Tuesday, September 29, 2026

Here are 100 rapid-fire CMA Part 1 questions covering the topic from US CMA part 1, formatted as one-liners, fill-in-the-blanks, True/False, and Odd One Out.

 


Here are 100 rapid-fire CMA Part 1 questions covering the topic from US CMA part 1, formatted as one-liners, fill-in-the-blanks, True/False, and Odd One Out. 


Section A: Financial Reporting under US GAAP


1. Under U.S. GAAP, what is the primary objective of financial reporting?

Answer: 

2. Intracompany transactions between a parent and its wholly owned subsidiary must be __________ when preparing consolidated financial statements.

Answer: 


3. Under ASC 606, revenue is recognized when the entity satisfies a __________ by transferring control of a promised good or service.

Answer:


4. True or False: Under U.S. GAAP, internal research and development costs are generally capitalized as intangible assets.

Answer: 

5. Which voting stock ownership level requires equity consolidation under U.S. GAAP?

Answer:


6. Under U.S. GAAP, comprehensive income includes net income plus __________.

Answer:


7. Fill in the blank: A decline in market value alone does not trigger impairment under U.S. GAAP; the carrying amount must exceed the __________ future cash flows.

Answer:


8. Which of the following is NOT a component of other comprehensive income? (a) Foreign currency translation adjustments, (b) Unrealized gains on available-for-sale securities, (c) Net income, (d) Pension liability adjustments.

Answer: 


9. True or False: Under U.S. GAAP, LIFO inventory valuation is permitted.

Answer:


10. Legal fees incurred to successfully defend a patent should be __________ as part of the intangible asset's cost.

Answer:


11. Under ASC 606, how many steps are in the revenue recognition model?

Answer: 


12. Fill in the blank: The __________ method is required for equity consolidation when an investor has significant influence but not control.

Answer:


13. True or False: Under U.S. GAAP, inventory write-downs are reversed if the market value later recovers.

Answer: 


14. Which financial statement reports changes in a company's equity during a period?

Answer: 


15. Under U.S. GAAP, which cost flow assumption results in the highest net income during periods of rising prices?

Answer:


16. Fill in the blank: The primary qualitative characteristics of useful financial information are relevance and __________.

Answer:


17. True or False: Under U.S. GAAP, a company must use the same inventory costing method for all inventories with similar characteristics.

Answer: 


18. Which of the following is a financing cash flow under U.S. GAAP? (a) Dividends received, (b) Dividends paid, (c) Interest received, (d) Purchase of equipment.

Answer: 


19. Under U.S. GAAP, how are prior period adjustments reported?

Answer


20. Fill in the blank: The __________ assumption assumes that the entity will continue in operation long enough to realize its assets and discharge its liabilities.

Answer:


---


Section B: Cost Classification & Types of Overheads


21. Prime cost consists of direct materials plus __________.

Answer: 


22. Fill in the blank: __________ is a method of dealing with overheads that involves spreading common costs over cost centers on the basis of benefit received.

Answer:


23. Which classification distinguishes between direct cost and indirect cost?

Answer:


24. True or False: Salaries paid to delivery drivers are a part of prime cost.

Answer: 


25. Which of the following is an example of a manufacturing overhead? (a) Direct materials, (b) Factory rent, (c) Sales commissions, (d) CEO salary.

Answer: 


26. Fill in the blank: __________ is anything for which a separate measurement of cost is required.

Answer:


27. Absorption costing is also referred to as __________ costing.

Answer:


28. True or False: Administrative overheads are part of prime cost.

Answer:


29. Which of the following is NOT a functional classification of cost? (a) Manufacturing cost, (b) Administrative cost, (c) Selling cost, (d) Sunk cost.

Answer: 


30. Fill in the blank: A __________ is a cost that changes in total in direct proportion to changes in the level of activity.

Answer: 


31. Which of the following costs is a period cost? (a) Direct materials, (b) Direct labor, (c) Sales commissions, (d) Factory utilities.

Answer:


32. True or False: Conversion cost equals direct labor plus manufacturing overhead.

Answer:


33. Fill in the blank: __________ costs are costs that have already been incurred and cannot be changed by any future decision.

Answer: 


34. Which of the following is an example of a semi-variable cost? (a) Direct materials, (b) Factory rent, (c) Electricity bill with a fixed minimum charge plus usage charge, (d) Sales commission based on units sold.

Answer: 

35. True or False: A cost driver is any factor that causes a change in the total cost of an activity.

Answer: 


36. Fill in the blank: The __________ is the rate at which a system generates money through sales, according to the Theory of Constraints.

Answer:


37. Which of the following is NOT a type of overhead? (a) Manufacturing overhead, (b) Selling overhead, (c) Distribution overhead, (d) Prime overhead.

Answer: 


38. True or False: Overhead absorption is the process of assigning overhead costs to cost objects.

Answer: 


39. Fill in the blank: Under-absorption of overheads occurs when the overheads absorbed are __________ than the actual overheads incurred.

Answer: 


40. Which of the following is an example of a cost allocation base? (a) Direct labor hours, (b) Machine hours, (c) Units produced, (d) All of the above.

Answer: 


---


Section C: Absorption Costing, Variable Costing & Super-Variable Costing


41. Under absorption costing, fixed manufacturing overhead is treated as a __________ cost.

Answer:


42. True or False: Under variable costing, fixed manufacturing overhead is expensed as a period cost.

Answer:


43. When production exceeds sales, which costing method reports higher net income?

Answer: 


44. Fill in the blank: The difference between absorption costing net income and variable costing net income equals the change in inventory multiplied by the __________ fixed manufacturing overhead rate.

Answer: 


45. Super-variable costing treats only __________ as a variable cost.

Answer: 


46. True or False: Under super-variable costing, all labor and overhead costs are treated as fixed period costs.

Answer:


47. Which costing method is also known as throughput costing?

Answer:


48. Fill in the blank: Under variable costing, the contribution margin equals sales revenue minus __________ costs.

Answer:


49. True or False: Absorption costing is required for external financial reporting under U.S. GAAP.

Answer: 


50. Which of the following is NOT a characteristic of variable costing? (a) Fixed manufacturing overhead is a period cost, (b) Product costs include only variable manufacturing costs, (c) Net income is affected by changes in inventory levels, (d) It is useful for internal decision-making.

Answer:


51. Fill in the blank: Gross margin is to absorption costing as __________ margin is to variable costing.

Answer:


52. True or False: Super-variable costing values ending inventory at the total of direct materials, direct labor, and variable overhead.

