Wednesday, September 9, 2026

Test your ability to apply fraud risk concepts—such as the fraud triangle, control deficiencies, and red flags—to real-world audit scenarios with Answers.

 


Case-based multiple-choice questions (MCQs) for the Certified Internal Auditor (CIA) Part 1 exam test your ability to apply fraud risk concepts—such as the fraud triangle, control deficiencies, and red flags—to real-world audit scenarios.

Section A…

Case 1: The Procurement Vulnerability

 

Scenario:During a routine procurement engagement, an internal auditor discovers that a single junior buyer has the authority to create new vendors in the vendor master file, issue purchase orders, and approve corresponding vendor invoices below a threshold of $10,000. Reviewing transactions under this threshold reveals multiple payments made to a newly created consulting firm with an address matching the junior buyer's residential address. No other supervisory reviews or independent matching procedures exist for invoices under the $10,000 limit.


Question 1:

Which element of the Fraud Triangle is most directly highlighted and enabled by the structural design of this procurement process?

  • A. Pressure, because the buyer is living beyond their means due to personal debt.
  • B. Opportunity, because weak segregation of duties allows one person to originate, execute, and conceal transactions.
  • C. Rationalization, because the buyer feels underpaid compared to industry peers.
  • D. Incentive, because management set aggressive cost-reduction targets for the department.

Correct Answer: BRationale: Opportunity arises when weak internal controls—such as a lack of segregation of duties—allow an individual to commit and conceal fraud without immediate detection. The other elements (pressure, rationalization) are internal psychological drivers, whereas the system design flaw creates the direct structural opportunity.

Case 2: The Overworked Controller

 

Scenario:An internal audit team is assessing the overall control environment and fraud risk governance of a mid-sized manufacturing division. Interviews and observations reveal that the division’s controller works late evenings and weekends, refuses to delegate core accounting tasks, and has not taken consecutive annual vacations or time off in over two years. Furthermore, the controller handles monthly bank reconciliations while simultaneously holding journal entry posting access.


Question 2:

Which combination of behavioral red flags and control risks is most evident in this scenario?

  • A. Management override of controls and aggressive revenue recognition.
  • B. Refusal to take vacation combined with inadequate segregation of duties over cash.
  • C. Document falsification and dual-custody breakdown.
  • D. Lapping of accounts receivable and lifestyle changes.

Correct Answer: BRationale: An employee refusing to take vacation or time off is a classic behavioral red flag, often because continuous presence is required to maintain concealment of an ongoing misappropriation. Combining this with custody of assets and record-keeping (bank reconciliations plus journal entry access) violates basic segregation principles.

 

Case 3: Auditor's Responsibility upon Suspicion

Scenario:While testing inventory receipts in a warehouse, an internal auditor notices that several receiving reports show quantities significantly lower than the packing slips, yet the full vendor invoices were paid in full. The warehouse supervisor casually mentions that the missing inventory represents "defective scrap written off," but there are no formal write-off documents, approval signatures, or credit memos from the vendor.


Question 3:

According to IIA guidance and professional standards, what is the internal auditor's most appropriate immediate course of action?

  • A. Immediately confront the warehouse supervisor with accusations of asset misappropriation.
  • B. Expand the sample size, gather sufficient preliminary evidence, and inform management or the appropriate authorities as defined by the organization's fraud program.
  • C. Disregard the discrepancy because the individual dollar amounts of missing inventory appear immaterial to the financial statements as a whole.
  • D. Immediately halt the entire internal audit engagement and launch a full-scale forensic criminal investigation.

Correct Answer: BRationale: Internal auditors must evaluate indicators of fraud and expand procedures to determine if further action is warranted. They should gather enough preliminary evidence and report suspicions to the appropriate level of management or the board rather than immediately accusing individuals or stepping out of their mandate into full police investigations

 

Section B…

CIA Part 1: Fraud Risk Management Case Quiz

1 / 5

1.

Sarah is the accounting manager at a mid-sized manufacturing firm. The company is publicly traded, and executive management's bonuses are tied strictly to achieving aggressive quarterly net income targets. Sarah is personally facing foreclosure on her home and massive medical debt. Under intense pressure from the CFO to "find a way" to make the numbers work, Sarah capitalizes routine operating expenses as capital assets to artificially inflate net income. Which element of the fraud triangle does Sarah’s personal debt and the CFO’s bonus structure primarily represent?

A.

Rationalization

B.

Opportunity

C.

Pressure/Incentive

D.

Collusion

Answer C…

A.

Rationalization

Incorrect. Rationalization involves the mindset or justification the individual uses to make the unethical act feel acceptable, rather than the external or internal driving force.

B.

Opportunity

Incorrect. Opportunity relates to weaknesses in internal control that allow a person to commit and conceal fraud, not the incentive or need that motivates them.

C.

Pressure/Incentive

Correct! Both personal financial distress (foreclosure/debt) and unrealistic performance goals/bonuses create the incentive or pressure that drives an individual to commit fraud.

D.

Collusion

Incorrect. Collusion refers to cooperation between two or more individuals to bypass controls, which is a structural aspect rather than the primary motivational driver described.

2.

David has worked as the sole accounts payable clerk at a wholesale distributor for 15 years. He is universally trusted by management, never takes consecutive days off, and processes all vendor invoices, inputs banking details, and performs monthly bank reconciliations without review or secondary authorization. An internal auditor discovers multiple payments made to a shell company owned by David. Which condition of the fraud triangle enabled David to execute this scheme?

