Sunday, September 27, 2026

Internal Control, COSO, COBIT, Governance, Risk Assessment, AIS, FCPA, and SOX — Comprehensive Exam Notes (CIA Part 1 & US CMA Part 1), Casebased Questions with answers:



mocktest sept27 sunday internal control governence risk assessment etc



Internal Control, COSO, COBIT, Governance, Risk Assessment, AIS, FCPA, and SOX — Comprehensive Exam Notes (CIA Part 1 & US CMA Part 1), Casebased Questions with answers:

 

1. The Internal Control System — Core Concepts

 

Definition (COSO): Internal control is a process, effected by an entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in three categories:

· Reliability of financial reporting

· Effectiveness and efficiency of operations

· Compliance with applicable laws and regulations

Reasonable assurance means a high level of confidence that financial statements or reports are free from material misstatements, while absolute assurance (Infalliability)means 100% certainty and zero risk of error.

Key limitation: Internal controls provide reasonable assurance, not absolute assurance. Limitations include human error, faulty judgment, collusion, management override, and cost-benefit constraints.

Internal controls provide reasonable rather than absolute assurance because they are subject to unavoidable inherent limitations rooted in human behavior, authority, and changing environments.

Human Error

  • Human Error occurs because people are prone to fatigue, carelessness, distraction, or misinterpretation of instructions.
  • Example: An accounting clerk accidentally enters an invoice amount as $120,000 instead of $1,200,000, and a tired reviewer fails to catch the typo during a routine check.

Collusion

  • Collusion happens when two or more individuals secretly cooperate to bypass controls, defeating systems like segregation of duties.
  • Example: A purchasing manager and an accounts payable clerk work together to approve fake vendor invoices and split the fraudulent payouts, bypassing the independent check between purchasing and payment.  

Management Override

  • Management Override arises when executives or individuals in positions of high authority use their power to bypass established policies.
  • Example: A CEO orders the finance department to bypass standard purchase order approvals to fast-track an unauthorized high-value contract for a personal friend's company.

Compromised Judgment

  • Compromised Judgment involves poor decision-making or flawed estimates made under pressure or with incomplete information.
  • Example: Management sets aggressive, unrealistic quarterly sales targets, pushing regional staff to log fake sales transactions or cut corners on credit checks just to meet goals.

Obsolescence and Changing Conditions

  • Obsolescence occurs when controls fail to adapt to shifts in business size, technology, regulations, or operations.
  • Example: An outdated manual approval workflow for software updates remains in place, leaving the company blind to newer automated cyber threats or cloud-infrastructure vulnerabilities.

 

Three objectives (the "control triad"): Operations, Reporting, Compliance.

The control triad consists of Operations, Reporting, and Compliance, which form the core objectives of internal control frameworks like COSO.

The Control Triad Components

  • Operations
    • Focuses on the effective and efficient use of an organization's resources.
    • Aims to achieve basic business objectives, safeguard assets, and improve performance.
    • Relates to day-to-day business execution and operational resilience.
  • Reporting
    • Focuses on the reliability, timeliness, and transparency of internal and external financial and non-financial reporting.
    • Ensures stakeholders receive accurate data for informed decision-making.
    • Includes regulatory filings and disclosures regarding serious disruptions or metrics.  
  • Compliance
    • Focuses on adherence to applicable laws, regulations, and internal policies.
    • Converts external legal and regulatory obligations into expected organizational behavior.
    • Ensures the business operates within statutory boundaries and ethical guidelines.

 

Types of controls by timing:

· Preventive — stop problems before they occur (e.g., segregation of duties, passwords, authorization).

· Detective — identify problems after they occur (e.g., reconciliations, variance analysis, physical counts).

· Corrective — fix problems once detected (e.g., error correction, backup restoration).

· Directive — guide behavior toward desired outcomes (e.g., policies, training).

 

Control classifications (CIA Part 1 emphasis): Preventive, detective, corrective, directive, input, processing, output, feedforward, feedback, key controls, compensating controls.

 

Compensating control: A secondary control that mitigates risk when a primary control cannot operate as designed or is absent. Example: daily supervisory review of deposit slips when cash receipts and recordkeeping cannot be segregated in a small department.

 

2. COSO Internal Control — Integrated Framework (2013)

The COSO Internal Control – Integrated Framework (2013) is the dominant framework for designing and evaluating internal control. It consists of five interrelated components and 17 principles.

2.1 Five Components

Control Environment The "tone at the top" — integrity, ethical values, organizational structure, competence, accountability

Risk Assessment Identifying and analyzing risks to objectives; determining how risks should be managed

Control Activities Policies and procedures that help ensure management directives are carried out

Information & Communication Relevant information identified, captured, and communicated in a timely manner

Monitoring Ongoing and separate evaluations to assess control effectiveness

 

The Control Environment is the foundation — all other components build upon it. Major corporate scandals (e.g., Enron) often stem from a toxic control environment rather than a lack of policies.

