Case Scenario
Apex Global Corp is a multinational manufacturing company. Recently, the Audit Committee appointed a new Chief Audit Executive (CAE). The CEO suggests that the internal audit (IA) activity should report administratively to the CFO and functionally to the CEO, while dropping the requirement for a formal board-approved audit charter to "save time and reduce bureaucracy."
During a subsequent routine audit of procurement, Senior Auditor Tom notices that a major local vendor is owned by the brother of the VP of Procurement. The VP of Procurement pressures Tom to ignore this relationship in his working papers, promising a glowing performance review and a fast-track promotion. Simultaneously, Apex’s management is rolling out a new automated inventory system. Tom is asked to evaluate whether the system meets the COSO Internal Control components and COBIT technology governance requirements before launch. During testing, Tom discovers that inventory quantities can be manually altered without leaving an audit trail—a classic fraud risk (Red Flag) indicator.
Multiple-Choice Questions (MCQs)
Q1: Audit Mandate & Governance (Foundations)
Question: Under global internal audit standards, how should the CAE address the CEO's proposal regarding reporting lines and the elimination of the internal audit charter?
· A) Accept the proposal, as reporting directly to the CEO maximizes operational efficiency.
· B) Reject the proposal; the IA activity must report functionally to the board/audit committee and have a formal, board-approved charter defining its mandate.
· C) Accept the elimination of the charter if senior management agrees in writing.
D) Report functionally to the CFO to maintain a close alignment with financial reporting structures
Correct Answer: B
Rationale: Organizational independence requires functional reporting to the board (audit committee) rather than management to ensure unbiased reporting. The internal audit charter is a mandatory document defining Apex’s IA mandate, authority, and responsibilities, and it must be approved by the board
Q2: Ethics & Professionalism
Question: How should Tom respond to the VP of Procurement's pressure to omit the vendor conflict-of-interest finding from the working papers?
· A) Omit the finding to protect the working relationship with the department head and secure a promotion.
· B) Comply with the request but document it informally in a private personal notebook.
· C) Uphold integrity and objectivity by fully reporting the conflict of interest without regard to personal consequences.
D) Report the matter directly to the CFO instead of including it in the formal audit communication
Correct Answer: C
Rationale: The IIA Code of Ethics requires internal auditors to perform their work with honesty, diligence, and responsibility (Integrity) and not be unduly influenced in their professional judgment (Objectivity)
Q3: Internal Control & COSO Components
Question: The ability to manually change inventory records without an audit trail represents a severe deficiency in which specific COSO internal control component?
· A) Control Environment
· B) Risk Assessment
· C) Control Activities
D) Information and Communication
Correct Answer: C
Rationale: Control activities are the policies and procedures (such as segregation of duties, access controls, and audit trails) designed to mitigate risks to the achievement of objectives. Lack of an audit trail is a direct control activity breakdown
Q4: Fraud Risk Assessment
Question: Regarding the hidden ownership of the vendor by the VP of Procurement's brother and the system manipulation vulnerability, Tom’s responsibility is to:
· A) Recognize these as red flags for potential fraud and expand testing to evaluate the extent of the risk.
· B) Immediately launch a full criminal investigation and interrogate the VP.
· C) Ignore the vendor relationship since management is ultimately responsible for fraud control.
D) Assume fraud has occurred and report the VP directly to external law enforcement
Correct Answer: A
Rationale: Internal auditors must have sufficient knowledge of fraud to identify red flags. While internal audit evaluates the adequacy of controls to deter/detect fraud, management holds primary responsibility for fraud prevention
COSO and COBIT are complementary internal control models: COSO focuses on enterprise-wide risk management and financial reporting, while COBIT targets IT governance and technology alignment
Practice Multiple Choice Questions (MCQs)
- Question 1: Primary Scope SelectionAn organization is designing an internal control system specifically to comply with Sarbanes-Oxley (SOX) Section 404 requirements for financial reporting and fraud prevention. Which framework provides the most appropriate foundational guidance?
- A) COBIT
- B) COSO Internal Control - Integrated Framework
- C) ITIL
- D) ISO 27001
- Answer: B
- Question 2: IT and Business AlignmentManagement wants to evaluate how well its information technology department supports overarching enterprise goals and manages specific tech-related risks. Which framework should the IT steering committee adopt?
- A) COSO ERM
- B) COSO Internal Control
- C) COBIT by ISACA
- D) COSO Control Environment
- Answer: C
- Question 3: Application Relationship Which statement best describes the practical relationship between COSO and COBIT within an enterprise?
- A) COBIT replaces COSO for all computerized processing environments.
- B) COSO is a subset of COBIT focused solely on database security.
