasses established controls to authorize an inappropriate transaction
C. An auditor tests a control
D. A supervisor reviews a reconciliation

Answer: B


19. EITHER/OR

Effective fraud risk management generally requires:

A. Preventive controls OR detective controls, but never both
B. Fraud risk identification, assessment, response, and monitoring
C. Internal audit ownership OR management ownership, but not both
D. Investigation OR prevention, but not both

Answer: B


20. COMPREHENSIVE CASE-BASED

A company has aggressive sales targets, weak segregation of duties, inadequate review of journal entries, and employees believe that manipulating results is acceptable because "everyone does it."

Which combination BEST describes the fraud risk environment?

A. Pressure, opportunity, and rationalization are all present
B. Only opportunity is present
C. Only rationalization is present
D. There is no significant fraud risk because management has established sales targets

Answer: A

CIA Part 1 — Control Application

 

 

 

 

10 Case-Based MCQs with Answers

These questions focus on control design, preventive/detective/corrective controls, segregation of duties, authorization, reconciliation, access controls, monitoring, and control deficiencies.

1 A company allows the same employee to create new vendors, enter invoices, and release payments. Management argues that the employee is trustworthy and has worked for the company for 10 years.

What is the GREATEST control concern?

A. Lack of employee training
B. Excessive documentation
C. Inadequate segregation of duties
D. Lack of physical security

Answer: C

Explanation: Combining vendor creation, invoice processing, and payment authorization creates an opportunity for fictitious vendors and fraudulent payments.

2A manufacturing company requires a purchase order to be approved by an authorized manager before a purchase can be made.

This is primarily what type of control?

A. Detective controlB. Corrective control
C. Preventive controlD. Compensating control

Answer: C

Explanation: The control is designed to prevent an unauthorized transaction from occurring.

3A company performs a monthly bank reconciliation. During the reconciliation, the accountant discovers an unauthorized payment that was processed during the month.

The bank reconciliation is primarily a:

A. Preventive controlB. Detective control
C. Corrective controlD. Directive control

Answer: B

Explanation: The reconciliation identifies an error or irregularity after the transaction has occurred.

4A payroll system allows employees to access payroll records using individual usernames and passwords. However, employees who leave the organization continue to have access for several weeks.

Which control weakness is MOST significant?

A. Lack of employee training
B. Inadequate termination access procedures
C. Excessive payroll documentation
D. Lack of physical inventory controls

Answer: B

Explanation: Access should be promptly removed when employees leave. Delayed termination of access increases the risk of unauthorized transactions or data manipulation.

5. Authorization Control

A company requires all expenses above ₹100,000 to be approved by the CFO. An employee divides a ₹300,000 purchase into three separate ₹100,000 invoices to avoid CFO approval.

Which control weakness is MOST evident?

A. Inadequate monitoring of transactions
B. Excessive segregation of duties
C. Lack of physical safeguards
D. Excessive management review

Answer: A

Explanation: Management should monitor transactions for unusual patterns such as transaction splitting designed to circumvent approval limits.


6. CASE — Inventory  A warehouse employee is responsible for receiving goods, updating inventory records, and approving inventory adjustments. No independent physical inventory count is performed.

Which recommendation would BEST strengthen internal control?

A. Give the employee additional authority
B. Eliminate inventory records
C. Separate custody, recordkeeping, and adjustment approval responsibilities
D. Allow inventory adjustments without documentation

Answer: C

Explanation: Separating incompatible duties reduces the opportunity for theft and manipulation of inventory records.

7. CASE — Corrective Control

A company has an automated system that detects duplicate vendor payments. When a duplicate payment is identified, the system automatically blocks the payment and generates an exception report for investigation.

The system's response to the detected duplicate payment is BEST classified as:

A. Preventive control only
B. Corrective control
C. Directive control only
D. Compensating control only

Answer: B

Explanation: Once an exception is identified, blocking the payment and initiating corrective action addresses the detected problem.

8The CEO of a company has authority to approve transactions above all normal approval limits. Internal audit discovers that the CEO approved several unusual transactions without supporting documentation.

What is the PRIMARY control concern?

A. Excessive employee training
B. Management override of controls
C. Excessive segregation of duties
D. Lack of inventory valuation

Answer: B

Explanation: Senior management's ability to bypass established controls creates a significant risk of inappropriate or fraudulent transactions.