Answer:


53. Under absorption costing, how is fixed manufacturing overhead treated when units are sold?

Answer:


54. Fill in the blank: The reconciliation between absorption costing income and variable costing income involves the change in inventory multiplied by the fixed overhead __________.

Answer: 


55. True or False: Throughput costing and super-variable costing are the same concept.

Answer: 


---


Section D: Throughput Accounting


56. In throughput accounting, throughput is calculated as sales revenue minus __________.

Answer:


57. Fill in the blank: The throughput accounting ratio (TPAR) equals throughput return per hour divided by __________ per hour.

Answer: 


58. True or False: In throughput accounting, direct labor is treated as a factory cost.

Answer: 


59. Which of the following is NOT a basic measure in the Theory of Constraints? (a) Throughput, (b) Inventory, (c) Operating expenses, (d) Gross margin.

Answer: 


60. Fill in the blank: A TPAR greater than __________ indicates that the product is profitable.

Answer:


61. True or False: Throughput accounting focuses on maximizing the output of the bottleneck resource.

Answer: 


62. Return per factory hour is calculated as throughput divided by __________.

Answer: 


63. Fill in the blank: In throughput accounting, all costs other than direct materials are considered __________ costs.

Answer:


64. True or False: Throughput accounting is a costing method used for external financial reporting.

Answer:


65. Which of the following is the correct formula for throughput? (a) Sales – Direct materials, (b) Sales – All variable costs, (c) Sales – Total costs, (d) Sales – Direct labor.

Answer: 


---


Section E: JIT, Kaizen & Cost of Quality


66. True or False: JIT production is driven by customer orders.

Answer: 


67. Fill in the blank: In a JIT system, inventory is viewed as a __________.

Answer:


68. Which of the following is NOT a characteristic of JIT? (a) Significant reduction in inventory, (b) Higher quality products in a shorter time, (c) Allowing minor defects without correction, (d) Eliminating rework costs.

Answer: 


69. True or False: Kaizen refers to continuous improvement.

Answer:


70. Fill in the blank: The cost of inspection at various stages of production is an example of a(n) __________ cost.

Answer:


71. Costs incurred to detect poor-quality goods are called __________ costs.

Answer:


72. True or False: Prevention costs are incurred to keep defects from occurring.

Answer: 


73. Which of the following is an example of an internal failure cost? (a) Warranty repairs, (b) Rework, (c) Inspection, (d) Training.

Answer:


74. Fill in the blank: External failure costs are incurred __________ the product is delivered to the customer.

Answer: 


75. True or False: Increasing prevention costs typically reduces appraisal, internal failure, and external failure costs over time.

Answer:


76. Which of the following is NOT a cost of quality category? (a) Prevention, (b) Appraisal, (c) Internal failure, (d) Prime cost.

Answer: 


77. Fill in the blank: The cost of training employees for quality improvement is classified as a __________ cost.

Answer:


78. True or False: Under JIT, a company relies on long-term consumer forecasts to drive production.

Answer: 


79. Kaizen costing focuses on cost reduction during the __________ stage of a product's life cycle.

Answer:


80. Fill in the blank: The cost of rework in a quality-improvement program is categorized as a(n) __________ failure cost.

Answer:


---


Section F: Mixed Review & Odd One Out


81. Odd One Out: Which of the following is not a period cost? (a) Sales commissions, (b) Administrative salaries, (c) Direct materials, (d) Advertising expense.

Answer: 


82. Fill in the blank: The __________ method of costing includes only direct materials, direct labor, and variable manufacturing overhead in product costs.

Answer: 


83. True or False: Throughput accounting is used for external financial reporting under U.S. GAAP.

Answer:


84. Odd One Out: Which is not a component of the cost of quality? (a) Prevention, (b) Appraisal, (c) Prime cost, (d) External failure.

Answer: 


85. Fill in the blank: The three basic measures in the Theory of Constraints are throughput, inventory, and __________.

Answer


86. True or False: Under JIT, materials are purchased in large quantities to obtain quantity discounts.

Answer:


87. Odd One Out: Which is not a characteristic of absorption costing? (a) Fixed overhead is a product cost, (b) Net income is affected by production volume, (c) It is used for internal decision-making only, (d) It is required for external reporting.

Answer: 

88. Fill in the blank: Under U.S. GAAP, the equity method is used when an investor owns __________ of the voting stock of an investee.

Answer:


89. True or False: Super-variable costing and throughput costing are identical concepts.

Answer: 


90. Odd One Out: Which of the following is not a type of overhead? (a) Manufacturing overhead, (b) Selling overhead, (c) Administrative overhead, (d) Prime overhead.

Answer:


91. Fill in the blank: The primary purpose of cost accounting is to provide information to management for __________.

Answer:


92. True or False: Under U.S. GAAP, LIFO is an acceptable inventory valuation method.

Answer:


93. Odd One Out: Which is not a JIT benefit? (a) Reduced inventory, (b) Increased lead times, (c) Improved quality, (d) Reduced waste.

Answer: 


94. Fill in the blank: In throughput accounting, the TPAR is calculated by dividing the return per factory hour by the __________ per factory hour.

Answer:


95. True or False: Kaizen costing is applied during the design phase of a product.

Answer: 

96. Odd One Out: Which is not a cost of quality? (a) Prevention, (b) Appraisal, (c) Internal failure, (d) Sunk cost.

Answer: 


97. Fill in the blank: Under variable costing, fixed selling and administrative expenses are treated as __________ costs.

Answer:


98. True or False: Absorption costing must be used for external financial reporting under U.S. GAAP.

Answer: 


99. Odd One Out: Which is not a type of cost classification? (a) By element, (b) By function, (c) By behavior, (d) By color.

Answer: 


100. Fill in the blank: The five-step model for revenue recognition under ASC 606 begins with identifying the __________ with a customer.

Answer: 

Sunday, September 27, 2026

Internal Control, COSO, COBIT, Governance, Risk Assessment, AIS, FCPA, and SOX — Comprehensive Exam Notes (CIA Part 1 & US CMA Part 1), Casebased Questions with answers:



mocktest sept27 sunday internal control governence risk assessment etc



Internal Control, COSO, COBIT, Governance, Risk Assessment, AIS, FCPA, and SOX — Comprehensive Exam Notes (CIA Part 1 & US CMA Part 1), Casebased Questions with answers:

 

1. The Internal Control System — Core Concepts

 

Definition (COSO): Internal control is a process, effected by an entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in three categories:

· Reliability of financial reporting

· Effectiveness and efficiency of operations

· Compliance with applicable laws and regulations

Reasonable assurance means a high level of confidence that financial statements or reports are free from material misstatements, while absolute assurance (Infalliability)means 100% certainty and zero risk of error.