- C) COSO establishes the broad enterprise control foundation, while COBIT extends detailed governance and controls into the IT environment. D) COBIT governs financial reporting, while COSO governs network infrastructure
- Answer: C
- Question 4: Governance Domain Application An IT auditor is reviewing IT strategy, enterprise architecture, and domain objectives for alignment with corporate goals. This application aligns best with:
- A) COSO Control Activities
- B) COSO Tone at the Top
- C) COSO Monitoring of Compliance
- D) COBIT governance and management objectives
- Answer:D
PL READ.. Comparing the COSO 5 components and COBIT 5 governance enablers reveals how internal control intersects with IT governance. Both frameworks use structural pillars to manage risk, but COSO focuses on organizational internal control, while COBIT uses seven broad drivers for enterprise IT.
Key Differences in Structure
· COSO 5 Components: Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities.
· COBIT 5 Enablers: Principles, Policies and Frameworks; Processes; Organizational Structures; Culture, Ethics and Behavior; Information; Services, Infrastructure and Applications; and People, Skills and Competencies
Practice Multiple Choice Questions (MCQs)
Question 1: Framework Scope and Focus
Which statement BEST describes the fundamental difference in scope between COSO's 5 components and COBIT 5 enablers?
· A) COSO provides a broad internal control and risk framework, whereas COBIT 5 enablers focus on the governance and management of enterprise IT.
· B) COSO focuses exclusively on IT infrastructure, while COBIT covers financial reporting.
· C) COSO contains seven enablers, and COBIT contains five components.
D) COSO is managed by ISACA, and COBIT is managed by the Treadway Commission
· Correct Answer: A
Question 2: Matching Controls and Enablers
Under COBIT 5, which governance enabler directly corresponds to the COSO component "Control Environment" regarding lines of authority, responsibility, and organizational setup?
· A) ProcessesB) InformationC) Organizational StructuresD) Services, Infrastructure and Applications
Correct Answer: C
Question 3:
In a comparative audit, the COSO component Information and Communication aligns most closely with which COBIT 5 enabler category?
A) Principles, Policies and Frameworks B) Information
· C) Culture, Ethics and Behavior D) People, Skills and Competencies
Correct Answer: B
Corporate Governance
Q1. Which of the following conditions represents the most severe weakness in an organization's corporate governance structure?
· A. The CEO also serves as the Chairman of the Board.
· B. The board meets only twice a year.
· C. The audit committee consists entirely of executive board members.
· D. The head of internal audit reports administratively to the CFO
· · Answer: C
· · Explanation: An audit committee must comprise independent non-executive members to provide unbiased oversight. Executive members create a severe self-review threat and lack independence. [1, 2]
· Q2. An internal auditor discovers that the board of directors rarely challenges management’s strategic proposals and financial forecasts. This situation indicates a breakdown in which governance attribute?
· A. Transparency and disclosure.
· B. Active board oversight and independence.
· C. Stakeholder engagement.
· D. Corporate social responsibility.
· · Answer: B
· · Explanation: A core principle of effective governance is an active, objective board that exercises independent judgment and critically evaluates management's plans
Q3. Which situation points to a deficiency in the organization’s ethical climate?
· A. Management distributes the code of conduct to new hires.
· B. Employees are instructed to report fraud directly to their line supervisors.
· C. There is no formal, confidential mechanism or hotline to report ethical violations.
· D. The company sponsors local community events.
· · Answer: C
· · Explanation: Without a confidential and anonymous reporting channel, employees may fear retaliation, leaving violations hidden. [1]
Q4. A board compensation committee bases executive bonuses strictly on short-term revenue spikes without regard to risk metrics. This design flaw encourages:
· A. Risk avoidance.
· B. Unethical behavior and excessive risk-taking.
· C. Improved internal control monitoring.
· D. Long-term corporate stability.
· · Answer: B
· · Explanation: Inappropriate or misaligned compensation incentives create severe behavioral risks, pushing management to override controls for short-term gains. [1]
Q5. When ownership is widely separated from day-to-day management control, governance structures must protect shareholders from:
· A. High market share.
· B. Agency conflicts and self-serving management actions.
· C. Excessively low leverage.
· D. Transparent financial reporting
· · Answer: B
· · Explanation: The agency problem occurs when managers act in their own self-interest rather than for the shareholders, requiring strong oversight boards. [1, 2]
Q6. An IT steering committee meets irregularly and does not coordinate with the risk management committee. This is a weakness in:
· A. Operational efficiency.
· B. Information technology governance.
· C. Financial accounting controls.
· D. Human resources management.