9A company maintains separate records for accounts receivable and cash receipts. The accounts receivable clerk prepares a monthly reconciliation between customer accounts and cash received. However, the reconciliation is reviewed by another employee only when differences are identified.

What is the BEST improvement?

A. Eliminate the reconciliation
B. Require independent review of every reconciliation
C. Allow the same clerk to approve differences
D. Reduce the frequency of reconciliations

Answer: B

Explanation: Independent review provides an important control over errors, omissions, and potential manipulation.


10. Comprehensive Case

A company implements a new ERP system. Employees can enter and approve their own transactions. Passwords are shared between employees, terminated employees' accounts are not promptly disabled, and management does not review system-generated exception reports.

Which combination represents the MOST significant control weaknesses?

A. Weak access controls, inadequate segregation of duties, and ineffective monitoring
B. Strong authorization, strong access controls, and effective monitoring
C. Excessive preventive controls and excessive documentation
D. Only inadequate employee training

Answer: A

Explanation: The case contains three major weaknesses:

Pl read…  Shared passwords → weak access/security controls

  Employees approving their own transactions → inadequate segregation of duties

  No review of exception reports → ineffective monitoring

  Terminated users retaining access → inadequate user-access management

MCQs — COSO & COBIT Governance Principles

COSO Internal Control Framework

1. Which COSO component establishes the foundation for all other components of internal control?

A. Risk assessmentB. Control activities
C. Control environmentD. Monitoring activities

Answer: C — Control environment


2. Which of the following is NOT one of the five COSO Internal Control components?

A. Risk assessmentB. Control activities
C. Governance and cultureD. Information and communication

Answer: C — Governance and culture

Governance and Culture is a component of COSO ERM, not the COSO Internal Control Framework.


3. Under COSO, management's identification and analysis of fraud risks falls primarily under:

A. Control environmentB. Risk assessment
C. Control activitiesD. Monitoring

Answer: B — Risk assessment


4. Which COSO principle addresses the board's responsibility to exercise oversight?

A. Principle 1B. Principle 2C. Principle 4D. Principle 5

Answer: B — Principle 2


5. Management establishes appropriate structures, reporting lines, and authorities. This relates to which COSO principle?

A. Principle 2B. Principle 3C. Principle 4D. Principle 6

Answer: B — Principle 3


6. An organization provides extensive training to ensure employees possess the skills necessary for their responsibilities. Which COSO principle is most directly addressed?

A. Demonstrates commitment to competence
B. Enforces accountability
C. Exercises oversight responsibility
D. Identifies and analyzes risk

Answer: A — Demonstrates commitment to competence


7. Which principle requires the organization to hold individuals accountable for their internal control responsibilities?

A. Principle 2B. Principle 3C. Principle 4D. Principle 5

Answer: D — Principle 5


8. Which of the following is associated with COSO Principle 6?

A. Identifying fraud riskB. Specifying suitable objectives
C. Selecting control activitiesD. Communicating externally

Answer: B — Specifying suitable objectives


9. A company identifies risks that could prevent it from achieving its objectives and evaluates their significance. This represents:

A. Principle 6B. Principle 7C. Principle 10D. Principle 13

Answer: B — Principle 7


10. Which COSO principle specifically addresses fraud risk?

A. Principle 5B. Principle 7C. Principle 8D. Principle 11

Answer: C — Principle 8


11. A new regulatory requirement significantly changes the organization's operating environment. Which COSO principle is most relevant?

A. Identifies and analyzes significant changeB. Uses relevant information
C. Deploys through policiesD. Enforces accountability

Answer: A — Principle 9


12. Which principle deals specifically with selecting and developing control activities?

A. Principle 8B. Principle 9C. Principle 10D. Principle 12

Answer: C — Principle 10


13. General controls over technology are specifically addressed by which COSO principle?

A. Principle 9B. Principle 10C. Principle 11D. Principle 13

Answer: C — Principle 11


14. Policies and procedures are used to communicate management's expectations regarding control activities. This primarily represents:

A. Principle 10B. Principle 11C. Principle 12D. Principle 14

Answer: C — Principle 12


15. Which COSO principle requires the organization to obtain and use relevant, quality information?

A. Principle 12B. Principle 13C. Principle 14D. Principle 15

Answer: B — Principle 13


16. Communication of important internal control information throughout the organization relates primarily to:

A. Principle 13B. Principle 14C. Principle 15D. Principle 16

Answer: B — Principle 14


17. Communication with external parties regarding relevant internal control matters is primarily addressed by:

A. Principle 12B. Principle 13C. Principle 14D. Principle 15

Answer: D — Principle 15


18. Which activity is most closely associated with COSO monitoring activities?

A. Establishing organizational objectives
B. Performing ongoing and separate evaluations
C. Establishing reporting lines
D. Identifying fraud risks