Key limitation: Internal controls provide reasonable assurance, not absolute assurance. Limitations include human error, faulty judgment, collusion, management override, and cost-benefit constraints.

Internal controls provide reasonable rather than absolute assurance because they are subject to unavoidable inherent limitations rooted in human behavior, authority, and changing environments.

Human Error

  • Human Error occurs because people are prone to fatigue, carelessness, distraction, or misinterpretation of instructions.
  • Example: An accounting clerk accidentally enters an invoice amount as $120,000 instead of $1,200,000, and a tired reviewer fails to catch the typo during a routine check.

Collusion

  • Collusion happens when two or more individuals secretly cooperate to bypass controls, defeating systems like segregation of duties.
  • Example: A purchasing manager and an accounts payable clerk work together to approve fake vendor invoices and split the fraudulent payouts, bypassing the independent check between purchasing and payment.  

Management Override

  • Management Override arises when executives or individuals in positions of high authority use their power to bypass established policies.
  • Example: A CEO orders the finance department to bypass standard purchase order approvals to fast-track an unauthorized high-value contract for a personal friend's company.

Compromised Judgment

  • Compromised Judgment involves poor decision-making or flawed estimates made under pressure or with incomplete information.
  • Example: Management sets aggressive, unrealistic quarterly sales targets, pushing regional staff to log fake sales transactions or cut corners on credit checks just to meet goals.

Obsolescence and Changing Conditions

  • Obsolescence occurs when controls fail to adapt to shifts in business size, technology, regulations, or operations.
  • Example: An outdated manual approval workflow for software updates remains in place, leaving the company blind to newer automated cyber threats or cloud-infrastructure vulnerabilities.

 

Three objectives (the "control triad"): Operations, Reporting, Compliance.

The control triad consists of Operations, Reporting, and Compliance, which form the core objectives of internal control frameworks like COSO.

The Control Triad Components

  • Operations
    • Focuses on the effective and efficient use of an organization's resources.
    • Aims to achieve basic business objectives, safeguard assets, and improve performance.
    • Relates to day-to-day business execution and operational resilience.
  • Reporting
    • Focuses on the reliability, timeliness, and transparency of internal and external financial and non-financial reporting.
    • Ensures stakeholders receive accurate data for informed decision-making.
    • Includes regulatory filings and disclosures regarding serious disruptions or metrics.  
  • Compliance
    • Focuses on adherence to applicable laws, regulations, and internal policies.
    • Converts external legal and regulatory obligations into expected organizational behavior.
    • Ensures the business operates within statutory boundaries and ethical guidelines.

 

Types of controls by timing:

· Preventive — stop problems before they occur (e.g., segregation of duties, passwords, authorization).

· Detective — identify problems after they occur (e.g., reconciliations, variance analysis, physical counts).

· Corrective — fix problems once detected (e.g., error correction, backup restoration).

· Directive — guide behavior toward desired outcomes (e.g., policies, training).

 

Control classifications (CIA Part 1 emphasis): Preventive, detective, corrective, directive, input, processing, output, feedforward, feedback, key controls, compensating controls.

 

Compensating control: A secondary control that mitigates risk when a primary control cannot operate as designed or is absent. Example: daily supervisory review of deposit slips when cash receipts and recordkeeping cannot be segregated in a small department.

 

2. COSO Internal Control — Integrated Framework (2013)

The COSO Internal Control – Integrated Framework (2013) is the dominant framework for designing and evaluating internal control. It consists of five interrelated components and 17 principles.

2.1 Five Components

Control Environment The "tone at the top" — integrity, ethical values, organizational structure, competence, accountability

Risk Assessment Identifying and analyzing risks to objectives; determining how risks should be managed

Control Activities Policies and procedures that help ensure management directives are carried out

Information & Communication Relevant information identified, captured, and communicated in a timely manner

Monitoring Ongoing and separate evaluations to assess control effectiveness

 

The Control Environment is the foundation — all other components build upon it. Major corporate scandals (e.g., Enron) often stem from a toxic control environment rather than a lack of policies.

 

2.2 The 17 Principles (by Component)

Control Environment (Principles 1–5)

1. Demonstrates commitment to integrity and ethical values

2. Board of directors demonstrates independence and exercises oversight

3. Establishes structure, authority, and responsibility

4. Demonstrates commitment to competence

5. Enforces accountability

 

Risk Assessment (Principles 6–9)

6. Specifies suitable objectives with sufficient clarity

7. Identifies and analyzes risks to achieving objectives

8. Assesses fraud risk

9. Identifies and analyzes significant change

 

Control Activities (Principles 10–12)

10. Selects and develops control activities

11. Selects and develops general controls over technology

12. Deploys control activities through policies and procedures

 

Information & Communication (Principles 13–15)

13. Obtains or generates relevant information

14. Communicates internally

15. Communicates externally

 

Monitoring Activities (Principles 16–17)

16. Conducts ongoing and/or separate evaluations

17. Evaluates and communicates deficiencies

 

Exam tip: The 2013 Framework introduced the codification of 17 principles and 51 points of focus.

 

2.3 COSO ERM (2017) — For CMA Part 1

COSO Enterprise Risk Management — Integrating with Strategy and Performance (2017) has five components and 20 principles:

1. Governance and Culture (5 principles)

2. Strategy and Objective-Setting (4 principles)

3. Performance (5 principles)

4. Review and Revision (3 principles)

5. Information, Communication, and Reporting (3 principles)

 

ERM expands internal control beyond financial reporting to strategy and enterprise-wide risk.

 

3. COBIT — IT Governance Framework

COBIT (Control Objectives for Information and Related Technologies), developed by ISACA, is the leading framework for governance and management of enterprise IT (GEIT).

3.1 COBIT 2019 — Six Governance Principles

 

COBIT 2019 is built on six principles for a governance system (expanded from five in COBIT 5):

1. Provide Stakeholder Value — Enterprises exist to create value for stakeholders by balancing benefits, risk optimization, and resource use.

2. Holistic Approach — Governance built from a number of interacting components working together.

3. Dynamic Governance System — Governance must adapt to changing enterprise needs.

4. Governance Distinct from Management — Governance ensures goals are achieved by evaluating needs, setting direction, and monitoring; management plans, builds, runs, and monitors activities.