· · Answer: B
· · Explanation: IT governance ensures that IT aligns with business goals and risk appetite; isolated IT decisions lead to unmanaged cyber and operational vulnerabilities. [1, 2]
7. A newly public company does not have an internal audit activity, claiming the external auditors provide sufficient review. What is the governance implication? [1]
· A. External audits fully replace internal audit governance.
· B. The company lacks continuous evaluation of internal controls and risk management.
· C. Regulatory compliance is automatically achieved.
· D. Management accountability is eliminated.
· · Answer: B
· · Explanation: External audits focus primarily on financial statements at year-end, whereas internal audit provides ongoing evaluation of governance, risk, and operations.
Q8. Which scenario describes a conflict of interest at the board level?
· A. A board member owns a significant vendor company that supplies raw materials to the enterprise without prior disclosure or recusal.
· B. A board member attends all scheduled committee meetings.
· C. The board reviews the external auditor's independence.
· D. Independent directors hold an executive session without management.
· · Answer: A
· · Explanation: Undisclosed business ties between directors and the firm compromise objectivity and breach fiduciary duties. [1, 2]
Q9. Line management regularly overrides internal controls on expense reports for top-performing sales staff because they fear the staff might quit. This severely damages which COSO component?
· A. Control Activities.
· B. Control Environment ("Tone at the Top").
· C. Risk Assessment.
· D. Monitoring.
· · Answer: B
· · Explanation: When management demonstrates that rules do not apply to favored employees, it destroys the ethical tone and undermines the entire control environment. [1]
Q10. A single clerk in the accounts payable department can create new vendors and approve invoices for payment. This deficiency represents a failure in: [1]
· A. Physical access controls.
· B. Segregation of duties.
· C. Information processing integrity.
· D. Management oversight.
· Answer: B
· Explanation: Custodial, authorization, and recording functions must be segregated to prevent and detect errors or fraud. [1, 2, 3]
Q11. Which of the following is an inherent limitation of any internal control system rather than a design weakness?
· A. Lack of an independent audit committee.
· B. Failure to segregate accounting duties.
· C. Collusion among two or more employees.
· D. Absence of written corporate policies.
· Answer: C
· Explanation: Collusion, human judgment errors, and management override are inherent limitations that can bypass even well-designed controls. [1, 2, 3]
Q12. Management fails to track customer complaints or product return trends, treating them as isolated events. Under COSO, this is a weakness in which component?
· A. Risk Assessment.
· B. Control Activities.
· C. Information and Communication.
· D. Monitoring.
· · Answer: A
· · Explanation: Risk assessment requires identifying and analyzing changes and operational data (like increasing returns/complaints) that could affect the achievement of objectives.
·
Case Scenario
During an operational audit of a mid-sized manufacturing firm’s payroll department, an internal auditor notes that the payroll clerk is responsible for collecting time cards, entering hours worked into the system, preparing the payroll register, and holding custody of the unissued signed paycheck signature stamp. [1]
Multiple Choice Question
Which of the following describes the most critical control weakness in this scenario?
· A. The payroll clerk prepares the payroll register.
· B. The payroll clerk has custody of the check signature stamp.
· C. Time cards are collected by the payroll department instead of an independent department.
· D. Paychecks are drawn on a separate payroll checking account
Correct Answer & Explanation
Correct Answer: B [1]
· Why it is a weakness: Segregation of duties requires that the individual who records or processes transactions (the payroll clerk entering hours and making the register) does not have custody of or access to the assets or the means to disburse funds (the check signature stamp). Combining recordkeeping and custody allows an employee to create a fictitious employee and easily sign the checks, leading to undetected fraud. [1, 2]
· Why others are incorrect: Preparing the payroll register (A) is a normal duty of a payroll clerk and proper if custody and authorization are segregated. Collecting time cards (C) is standard operational procedure if entry is checked. Drawing paychecks on a separate impress/checking account (D) is actually a control strength, not a weakness. [1]
Q13. An organization has documented its internal controls, but management performs no ongoing or periodic evaluations to see if they are working. This is a failure of: [1]
· A. Control activities.
· B. Monitoring.
· C. Information systems.
· D. Risk response.
· · Answer: B
· · Explanation: Monitoring involves ongoing evaluations, separate evaluations, or a combination of both to ascertain whether each component of internal control is present and functioning. [1, 2]
Q14. Password controls for a core financial application allow users to keep the same password indefinitely and do not lock after multiple failed attempts. This is a weakness in:
· A. Application-level preventive controls.
· B. IT general preventive controls.
· C. Detective control tracking.
· D. Corrective feedback loops.
· · Answer: B
· · Explanation: Access security parameters (password expiration, lockouts) are foundational IT general controls meant to prevent unauthorized entry
Q15. Physical inventory counts are conducted annually by the warehouse manager, who also maintains the perpetual inventory master records. What is the risk/weakness?