A.

Ineffective internal controls creating an Opportunity

B.

An overwhelming Financial Pressure due to personal debts

C.

A robust Rationalization that the company owes him for years of low pay

D.

External market incentives forcing the behavior

Answer A…

A.

Ineffective internal controls creating an Opportunity

Correct! A lack of segregation of duties and lack of independent supervisory review create a massive window of opportunity for an employee to commit and conceal fraud.

B.

An overwhelming Financial Pressure due to personal debts

Incorrect. While David may have had financial motivations, the scenario highlights his total control over incompatible duties, which directly addresses the structural ease of committing the fraud.

C.

A robust Rationalization that the company owes him for years of low pay

Incorrect. Although rationalization likely existed, the absence of segregation of duties is the primary environmental factor that physically allows the execution of the scheme.

D.

External market incentives forcing the behavior

Incorrect. External market incentives do not explain an internal AP clerk embezzling through shell companies; internal control failure is the core facilitator here.

3.

During an operational audit of the procurement department, the internal auditor notices that the senior buyer of IT equipment drives a luxury sports car far exceeding his salary level, refuses to take annual vacations, and consistently awards contracts to a vendor whose primary contact shares the same last name and home address as the buyer. How should the internal auditor classify these observations?

A.

Normal operational efficiencies and personal wealth accumulation

B.

Behavioral and operational red flags indicating potential conflict of interest and fraud

C.

Evidence of effective segregation of duties within procurement

D.

Compliance indicators that vendor selection is objective

Answer B…

A.

Normal operational efficiencies and personal wealth accumulation

Incorrect. Awarding contracts to family members and refusing vacations are classic danger signs, not normal operating behavior or simple wealth building.

B.

Behavioral and operational red flags indicating potential conflict of interest and fraud

Correct! Living beyond one's means, refusing to take vacations (which hides concealment), and familial ties to a vendor are textbook behavioral and operational red flags for procurement fraud.

C.

Evidence of effective segregation of duties within procurement

Incorrect. Awarding contracts to a related party without proper disclosure or competitive bidding demonstrates a complete breakdown of procurement controls.

D.

Compliance indicators that vendor selection is objective

Incorrect. Selecting a vendor with the same last name and home address strongly indicates non-objective, biased selection and potential kickbacks.

4.

An internal auditor is conducting a routine review of general ledger journal entries. She identifies several large, non-standard manual journal entries posted on New Year’s Eve with descriptions like "miscellaneous accrual" that lack supporting documentation or required supervisory sign-offs. According to IIA standards, what is the internal auditor's immediate responsibility?

A.

Ignore the entries since they are standard year-end closing adjustments

B.

Automatically assume management is committing fraud and immediately notify local law enforcement

C.

Delete the entries to protect the integrity of the financial records

D.

Exercise professional skepticism, investigate the business rationale of these entries, and report the control deficiency

Answer D..

A.

Ignore the entries since they are standard year-end closing adjustments

Incorrect. Manual entries without documentation or sign-offs are major warning signs of potential manipulation and should never be ignored.

B.

Automatically assume management is committing fraud and immediately notify local law enforcement

Incorrect. Internal auditors must evaluate findings and perform further procedures first, rather than escalating directly outside the organization without proper internal investigation and reporting protocols.

C.

Delete the entries to protect the integrity of the financial records

Incorrect. Deleting ledger entries destroys audit trails and violates fundamental accounting and auditing principles.

D.

Exercise professional skepticism, investigate the business rationale of these entries, and report the control deficiency

Correct! The internal auditor must exercise professional skepticism, evaluate the lack of controls/documentation, extend procedures to see if fraud indicators exist, and report the control breakdown to appropriate management.

5.

The Chief Executive Officer (CEO) of a retail company routinely bypasses dual-authorization controls for wire transfers exceeding $100,000, instructing the treasurer to execute payments directly. When questioned by the internal audit activity, the CEO dismisses the concern, stating, "I founded this company; the rules are meant for junior employees, and I need to move fast to seize market opportunities." This attitude exemplifies which element of the fraud triangle and organizational risk?

A.

Rationalization and tone-at-the-top risk leading to management override

B.

Financial pressure caused by declining retail sales

C.

Lack of technological opportunity to perform authorized sign-offs

D.

Standard operational delegation of authority

Answer A….

A.

Rationalization and tone-at-the-top risk leading to management override

Correct! The CEO's belief that rules do not apply to leadership represents a toxic tone-at-the-top and an inherent rationalization that bypasses controls, creating profound risk through management override.

B.

Financial pressure caused by declining retail sales

Incorrect. The prompt does not state sales are declining; the rationale given is entitlement and speed, not financial hardship.

C.

Lack of technological opportunity to perform authorized sign-offs

Incorrect. The issue is a behavioral disregard for established controls by leadership, not a technological limitation.

D.

Standard operational delegation of authority

Incorrect. Bypassing dual-authorization controls explicitly meant for high-value financial transfers is an override of controls, not a standard delegation process.

 

Section C…

Case-based multiple-choice questions (MCQs) for CIA Part 1 (Essentials of Internal Auditing) focus on the application of the Fraud Triangle, control evaluations, indicators (red flags), and auditor responsibilities regarding fraud.

 

Case 1: Procurement and Segregation of Duties

 

Scenario:During a routine operational audit of the procurement department, an internal auditor observes that a single senior buyer has the authority to create new vendor profiles in the enterprise system, issue purchase orders up to $50,000, and approve the resulting vendor invoices for payment matching the receiving slips. Management notes this flexibility is required to maintain operational efficiency during peak manufacturing cycles.