5. Tailored to Enterprise Needs — Frameworks must be customized to the enterprise's context.

6. End-to-End Governance System — Covers the entire enterprise, treating information and technology as assets.

 

3.2 COBIT 2019 — Seven Enablers

1. Principles, policies, and frameworks

2. Processes

3. Organizational structures

4. Culture, ethics, and behavior

5. Information

6. Services, IT infrastructure, and applications

7. People, skills, and competencies

 

3.3 COBIT Domains (40 Objectives)

· EDM — Evaluate, Direct, Monitor (Governance)

· APO — Align, Plan, Organize (Management)

· BAI — Build, Acquire, Implement

· DSS — Deliver, Service, Support

· MEA — Monitor, Evaluate, Assess

 

Exam relevance: COBIT's MEA02 process specifically addresses monitoring and evaluating the system of internal control. COBIT is used to translate regulatory obligations (SOX, ISO 27001, PCI DSS, DORA) into a single control architecture.

 

4. Governance — CIA Part 1 Context

 

4.1 Definition and Ownership

Governance is the combination of processes and structures the board uses to inform, direct, manage, and monitor the organization toward its objectives.

· Owned by: The board / governing body

· Internal audit's role: Evaluate and contribute to improving governance — not to own or operate it

 

4.2 The IIA Three Lines Model (2020)

Replaced the older "Three Lines of Defense":

Line Role

Governing Body Oversight and direction

First Line Management — owns and manages risk

Second Line Risk management and compliance functions

Third Line Internal audit — independent assurance

 

Hard rule: Management owns risk and control; the board oversees; internal audit assures.

 

4.3 Governance, Risk, and Control — Interlocking Processes

 

1. Governance sets direction and oversight

2. Risk management identifies what could derail objectives

3. Control provides assurance objectives are met

 

The board sets objectives, risk appetite, ethical tone, and oversight expectations. Management identifies risks and decides responses. Controls are the specific actions that bring risk down to acceptable levels.

 

5. Risk Assessment — CIA Part 1 & CMA Part 1

5.1 Risk Vocabulary

· Risk: The possibility that events will affect the achievement of objectives — positively or negatively.

· Inherent risk: Risk before any controls.

· Residual risk: Risk remaining after controls.

· Risk appetite: The amount of risk the organization is willing to accept.

· Risk tolerance: Acceptable variation around the risk appetite.

· Risk response: Avoid, reduce, share/transfer, accept.

 

5.2 Risk Assessment Process (COSO)

The Risk Assessment component of COSO (Principles 6–9) requires:

1. Specifying suitable objectives — objectives must be clear enough to identify risks.

2. Identifying and analyzing risks — assess likelihood and impact.

3. Assessing fraud risk — specifically consider fraud in risk assessment.

4. Identifying significant change — monitor changes that could affect internal control.

 

Risk assessment techniques: Risk mapping based on likelihood and impact, use of matrices, risk registers.

 

5.3 Internal Audit's Role in Risk Assessment

· Primary role: Provide objective evaluations of risk and contribute to the risk management process.

· CIA Part 1 weight: Internal Control & Risk is 25–35% of the exam.

· Internal audit evaluates adequacy and effectiveness of risk management — it does not perform the risk assessment for management (would impair objectivity).

 

6. Accounting Information Systems (AIS) Controls

6.1 General Controls (ITGCs)

IT General Controls apply to all systems in the IT environment:

· Logical access security — passwords, user access rights

· Change management — controlling modifications to systems

· Computer operations — job scheduling, backups, disaster recovery

· Segregation of incompatible duties in IT

· System development procedures

· Physical security — hardware, facilities

 

ITGCs are pervasive — they support the integrity of every application running in the environment.

 

6.2 Application Controls

Application controls are specific to a particular application and relate to individual transactions:

Category Purpose Examples

Input Controls Ensure accuracy and completeness of data entered Check digits, field validation, batch totals, edit checks

Processing Controls Ensure data is processed correctly Run-to-run totals, reasonableness checks, sequence checks

Output Controls Ensure outputs are accurate, complete, and delivered securely Distribution lists, reconciliation of output totals

Data File Controls Ensure integrity of stored data File maintenance controls, access restrictions

 

Check digit: An algorithmic validation embedded in an input field (e.g., customer or account number) that detects transposition and transcription errors at data entry — a classic input application control.

 

6.3 Relationship Between ITGCs and Application Controls

 

ITGCs provide the environment in which application controls operate. If ITGCs are weak, application controls may not function reliably. Auditors typically test ITGCs first, then application controls.

 

7. FCPA — Foreign Corrupt Practices Act (1977)

7.1 Two Sets of Provisions

The FCPA has two major provisions:

1. Anti-bribery provisions — prohibit corrupt payments to foreign officials.

2. Accounting provisions — require issuers to:

   · Make and keep books and records that accurately and fairly reflect transactions

   · Devise and maintain a system of internal accounting controls sufficient to provide reasonable assurance that:

     · Transactions are executed in accordance with management's authorization

     · Transactions are recorded to permit preparation of financial statements in conformity with GAAP

     · Access to assets is permitted only in accordance with management's authorization

     · Recorded accountability for assets is compared with existing assets at reasonable intervals

 

7.2 FCPA and Internal Controls

The FCPA was the first law to openly hold management accountable for maintaining adequate books, records, and internal accounting controls. It "made it clear that it is illegal for a public company to have an inadequate system of internal control".

 

Key point: A violation of the anti-bribery provision is not required to violate the internal control provision. The accounting provisions are independent.

 

7.3 FCPA vs. SOX — Critical Distinction

 

 FCPA SOX §404

Materiality threshold None — no financial threshold Material weakness threshold

Scope Internal accounting controls (broad) Internal control over financial reporting (ICFR)

Focus Accurate books, management control over assets Detection of material misstatement

 

A $75,000 payment may be immaterial for SOX purposes but still violate FCPA's internal control provision.

 

Compliance guidance: Organizations should review and test controls, and maintain a well-constructed compliance and ethics program to prevent, detect, remediate, and report misconduct.