Answer: B — Performing ongoing and separate evaluations


19. A manager periodically evaluates whether internal controls continue to operate effectively. This is an example of:

A. Risk identificationB. Monitoring
C. Control environmentD. Control design

Answer: B — Monitoring


20. A control deficiency is identified and communicated to those responsible for corrective action. Which COSO principle is most relevant?

A. Principle 15B. Principle 16C. Principle 17D. Principle 10

Answer: C — Principle 17


COSO — Application & Exam Traps

21. Which statement BEST describes COSO Internal Control?

A. It guarantees elimination of fraud.
B. It provides reasonable assurance regarding achievement of objectives.
C. It transfers management's control responsibilities to internal audit.
D. It focuses exclusively on financial reporting.

Answer: B — It provides reasonable assurance regarding achievement of objectives.

COSO emphasizes internal control as supporting achievement of objectives in operations, reporting, and compliance—not merely financial reporting.


22. Which of the following is NOT an objective category of COSO Internal Control?

A. OperationsB. ReportingC. ComplianceD. Investment return maximization

Answer: D — Investment return maximization


23. Which statement about COSO principles is MOST accurate?

A. Each principle applies only to public companies.
B. The principles are unrelated to the five components.
C. The principles support the five components of internal control.
D. The principles replace management's judgment regarding controls.

Answer: C — The principles support the five components of internal control.


24. Which situation BEST illustrates a control environment weakness?

A. Bank reconciliations are not performed monthly.
B. Senior management ignores established ethical standards.
C. An invoice lacks a purchase order.
D. A password expires after 90 days.

Answer: B — Senior management ignores established ethical standards.


25. Which situation BEST illustrates a risk assessment activity?

A. Separating authorization from custody
B. Reviewing employee performance
C. Evaluating the likelihood and impact of a cyberattack
D. Reconciling the bank account

Answer: C — Evaluating the likelihood and impact of a cyberattack


26. Which situation BEST represents a control activity rather than a risk assessment activity?

A. Identifying a new supply-chain riskB. Evaluating fraud exposure
C. Requiring two approvals for large paymentsD. Assessing the impact of inflation

Answer: C — Requiring two approvals for large payments


27. An organization has excellent policies but employees do not understand how to perform their control responsibilities. Which COSO component is MOST directly affected?

A. Information and communicationB. Risk assessment
C. Control activitiesD. Monitoring

Answer: A — Information and communication


28. Internal audit discovers that a control operates effectively but no longer addresses a newly emerging risk. Which COSO area deserves the MOST attention?

A. Control environmentB. Risk assessment
C. Segregation of dutiesD. External communication

Answer: B — Risk assessment


COSO ERM

29. Which of the following is a COSO ERM component under the 2017 framework?

A. Control activitiesB. Risk assessment
C. PerformanceD. Monitoring activities

Answer: C — Performance

COSO ERM 2017 contains five components: Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; Information, Communication, and Reporting.


30. Risk appetite is most closely associated with which COSO ERM component?

A. Strategy and Objective-Setting
B. Review and Revision
C. Information and Communication
D. Monitoring Activities

Answer: A — Strategy and Objective-Setting


31. Which COSO ERM concept represents the amount and type of risk an organization is willing to accept in pursuit of its objectives?

A. Risk capacityB. Risk appetiteC. Residual riskD. Control deficiency

Answer: B — Risk appetite


32. An organization evaluates whether its strategy remains appropriate after a major change in market conditions. Which COSO ERM component is MOST relevant?

A. Governance and CultureB. Review and Revision
C. PerformanceD. Information, Communication, and Reporting

Answer: B — Review and Revision


COBIT Governance Principles

33. Which of the following is NOT one of the five COBIT 2019 governance system principles?

A. Meeting stakeholder needsB. Covering the enterprise end-to-end
C. Separating governance from managementD. Maximizing shareholder wealth

Answer: D — Maximizing shareholder wealth

The five COBIT governance system principles are meeting stakeholder needs, covering the enterprise end-to-end, applying a single integrated framework, enabling a holistic approach, and separating governance from management.