 

2.2 The 17 Principles (by Component)

Control Environment (Principles 1–5)

1. Demonstrates commitment to integrity and ethical values

2. Board of directors demonstrates independence and exercises oversight

3. Establishes structure, authority, and responsibility

4. Demonstrates commitment to competence

5. Enforces accountability

 

Risk Assessment (Principles 6–9)

6. Specifies suitable objectives with sufficient clarity

7. Identifies and analyzes risks to achieving objectives

8. Assesses fraud risk

9. Identifies and analyzes significant change

 

Control Activities (Principles 10–12)

10. Selects and develops control activities

11. Selects and develops general controls over technology

12. Deploys control activities through policies and procedures

 

Information & Communication (Principles 13–15)

13. Obtains or generates relevant information

14. Communicates internally

15. Communicates externally

 

Monitoring Activities (Principles 16–17)

16. Conducts ongoing and/or separate evaluations

17. Evaluates and communicates deficiencies

 

Exam tip: The 2013 Framework introduced the codification of 17 principles and 51 points of focus.

 

2.3 COSO ERM (2017) — For CMA Part 1

COSO Enterprise Risk Management — Integrating with Strategy and Performance (2017) has five components and 20 principles:

1. Governance and Culture (5 principles)

2. Strategy and Objective-Setting (4 principles)

3. Performance (5 principles)

4. Review and Revision (3 principles)

5. Information, Communication, and Reporting (3 principles)

 

ERM expands internal control beyond financial reporting to strategy and enterprise-wide risk.

 

3. COBIT — IT Governance Framework

COBIT (Control Objectives for Information and Related Technologies), developed by ISACA, is the leading framework for governance and management of enterprise IT (GEIT).

3.1 COBIT 2019 — Six Governance Principles

 

COBIT 2019 is built on six principles for a governance system (expanded from five in COBIT 5):

1. Provide Stakeholder Value — Enterprises exist to create value for stakeholders by balancing benefits, risk optimization, and resource use.

2. Holistic Approach — Governance built from a number of interacting components working together.

3. Dynamic Governance System — Governance must adapt to changing enterprise needs.

4. Governance Distinct from Management — Governance ensures goals are achieved by evaluating needs, setting direction, and monitoring; management plans, builds, runs, and monitors activities.

5. Tailored to Enterprise Needs — Frameworks must be customized to the enterprise's context.

6. End-to-End Governance System — Covers the entire enterprise, treating information and technology as assets.

 

3.2 COBIT 2019 — Seven Enablers

1. Principles, policies, and frameworks

2. Processes

3. Organizational structures

4. Culture, ethics, and behavior

5. Information

6. Services, IT infrastructure, and applications

7. People, skills, and competencies

 

3.3 COBIT Domains (40 Objectives)

· EDM — Evaluate, Direct, Monitor (Governance)

· APO — Align, Plan, Organize (Management)

· BAI — Build, Acquire, Implement

· DSS — Deliver, Service, Support

· MEA — Monitor, Evaluate, Assess

 

Exam relevance: COBIT's MEA02 process specifically addresses monitoring and evaluating the system of internal control. COBIT is used to translate regulatory obligations (SOX, ISO 27001, PCI DSS, DORA) into a single control architecture.

 

4. Governance — CIA Part 1 Context

 

4.1 Definition and Ownership

Governance is the combination of processes and structures the board uses to inform, direct, manage, and monitor the organization toward its objectives.

· Owned by: The board / governing body

· Internal audit's role: Evaluate and contribute to improving governance — not to own or operate it

 

4.2 The IIA Three Lines Model (2020)

Replaced the older "Three Lines of Defense":

Line Role

Governing Body Oversight and direction

First Line Management — owns and manages risk

Second Line Risk management and compliance functions

Third Line Internal audit — independent assurance

 

Hard rule: Management owns risk and control; the board oversees; internal audit assures.

 

4.3 Governance, Risk, and Control — Interlocking Processes

 

1. Governance sets direction and oversight

2. Risk management identifies what could derail objectives

3. Control provides assurance objectives are met

 

The board sets objectives, risk appetite, ethical tone, and oversight expectations. Management identifies risks and decides responses. Controls are the specific actions that bring risk down to acceptable levels.

 

5. Risk Assessment — CIA Part 1 & CMA Part 1

5.1 Risk Vocabulary

· Risk: The possibility that events will affect the achievement of objectives — positively or negatively.

· Inherent risk: Risk before any controls.

· Residual risk: Risk remaining after controls.

· Risk appetite: The amount of risk the organization is willing to accept.

· Risk tolerance: Acceptable variation around the risk appetite.

· Risk response: Avoid, reduce, share/transfer, accept.

 

5.2 Risk Assessment Process (COSO)

The Risk Assessment component of COSO (Principles 6–9) requires:

1. Specifying suitable objectives — objectives must be clear enough to identify risks.

2. Identifying and analyzing risks — assess likelihood and impact.

3. Assessing fraud risk — specifically consider fraud in risk assessment.

4. Identifying significant change — monitor changes that could affect internal control.

 

Risk assessment techniques: Risk mapping based on likelihood and impact, use of matrices, risk registers.