· A. The inventory count will take too long.
· B. The valuation method will be misstated.
· C. Physical controls are too rigid.
· D. The manager has both custody and record-keeping responsibilities, masking inventory shrinkage or theft
· Answer: D
· · Explanation: Combining asset custody with accounting records enables concealment of discrepancies or inventory losses.
Q16. Management implements complex automated controls within an enterprise system but does not train staff on exceptions handling. This causes a breakdown in:
· A. Control environment.
· B. Information and Communication.
· C. Operational efficiency.
· D. Risk appetite definition.
· · Answer: B
· · Explanation: Personnel must understand their control responsibilities and how to communicate control anomalies or exceptions
Q17. A company relies on a single supplier for a critical component without a backup plan or secondary contract. From a risk and control perspective, this is a failure of:
· A. Risk identification and mitigation strategies.
· B. Segregation of duties.
· C. Detective accounting controls.
· D. Employee supervision.
· · Answer: A
· · Explanation: Identifying operational vulnerabilities and establishing adequate risk responses (such as dual sourcing) is part of enterprise risk management. [1, 2, 3]
Q18. Which of the following conditions in the purchasing cycle most directly exposes an organization to fictitious vendor fraud?
· A. Purchase orders are pre-numbered.
· B. Receiving reports are matched to invoices.
· C. New vendor master files can be added by disbursements personnel without independent verification.
· D. Checks are signed by the treasurer.
· · Answer: C
· · Explanation: Allowing the same personnel who process payments to add vendors allows the creation of shell companies for personal enrichment. [1, 2, 3]
Q19. Internal auditors find that management routinely corrects control deficiencies identified in prior audits only to see the same deficiencies reoccur next year. This indicates a failure in:
· A. Corrective action follow-up and sustainable remediation.
· B. Initial risk scoring.
· C. Audit charter authorization.
· D. External oversight.
· · Answer: A
· · Explanation: True internal control strength requires permanent structural remediation rather than temporary, superficial fixes when auditors are on-site.
Q20. An organization's whistleblower hotline reports are routed exclusively to the Chief Executive Officer—the individual frequently named in the complaints. What is the control/governance flaw?
· A. The audit committee is overstepping its bounds.
· B. The reporting channel lacks independence, creating a self-review/concealment risk.
· C. Communication is too transparent.
· D. The internal audit charter is violated.
· · Answer: B
· · Explanation: Whistleblower reports concerning executive leadership must go directly to an independent body like the Audit Committee or Board Chairman to prevent evidence destruction or retaliation. [1]
· Case Scenario
· Apex Manufacturing recently expanded rapidly and opened a new foreign branch. To manage operations, top management allowed local branch managers full autonomy to bypass standard vendor approval procedures if they felt it sped up production. Within six months, an internal audit discovered multiple unverified payments made to fictitious vendors set up by a local manager.
Multiple Choice Question
Which core component of the COSO Integrated Framework was primarily compromised by management’s decision to allow local branch managers to bypass standard approval procedures?
· A. Risk AssessmentB. Information and CommunicationC. MonitoringD. Control Environment
Correct Answer & Explanation
· Correct Answer: D. Control Environment [1]
· Why it is correct: The Control Environment sets the tone of an organization, influencing the control consciousness of its people. It encompasses integrity, ethical values, and the operating style/authority structure established by management. Permitting regular overrides of basic controls weakens the foundational "tone at the top."
· Why others are incorrect:
o Risk Assessment involves identifying risks, but the failure here was an intentional override of structural governance.
o Monitoring evaluates control performance over time, which is a secondary failure compared to the flawed foundational culture.
· Information and Communication deals with processing and distributing accurate data, not the behavioral rules of authorization itself.
PL READ..
Here is a case-based multiple-choice question focusing on Control Activities and Risk Assessment within the COSO Integrated Framework.
Case Scenario
Global Logistics Inc. recently upgraded its central software to automate inventory routing. While configuring the system, management identified that system glitches could cause misplaced shipments. To prevent this, they implemented a rule requiring the system to auto-reconcile physical barcodes against the digital manifests before any truck departs. Furthermore, supervisors must manually review and digitally sign off on a daily variance report detailing any reconciliation failures.
Multiple Choice Question
The automated system reconciliation rule and the mandatory daily supervisor review of variance reports are direct examples of which COSO component?