34. The primary purpose of COBIT is MOST closely related to:

A. Managing only financial statementsB. Governance and management of enterprise information and technologyC. Replacing the external audit function
D. Eliminating all IT risks

Answer: B — Governance and management of enterprise information and technology


35. Which COBIT principle emphasizes that governance should consider all relevant stakeholders and their needs?

A. Applying a single integrated framework
B. Meeting stakeholder needs
C. Enabling a holistic approach
D. Separating governance from management

Answer: B — Meeting stakeholder needs


36. A company evaluates its IT governance from the perspective of the entire enterprise rather than only the IT department. Which COBIT principle is MOST relevant?

A. Covering the enterprise end-to-end
B. Meeting stakeholder needs
C. Applying a single integrated framework
D. Separating governance from management

Answer: A — Covering the enterprise end-to-end


37. An organization integrates COBIT with other applicable standards and frameworks rather than creating isolated governance structures. Which principle applies?

A. Meeting stakeholder needs
B. Applying a single integrated framework
C. Enabling a holistic approach
D. Separating governance from management

Answer: B — Applying a single integrated framework


38. COBIT's holistic approach recognizes that effective governance depends on:

A. Technology aloneB. Policies aloneC. Multiple interconnected components
D. Internal audit alone

Answer: C — Multiple interconnected components


39. Which COBIT principle emphasizes the distinction between governance responsibilities and management responsibilities?

A. Meeting stakeholder needs
B. Covering the enterprise end-to-end
C. Separating governance from management
D. Applying a single integrated framework

Answer: C — Separating governance from management


40. Under COBIT, governance is primarily concerned with:

A. Evaluating, directing, and monitoring
B. Performing every operational IT activity
C. Preparing journal entries
D. Hiring all IT employees

Answer: A — Evaluating, directing, and monitoring


Integrated COSO–COBIT Questions

41. Which framework is generally more specifically focused on enterprise governance and management of information and technology?

A. COSO Internal ControlB. COBITC. COSO ERM onlyD. Basel framework

Answer: B — COBIT


42. Which framework would generally be MOST useful for evaluating whether an organization's overall internal control system is appropriately designed across operations, reporting, and compliance?

A. COSO Internal ControlB. COBIT onlyC. ITIL
D. PMBOK

Answer: A — COSO Internal Control


43. An internal auditor is evaluating IT governance, technology processes, and alignment of IT objectives with enterprise objectives. Which framework would provide particularly relevant guidance?

A. COBITB. COSO Internal Control only
C. GAAPD. IFRS

Answer: A — COBIT


44. Which statement BEST describes the relationship between COSO and COBIT?

A. COBIT completely replaces COSO.
B. COSO completely replaces COBIT.
C. They can be complementary frameworks.
D. They address exactly the same objectives and processes.

Answer: C — They can be complementary frameworks.

COSO and COBIT can be used together because COSO provides a broader internal-control perspective while COBIT provides detailed governance and management guidance for information and technology.


45. A company uses COSO to assess enterprise internal control and COBIT to strengthen IT governance. This approach is:

A. Inconsistent because only one framework may be usedB. Appropriate because frameworks can complement each otherC. Appropriate only for external auditorsD. Prohibited under COSO

Answer: B — Appropriate because frameworks can complement each other


Tricky CIA-Style Questions

46. Which statement is TRUE regarding COSO internal control?

A. A strong control environment eliminates the need for monitoring.B. Effective controls provide absolute assurance.C. Internal control is a process involving people and actions.D. Internal audit owns the organization's internal control system.

Answer: C — Internal control is a process involving people and actions.


47. An organization has all five COSO components documented, but employees do not actually perform the required controls. Which conclusion is MOST appropriate?

A. Internal control is automatically effective because all five components exist on paper.
B. Documentation alone is insufficient; controls must be present and functioning.
C. The organization has no risk.
D. Internal audit should take over management's control responsibilities.

Answer: B — Documentation alone is insufficient; controls must be present and functioning.

COSO's effectiveness concept requires the relevant components and principles to be present and functioning, operating together as an integrated system.


48. Which of the following represents the BEST distinction between governance and management in COBIT?

A. Governance performs daily operations; management monitors the board.
B. Governance evaluates, directs, and monitors; management plans, builds, runs, and monitors operational activities.
C. Governance and management have identical responsibilities.
D. Governance is performed only by the internal audit function

Answer: B — Governance evaluates, directs, and monitors; management handles management/operational activities.