 

5.3 Internal Audit's Role in Risk Assessment

· Primary role: Provide objective evaluations of risk and contribute to the risk management process.

· CIA Part 1 weight: Internal Control & Risk is 25–35% of the exam.

· Internal audit evaluates adequacy and effectiveness of risk management — it does not perform the risk assessment for management (would impair objectivity).

 

6. Accounting Information Systems (AIS) Controls

6.1 General Controls (ITGCs)

IT General Controls apply to all systems in the IT environment:

· Logical access security — passwords, user access rights

· Change management — controlling modifications to systems

· Computer operations — job scheduling, backups, disaster recovery

· Segregation of incompatible duties in IT

· System development procedures

· Physical security — hardware, facilities

 

ITGCs are pervasive — they support the integrity of every application running in the environment.

 

6.2 Application Controls

Application controls are specific to a particular application and relate to individual transactions:

Category Purpose Examples

Input Controls Ensure accuracy and completeness of data entered Check digits, field validation, batch totals, edit checks

Processing Controls Ensure data is processed correctly Run-to-run totals, reasonableness checks, sequence checks

Output Controls Ensure outputs are accurate, complete, and delivered securely Distribution lists, reconciliation of output totals

Data File Controls Ensure integrity of stored data File maintenance controls, access restrictions

 

Check digit: An algorithmic validation embedded in an input field (e.g., customer or account number) that detects transposition and transcription errors at data entry — a classic input application control.

 

6.3 Relationship Between ITGCs and Application Controls

 

ITGCs provide the environment in which application controls operate. If ITGCs are weak, application controls may not function reliably. Auditors typically test ITGCs first, then application controls.

 

7. FCPA — Foreign Corrupt Practices Act (1977)

7.1 Two Sets of Provisions

The FCPA has two major provisions:

1. Anti-bribery provisions — prohibit corrupt payments to foreign officials.

2. Accounting provisions — require issuers to:

   · Make and keep books and records that accurately and fairly reflect transactions

   · Devise and maintain a system of internal accounting controls sufficient to provide reasonable assurance that:

     · Transactions are executed in accordance with management's authorization

     · Transactions are recorded to permit preparation of financial statements in conformity with GAAP

     · Access to assets is permitted only in accordance with management's authorization

     · Recorded accountability for assets is compared with existing assets at reasonable intervals

 

7.2 FCPA and Internal Controls

The FCPA was the first law to openly hold management accountable for maintaining adequate books, records, and internal accounting controls. It "made it clear that it is illegal for a public company to have an inadequate system of internal control".

 

Key point: A violation of the anti-bribery provision is not required to violate the internal control provision. The accounting provisions are independent.

 

7.3 FCPA vs. SOX — Critical Distinction

 

 FCPA SOX §404

Materiality threshold None — no financial threshold Material weakness threshold

Scope Internal accounting controls (broad) Internal control over financial reporting (ICFR)

Focus Accurate books, management control over assets Detection of material misstatement

 

A $75,000 payment may be immaterial for SOX purposes but still violate FCPA's internal control provision.

 

Compliance guidance: Organizations should review and test controls, and maintain a well-constructed compliance and ethics program to prevent, detect, remediate, and report misconduct.

 

 

8. Sarbanes-Oxley Act (SOX) 2002

8.1 Key Sections for Internal Control

Section 302 — Corporate Responsibility for Financial Reports

· CEO and CFO must personally certify the accuracy of financial statements in quarterly and annual reports

· Must certify they have evaluated the effectiveness of disclosure controls and procedures

· Must disclose all significant deficiencies in internal control

 

Section 404 — Management Assessment of Internal Controls

· Management must assess and report on the effectiveness of internal control over financial reporting (ICFR)

· External auditors must attest to management's assessment

· Section 404(a) requires an internal control report in the annual report

 

8.2 SOX and COSO

SOX §404 effectively mandates the use of a recognized internal control framework. COSO Internal Control – Integrated Framework (2013) is the most widely used framework for SOX compliance in the U.S..

 

8.3 SOX and FCPA Interplay

 

SOX and FCPA compliance are not equivalent:

· SOX compliance ≠ FCPA compliance

· SOX internal auditors focus on financial reporting controls; FCPA compliance requires forensic accounting skills and transaction testing of compliance-sensitive accounts (commissions, gifts, charitable contributions)

· SOX walkthroughs may not reveal anomalies when controls are compromised through collusion; FCPA transaction testing is more likely to detect such issues

 

9. Summary — Key Distinctions for Exam

Concept Key Point

COSO IC (2013) 5 components, 17 principles; reasonable assurance; foundation = Control Environment

COSO ERM (2017) 5 components, 20 principles; expands to strategy and enterprise risk