· A. Control Activities
· B. Risk Assessment
· C. Information and Communication
· D. Control Environment
Correct Answer & Explanation
· Correct Answer: A. Control Activities
· Why it is correct: Control Activities are the specific policies, procedures, and mechanisms put in place to ensure management directives are carried out and that risks are mitigated. Automated reconciliations and supervisor sign-offs are classic operational controls designed to keep risks within acceptable levels. [1, 2, 3, 4]
· Why others are incorrect:
o Risk Assessment is the prior stage where management identified that glitches could cause misplaced shipments; the rules themselves are the response to that risk.
o Information and Communication refers to how data is captured and shared across the company, but it does not represent the policy or preventive action itself.
o Control Environment refers to the overall "tone at the top" and organizational integrity, rather than specific operational procedures
PL READ..
The COSO Internal Control — Integrated Framework breaks down internal control into five components and 17 core principles. Multiple-choice questions (MCQs) on this topic typically test your ability to match a specific principle to its correct component or identify what is not a COSO component or principle.
Control Environment (Principles 1–5)
· Principle 1: Demonstrates commitment to integrity and ethical values.
· Principle 2: Exercises oversight responsibility (Board of directors).
· Principle 3: Establishes structure, authority, and responsibility.
· Principle 4: Demonstrates commitment to competence.
· Principle 5: Enforces accountability.
· Mnemonic: EBOCA (Ethics, Board, Organizational structure, Competence, Accountability).
Risk Assessment (Principles 6–9)
· Principle 6–9: Focuses on setting objectives, analyzing risks, assessing fraud, and evaluating changes.
· Mnemonic: SAFR.
Control Activities (Principles 10–12)
· Principle 10–12: Involves selecting, developing, and deploying technology and policy controls to mitigate risk.
· Mnemonic: CaTP.
Information and Communication (Principles 13–15)
· Principle 13–15: Centers on obtaining relevant information and communicating internally and externally.
· Mnemonic: OIE.
Monitoring Activities (Principles 16–17)
· Principle 16–17: Covers ongoing evaluations and communicating deficiencies.
· Mnemonic: SoD.
Case Scenario
Apex Retail Ltd. recently expanded rapidly by opening 20 new stores. To cope with the growth, the store managers were given full autonomy to hire local vendors, approve invoices, and disburse petty cash without central sign-off or background checks. The CEO emphasized trust over bureaucracy. Six months later, an internal audit discovered fictitious vendor payments totaling $150,000 processed by a store manager in collusion with a fake supplier. The audit committee also found that no risk assessment was conducted for the new purchasing workflow, and no technology general controls restricted invoice entry modifications.
Multiple Choice Questions (MCQs)
Q1. Which COSO internal control component was most directly violated by the CEO’s extreme focus on trust without enforcing background checks or structure?
· A) Risk AssessmentB) Monitoring Activities C) Control Environment D) Information and Communication
· Correct Answer: C) Control Environment
Explanation: Principle 1 (Integrity and Ethical Values) and Principle 5 (Enforcing Accountability) fall under the Control Environment, which sets the ethical tone and governance structure. Leadership failed to establish proper oversight and authority lines
Q2. The absence of evaluations regarding new store purchasing workflows and vendor onboarding points to a breakdown in which COSO principle?
· A) Principle 3: Establishes structure, authority, and responsibility
· B) Principle 8: Assesses fraud risk
· C) Principle 12: Bases controls on thorough policies and procedures
· D) Principle 16: Conducts ongoing and/or separate evaluations
· B) Principle 8: Assesses fraud risk
Explanation: Under the Risk Assessment component, management must explicitly assess the potential for fraud when altering operational scope or decentralizing workflows.
Q3. According to the COSO framework requirements for an effective internal control system, what is the status of Apex Retail Ltd.’s internal control?
- A) Effective, because the operational growth objective was successfully met.
- B) Effective, because local autonomy speeds up operational efficiency.
- C) Ineffective, because not all five components and relevant principles are present and functioning together.
- D) Ineffective, solely due to a minor failure in external communication.
·
Accounting Information Systems & Internal Control MCQs
1. What is the primary objective of an Accounting Information System (AIS)?
· A) To handle marketing tasks
· B) To process data and report financial results
· C) To replace human workers completely
· D) To eliminate all business risks
· Answer: B [1, 2]
2. Which of the following is NOT a core component of an AIS? [1]
· A) People
· B) Hardware
· C) Weather forecasts
· D) Internal controls
· Answer: C [1]
3. What type of control is designed to stop an error or fraud from happening in the first place? [1]
· A) Detective control
· B) Corrective control
· C) Preventive control
· D) Compensating control
· Answer: C [1]
4. Reconciling the bank statement each month is an example of which control type? [1]
· A) Preventive control
· B) Detective control
· C) Directive control
· D) Environmental control
· Answer: B [1]