 

 

8. Sarbanes-Oxley Act (SOX) 2002

8.1 Key Sections for Internal Control

Section 302 — Corporate Responsibility for Financial Reports

· CEO and CFO must personally certify the accuracy of financial statements in quarterly and annual reports

· Must certify they have evaluated the effectiveness of disclosure controls and procedures

· Must disclose all significant deficiencies in internal control

 

Section 404 — Management Assessment of Internal Controls

· Management must assess and report on the effectiveness of internal control over financial reporting (ICFR)

· External auditors must attest to management's assessment

· Section 404(a) requires an internal control report in the annual report

 

8.2 SOX and COSO

SOX §404 effectively mandates the use of a recognized internal control framework. COSO Internal Control – Integrated Framework (2013) is the most widely used framework for SOX compliance in the U.S..

 

8.3 SOX and FCPA Interplay

 

SOX and FCPA compliance are not equivalent:

· SOX compliance ≠ FCPA compliance

· SOX internal auditors focus on financial reporting controls; FCPA compliance requires forensic accounting skills and transaction testing of compliance-sensitive accounts (commissions, gifts, charitable contributions)

· SOX walkthroughs may not reveal anomalies when controls are compromised through collusion; FCPA transaction testing is more likely to detect such issues

 

9. Summary — Key Distinctions for Exam

Concept Key Point

COSO IC (2013) 5 components, 17 principles; reasonable assurance; foundation = Control Environment

COSO ERM (2017) 5 components, 20 principles; expands to strategy and enterprise risk

COBIT 2019 6 governance principles, 7 enablers, 40 objectives across 5 domains

Governance Board owns; sets direction, risk appetite, oversight

Risk management Management owns; identifies, assesses, responds to risks

Internal audit Assures; evaluates adequacy and effectiveness — does not own or operate

ITGCs Pervasive controls (access, change mgmt, operations)

Application controls Input, processing, output — specific to an application

FCPA No materiality threshold; books & records + internal accounting controls

SOX §302 CEO/CFO certification of financials and disclosure controls

SOX §404 Management assessment + auditor attestation of ICFR

 

10. Exam Weightings (for prioritization)

 

CIA Part 1:

 

· Section A (Foundations of Internal Auditing): 35%

· Section C (Governance, Risk Management, and Control): 30% — includes COSO, Three Lines Model, governance, risk, control concepts

· Internal Control & Risk specifically: 25–35%

 

CMA Part 1:

· Internal Controls: 15% — covers COSO IC and ERM frameworks, control activities, limitations, SOX §302/§404, FCPA, IT controls, SOC reports

 

CIA Part 1 & US CMA Part 1 – Internal Control, COSO, COBIT, Governance, Risk, AIS, FCPA, SOX

Internal Control Basics (1–10)

1. Which of the following is NOT one of the three categories of objectives in the COSO internal control framework?

A. Reliability of financial reporting

B. Effectiveness and efficiency of operations

C. Compliance with laws and regulations

D. Maximization of shareholder wealth

Answer: D

 

2. Internal control provides:

A. Absolute assurance

B. Reasonable assurance

C. No assurance

D. Guaranteed assurance

Answer: B

3. Which type of control is designed to detect errors after they occur?

A. Preventive

B. Detective

C. Corrective

D. Directive

Answer: B

4. Segregation of duties is an example of which type of control?

A. Preventive

B. Detective

C. Corrective

D. Directive

Answer: A

5. Which of the following is a limitation of internal control?

A. Human error

B. Collusion

C. Management override

D. All of the above

Answer: D

6. A compensating control is used when:

A. A primary control fails

B. A primary control cannot be implemented

C. Management wants to reduce costs

D. Both A and B

Answer: D

7. Which of the following is NOT a component of the COSO internal control framework?

A. Control environment

B. Risk assessment

C. Control activities

D. Financial reporting

Answer: D

 

8. The "tone at the top" is most closely associated with which COSO component?

A. Control environment

B. Risk assessment

C. Control activities

D. Monitoring

Answer: A

9. Which of the following is a corrective control?

A. Password protection

B. Bank reconciliation

C. Backup restoration

D. Training

Answer: C

10. The primary purpose of internal control is to:

A. Eliminate all risks

B. Ensure achievement of objectives

C. Guarantee profitability

D. Prevent fraud entirely

Answer: B

 

COSO Internal Control Framework (11–25)

11. How many principles are in the COSO 2013 internal control framework?

A. 5

B. 17

C. 20

D. 25

Answer: B

 

12. Which COSO component is considered the foundation of all other components?

A. Risk assessment

B. Control activities

C. Control environment

D. Monitoring

Answer: C

 

13. Which principle requires the organization to demonstrate a commitment to integrity and ethical values?

A. Principle 1

B. Principle 2

C. Principle 3

D. Principle 4

Answer: A

14. Assessing fraud risk is part of which COSO component?

A. Control environment

B. Risk assessment

C. Control activities

D. Monitoring

Answer: B

15. Which COSO component includes selecting and developing control activities?

A. Control environment

B. Risk assessment

C. Control activities

D. Information and communication

Answer: C

16. Which of the following is NOT a principle of the control environment?

A. Demonstrates commitment to integrity and ethical values

B. Board of directors demonstrates independence

C. Identifies and analyzes risks

D. Enforces accountability

Answer: C

 

17. The COSO framework requires organizations to identify and analyze significant changes. This is part of:

A. Risk assessment

B. Control activities

C. Monitoring

D. Information and communication

Answer: A

18. Which component ensures that information is identified, captured, and communicated timely?

A. Control environment

B. Risk assessment

C. Information and communication

D. Monitoring

Answer: C

19. Monitoring activities in COSO include:

A. Ongoing evaluations

B. Separate evaluations

C. Both A and B

D. Neither A nor B

Answer: C

20. Which of the following is a point of focus under the control environment?

A. Assigning authority and responsibility

B. Selecting and developing control activities

C. Communicating externally

D. Conducting separate evaluations

Answer: A

21. The COSO framework is used for:

A. Financial reporting only

B. Internal control over financial reporting

C. All aspects of internal control

D. IT governance only

Answer: C

 

22. Which of the following best describes the relationship between COSO components?

A. They are independent

B. They are interrelated

C. Only one is needed

D. They apply only to large companies

Answer: B

23. The COSO framework was originally published in:

A. 1985

B. 1992

C. 2002

D. 2013

Answer: B

24. The 2013 COSO framework update emphasized:

A. Increased focus on IT controls

B. Codification of principles

C. Both A and B

D. Only financial reporting

Answer: C

25. Which of the following is NOT one of the 17 principles?

A. Demonstrates commitment to competence

B. Identifies and analyzes risks

C. Conducts external audits

D. Evaluates and communicates deficiencies

Answer: C

COSO ERM (26–30)