COBIT 2019 6 governance principles, 7 enablers, 40 objectives across 5 domains

Governance Board owns; sets direction, risk appetite, oversight

Risk management Management owns; identifies, assesses, responds to risks

Internal audit Assures; evaluates adequacy and effectiveness — does not own or operate

ITGCs Pervasive controls (access, change mgmt, operations)

Application controls Input, processing, output — specific to an application

FCPA No materiality threshold; books & records + internal accounting controls

SOX §302 CEO/CFO certification of financials and disclosure controls

SOX §404 Management assessment + auditor attestation of ICFR

 

10. Exam Weightings (for prioritization)

 

CIA Part 1:

 

· Section A (Foundations of Internal Auditing): 35%

· Section C (Governance, Risk Management, and Control): 30% — includes COSO, Three Lines Model, governance, risk, control concepts

· Internal Control & Risk specifically: 25–35%

 

CMA Part 1:

· Internal Controls: 15% — covers COSO IC and ERM frameworks, control activities, limitations, SOX §302/§404, FCPA, IT controls, SOC reports

 

CIA Part 1 & US CMA Part 1 – Internal Control, COSO, COBIT, Governance, Risk, AIS, FCPA, SOX

Internal Control Basics (1–10)

1. Which of the following is NOT one of the three categories of objectives in the COSO internal control framework?

A. Reliability of financial reporting

B. Effectiveness and efficiency of operations

C. Compliance with laws and regulations

D. Maximization of shareholder wealth

Answer: D

 

2. Internal control provides:

A. Absolute assurance

B. Reasonable assurance

C. No assurance

D. Guaranteed assurance

Answer: B

3. Which type of control is designed to detect errors after they occur?

A. Preventive

B. Detective

C. Corrective

D. Directive

Answer: B

4. Segregation of duties is an example of which type of control?

A. Preventive

B. Detective

C. Corrective

D. Directive

Answer: A

5. Which of the following is a limitation of internal control?

A. Human error

B. Collusion

C. Management override

D. All of the above

Answer: D

6. A compensating control is used when:

A. A primary control fails

B. A primary control cannot be implemented

C. Management wants to reduce costs

D. Both A and B

Answer: D

7. Which of the following is NOT a component of the COSO internal control framework?

A. Control environment

B. Risk assessment

C. Control activities

D. Financial reporting

Answer: D

 

8. The "tone at the top" is most closely associated with which COSO component?

A. Control environment

B. Risk assessment

C. Control activities

D. Monitoring

Answer: A

9. Which of the following is a corrective control?

A. Password protection

B. Bank reconciliation

C. Backup restoration

D. Training

Answer: C

10. The primary purpose of internal control is to:

A. Eliminate all risks

B. Ensure achievement of objectives

C. Guarantee profitability

D. Prevent fraud entirely

Answer: B

 

COSO Internal Control Framework (11–25)

11. How many principles are in the COSO 2013 internal control framework?

A. 5

B. 17

C. 20

D. 25

Answer: B

 

12. Which COSO component is considered the foundation of all other components?

A. Risk assessment

B. Control activities

C. Control environment

D. Monitoring

Answer: C

 

13. Which principle requires the organization to demonstrate a commitment to integrity and ethical values?

A. Principle 1

B. Principle 2

C. Principle 3

D. Principle 4

Answer: A

14. Assessing fraud risk is part of which COSO component?

A. Control environment

B. Risk assessment

C. Control activities

D. Monitoring

Answer: B

15. Which COSO component includes selecting and developing control activities?

A. Control environment

B. Risk assessment

C. Control activities

D. Information and communication

Answer: C

16. Which of the following is NOT a principle of the control environment?

A. Demonstrates commitment to integrity and ethical values

B. Board of directors demonstrates independence

C. Identifies and analyzes risks

D. Enforces accountability

Answer: C

 

17. The COSO framework requires organizations to identify and analyze significant changes. This is part of:

A. Risk assessment

B. Control activities

C. Monitoring

D. Information and communication

Answer: A

18. Which component ensures that information is identified, captured, and communicated timely?

A. Control environment

B. Risk assessment

C. Information and communication

D. Monitoring

Answer: C

19. Monitoring activities in COSO include:

A. Ongoing evaluations

B. Separate evaluations

C. Both A and B

D. Neither A nor B

Answer: C

20. Which of the following is a point of focus under the control environment?

A. Assigning authority and responsibility

B. Selecting and developing control activities

C. Communicating externally

D. Conducting separate evaluations

Answer: A

21. The COSO framework is used for:

A. Financial reporting only

B. Internal control over financial reporting

C. All aspects of internal control

D. IT governance only

Answer: C

 

22. Which of the following best describes the relationship between COSO components?

A. They are independent

B. They are interrelated

C. Only one is needed

D. They apply only to large companies

Answer: B

23. The COSO framework was originally published in:

A. 1985

B. 1992

C. 2002

D. 2013

Answer: B

24. The 2013 COSO framework update emphasized:

A. Increased focus on IT controls

B. Codification of principles

C. Both A and B

D. Only financial reporting

Answer: C

25. Which of the following is NOT one of the 17 principles?

A. Demonstrates commitment to competence

B. Identifies and analyzes risks

C. Conducts external audits

D. Evaluates and communicates deficiencies

Answer: C

COSO ERM (26–30)