49. A board establishes the organization's desired level of risk, while management develops processes to operate within that level. Which concept is BEST illustrated?

A. Governance and management distinction
B. Segregation of duties only
C. Detective control
D. Corrective control

Answer: A — Governance and management distinction


50. Which combination is MOST appropriate for an internal auditor assessing enterprise internal control and IT governance?

A. COSO for internal control and COBIT for IT governance
B. COBIT for financial accounting and GAAP for IT governance
C. GAAP for internal control and COSO for programming standards
D. IFRS for cybersecurity and COBIT for financial statement presentation

Answer: A — COSO for internal control and COBIT for IT governance

 

 

Quick CIA Part 1 Memory Map

Framework

Remember

COSO Internal Control

5 components + 17 principles

Control Environment

Principles 1–5

Risk Assessment

Principles 6–9

Control Activities

Principles 10–12

Information & Communication

Principles 13–15

Monitoring

Principles 16–17

COSO ERM

5 components + 20 principles

COBIT Governance

5 governance system principles

COBIT Principle 1

Meeting stakeholder needs

COBIT Principle 2

Covering enterprise end-to-end

COBIT Principle 3

Single integrated framework

COBIT Principle 4

Holistic approach

COBIT Principle 5

Separate governance from management

These distinctions are especially useful for CIA Part 1 questions that use “MOST appropriate,” “BEST,” “EXCEPT,” “NOT,” and scenario-based wording.

 

short, exam-focused list of the 17 COSO Internal Control Principles, grouped under the 5 components.

COSO — 17 Principles in Short

1. Control Environment — Principles 1–5

1.     Integrity & Ethical Values — Demonstrate commitment to integrity and ethics.

2.     Board Oversight — Board exercises oversight responsibility.

3.     Structure, Authority & Responsibility — Establish appropriate organizational structure.

4.     Competence — Demonstrate commitment to competent personnel.

5.     Accountability — Enforce accountability for internal control responsibilities.

2. Risk Assessment — Principles 6–9
6. Suitable Objectives — Specify suitable objectives.
7. Identify & Analyze Risks — Identify and analyze risks.
8. Fraud Risk — Assess fraud risks.
9. Significant Change — Identify and assess significant changes.

3. Control Activities — Principles 10–12
10. Select & Develop Controls — Select and develop control activities.
11. Technology Controls — Select and develop general controls over technology.
12. Policies & Procedures — Deploy controls through policies and procedures.

4. Information & Communication — Principles 13–15
13. Relevant Information — Obtain/use relevant, quality information.
14. Internal Communication — Communicate internally.
15. External Communication — Communicate externally.

5. Monitoring Activities — Principles 16–17
16. Ongoing/Separate Evaluations — Perform evaluations to determine whether controls are functioning.
17. Communicate Deficiencies — Communicate control deficiencies to responsible parties.

🧠 Easy Memory Formula

CE → RA → CA → IC → MA

1–5: Ethics → Board → Structure → Competence → Accountability
6–9: Objectives → Risks → Fraud → Change
10–12: Controls → Technology → Policies
13–15: Information → Internal → External
16–17: Evaluate → Deficiencies

This is the COSO Internal Control Framework, not the COSO ERM framework.

 

exam-focused explanation of all 17 COSO Internal Control Principles with simple practical examples, useful for CIA Part 1 preparation.

COSO 17 Principles with Examples

1. Demonstrates Commitment to Integrity and Ethical Values

Meaning: Management and the board establish and demonstrate ethical behavior.

Example:
The CEO follows the company's code of conduct and takes disciplinary action against a senior employee who commits fraud, even though the employee is a top performer.

CIA clue: Ethics, integrity, code of conduct, "tone at the top."


2. Exercises Oversight Responsibility

Meaning: The board or audit committee independently oversees internal control.

Example:
The audit committee regularly reviews internal audit reports, significant control deficiencies, and management's corrective actions.

CIA clue: Board, audit committee, oversight.


3. Establishes Structure, Authority, and Responsibility

Meaning: The organization establishes appropriate reporting lines, authority, and responsibilities.

Example:
The CFO is responsible for financial reporting, while the controller manages accounting operations and reports to the CFO.

CIA clue: Organization chart, reporting lines, authority, responsibility.


4. Demonstrates Commitment to Competence

Meaning: The organization recruits, develops, and retains employees with the required knowledge and skills.