Question:

Which of the following actions exposes the organization to the highest fraud risk under this operating condition?

  • A. Purchase orders are issued sequentially and matched to receiving reports.
  • B. The procurement policy manual was last updated twenty-four months ago.
  • C. A single individual maintains the vendor master file and approves payment invoices below the review threshold.
  • D. Vendor payment terms are renegotiated annually following a competitive bidding round.

Correct Answer: CRationale: Fraud risk is heavily concentrated where a single person holds incompatible duties, creating the opportunity to both originate and conceal a scheme (e.g., setting up a fictitious vendor and authorizing payments). Options A, B, and D describe standard administrative conditions or ordinary controls rather than a direct breakdown in segregation of duties.

Case 2: Concealment and Journal Entry Red Flags

 

Scenario:An internal audit team is examining inventory management controls at a regional distribution center. The warehouse manager recently purchased a luxury sports car and took no annual leave over a three-year period. The financial statement review reveals an unusual pattern: inventory counts match physical stock, but several non-routine manual journal entries were posted at the end of each quarter, debiting operating expense accounts and crediting inventory values to absorb unexplained shrinkage.


Question:

To conceal the ongoing theft of physical inventory assets, which type of accounting entry did the perpetrator most likely execute through these manual overrides?

  • A. Debit an asset account and credit another asset account.
  • B. Debit an expense account and credit the asset account.
  • C. Debit revenue and credit the asset account.
  • D. Debit the asset account and credit an income statement liability.

Correct Answer: BRationale: Perpetrators typically conceal asset thefts (like inventory) by writing them off directly to operating expenses. This debits the expense account (increasing expenses) and credits the asset account (reducing the recorded balance to match the stolen reality).

Case 3: Auditor Due Professional Care and Scope Limitations

 

Scenario:An internal auditor finishes an engagement covering cash operations and disbursements. Two months later, management uncovers a sophisticated skimming scheme perpetrated through collusion between the cashier and the assistant controller. The working papers prove that the auditor tested a statistically valid sample of material transactions, none of which included the fraudulent items because they were concealed beneath testing materiality thresholds.


Question:

How does this discovery impact the evaluation of the internal auditor's performance?

  • A. The internal auditors failed to exercise due professional care because fraud occurred during the active review period.
  • B. The internal auditor acted with due professional care by testing an appropriate statistical sample of material transactions.
  • C. The internal audit department is legally responsible for guaranteeing 100% detection in high-risk cash cycles.
  • D. Internal audit standards completely exempt staff from considering fraud risk in operational environments.

Correct Answer: BRationale: Internal auditors are not expected to detect every single instance of sophisticated collusive fraud if they apply due professional care, design appropriate statistical samples, and execute standard testing. Absolute assurance is unattainable.

 

Here are more case-based practice questions for the CIA Part 1 exam, focusing on preventive vs. detective controls and behavioral red flags of fraud.

Case 4: Preventive vs. Detective Controls in E-Commerce

Scenario:
An international retailer experiences an incident where an IT systems administrator uses elevated database privileges to modify customer shipping addresses on high-value orders right before shipment. This allowed the administrator to redirect goods to an off-site locker. The fraud was uncovered three weeks later when customers complained about missing orders, prompting a forensic review of system access logs.

Question:

Which of the following modifications represents the most effective preventive control to mitigate this specific risk in the future?

  • A. Implementation of an automated script that emails a weekly summary of all address changes to the internal audit team.
  • B. Enforcement of dual-authorization or "four-eyes" approval within the system before any administrative change to an active order's shipping address takes effect.
  • C. A daily reconciliation report comparing customer-entered addresses against the final carrier shipping manifests.
  • D. Periodic mandatory rotation of IT administrators' assigned accounts and system responsibilities.

Correct Answer: B
Rationale: A preventive control stops fraud before it occurs. Requiring a second authorized user to approve the change actively blocks a single rogue administrator from completing the fraudulent alteration alone. Options A and C are detective controls because they identify the anomaly after the fact. Option D is an administrative control that might disrupt ongoing fraud but does not strictly prevent a specific transaction.

Case 5: Behavioral Red Flags and the Fraud Triangle

Scenario:
During an audit of the accounts payable function, an internal auditor reviews employee performance data and files. The auditor notes that the department manager has refused to take a vacation for four consecutive years, insists on personally picking up and opening all mail from a specific geographic region, and frequently overrides system alerts regarding duplicate invoice numbers, claiming "system glitches."

Question:

According to the Fraud Triangle, which element is most strongly indicated by the manager's refusal to take vacations and isolation of incoming mail?

  • A. Rationalization
  • B. Pressure
  • C. Capability
  • D. Opportunity (Concealment)

Correct Answer: D
Rationale: Refusing to take vacation and strictly controlling work inputs (like mail) are classic behavioral red flags of an employee trying to maintain the opportunity to conceal an active fraud scheme. If they take time off, a replacement worker would likely uncover the irregularities.

Case 6: Assessing Management Pressure and Financial Statement Fraud

Scenario:
A manufacturing company's executive bonuses are heavily tied to meeting a strict 15% year-over-year revenue growth target. During the fourth quarter, market demand drops sharply. Internal audit reviews late-quarter transactions and discovers that management pressured the shipping department to record "bill-and-hold" transactions for goods that have not yet been manufactured or legally transferred to customers.