26. How many components are in the COSO ERM 2017 framework?

A. 5

B. 8

C. 17

D. 20

Answer: A

 

27. Which component of COSO ERM focuses on governance and culture?

A. Governance and Culture

B. Strategy and Objective-Setting

C. Performance

D. Review and Revision

Answer: A

28. COSO ERM 2017 has how many principles?

A. 5

B. 17

C. 20

D. 25

Answer: C

29. The COSO ERM framework expands internal control to include:

A. Strategy and enterprise-wide risk

B. Only financial reporting

C. Only IT risks

D. Only compliance risks

Answer: A

30. Which of the following is a component of COSO ERM?

A. Information, Communication, and Reporting

B. Control Activities

C. Monitoring

D. Risk Assessment

Answer: A

COBIT (31–40)

31. COBIT is developed by:

A. COSO

B. ISACA

C. IIA

D. AICPA

Answer: B

 

32. How many governance principles are in COBIT 2019?

A. 5

B. 6

C. 7

D. 8

Answer: B

33. Which of the following is NOT a COBIT 2019 governance principle?

A. Provide Stakeholder Value

B. Holistic Approach

C. Dynamic Governance System

D. Maximize Shareholder Wealth

Answer: D

34. How many enablers are in COBIT 2019?

A. 5

B. 6

C. 7

D. 8

Answer: C

35. Which COBIT domain covers Evaluate, Direct, Monitor?

A. EDM

B. APO

C. BAI

D. DSS

Answer: A

36. Which COBIT domain covers Build, Acquire, Implement?

A. EDM

B. APO

C. BAI

D. MEA

Answer: C

 

37. COBIT is primarily used for:

A. Financial auditing

B. IT governance

C. Risk management only

D. Internal control over financial reporting

Answer: B

38. Which COBIT process addresses monitoring and evaluating the system of internal control?

A. MEA02

B. APO01

C. BAI03

D. DSS01

Answer: A

39. COBIT 2019 emphasizes governance distinct from:

A. Management

B. Auditing

C. Compliance

D. Risk

Answer: A

40. Which of the following is a COBIT enabler?

A. Processes

B. Organizational structures

C. Culture, ethics, and behavior

D. All of the above

Answer: D

Governance (41–50)

41. Governance is primarily the responsibility of:

A. Management

B. Board of directors

C. Internal audit

D. External audit

Answer: B

 

42. The IIA Three Lines Model includes:

A. Three lines of defense

B. Governing body, management, internal audit

C. First line, second line, third line

D. Both B and C

Answer: D

43. In the Three Lines Model, who owns and manages risk?

A. First line

B. Second line

C. Third line

D. Governing body

Answer: A

44. Internal audit's role in governance is to:

A. Own governance

B. Evaluate and contribute to improving governance

C. Manage risk

D. Set risk appetite

Answer: B

45. Which of the following is NOT a governance responsibility?

A. Setting risk appetite

B. Overseeing management

C. Preparing financial statements

D. Ensuring ethical tone

Answer: C

46. The board's oversight role includes:

A. Approving strategy

B. Monitoring management

C. Ensuring compliance

D. All of the above

Answer: D

 

47. Which of the following best describes the relationship between governance, risk, and control?

A. Independent

B. Interlocking

C. Sequential

D. Random

Answer: B

48. The governing body is responsible for:

A. Directing the organization

B. Managing daily operations

C. Conducting internal audits

D. Preparing tax returns

Answer: A

49. Which of the following is a key governance principle?

A. Transparency

B. Accountability

C. Fairness

D. All of the above

Answer: D

50. Internal audit independence is essential for:

A. Governance

B. Risk management

C. Control

D. All of the above

Answer: D

Risk Assessment (51–60)

51. Risk is defined as:

A. Certainty of loss

B. Possibility that events will affect objectives

C. Guaranteed profit

D. Absence of controls

Answer: B

52. Inherent risk is:

A. Risk after controls

B. Risk before controls

C. Risk that is accepted

D. Risk that is transferred

Answer: B

53. Residual risk is:

A. Risk before controls

B. Risk after controls

C. Risk that is avoided

D. Risk that is shared

Answer: B

54. Risk appetite is:

A. The amount of risk an organization is willing to accept

B. The amount of risk an organization can eliminate

C. The amount of risk internal audit can ignore

D. The amount of risk that is always zero

Answer: A

55. Which of the following is a risk response?

A. Avoid

B. Reduce

C. Share

D. All of the above

Answer: D

56. Which COSO component requires assessing fraud risk?

A. Control environment

B. Risk assessment

C. Control activities

D. Monitoring

Answer: B

 