26. How many components are in the COSO ERM 2017 framework?

A. 5

B. 8

C. 17

D. 20

Answer: A

 

27. Which component of COSO ERM focuses on governance and culture?

A. Governance and Culture

B. Strategy and Objective-Setting

C. Performance

D. Review and Revision

Answer: A

28. COSO ERM 2017 has how many principles?

A. 5

B. 17

C. 20

D. 25

Answer: C

29. The COSO ERM framework expands internal control to include:

A. Strategy and enterprise-wide risk

B. Only financial reporting

C. Only IT risks

D. Only compliance risks

Answer: A

30. Which of the following is a component of COSO ERM?

A. Information, Communication, and Reporting

B. Control Activities

C. Monitoring

D. Risk Assessment

Answer: A

COBIT (31–40)

31. COBIT is developed by:

A. COSO

B. ISACA

C. IIA

D. AICPA

Answer: B

 

32. How many governance principles are in COBIT 2019?

A. 5

B. 6

C. 7

D. 8

Answer: B

33. Which of the following is NOT a COBIT 2019 governance principle?

A. Provide Stakeholder Value

B. Holistic Approach

C. Dynamic Governance System

D. Maximize Shareholder Wealth

Answer: D

34. How many enablers are in COBIT 2019?

A. 5

B. 6

C. 7

D. 8

Answer: C

35. Which COBIT domain covers Evaluate, Direct, Monitor?

A. EDM

B. APO

C. BAI

D. DSS

Answer: A

36. Which COBIT domain covers Build, Acquire, Implement?

A. EDM

B. APO

C. BAI

D. MEA

Answer: C

 

37. COBIT is primarily used for:

A. Financial auditing

B. IT governance

C. Risk management only

D. Internal control over financial reporting

Answer: B

38. Which COBIT process addresses monitoring and evaluating the system of internal control?

A. MEA02

B. APO01

C. BAI03

D. DSS01

Answer: A

39. COBIT 2019 emphasizes governance distinct from:

A. Management

B. Auditing

C. Compliance

D. Risk

Answer: A

40. Which of the following is a COBIT enabler?

A. Processes

B. Organizational structures

C. Culture, ethics, and behavior

D. All of the above

Answer: D

Governance (41–50)

41. Governance is primarily the responsibility of:

A. Management

B. Board of directors

C. Internal audit

D. External audit

Answer: B

 

42. The IIA Three Lines Model includes:

A. Three lines of defense

B. Governing body, management, internal audit

C. First line, second line, third line

D. Both B and C

Answer: D

43. In the Three Lines Model, who owns and manages risk?

A. First line

B. Second line

C. Third line

D. Governing body

Answer: A

44. Internal audit's role in governance is to:

A. Own governance

B. Evaluate and contribute to improving governance

C. Manage risk

D. Set risk appetite

Answer: B

45. Which of the following is NOT a governance responsibility?

A. Setting risk appetite

B. Overseeing management

C. Preparing financial statements

D. Ensuring ethical tone

Answer: C

46. The board's oversight role includes:

A. Approving strategy

B. Monitoring management

C. Ensuring compliance

D. All of the above

Answer: D

 

47. Which of the following best describes the relationship between governance, risk, and control?

A. Independent

B. Interlocking

C. Sequential

D. Random

Answer: B

48. The governing body is responsible for:

A. Directing the organization

B. Managing daily operations

C. Conducting internal audits

D. Preparing tax returns

Answer: A

49. Which of the following is a key governance principle?

A. Transparency

B. Accountability

C. Fairness

D. All of the above

Answer: D

50. Internal audit independence is essential for:

A. Governance

B. Risk management

C. Control

D. All of the above

Answer: D

Risk Assessment (51–60)

51. Risk is defined as:

A. Certainty of loss

B. Possibility that events will affect objectives

C. Guaranteed profit

D. Absence of controls

Answer: B

52. Inherent risk is:

A. Risk after controls

B. Risk before controls

C. Risk that is accepted

D. Risk that is transferred

Answer: B

53. Residual risk is:

A. Risk before controls

B. Risk after controls

C. Risk that is avoided

D. Risk that is shared

Answer: B

54. Risk appetite is:

A. The amount of risk an organization is willing to accept

B. The amount of risk an organization can eliminate

C. The amount of risk internal audit can ignore

D. The amount of risk that is always zero

Answer: A

55. Which of the following is a risk response?

A. Avoid

B. Reduce

C. Share

D. All of the above

Answer: D

56. Which COSO component requires assessing fraud risk?

A. Control environment

B. Risk assessment

C. Control activities

D. Monitoring

Answer: B

 

57. Risk assessment involves:

A. Identifying risks

B. Analyzing risks

C. Both A and B

D. Neither A nor B

Answer: C

58. Internal audit's role in risk management is to:

A. Perform risk assessment for management

B. Provide objective evaluations of risk

C. Accept risks on behalf of the organization

D. Eliminate all risks

Answer: B

59. Which of the following is a risk assessment technique?

A. Risk mapping

B. Likelihood and impact analysis

C. Risk registers

D. All of the above

Answer: D

60. Significant change that could affect internal control should be identified as part of:

A. Control environment

B. Risk assessment

C. Control activities

D. Monitoring

Answer: B

AIS & IT Controls (61–70)

61. IT General Controls (ITGCs) apply to:

A. Specific applications

B. All systems in the IT environment

C. Only financial systems

D. Only hardware

Answer: B

62. Which of the following is an ITGC?

A. Logical access security

B. Change management

C. Computer operations

D. All of the above

Answer: D

63. Application controls are specific to:

A. All systems

B. A particular application

C. Hardware only

D. Network only

Answer: B

64. Input controls ensure:

A. Accuracy and completeness of data entered

B. Data is processed correctly

C. Output is accurate

D. Data is stored securely

Answer: A

65. A check digit is an example of:

A. Input control

B. Processing control

C. Output control

D. Data file control

Answer: A

66. Processing controls include:

A. Run-to-run totals

B. Reasonableness checks

C. Sequence checks

D. All of the above

Answer: D

67. Output controls ensure:

A. Data is entered correctly

B. Data is processed correctly

C. Outputs are accurate, complete, and delivered securely

D. Data is stored correctly

Answer: C

68. Which of the following is a data file control?

A. File maintenance controls

B. Access restrictions

C. Both A and B

D. Neither A nor B

Answer: C

69. ITGCs provide the environment in which:

A. Application controls operate

B. Financial statements are prepared

C. Management overrides controls

D. Auditors issue opinions

Answer: A

70. If ITGCs are weak, application controls:

A. Are always effective

B. May not function reliably

C. Are not needed

D. Become unnecessary

Answer: B

FCPA (71–80)

71. The FCPA was enacted in:

A. 1977

B. 1992

C. 2002

D. 2010

Answer: A

72. The FCPA has how many major provisions?

A. One

B. Two

C. Three

D. Four

Answer: B

73. The FCPA's accounting provisions require issuers to:

A. Make and keep accurate books and records

B. Maintain a system of internal accounting controls

C. Both A and B

D. Neither A nor B

Answer: C

74. Under the FCPA, a violation of the anti-bribery provision is required to violate the internal control provision.

A. True

B. False

Answer: B. False

Under the Foreign Corrupt Practices Act (FCPA), the anti-bribery provisions and the internal control/accounting provisions operate independently of each other.