Example:
Employees responsible for cybersecurity are required to maintain appropriate professional certifications and receive regular technical training.

CIA clue: Skills, qualifications, training, competency.


5. Enforces Accountability

Meaning: Individuals are held accountable for performing their internal control responsibilities.

Example:
A purchasing manager's performance evaluation includes compliance with procurement approval procedures.

CIA clue: Performance evaluation, responsibility, accountability.


Risk Assessment — Principles 6–9

6. Specifies Suitable Objectives

Meaning: Management establishes clear objectives that allow risks to be identified and assessed.

Example:
A company establishes an objective to maintain 99.9% system availability for its online banking platform.

CIA clue: Objectives must be clear and measurable.


7. Identifies and Analyzes Risk

Meaning: The organization identifies risks that could prevent achievement of its objectives and evaluates their significance.

Example:
A company identifies a potential supplier failure as a risk to its production objective and evaluates its likelihood and potential impact.

CIA clue: Identify → analyze → likelihood/impact.


8. Assesses Fraud Risk

Meaning: The organization considers the possibility of fraud when assessing risks.

Example:
Management identifies the risk that an employee could create a fictitious vendor and make payments to the vendor.

CIA clue: Fraud schemes, incentives, opportunities, management override.


9. Identifies and Analyzes Significant Change

Meaning: The organization assesses changes that could significantly affect internal control.

Example:
After acquiring another company, management reassesses its controls because employees, systems, processes, and reporting structures have changed.

CIA clue: Acquisition, new technology, new regulations, restructuring, new business model.


Control Activities — Principles 10–12

10. Selects and Develops Control Activities

Meaning: Management selects appropriate controls to mitigate identified risks.

Example:
To reduce unauthorized payments, the company requires invoices to be approved before payment.

CIA clue: Authorization, approval, reconciliation, verification, segregation of duties.


11. Selects and Develops General Controls Over Technology

Meaning: The organization establishes general IT controls supporting the proper functioning of technology.

Example:
Only authorized IT administrators can modify the company's financial application, and all system changes require approval and testing.

CIA clue: Access controls, change management, backup, system security.


12. Deploys Through Policies and Procedures

Meaning: Control activities are implemented through policies that specify what should be done and procedures that explain how it should be done.

Example:
The company has a policy requiring monthly bank reconciliations and a procedure explaining who prepares, reviews, and approves the reconciliation.

CIA clue: Policy = what; procedure = how.


Information & Communication — Principles 13–15

13. Uses Relevant, Quality Information

Meaning: The organization obtains and uses reliable information needed to support internal control.

Example:
Management uses accurate, timely inventory reports to identify slow-moving and obsolete inventory.

CIA clue: Relevant + quality + timely + accurate information.


14. Communicates Internally

Meaning: Important control information is communicated throughout the organization.

Example:
Management informs employees about a new cybersecurity policy through training, email, and the company's internal portal.

CIA clue: Communication from management → employees and across departments.


15. Communicates Externally

Meaning: Relevant information is communicated to external parties when necessary.

Example:
The company communicates significant control deficiencies to its external auditor or regulatory authority when appropriate.

CIA clue: Customers, suppliers, regulators, external auditors, shareholders.


Monitoring Activities — Principles 16–17

16. Conducts Ongoing and/or Separate Evaluations

Meaning: The organization evaluates whether internal controls are present, functioning, and effective.

Example:
Internal audit periodically tests whether employees are following the company's procurement approval controls.

CIA clue: Ongoing monitoring + separate evaluations.


17. Evaluates and Communicates Deficiencies

Meaning: Control deficiencies are identified, evaluated, and communicated to those responsible for corrective action.

Example:
Internal audit discovers that purchase orders are frequently approved after purchases are made. The deficiency is reported to management, which develops a corrective action plan.

CIA clue: Deficiency → communicate → corrective action.