Question:

In analyzing fraud risk factors, the pressure placed on the shipping department to record unearned revenue is a direct manifestation of which dynamic?

  • A. A breakdown in detective transactional controls within logistics.
  • B. An incentive/pressure risk factor originating from corporate compensation structures.
  • C. A lack of technical capability within the internal accounting team.
  • D. A rationalization that the market downturn is temporary.

Correct Answer: B
Rationale: The scenario explicitly links management's fraudulent behavior to executive bonus structures tied to aggressive targets. This represents the Incentive/Pressure component of the Fraud Triangle, which often drives management override of controls.

www.gmsisuccess.in



 

 

Casebased MCQ questions on Accounting Information System,types of department in manufacturing business and its risk owner with their duties, documents and deliverables during revenue cycle payroll cycle & procurement cycle, internal control & AIS, internal control & control application etc from CIA Part 1 & from US CMA part 1 exam new syllabus



Casebased MCQ questions on Accounting Information System,types of department in manufacturing business and its risk owner with their duties, documents and deliverables during revenue cycle payroll cycle & procurement cycle, internal control & AIS, internal control & control application etc from CIA Part 1 & from US CMA part 1 exam new syllabus

 This is the MOST CONFUSING topic for CMA & CIA - But 6-8 Questions are 100% from here in both exams. Here is *Complete Case-Based Pack for AIS Cycles* as per CIA Part 1 + CMA Part 1 New Syllabus.


PART A: MANUFACTURING BUSINESS - DEPARTMENT, RISK OWNER, DUTIES

Department Risk Owner Main Duties Key Risk if fails

**Sales & Marketing** Sales Manager Takes customer order, credit check request, pricing Fictitious sales, wrong price

**Credit Dept** Credit Manager Approves credit limit - INDEPENDENT from Sales Bad debts, sales to bad customer

**Warehouse / Inventory** Warehouse Manager Stores, picks, packs, updates inventory records Theft, stock-out, obsolescence

**Shipping / Logistics** Shipping Manager Ships goods, prepares Bill of Lading Shipment error, revenue before shipment

**Production** Production Manager Manufacturing, Quality control, BOM Wastage, quality failure

**HR Department** HR Manager Hiring, termination, salary rate approval Ghost employees, wrong pay rate

**Timekeeping** Timekeeping Supervisor Records time worked - Independent from Payroll Buddy punching, inflated hours

**Payroll Dept** Payroll Manager Calculates payroll, deductions, prepares payroll register Miscalculation, unauthorized payments

**Purchasing** Purchasing Manager Issues PO, selects vendor, price negotiation Kickbacks, overpricing, fictitious vendors

**Receiving** Receiving Manager Counts, inspects goods, prepares Receiving Report - Independent from Purchasing Accepting damaged goods, collusion

**Accounts Payable** AP Manager 3-way match, processes payment Duplicate payment, paying for not received

**Accounts Receivable / Billing** AR Manager Invoicing, collections, AR ledger Lapping, misstatement of revenue

> *Golden Rule for EXAM: Authorization + Custody + Recording must be SEPARATE. That's SOD - Segregation of Duties.*


---


PART B: 35 CASE-BASED MCQs - CYCLES + DOCUMENTS + CONTROLS


*CYCLE 1: REVENUE CYCLE - O2C - Order to Cash*


*Documents Chain - MUST REMEMBER:* Customer PO -> Sales Order -> Credit Approval -> Pick List -> Shipping Doc/Bill of Lading -> Sales Invoice -> AR Ledger -> Cash Receipt


*Q1. Case:* Salesman takes order, approves credit of his friend, and also edits AR ledger to hide bad debt. Which control fails?

A) Input control

B) Segregation of Duties - Credit approval must be independent from Sales - P10 Control Activities - Risk Owner: Credit Manager, not Sales

C) Output control

D) No failure


*Ans: B - Classic. Sales should NEVER approve credit. Risk Owner violation = Credit Manager.*


*Q2. Case:* Warehouse ships goods without approved Sales Order. Shipping clerk uses verbal instruction. Deliverable at risk?

A) No risk

B) Unauthorized shipment - Missing document: Approved Sales Order - Control: All shipments must match approved SO + Pick list

C) Payroll risk

D) Production risk


*Ans: B - Deliverable missing = Approved SO. AIS control = Sequence check + Authorization.*


*Q3. Case:* Goods shipped on Dec 31, but invoice created on Jan 2 next year. Revenue recognized in Jan.

A) Correct - Invoice date matters

B) Wrong - Violation of Cut-off - Revenue must be recognized when shipment occurs - Document: Bill of Lading date is evidence of transfer of title - Risk Owner: AR/Billing Manager + Shipping

C) No control

D) Payroll cut-off


*Ans: B - Cut-off error - Biggest revenue cycle risk. Exam asks: Which document proves cut-off? Bill of Lading / Shipping Doc.*


*Q4. Case:* System allows invoice creation without matching shipping document.

A) Preventive control failure - Application Control - Must have automated 2-way match: Shipping doc vs Sales Order before invoicing - P11 General Controls

B) Detective control

C) No failure

D) Payroll control


*Ans: A - Input/Processing control failure. Revenue should not be recorded without proof of shipment.*


*Q5. Case:* Customer pays $10,000. Cashier pockets money and writes off as bad debt. Which control missing?