57. Risk assessment involves:

A. Identifying risks

B. Analyzing risks

C. Both A and B

D. Neither A nor B

Answer: C

58. Internal audit's role in risk management is to:

A. Perform risk assessment for management

B. Provide objective evaluations of risk

C. Accept risks on behalf of the organization

D. Eliminate all risks

Answer: B

59. Which of the following is a risk assessment technique?

A. Risk mapping

B. Likelihood and impact analysis

C. Risk registers

D. All of the above

Answer: D

60. Significant change that could affect internal control should be identified as part of:

A. Control environment

B. Risk assessment

C. Control activities

D. Monitoring

Answer: B

AIS & IT Controls (61–70)

61. IT General Controls (ITGCs) apply to:

A. Specific applications

B. All systems in the IT environment

C. Only financial systems

D. Only hardware

Answer: B

62. Which of the following is an ITGC?

A. Logical access security

B. Change management

C. Computer operations

D. All of the above

Answer: D

63. Application controls are specific to:

A. All systems

B. A particular application

C. Hardware only

D. Network only

Answer: B

64. Input controls ensure:

A. Accuracy and completeness of data entered

B. Data is processed correctly

C. Output is accurate

D. Data is stored securely

Answer: A

65. A check digit is an example of:

A. Input control

B. Processing control

C. Output control

D. Data file control

Answer: A

66. Processing controls include:

A. Run-to-run totals

B. Reasonableness checks

C. Sequence checks

D. All of the above

Answer: D

67. Output controls ensure:

A. Data is entered correctly

B. Data is processed correctly

C. Outputs are accurate, complete, and delivered securely

D. Data is stored correctly

Answer: C

68. Which of the following is a data file control?

A. File maintenance controls

B. Access restrictions

C. Both A and B

D. Neither A nor B

Answer: C

69. ITGCs provide the environment in which:

A. Application controls operate

B. Financial statements are prepared

C. Management overrides controls

D. Auditors issue opinions

Answer: A

70. If ITGCs are weak, application controls:

A. Are always effective

B. May not function reliably

C. Are not needed

D. Become unnecessary

Answer: B

FCPA (71–80)

71. The FCPA was enacted in:

A. 1977

B. 1992

C. 2002

D. 2010

Answer: A

72. The FCPA has how many major provisions?

A. One

B. Two

C. Three

D. Four

Answer: B

73. The FCPA's accounting provisions require issuers to:

A. Make and keep accurate books and records

B. Maintain a system of internal accounting controls

C. Both A and B

D. Neither A nor B

Answer: C

74. Under the FCPA, a violation of the anti-bribery provision is required to violate the internal control provision.

A. True

B. False

Answer: B. False

Under the Foreign Corrupt Practices Act (FCPA), the anti-bribery provisions and the internal control/accounting provisions operate independently of each other.

  • Independent Enforcement: A company or individual can be prosecuted and charged with a violation of the internal control provisions even if there is no underlying or accompanying violation of the anti-bribery provisions.
  • Separate Requirements: The anti-bribery provisions prohibit corrupt payments to foreign officials, whereas the accounting and internal control provisions require issuers to maintain accurate books and reasonable accounting controls to prevent and detect potential misconduct, regardless of whether actual bribery occurred.

75. The FCPA has a materiality threshold for internal control violations.

A. True

B. False

Answer B. False

The Foreign Corrupt Practices Act (FCPA) does not have a materiality threshold for its accounting provisions, which include both the books-and-records and the internal accounting controls rules.

Instead of a financial materiality limit, the law requires issuers to maintain records in "reasonable detail" and devise internal controls that provide "reasonable assurances" that transactions are executed with management's authorization. Under the law, even minor or quantitatively small transactions can trigger an FCPA violation if they bypass internal control mechanisms or are recorded

76. Which of the following is required by the FCPA's internal accounting controls?

A. Transactions are executed in accordance with management's authorization

B. Transactions are recorded to permit preparation of financial statements in conformity with GAAP

C. Access to assets is permitted only in accordance with management's authorization

D. All of the above

Answer: D

77. The FCPA applies to:

A. U.S. companies only

B. Foreign companies only

C. Issuers and domestic concerns

D. Only government entities

Answer: C

78. Which of the following is a key difference between FCPA and SOX?

A. FCPA has no materiality threshold

B. SOX has no materiality threshold

C. FCPA applies only to foreign companies

D. SOX applies only to private companies

Answer: A

79. To comply with FCPA, organizations should:

A. Review and test controls

B. Maintain a compliance and ethics program

C. Prevent, detect, remediate, and report misconduct

D. All of the above

Answer: D

80. The FCPA's books and records provision requires:

A. Accurate and fair reflection of transactions

B. Only annual reporting

C. Only internal audits

D. Only external audits

Answer: A

 

SOX (81–90)