5. Fixing a discovered data entry error by re-entering the correct data is an example of what?
· A) Preventive control
· B) Corrective control
· C) General control
· D) Inherent control
· Answer: B [1]
6. Separation of duties means dividing which key functions among different people? [1]
· A) Custody of assets, authorization, and recording
· B) Sales, marketing, and production
· C) Hiring, firing, and training
· D) Auditing, managing, and owning
· Answer: A [1, 2, 3]
7. What level of assurance do internal controls provide to an organization? [1]
· A) Absolute assurance
· B) Reasonable assurance
· C) Zero assurance
· D) Perfect certainty
· Answer: B [1, 2]
8. Which COSO framework component sets the "tone at the top" of an organization? [1]
· A) Control Activities
· B) Risk Assessment
· C) Control Environment
· D) Monitoring
· Answer: C [1]
9. What is the main purpose of application controls in a computer system?
· A) To manage the entire operating system
· B) To ensure accuracy and completeness of specific data processing
· C) To control physical building access
· D) To fix hardware malfunctions
· Answer: B [1, 2, 3]
10. An input control that checks whether a field contains only numbers (not letters) is called:
· A) Limit check
· B) Field check
· C) Sequence check
· D) Sign check
· Answer: B
11. Which input control checks if an identification number falls within a valid numerical range? [1]
· A) Limit check
· B) Validity check
· C) Completeness check
· D) Batch total
· Answer: A
12. What do you call a control that tests if all required data fields have been filled in before saving?
· A) Completeness check
· B) Reasonableness test
· C) Sign check
· D) Redundancy check
· Answer: A
13. General controls in an IT system apply to:
· A) Only the payroll application
· B) Only the sales order entry
· C) Overall IT infrastructure and operations
· D) Manual cash counts only
· Answer: C [1, 2, 3, 4, 5]
14. Which employee should ideally NOT have access to accounting records if they handle physical cash? [1]
· A) Internal Auditor
· B) Cashier / Custodian of cash
· C) External tax preparer
· D) Board member
· Answer: B [1]
15. An inherent limitation of any internal control system is:
· A) Management override and collusion
· B) Infinite cost efficiency
· C) Complete elimination of risk
· D) Automatic error correction
· Answer: A [1, 2]
16. Which process groups transactions together in a package and checks control totals at the end? [1]
· A) Real-time processing
· B) Batch processing
· C) Continuous auditing
· D) Online inquiry
· Answer: B [1]
17. A log file that records every attempt to access a computer system serves as what type of control?
· A) Preventive
· B) Detective
· C) Directive
· D) Redundant
· Answer: B
18. Which entity is primarily responsible for establishing and maintaining internal controls? [1]
· A) External auditors
· B) Management
· C) Internal revenue service
· D) Shareholder
· Answer: B [1]
19. What is a "turnaround document"?
· A) A document sent to the bank to reverse a fee
· B) A company output sent to a customer who returns it as an input document
· C) An audit report that needs revision
· D) A deleted database record
· Answer: B [1, 2, 3, 4]
20. A hash total is best described as:
· A) The sum of financial amounts in a batch
· B) The total count of records in a file
· C) A meaningless sum of numeric fields (like customer account numbers) used for control verification
· D) The total tax applied to items
Answer c
COSO Practice Questions
· Question 1: Fraud Risk Assessment
Under the COSO Internal Control – Integrated Framework, which component explicitly requires an organization to consider the potential for fraud when assessing risks to the achievement of objectives?
o A) Control Environment
o B) Control Activities
o C) Risk Assessment
o D) Monitoring
· · Answer: C — Explanation: Principle 8 of the Risk Assessment component specifically mandates that the organization assesses fraud risk, considering incentives, pressures, opportunities, and rationalization. [1, 2, 3]
· Question 2: Management Override
Which approach is most consistent with COSO guidance for mitigating the risk of management override of internal controls?
· A) Relying entirely on external audit reviews
· B) Strengthening the oversight role of the board of directors and an active audit committee alongside whistleblower channels
· C) Assuming senior leadership is inherently trustworthy and exempt from routine controls
· D) Implementing specialized fraud-specific software without changing authorization limits
Answer b — Explanation: The Control Environment component emphasizes independent board oversight, governance structures, and transparent communication channels to deter override.
Q3 An entity implemented all 17 COSO principles effectively, yet a material misstatement occurred due to two employees conspiring to bypass authorization controls. This demonstrates which foundational concept of the framework?
· A) Control deficiency
· B) Inherent limitation of internal control (collusion)
· C) Failure of the monitoring component
· D) Absence of a control activity
Answer: B — Explanation: COSO provides reasonable, not absolute, assurance. Collusion, human error, and management override remain inherent limitations
Governance, Risk Management & Control
Q1. Management has identified a risk that could significantly affect the achievement of strategic objectives. What should management do FIRST?