A) Segregation - Cash handling and AR write-off authorization must be separate - Cashier should not have access to AR ledger - Lapping risk - Risk Owners: Cashier vs AR Manager vs Credit Manager for write-off approval

B) Input control

C) No control

D) Payroll control


*Ans: A - Lapping fraud. Duties: Cash receipt -> Treasurer, AR ledger -> AR Dept, Write-off -> Credit Manager + Management approval > limit.*


*Q6. AIS Control Case:* Customer master file - Salesperson creates new customer "ABC Ltd" which is his own shell company. No approval workflow.

A) Failure of Master File Change Control - Application Control - New customer must be approved by Credit Manager independent - Document: Customer Master Change Request

B) Correct process

C) Input control only

D) No risk


*Ans: A - Master file control = P10 + P11. Fictitious customer = Revenue fraud.*


*CYCLE 2: PROCUREMENT CYCLE - P2P - Procure to Pay - HIGHEST FRAUD RISK*


*Documents Chain:* Purchase Requisition -> Purchase Order PO -> Vendor Selection -> Receiving Report / GRN -> Inspection Report -> Vendor Invoice -> 3-Way Match -> AP Ledger -> Payment Voucher -> Check / EFT


*Q7. Case:* Production dept needs raw material. Production supervisor directly calls vendor, receives goods, and asks AP to pay without PO.

A) Correct - Production needs material urgently

B) Control failure - No Purchase Requisition, No PO, No receiving segregation - Duties: Requester cannot be buyer. Must have approved PR -> PO by Purchasing Manager - Risk Owner: Purchasing Manager

C) No failure

D) Payroll issue


*Ans: B - Without PO, you cannot do 3-way match. Biggest control failure in exam.*


*Q8. Case:* Same person in Purchasing creates vendor, issues PO to that vendor, and also is Receiving manager who confirms receipt.

A) No issue if trusted

B) Major SOD failure - Vendor creation must be independent from Purchasing + Receiving must be independent from Purchasing - Fictitious vendor fraud possible - Risk Owner: Vendor master = AP/Finance independent, Purchasing = Purchasing Manager, Receiving = Receiving Manager

C) Only payroll risk

D) Detective control enough


*Ans: B - 3 roles cannot be same person. This is 100% exam case.*


*Q9. Case:* AP clerk pays invoice of $15,000 without checking Receiving Report. Later found goods never received.

A) Failure of 3-Way Match Control - Preventive Application Control - Must match PO + Receiving Report + Vendor Invoice - All 3 must agree in qty, price - Risk Owner: AP Manager owns 3-way match deliverable

B) No failure

C) Revenue control

D) Payroll control


*Ans: A - 3-way match is the KEY deliverable in procurement. Without it, pay for goods not received.*


*Q10. Case:* PO price is $10 per unit, but Vendor Invoice is $12 per unit, but AP pays $12 because vendor is relative of AP clerk.

A) Failure of Price check - Processing control - System should flag price variance - Also conflict of interest - P1 Control Environment Ethics + P10 Control Activity

B) Correct

C) No control

D) Timekeeping control


*Ans: A - Price variance check + Vendor master conflict.*


*Q11. Case:* Receiving clerk receives 100 units but records 120 units to help vendor get more payment, and shares kickback.

A) Collusion + Need for independent inspection + Count - Control: Blind receiving - Receiving clerk should not know ordered qty - Document: Blind copy of PO - Risk Owner: Receiving Manager

B) No control can prevent

C) Correct

D) Only detective


*Ans: A - Blind receiving is BEST practice to prevent this. Also job rotation, surprise counts.*


*Q12. Case:* Which document is evidence that liability should be recorded?

A) PO

B) Receiving Report / GRN - Once goods received and inspected, liability incurred - GRN triggers accrual

C) Purchase Requisition

D) Payment voucher


*Ans: B - GRN = Trigger for liability, not PO. Exam trick.*


*Q13. Case:* Vendor master file - Who should own / approve new vendor creation?

A) Purchasing

B) Independent from Purchasing - Finance / AP or Vendor Master team after due diligence - To prevent fictitious vendor

C) Receiving

D) Sales


*Ans: B*


*CYCLE 3: PAYROLL CYCLE - H2P - Hire to Pay*


*Documents Chain:* Hiring Authorization -> HR Master -> Time Card / Time Sheet -> Approved Time -> Payroll Rate Authorization -> Payroll Register -> Deduction Authorization -> Paycheck / Direct Deposit -> Payroll Tax Filing


*Q14. Case:* HR manager hires ghost employee "Ramesh Kumar", approves timecard, and also is payroll clerk who issues paycheck to his own account.

A) Major SOD failure - Hiring + Timekeeping + Payroll + Distribution must be separate - Duties: HR = Hiring, Timekeeping = Independent attendance, Payroll = Calculation, Treasurer = Distribution - Risk Owner: HR Manager, Timekeeping Supervisor, Payroll Manager

B) No failure if manager is senior

C) Only revenue risk

D) Correct process


*Ans: A - Ghost employee fraud - #1 payroll fraud - Control: Master file change independent, surprise distribution.*


*Q15. Case:* Factory supervisor approves timecards of his team, inflates hours to earn overtime for friends.

A) SOD failure - Supervisor should not approve his own team's time without independent timekeeping check - Use biometric / Badge system + Timekeeping dept independent - Deliverable: Approved time sheet by Timekeeping, not just supervisor

B) Correct

C) No risk

D) Procurement control


*Ans: A - Buddy punching risk.*


*Q16. Case:* Payroll clerk changes pay rate from $20/hr to $30/hr without authorization, increases his own salary.