81. SOX was enacted in:

A. 1977

B. 1992

C. 2002

D. 2010

Answer: C

82. SOX Section 302 requires:

A. CEO and CFO certification of financial statements

B. Management assessment of internal controls

C. Auditor attestation of internal controls

D. All of the above

Answer: A

83. SOX Section 404 requires:

A. CEO and CFO certification

B. Management assessment of internal controls

C. Both A and B

D. Neither A nor B

Answer: B

84. Under SOX 404, management must:

A. Assess and report on effectiveness of ICFR

B. Guarantee no fraud

C. Eliminate all risks

D. Prepare tax returns

Answer: A

85. SOX 404(b) requires:

A. Management assessment

B. External auditor attestation

C. Internal audit assessment

D. None of the above

Answer: B

86. SOX effectively mandates the use of which framework?

A. COBIT

B. COSO

C. ISO 27001

D. ITIL

Answer: B

87. SOX compliance is equivalent to FCPA compliance.

A. True

B. False

Answer: B

88. Which section of SOX requires disclosure of significant deficiencies in internal control?

A. Section 302

B. Section 404

C. Section 906

D. Section 802

Answer: A

89. SOX applies to:

A. All companies

B. Public companies

C. Private companies only

D. Non-profit organizations

Answer: B

90. SOX Section 404(a) requires:

A. Management's internal control report in annual report

B. Auditor's attestation

C. CEO certification

D. CFO certification

Answer: A

 

---

 

Control Applications & Other (91–100)

91. Which of the following is an example of a preventive control?

A. Bank reconciliation

B. Segregation of duties

C. Backup restoration

D. Variance analysis

Answer: B

92. Which of the following is an example of a detective control?

A. Password protection

B. Physical counts

C. Authorization

D. Training

Answer: B

93. Which of the following is a directive control?

A. Policies and procedures

B. Reconciliations

C. Error correction

D. Backups

Answer: A

94. A key control is:

A. A control that is essential to achieving objectives

B. A control that is optional

C. A control that is always automated

D. A control that is always manual

Answer: A

95. Compensating controls are used when:

A. Primary controls are ineffective

B. Primary controls cannot be implemented

C. Management wants to reduce costs

D. Both A and B

Answer: D

96. Which of the following is NOT a component of the COSO internal control framework?

A. Control environment

B. Risk assessment

C. Control activities

D. Financial reporting

Answer: D

97. The IIA Three Lines Model replaced:

A. Three Lines of Defense

B. COSO framework

C. COBIT framework

D. SOX

Answer: A

98. Which of the following is a governance responsibility?

A. Setting risk appetite

B. Overseeing management

C. Ensuring ethical tone

D. All of the above

Answer: D

99. Which of the following is a risk response?

A. Avoid

B. Reduce

C. Share

D. All of the above

Answer: D

100. Which of the following is a COBIT domain?

A. EDM

B. APO

C. BAI

D. All of the above

Answer: D

Case-based and scenario-based questions in CIA Part 1 (Essentials of Internal Auditing) and US CMA Part 1 (Financial Planning, Performance, and Analytics) test your ability to apply governance, internal control, and risk concepts to real-world business situations rather than just recalling definitions.

Case 1: Segregation of Duties & Cash Controls Scenario:

A small manufacturing company’s cashier opens incoming mail, records customer checks in the cash receipts journal, prepares the daily bank deposit slip, and periodically reconciles the bank statement. During an internal audit review, management is questioned about this setup.  

Question: Which internal control principle is being violated, and what is the primary risk?    Violation: =?  , Risk:? ,  Correct Control: ?

Answer & Analysis:

  • Violation: Failure to segregate incompatible functions. The cashier has both custody of assets (handling checks/cash) and recording of transactions (posting to the journal/reconciling the bank).
  • Risk: The individual can perpetrate an error or theft and conceal it in the normal course of their duties (e.g., kiting or skimming cash and manipulating the ledger or bank reconciliation).
  • Correct Control: Separate custody, recording, and authorization functions. Another employee who does not handle cash should perform the bank reconciliation.

Case 2: Governance & Board Responsibilities Scenario:

A newly appointed board of directors at an SEC-registered company is revising its corporate governance charter. A board member proposes that the board draft all operational compliance policies and directly manage the internal audit budget and staffing selections to ensure tight oversight.    Question: Is the board member's proposal aligned with proper corporate governance structures tested in CIA/CMA exams?      Evaluation:?     ,  Management’s Role:?  , Board/Audit Committee’s Role:?

Answer & Analysis:

  • Evaluation: The proposal misallocates duties between the board, management, and internal audit.
  • Management’s Role: Management is responsible for designing, implementing, and operating the system of internal controls and drafting detailed operational policies.
  • Board/Audit Committee’s Role: The board provides oversight, establishes the governance tone, and the audit committee specifically approves the internal audit charter, budget, and resource plan—as well as appoints/dismisses the Chief Audit Executive (CAE)—rather than writing operational policies or executing day-to-day administrative control.