A. Design detective controls
B. Assess the likelihood and impact of the risk
C. Transfer the risk through insurance
D. Report the risk to internal audit
Answer: B
Q2. Which statement BEST describes risk appetite?
A. The amount of loss already incurred
B. The amount of risk an organization is willing to accept in pursuit of objectives
C. The probability that fraud will occur
D. The maximum insurance coverage purchased
Answer: B
Q3. An internal auditor discovers that management intentionally accepts a high-risk activity because the expected return is significant and within approved limits. This is an example of:
A. Risk avoidance
B. Risk acceptance
C. Risk transfer
D. Risk elimination
Answer: B
Q4. Which of the following is the BEST example of a preventive control?
A. Monthly bank reconciliation
B. Annual external audit
C. Segregation of duties in cash receipts
D. Exception report review
Answer: C
Q5. Which framework is MOST widely recognized for enterprise risk management?
A. COBIT
B. COSO ERM
C. ISO 9001
D. ITIL
Answer: B
Q6. The PRIMARY responsibility for identifying and managing organizational risks belongs to:
A. Internal auditors
B. External auditors
C. Management
D. Audit committee
Answer: C
Q7. Which activity is NOT an appropriate role of internal audit in risk management?
A. Evaluating risk management effectiveness
B. Providing assurance on risk processes
C. Assuming ownership of organizational risks
D. Recommending improvements
Answer: C
Q8. A company purchases insurance against fire losses. This is an example of:
A. Risk reduction
B. Risk transfer
C. Risk avoidance
D. Risk acceptance
Answer: B
Q9. Which statement BEST describes inherent risk?
A. Risk remaining after controls are applied
B. Risk eliminated by internal controls
C. Risk before any controls are implemented
D. Risk transferred through insurance
Answer: C
Q10. Residual risk is:
A. The total risk identified during planning
B. Risk remaining after management implements controls
C. Risk accepted by the external auditor
D. Risk transferred to a third party
Answer: B
Q11.
Which of the following is the BEST example of strategic risk?
A. Employee payroll fraud
B. Failure to adapt to new technology
C. Incorrect invoice processing
D. Unauthorized access to petty cash
Answer: B
Q12.
Which risk response completely removes exposure to a risk?
A. Transfer
B. Acceptance
C. Avoidance
D. Reduction
Answer: C
Q13.
Management installs surveillance cameras to discourage theft. This is primarily a:
A. Corrective control
B. Detective control
C. Preventive control
D. Compensating control
Answer: C
Q14.
Which is the BEST indicator of an effective risk management process?
A. No risks exist
B. Risks are identified, assessed, monitored, and reported
C. Internal audit manages all risks
D. External auditors approve all controls
Answer: B
Q15.
The board approves the organization's risk appetite. Who is primarily responsible for operating within it?
A. External auditors
B. Internal auditors
C. Management
D. Regulators
Answer: C
Q16.
A company purchases backup servers to reduce downtime after system failure. This represents:
A. Risk reduction
B. Risk transfer
C. Risk avoidance
D. Risk acceptance
Answer: A
Q17.
Which document normally identifies major organizational risks and assigned owners?
A. Organization chart
B. Risk Register
C. Audit Charter
D. Financial Statements
Answer: B
Q18.
Residual risk should always be:
A. Eliminated
B. Accepted without review
C. Compared with risk appetite
D. Ignored after audit
Answer: C
Q19.
Which statement regarding risk assessment is TRUE?
A. It is performed only once each year.
B. It should be continuous and updated.
C. Only internal audit performs it.
D. It excludes emerging risks.
Answer: B
Q20.
Cybersecurity threats are generally classified as:
A. Compliance risk only
B. Operational risk
C. Liquidity risk
D. Credit risk
Answer: B
Q21.
Which is the BEST example of emerging risk?
A. Payroll processingB. Artificial intelligence regulations
C. Bank reconciliationD. Inventory counting
Answer: B
Q22.
Internal auditors should evaluate whether:
A. Management has accepted only appropriate residual risk.
B. All risks are eliminated.
C. Internal audit owns the ERM process.
D. External auditors determine risk appetite
Answer: A
Q23.
Which of the following BEST demonstrates risk monitoring?
A. Reviewing KRIs monthly
B. Hiring employees
C. Purchasing insurance
D. Recording journal entries
Answer: A
Q24.
A Key Risk Indicator (KRI) primarily helps:
A. Detect future risk trendsB. Prepare financial statementsC. Calculate taxes
D. Replace internal controls
Answer: A
Q25.