  • Independent Enforcement: A company or individual can be prosecuted and charged with a violation of the internal control provisions even if there is no underlying or accompanying violation of the anti-bribery provisions.
  • Separate Requirements: The anti-bribery provisions prohibit corrupt payments to foreign officials, whereas the accounting and internal control provisions require issuers to maintain accurate books and reasonable accounting controls to prevent and detect potential misconduct, regardless of whether actual bribery occurred.

75. The FCPA has a materiality threshold for internal control violations.

A. True

B. False

Answer B. False

The Foreign Corrupt Practices Act (FCPA) does not have a materiality threshold for its accounting provisions, which include both the books-and-records and the internal accounting controls rules.

Instead of a financial materiality limit, the law requires issuers to maintain records in "reasonable detail" and devise internal controls that provide "reasonable assurances" that transactions are executed with management's authorization. Under the law, even minor or quantitatively small transactions can trigger an FCPA violation if they bypass internal control mechanisms or are recorded

76. Which of the following is required by the FCPA's internal accounting controls?

A. Transactions are executed in accordance with management's authorization

B. Transactions are recorded to permit preparation of financial statements in conformity with GAAP

C. Access to assets is permitted only in accordance with management's authorization

D. All of the above

Answer: D

77. The FCPA applies to:

A. U.S. companies only

B. Foreign companies only

C. Issuers and domestic concerns

D. Only government entities

Answer: C

78. Which of the following is a key difference between FCPA and SOX?

A. FCPA has no materiality threshold

B. SOX has no materiality threshold

C. FCPA applies only to foreign companies

D. SOX applies only to private companies

Answer: A

79. To comply with FCPA, organizations should:

A. Review and test controls

B. Maintain a compliance and ethics program

C. Prevent, detect, remediate, and report misconduct

D. All of the above

Answer: D

80. The FCPA's books and records provision requires:

A. Accurate and fair reflection of transactions

B. Only annual reporting

C. Only internal audits

D. Only external audits

Answer: A

 

SOX (81–90)

81. SOX was enacted in:

A. 1977

B. 1992

C. 2002

D. 2010

Answer: C

82. SOX Section 302 requires:

A. CEO and CFO certification of financial statements

B. Management assessment of internal controls

C. Auditor attestation of internal controls

D. All of the above

Answer: A

83. SOX Section 404 requires:

A. CEO and CFO certification

B. Management assessment of internal controls

C. Both A and B

D. Neither A nor B

Answer: B

84. Under SOX 404, management must:

A. Assess and report on effectiveness of ICFR

B. Guarantee no fraud

C. Eliminate all risks

D. Prepare tax returns

Answer: A

85. SOX 404(b) requires:

A. Management assessment

B. External auditor attestation

C. Internal audit assessment

D. None of the above

Answer: B

86. SOX effectively mandates the use of which framework?

A. COBIT

B. COSO

C. ISO 27001

D. ITIL

Answer: B

87. SOX compliance is equivalent to FCPA compliance.

A. True

B. False

Answer: B

88. Which section of SOX requires disclosure of significant deficiencies in internal control?

A. Section 302

B. Section 404

C. Section 906

D. Section 802

Answer: A

89. SOX applies to:

A. All companies

B. Public companies

C. Private companies only

D. Non-profit organizations

Answer: B

90. SOX Section 404(a) requires:

A. Management's internal control report in annual report

B. Auditor's attestation

C. CEO certification

D. CFO certification

Answer: A

 

---

 

Control Applications & Other (91–100)

91. Which of the following is an example of a preventive control?

A. Bank reconciliation

B. Segregation of duties

C. Backup restoration

D. Variance analysis

Answer: B

92. Which of the following is an example of a detective control?

A. Password protection

B. Physical counts

C. Authorization

D. Training

Answer: B

93. Which of the following is a directive control?

A. Policies and procedures

B. Reconciliations

C. Error correction

D. Backups

Answer: A

94. A key control is:

A. A control that is essential to achieving objectives

B. A control that is optional

C. A control that is always automated

D. A control that is always manual

Answer: A

95. Compensating controls are used when:

A. Primary controls are ineffective

B. Primary controls cannot be implemented

C. Management wants to reduce costs

D. Both A and B

Answer: D

96. Which of the following is NOT a component of the COSO internal control framework?

A. Control environment

B. Risk assessment

C. Control activities

D. Financial reporting

Answer: D

97. The IIA Three Lines Model replaced:

A. Three Lines of Defense

B. COSO framework

C. COBIT framework

D. SOX

Answer: A

98. Which of the following is a governance responsibility?

A. Setting risk appetite

B. Overseeing management

C. Ensuring ethical tone

D. All of the above

Answer: D

99. Which of the following is a risk response?

A. Avoid

B. Reduce

C. Share

D. All of the above

Answer: D

100. Which of the following is a COBIT domain?

A. EDM

B. APO

C. BAI

D. All of the above

Answer: D

Case-based and scenario-based questions in CIA Part 1 (Essentials of Internal Auditing) and US CMA Part 1 (Financial Planning, Performance, and Analytics) test your ability to apply governance, internal control, and risk concepts to real-world business situations rather than just recalling definitions.

Case 1: Segregation of Duties & Cash Controls Scenario:

A small manufacturing company’s cashier opens incoming mail, records customer checks in the cash receipts journal, prepares the daily bank deposit slip, and periodically reconciles the bank statement. During an internal audit review, management is questioned about this setup.  

Question: Which internal control principle is being violated, and what is the primary risk?    Violation: =?  , Risk:? ,  Correct Control: ?