Case 3: Limitations of Internal ControlsScenario: A retail chain implements a state-of-the-art automated inventory management and point-of-sale control system. Two senior store managers collude to bypass the system's override protocols by using shared administrator credentials, falsifying shrinkage reports, and stealing high-value merchandise over six months.    Question: What fundamental concept regarding internal controls does this scenario illustrate?        Concept:? , Explanation:? , Key Limitations Highlighted:?

Answer & Analysis:

  • Concept: Inherent limitations of internal control systems.
  • Explanation: No matter how well-designed or automated a system is, internal controls can only provide reasonable assurance (not absolute assurance) regarding the achievement of objectives.
  • Key Limitations Highlighted:

1.   Collusion: Two or more individuals working together can bypass physical and digital segregation controls.

2.   Management Override: Individuals in authority positions have the power to override automated checks or procedural controls.

3.   Human Error or Judgment: Flaws in handling or sharing credentials

case scenarios covering Accounting Information Systems (AIS), deliverables, risk ownership, and internal control frameworks as tested in the CIA Part 1 and US CMA Part 1 exams.

Scenario 1: AIS Deliverables, Change Management, & Risk OwnershipThe Case: Global Retail Corp. is upgrading its ERP system to handle automated inventory restocking. The Project Manager (PM) is racing against a tight deadline. To meet the go-live date, the PM decides to skip the user acceptance testing (UAT) sign-off—a critical project deliverable—and plans to run the system migration over a holiday weekend. The Chief Financial Officer (CFO), who is the executive sponsor and risk owner for financial reporting accuracy, is not informed of this shortcut.      Question: What control vulnerability exists regarding risk ownership, and what is the potential impact on the AIS   deliverables?     Control Vulnerability? , Impact on Deliverables:? ,Correct Protocol: ?

Answer & Analysis:

  • Control Vulnerability: The Project Manager is inappropriately acting as the risk owner by accepting the operational risk of skipping UAT. In corporate governance, the PM is a risk custodian or manager, while the CFO is the actual risk owner accountable for the integrity of the AIS data.
  • Impact on Deliverables: Bypassing UAT threatens the reliability of the system's output (the core deliverable). Without testing, the AIS could generate corrupted financial reports, erroneous automated purchase orders, or inaccurate inventory valuations, leading to material financial statement misstatements.
  • Correct Protocol: The PM must present the timeline risk to the CFO. Only the risk owner has the authority to formally accept the risk or allocate more resources to complete the deliverable safely.

 

Scenario 2: AIS Application Controls & Data IntegrityThe Case: An internal auditor is reviewing the automated procurement module of a company's AIS. The system is designed to automatically generate a purchase order (PO) when raw material inventory falls below a reorder point. During the review, the auditor discovers that a data entry clerk accidentally typed an extra zero into a manual batch override, resulting in an authorized purchase order for 100,000 units instead of 10,000 units. The system processed the transaction without flagging it.    Question: What type of internal control failed, and what specific AIS application controls should have prevented this error?     Control Failure:?,   Missing AIS Controls:?

Answer & Analysis:

  • Control Failure: A failure of automated application controls (specifically input controls).
  • Missing AIS Controls:
    • Limit/Reasonableness Check: The AIS should have a pre-programmed field limit that flags or blocks order quantities that deviate significantly from historical averages or maximum warehouse capacities.
    • Range Check: A control that ensures data falls within predetermined upper and lower statistical bounds.
    • Sign-off/Authorization Threshold: The system should automatically route abnormally high-value POs to a senior procurement manager for manual secondary approval before transmission to the vendor.

 

Scenario 3: Bypassing IT Governance & "Shadow IT" Risks The Case: The regional sales division of a logistics firm is frustrated by the slow reporting capabilities of the centralized enterprise AIS. To get faster insights, the regional director hires an external developer to build a standalone, cloud-based sales tracking dashboard using live corporate data. The corporate IT department and the internal audit team are completely unaware of this dashboard.Question: What governance and internal control risks are introduced by this standalone system?    Risk Classification:?,  Key Controls Compromised:?

Answer & Analysis:

  • Risk Classification: This introduces Shadow IT risks and violates fundamental IT governance principles.
  • Key Controls Compromised:
    • Data Integrity & Reconciliation: The standalone system creates a "second version of the truth." If data definitions or timing cut-offs differ from the main AIS, it will produce conflicting financial deliverables.
    • Information Security: Because the application bypassed IT department review, it may lack standard company protocols like multi-factor authentication (MFA), role-based access controls, or data encryption, exposing sensitive corporate data to leaks.
    • Lack of Risk Ownership: No formal risk owner has been assigned to monitor the compliance, backup, or business continuity plans of this rogue application.

Key Exam Takeaways for CIA & CMA Part 1

  • AIS Input controls (edit checks, batch totals) are the most cost-effective way to ensure data integrity before it enters the ledger.
  • Risk Owners must be business unit leaders or executives who have the organizational authority to mitigate, transfer, or accept risks. They cannot delegate accountability to project managers or IT staff.
 


Internal Control governence risk assessment ais etc sept27.docx
201K View as HTML Scan and download