A) Failure of Pay Rate Authorization Control - Pay rate changes must be approved by HR Manager, not Payroll - HR owns HR Master deliverable - System should have access control - P11 IT Controls

B) No failure

C) Revenue control

D) Receiving control


*Ans: A - HR Master change = P11 + P10.*


*Q17. Case:* Which is BEST control against ghost employees?

A) Reconciliation of payroll register to HR master by independent person + Surprise payroll distribution + Biometric attendance + Mandatory vacation

B) Only timecard

C) Only PO

D) No control needed


*Ans: A - All together.*


*Q18. Case:* Timecards are paper-based, no approval, payroll processes whatever is submitted.

A) Failure of Input Validation + Authorization - Need automated time system + Supervisor approval + Timekeeping approval

B) Correct

C) No risk

D) Procurement risk


*Ans: A*


*Q19. Case:* Payroll taxes not deposited on time, penalty incurred. Whose duty?

A) Sales Manager

B) Payroll Manager owns compliance deliverable: Payroll Tax Filing + Deposit - Requires calendar control + Review by Finance Manager

C) Receiving

D) Purchasing


*Ans: B*


*Q20. Case:* Overtime not authorized in advance, but payroll pays it because timecard shows overtime.

A) Preventive control failure - Overtime must be pre-approved by Production Manager + HR - Document: Overtime Authorization Form

B) Correct

C) No control

D) 3-way match


*Ans: A*


*CYCLE 4: AIS + INTERNAL CONTROL + CONTROL APPLICATION - COMMON FOR BOTH EXAMS*


*Q21. Case:* Which is Application Control vs General IT Control?

A) Input validation, sequence check, limit check, check digit = Application Control; Access to program, change management, backup = General IT Control - GITC affects all applications

B) Same

C) Application is general

D) None


*Ans: A - CMA loves this distinction. If GITC fails, Application controls cannot be relied upon.*


*Q22. Case:* Check digit on customer account number - What control type?

A) Preventive Application - Input Control - Detects transposition errors

B) General control

C) Detective

D) Corrective


*Ans: A*


*Q23. Case:* Exception report of all payroll changes >10% - Reviewed by HR Manager weekly.

A) Detective Application Control + Monitoring - P16 - Review of exception report is monitoring

B) Preventive

C) No control

D) General control


*Ans: A*


*Q24. Case:* System allows user to enter sales order date as Feb 30.

A) Failure of Format check / Validity check - Application Input Control - P10

B) Correct

C) General control

D) Monitoring


*Ans: A*


*Q25. Case:* Database administrator can directly edit payroll table in production to fix error.

A) Severe P11 violation - Direct data file change should NEVER be allowed - Must go through application with audit trail - Risk Owner: IT Manager / DBA

B) Allowed for efficiency

C) Application control

D) No risk


*Ans: A - Direct DB edit destroys audit trail.*


*Q26. Case:* During revenue cycle, which risk owner approves credit memo for returned goods?

A) Salesperson

B) Credit Manager + Receiving confirms goods returned + Inspection - Document: Credit Memo + Receiving Report for returns

C) Warehouse

D) Payroll clerk


*Ans: B - Returns need same controls as shipment reverse.*


*Q27. Case:* Batch total of hours entered is 500 hrs, but system calculated payroll for 550 hrs. What control detects?

A) Batch total / Hash total / Record count - Input control that sums to ensure completeness

B) No control

C) General control

D) Monitoring


*Ans: A - Batch total mismatch = Some records added/altered.*


*Q28. Case:* All 3 cycles: Who is ultimate owner of internal control?

A) Internal Auditor

B) Management - CEO owns, Board oversees, Internal Audit evaluates - As per COSO and IIA

C) External auditor

D) AP clerk


*Ans: B - Management owns controls, not auditors.*


*Q29. Case:* In ERP, user has access to both create PO and approve payment - System shows SOD conflict but IT says "we have small team, can't segregate"

A) Must have compensating control - e.g., independent manager review of all transactions by that user + exception report review - P10 + P12 - Cannot just ignore - Must document compensating control

B) Acceptable to ignore

C) No control needed

D) Payroll control


*Ans: A - Small company SOD issue = Need compensating detective control. Exam asks compensating control.*


*Q30. Case:* Which cycle has highest inherent fraud risk per ACFE?

A) Revenue

B) Procurement/Purchasing - Corruption, kickbacks, fictitious vendors - Most common in manufacturing

C) Payroll

D) None


*Ans: B - Procurement/P2P has highest corruption risk.*


*... And 5 more super exam-oriented cases:*


*Q31.* Document that triggers AP liability? *Ans: Receiving Report / GRN.*


*Q32.* Document that triggers revenue recognition? *Ans: Bill of Lading / Shipping Document, not Invoice.*


*Q33.* Risk owner for Vendor Master? *Ans: Finance / AP Manager independent of Purchasing.*


*Q34.* Payroll cycle - Best preventive for inflated hours? *Ans: Independent Timekeeping + Biometric + Pre-approved overtime.*


*Q35.* AIS - Which control ensures completeness of revenue? *Ans: Sequence check on pre-numbered shipping docs and invoices + Reconcile shipping log to invoice log daily - Deliverable: Daily Sales-Shipment Reconciliation by AR Manager.*



Case-based multiple-choice questions (MCQs) for the Certified Internal Auditor (CIA) Part 1 exam test your ability to apply fraud risk concepts—such as the fraud triangle, control deficiencies, and red flags—to real-world audit scenarios.