Answer & Analysis:

  • Violation: Failure to segregate incompatible functions. The cashier has both custody of assets (handling checks/cash) and recording of transactions (posting to the journal/reconciling the bank).
  • Risk: The individual can perpetrate an error or theft and conceal it in the normal course of their duties (e.g., kiting or skimming cash and manipulating the ledger or bank reconciliation).
  • Correct Control: Separate custody, recording, and authorization functions. Another employee who does not handle cash should perform the bank reconciliation.

Case 2: Governance & Board Responsibilities Scenario:

A newly appointed board of directors at an SEC-registered company is revising its corporate governance charter. A board member proposes that the board draft all operational compliance policies and directly manage the internal audit budget and staffing selections to ensure tight oversight.    Question: Is the board member's proposal aligned with proper corporate governance structures tested in CIA/CMA exams?      Evaluation:?     ,  Management’s Role:?  , Board/Audit Committee’s Role:?

Answer & Analysis:

  • Evaluation: The proposal misallocates duties between the board, management, and internal audit.
  • Management’s Role: Management is responsible for designing, implementing, and operating the system of internal controls and drafting detailed operational policies.
  • Board/Audit Committee’s Role: The board provides oversight, establishes the governance tone, and the audit committee specifically approves the internal audit charter, budget, and resource plan—as well as appoints/dismisses the Chief Audit Executive (CAE)—rather than writing operational policies or executing day-to-day administrative control.

Case 3: Limitations of Internal ControlsScenario: A retail chain implements a state-of-the-art automated inventory management and point-of-sale control system. Two senior store managers collude to bypass the system's override protocols by using shared administrator credentials, falsifying shrinkage reports, and stealing high-value merchandise over six months.    Question: What fundamental concept regarding internal controls does this scenario illustrate?        Concept:? , Explanation:? , Key Limitations Highlighted:?

Answer & Analysis:

  • Concept: Inherent limitations of internal control systems.
  • Explanation: No matter how well-designed or automated a system is, internal controls can only provide reasonable assurance (not absolute assurance) regarding the achievement of objectives.
  • Key Limitations Highlighted:

1.   Collusion: Two or more individuals working together can bypass physical and digital segregation controls.

2.   Management Override: Individuals in authority positions have the power to override automated checks or procedural controls.

3.   Human Error or Judgment: Flaws in handling or sharing credentials

case scenarios covering Accounting Information Systems (AIS), deliverables, risk ownership, and internal control frameworks as tested in the CIA Part 1 and US CMA Part 1 exams.

Scenario 1: AIS Deliverables, Change Management, & Risk OwnershipThe Case: Global Retail Corp. is upgrading its ERP system to handle automated inventory restocking. The Project Manager (PM) is racing against a tight deadline. To meet the go-live date, the PM decides to skip the user acceptance testing (UAT) sign-off—a critical project deliverable—and plans to run the system migration over a holiday weekend. The Chief Financial Officer (CFO), who is the executive sponsor and risk owner for financial reporting accuracy, is not informed of this shortcut.      Question: What control vulnerability exists regarding risk ownership, and what is the potential impact on the AIS   deliverables?     Control Vulnerability? , Impact on Deliverables:? ,Correct Protocol: ?

Answer & Analysis:

  • Control Vulnerability: The Project Manager is inappropriately acting as the risk owner by accepting the operational risk of skipping UAT. In corporate governance, the PM is a risk custodian or manager, while the CFO is the actual risk owner accountable for the integrity of the AIS data.
  • Impact on Deliverables: Bypassing UAT threatens the reliability of the system's output (the core deliverable). Without testing, the AIS could generate corrupted financial reports, erroneous automated purchase orders, or inaccurate inventory valuations, leading to material financial statement misstatements.
  • Correct Protocol: The PM must present the timeline risk to the CFO. Only the risk owner has the authority to formally accept the risk or allocate more resources to complete the deliverable safely.

 

Scenario 2: AIS Application Controls & Data IntegrityThe Case: An internal auditor is reviewing the automated procurement module of a company's AIS. The system is designed to automatically generate a purchase order (PO) when raw material inventory falls below a reorder point. During the review, the auditor discovers that a data entry clerk accidentally typed an extra zero into a manual batch override, resulting in an authorized purchase order for 100,000 units instead of 10,000 units. The system processed the transaction without flagging it.    Question: What type of internal control failed, and what specific AIS application controls should have prevented this error?     Control Failure:?,   Missing AIS Controls:?

Answer & Analysis:

  • Control Failure: A failure of automated application controls (specifically input controls).
  • Missing AIS Controls:
    • Limit/Reasonableness Check: The AIS should have a pre-programmed field limit that flags or blocks order quantities that deviate significantly from historical averages or maximum warehouse capacities.
    • Range Check: A control that ensures data falls within predetermined upper and lower statistical bounds.
    • Sign-off/Authorization Threshold: The system should automatically route abnormally high-value POs to a senior procurement manager for manual secondary approval before transmission to the vendor.

 

Scenario 3: Bypassing IT Governance & "Shadow IT" Risks The Case: The regional sales division of a logistics firm is frustrated by the slow reporting capabilities of the centralized enterprise AIS. To get faster insights, the regional director hires an external developer to build a standalone, cloud-based sales tracking dashboard using live corporate data. The corporate IT department and the internal audit team are completely unaware of this dashboard.Question: What governance and internal control risks are introduced by this standalone system?    Risk Classification:?,  Key Controls Compromised:?

Answer & Analysis:

  • Risk Classification: This introduces Shadow IT risks and violates fundamental IT governance principles.
  • Key Controls Compromised:
    • Data Integrity & Reconciliation: The standalone system creates a "second version of the truth." If data definitions or timing cut-offs differ from the main AIS, it will produce conflicting financial deliverables.
    • Information Security: Because the application bypassed IT department review, it may lack standard company protocols like multi-factor authentication (MFA), role-based access controls, or data encryption, exposing sensitive corporate data to leaks.
    • Lack of Risk Ownership: No formal risk owner has been assigned to monitor the compliance, backup, or business continuity plans of this rogue application.

Key Exam Takeaways for CIA & CMA Part 1

  • AIS Input controls (edit checks, batch totals) are the most cost-effective way to ensure data integrity before it enters the ledger.
  • Risk Owners must be business unit leaders or executives who have the organizational authority to mitigate, transfer, or accept risks. They cannot delegate accountability to project managers or IT staff.
 


Internal Control governence risk assessment ais etc sept27.docx
201K View as HTML Scan and download