🔥 CIA Exam Memory Table

Principle

Short Keyword

Easy Example

1

Ethics

CEO follows code of conduct

2

Oversight

Audit committee reviews controls

3

Structure

Clear reporting lines

4

Competence

Employee training/certification

5

Accountability

Employee evaluated for control performance

6

Objectives

99.9% system availability target

7

Risk

Supplier failure risk

8

Fraud

Fictitious vendor

9

Change

Acquisition/restructuring

10

Control Activities

Payment approval

11

Technology

IT access/change controls

12

Policies

Purchasing policy & procedure

13

Information

Accurate inventory report

14

Internal Communication

Cybersecurity training

15

External Communication

Regulatory reporting

16

Evaluation

Internal audit testing

17

Deficiencies

Report weakness & corrective action

🧠 Super-fast sequence for CIA Part 1

1–5: ETHICS → BOARD → STRUCTURE → COMPETENCE → ACCOUNTABILITY

6–9: OBJECTIVES → RISK → FRAUD → CHANGE

10–12: CONTROL → TECHNOLOGY → POLICY

13–15: INFORMATION → INTERNAL → EXTERNAL

16–17: EVALUATE → DEFICIENCY

One important CIA exam distinction:
Principle 7 = risks generally
Principle 8 = fraud risks specifically
Principle 9 = significant changes

That distinction is frequently useful in scenario-based questions.

 

 5 COBIT 2019 Governance System Principles with simple examples, especially useful for CIA Part 1 exam preparation.

COBIT 5 Governance Principles — With Examples

Important: If you mean COBIT 5 specifically, its five principles are different in wording from COBIT 2019. The list below is for COBIT 5.

1. Meeting Stakeholder Needs

Meaning:
The governance system should create value for stakeholders by balancing benefits, risk, and resources.

Example:
A bank's customers want secure and fast mobile banking. Management invests in cybersecurity and system availability while considering the cost and acceptable level of risk.

CIA exam clue:
Stakeholder needs → Benefits + Risk + Resources


2. Covering the Enterprise End-to-End

Meaning:
COBIT governance applies to the entire enterprise, not just the IT department.

It covers:

  • IT and business processes
  • Internal and external stakeholders
  • Information and technology across the organization

Example:
A company's cybersecurity program covers not only the IT department but also HR, finance, procurement, operations, employees, suppliers, and third-party service providers.

CIA exam clue:
Enterprise-wide, not IT-only.


3. Applying a Single Integrated Framework

Meaning:
COBIT provides a framework that can integrate and align with other standards, frameworks, and regulations.

Example:
A company uses COBIT for IT governance while also using COSO for internal control and ISO 27001 for information security.

Rather than creating completely separate governance systems, the organization aligns them.

CIA exam clue:
COBIT + COSO + ISO + other frameworks → integrated approach.


4. Enabling a Holistic Approach

Meaning:
Effective governance requires consideration of multiple interconnected components, rather than focusing on technology alone.

COBIT 5 refers to seven enablers, including:

1.     Principles, policies and frameworks

2.     Processes

3.     Organizational structures

4.     Information

5.     Services, infrastructure and applications

6.     People, skills and competencies

7.     Culture, ethics and behavior

Example:
A company implements a new ERP system. Successful governance requires not only the software but also trained employees, appropriate processes, organizational responsibilities, policies, accurate data, and an appropriate control culture.

CIA exam clue:
People + Process + Technology + Information + Culture + Structure + Policies


5. Separating Governance From Management

Meaning:
Governance and management have different responsibilities.

Governance:
Evaluates stakeholder needs, conditions, and options; directs through prioritization and decision-making; and monitors performance and compliance.

Management:
Plans, builds, runs, and monitors activities in accordance with the direction established by governance.

Example:

Board:
"We require customer data protection and want cybersecurity risk maintained within our approved risk appetite."

Management:
"We will implement access controls, encryption, employee training, monitoring, and incident-response procedures."

CIA exam clue:
Governance = Evaluate → Direct → Monitor
Management = Plan → Build → Run → Monitor


🧠 Easy Memory Formula

S-E-I-H-G

S — Stakeholder Needs
E — Enterprise End-to-End
I — Integrated Framework
H — Holistic Approach
G — Governance ≠ Management

Quick Revision Table

COBIT 5 Principle

Remember

Example

1

Stakeholder Needs

Balance benefits, risk & resources

2

Enterprise End-to-End

IT governance across entire organization

3

Integrated Framework

COBIT + COSO + ISO

4

Holistic Approach

People + process + technology

5

Governance ≠ Management

Board directs; management executes

⚠️ CIA Exam Trap: COBIT 5 vs COBIT 2019

The first four principles are the same, but the fifth principle is worded differently:

  • COBIT 5: Separating Governance From Management
  • COBIT 2019: Separating Governance From Management — still retained as a governance-system principle.

So for CIA questions, always check whether the question specifically asks about COBIT 5 or COBIT 2019.

www.gmsisuccess.in