 


Case-based multiple-choice questions (MCQs) for the Certified Internal Auditor (CIA) Part 1 exam test your ability to apply fraud risk concepts—such as the fraud triangle, control deficiencies, and red flags—to real-world audit scenarios.


 Section A.....

Case 1: The Procurement Vulnerability

 

Scenario:During a routine procurement engagement, an internal auditor discovers that a single junior buyer has the authority to create new vendors in the vendor master file, issue purchase orders, and approve corresponding vendor invoices below a threshold of $10,000. Reviewing transactions under this threshold reveals multiple payments made to a newly created consulting firm with an address matching the junior buyer's residential address. No other supervisory reviews or independent matching procedures exist for invoices under the $10,000 limit.


Question 1:

Which element of the Fraud Triangle is most directly highlighted and enabled by the structural design of this procurement process?

  • A. Pressure, because the buyer is living beyond their means due to personal debt.
  • B. Opportunity, because weak segregation of duties allows one person to originate, execute, and conceal transactions.
  • C. Rationalization, because the buyer feels underpaid compared to industry peers.
  • D. Incentive, because management set aggressive cost-reduction targets for the department.

Correct Answer:

Case 2: The Overworked Controller

 

Scenario:An internal audit team is assessing the overall control environment and fraud risk governance of a mid-sized manufacturing division. Interviews and observations reveal that the division’s controller works late evenings and weekends, refuses to delegate core accounting tasks, and has not taken consecutive annual vacations or time off in over two years. Furthermore, the controller handles monthly bank reconciliations while simultaneously holding journal entry posting access.


Question 2:

Which combination of behavioral red flags and control risks is most evident in this scenario?

  • A. Management override of controls and aggressive revenue recognition.
  • B. Refusal to take vacation combined with inadequate segregation of duties over cash.
  • C. Document falsification and dual-custody breakdown.
  • D. Lapping of accounts receivable and lifestyle changes.

Correct Answer:

 

Case 3: Auditor's Responsibility upon Suspicion

Scenario:While testing inventory receipts in a warehouse, an internal auditor notices that several receiving reports show quantities significantly lower than the packing slips, yet the full vendor invoices were paid in full. The warehouse supervisor casually mentions that the missing inventory represents "defective scrap written off," but there are no formal write-off documents, approval signatures, or credit memos from the vendor.


Question 3:

According to IIA guidance and professional standards, what is the internal auditor's most appropriate immediate course of action?

  • A. Immediately confront the warehouse supervisor with accusations of asset misappropriation.
  • B. Expand the sample size, gather sufficient preliminary evidence, and inform management or the appropriate authorities as defined by the organization's fraud program.
  • C. Disregard the discrepancy because the individual dollar amounts of missing inventory appear immaterial to the financial statements as a whole.
  • D. Immediately halt the entire internal audit engagement and launch a full-scale forensic criminal investigation.

Correct Answer: 

Section B...

CIA Part 1: Fraud Risk Management Case Quiz

1 / 5

1.

Sarah is the accounting manager at a mid-sized manufacturing firm. The company is publicly traded, and executive management's bonuses are tied strictly to achieving aggressive quarterly net income targets. Sarah is personally facing foreclosure on her home and massive medical debt. Under intense pressure from the CFO to "find a way" to make the numbers work, Sarah capitalizes routine operating expenses as capital assets to artificially inflate net income. Which element of the fraud triangle does Sarah’s personal debt and the CFO’s bonus structure primarily represent?

A.

Rationalization

B.

Opportunity

C.

Pressure/Incentive

D.

Collusion

Answer

2.

David has worked as the sole accounts payable clerk at a wholesale distributor for 15 years. He is universally trusted by management, never takes consecutive days off, and processes all vendor invoices, inputs banking details, and performs monthly bank reconciliations without review or secondary authorization. An internal auditor discovers multiple payments made to a shell company owned by David. Which condition of the fraud triangle enabled David to execute this scheme?

A.

Ineffective internal controls creating an Opportunity

B.

An overwhelming Financial Pressure due to personal debts

C.

A robust Rationalization that the company owes him for years of low pay

D.

External market incentives forcing the behavior

Answer

3.

During an operational audit of the procurement department, the internal auditor notices that the senior buyer of IT equipment drives a luxury sports car far exceeding his salary level, refuses to take annual vacations, and consistently awards contracts to a vendor whose primary contact shares the same last name and home address as the buyer. How should the internal auditor classify these observations?

A.

Normal operational efficiencies and personal wealth accumulation

B.

Behavioral and operational red flags indicating potential conflict of interest and fraud

C.

Evidence of effective segregation of duties within procurement

D.

Compliance indicators that vendor selection is objective

Answer

4.

An internal auditor is conducting a routine review of general ledger journal entries. She identifies several large, non-standard manual journal entries posted on New Year’s Eve with descriptions like "miscellaneous accrual" that lack supporting documentation or required supervisory sign-offs. According to IIA standards, what is the internal auditor's immediate responsibility?

A.

Ignore the entries since they are standard year-end closing adjustments

B.

Automatically assume management is committing fraud and immediately notify local law enforcement

C.

Delete the entries to protect the integrity of the financial records

D.

Exercise professional skepticism, investigate the business rationale of these entries, and report the control deficiency

Answer 


5.

The Chief Executive Officer (CEO) of a retail company routinely bypasses dual-authorization controls for wire transfers exceeding $100,000, instructing the treasurer to execute payments directly. When questioned by the internal audit activity, the CEO dismisses the concern, stating, "I founded this company; the rules are meant for junior employees, and I need to move fast to seize market opportunities." This attitude exemplifies which element of the fraud triangle and organizational risk?

A.

Rationalization and tone-at-the-top risk leading to management override

B.

Financial pressure caused by declining retail sales

C.

Lack of technological opportunity to perform authorized sign-offs

D.

Standard operational delegation of authority

Answer

Section C...

Case-based multiple-choice questions (MCQs) for CIA Part 1 (Essentials of Internal Auditing) focus on the application of the Fraud Triangle, control evaluations, indicators (red flags), and auditor responsibilities regarding fraud.

 

Case 1: Procurement and Segregation of Duties

 

Scenario:During a routine operational audit of the procurement department, an internal auditor observes that a single senior buyer has the authority to create new vendor profiles in the enterprise system, issue purchase orders up to $50,000, and approve the resulting vendor invoices for payment matching the receiving slips. Management notes this flexibility is required to maintain operational efficiency during peak manufacturing cycles.


Question:

Which of the following actions exposes the organization to the highest fraud risk under this operating condition?

  • A. Purchase orders are issued sequentially and matched to receiving reports.
  • B. The procurement policy manual was last updated twenty-four months ago.
  • C. A single individual maintains the vendor master file and approves payment invoices below the review threshold.
  • D. Vendor payment terms are renegotiated annually following a competitive bidding round.

Correct Answer: 

Case 2: Concealment and Journal Entry Red Flags

 

Scenario:An internal audit team is examining inventory management controls at a regional distribution center. The warehouse manager recently purchased a luxury sports car and took no annual leave over a three-year period. The financial statement review reveals an unusual pattern: inventory counts match physical stock, but several non-routine manual journal entries were posted at the end of each quarter, debiting operating expense accounts and crediting inventory values to absorb unexplained shrinkage.


Question:

To conceal the ongoing theft of physical inventory assets, which type of accounting entry did the perpetrator most likely execute through these manual overrides?

  • A. Debit an asset account and credit another asset account.
  • B. Debit an expense account and credit the asset account.
  • C. Debit revenue and credit the asset account.
  • D. Debit the asset account and credit an income statement liability.

Correct Answer: 

Case 3: Auditor Due Professional Care and Scope Limitations

 

Scenario:An internal auditor finishes an engagement covering cash operations and disbursements. Two months later, management uncovers a sophisticated skimming scheme perpetrated through collusion between the cashier and the assistant controller. The working papers prove that the auditor tested a statistically valid sample of material transactions, none of which included the fraudulent items because they were concealed beneath testing materiality thresholds.


Question:

How does this discovery impact the evaluation of the internal auditor's performance?

  • A. The internal auditors failed to exercise due professional care because fraud occurred during the active review period.
  • B. The internal auditor acted with due professional care by testing an appropriate statistical sample of material transactions.
  • C. The internal audit department is legally responsible for guaranteeing 100% detection in high-risk cash cycles.
  • D. Internal audit standards completely exempt staff from considering fraud risk in operational environments.

Correct Answer: 


Here are more case-based practice questions for the CIA Part 1 exam, focusing on preventive vs. detective controls and behavioral red flags of fraud.

Case 4: Preventive vs. Detective Controls in E-Commerce

Scenario:
An international retailer experiences an incident where an IT systems administrator uses elevated database privileges to modify customer shipping addresses on high-value orders right before shipment. This allowed the administrator to redirect goods to an off-site locker. The fraud was uncovered three weeks later when customers complained about missing orders, prompting a forensic review of system access logs.

Question:

Which of the following modifications represents the most effective preventive control to mitigate this specific risk in the future?

  • A. Implementation of an automated script that emails a weekly summary of all address changes to the internal audit team.
  • B. Enforcement of dual-authorization or "four-eyes" approval within the system before any administrative change to an active order's shipping address takes effect.
  • C. A daily reconciliation report comparing customer-entered addresses against the final carrier shipping manifests.
  • D. Periodic mandatory rotation of IT administrators' assigned accounts and system responsibilities.

Correct Answer: 

Case 5: Behavioral Red Flags and the Fraud Triangle

Scenario:
During an audit of the accounts payable function, an internal auditor reviews employee performance data and files. The auditor notes that the department manager has refused to take a vacation for four consecutive years, insists on personally picking up and opening all mail from a specific geographic region, and frequently overrides system alerts regarding duplicate invoice numbers, claiming "system glitches."

Question:

According to the Fraud Triangle, which element is most strongly indicated by the manager's refusal to take vacations and isolation of incoming mail?

  • A. Rationalization
  • B. Pressure
  • C. Capability
  • D. Opportunity (Concealment)

Correct Answer: 


Case 6: Assessing Management Pressure and Financial Statement Fraud

Scenario:
A manufacturing company's executive bonuses are heavily tied to meeting a strict 15% year-over-year revenue growth target. During the fourth quarter, market demand drops sharply. Internal audit reviews late-quarter transactions and discovers that management pressured the shipping department to record "bill-and-hold" transactions for goods that have not yet been manufactured or legally transferred to customers.

Question:

In analyzing fraud risk factors, the pressure placed on the shipping department to record unearned revenue is a direct manifestation of which dynamic?

  • A. A breakdown in detective transactional controls within logistics.
  • B. An incentive/pressure risk factor originating from corporate compensation structures.
  • C. A lack of technical capability within the internal accounting team.
  • D. A rationalization that the market downturn is temporary.

Correct Answer: 

www.gmsisuccess.in