Which risk response shares risk with another party?
A. AcceptanceB. ReductionC. TransferD. Avoidance
Answer: C
Q26.
Which is an example of compliance risk?
A. Foreign exchange fluctuations
B. Violation of environmental regulations
C. Declining customer demand
D. Machine breakdown
Answer: B
Q27.
The MOST important purpose of enterprise risk management is to:
A. Eliminate all uncertainty.
B. Help achieve organizational objectives.
C. Increase audit findings.
D. Reduce audit costs.
Answer: B
Q28.
Who has ultimate oversight responsibility for risk governance?
A. EmployeesB. Board of DirectorsC. CustomersD. Suppliers
Answer: B
Q29.
Risk velocity refers to:
A. Size of financial lossB. Speed at which a risk impacts objectives
C. Number of audit findingsD. Cost of insurance
Answer: B
Q30.
Which factor is assessed together with likelihood during risk assessment?
A. Revenue
B. Impact
C. Number of employees
D. Share price
Answer: B
Q31.
Which is the BEST example of risk acceptance?
A. Buying insurance
B. Closing a risky business unit
C. Deciding not to install an expensive control because the risk is low
D. Installing CCTV
Answer: C
Q32.
A risk heat map primarily displays:
A. Budget performance
B. Likelihood versus impactC. Employee productivityD. Audit costs
Answer: B
Q33.
A control that detects duplicate payments is:
A. PreventiveB. DetectiveC. DirectiveD. Corrective
Answer: B
Q34.
Which activity BEST reduces fraud risk?
A. One employee performs all accounting duties.
B. Segregation of duties.
C. Eliminating internal audit.
D. Removing approval requirements.
Answer: B
Q35.
Which risk is MOST associated with natural disasters?
A. Strategic
B. Operational
C. Compliance
D. Reputation
Answer: B
Q36.
A company outsources payroll processing to a specialist. This is primarily:
A. Risk transfer
B. Risk avoidance
C. Risk elimination
D. Risk acceptance
Answer: A
Q37.
Management reviews risk indicators every quarter. This demonstrates:
A. Risk monitoringB. Risk avoidanceC. Fraud investigationD. Assurance mapping
Answer: A
Q38.
Which statement about residual risk is TRUE?
A. It should never exist.B. It always equals inherent risk.C. It remains after controls are implemented.D. It is ignored during audits.
Answer: C
Q39.
Which risk category is MOST affected by negative social media publicity?
A. Liquidity
B. Reputational
C. Credit
D. Market
Answer: B
Q40.
The BEST reason to establish risk appetite is to:
A. Eliminate uncertainty
B. Guide management decision-making
C. Reduce audit hours
D. Increase profits automatically
Answer: B
Q41.
Which document summarizes identified risks, ratings, responses, and owners?
A. Risk RegisterB. Audit ProgramC. Trial BalanceD. Policy Manual
Answer: A
Q42.
Which of the following is NOT a common risk response?
A. AcceptB. ReduceC. TransferD. Ignore
Answer: D
Q43.
Which type of control corrects errors after they occur?
A. PreventiveB. DetectiveC. CorrectiveD. Directive
Answer: C
Q44.
Which risk management principle is MOST important?
A. Risk management supports achievement of objectives.B. Risk management eliminates all risk.
C. Risk management belongs only to internal audit.D. Risk management replaces governance.
Answer: A
Q45.
An organization continues operations despite a known low-level risk because mitigation costs exceed expected losses. This is:
A. Risk acceptanceB. Risk avoidanceC. Risk transferD. Risk elimination
Answer: A
Q46.
The FIRST step in the risk management process is:
A. Risk response
B. Risk identification
C. Risk monitoring
D. Reporting
Answer: B
Q47.
Which is the BEST source for identifying organizational risks?
A. Risk workshops with managementB. Internal audit workpapers only
C. Financial statements onlyD. External audit reports only
Answer: A
Q48.
Which role should internal audit play regarding ERM?
A. Own the ERM processB. Provide independent assurance and advice
C. Approve risk appetiteD. Accept residual risk
Answer: B
Q49.
An increase in customer complaints is an example of a:
A. Key Risk IndicatorB. Financial ratioC. Performance appraisalD. Budget variance
Answer: A
Q50.
According to the IIA, effective risk management is achieved when:
A. Internal audit manages all risks.
B. Management identifies, assesses, responds to, and monitors risks within the organization's risk appetite.
C. External auditors approve every risk response.
D. Every risk is eliminated.
Answer: B
Case-Based MCQs on Enterprise Risk Management (ERM)
These questions are designed in the style of the new CIA Part 1 examination, where candidates must identify the BEST answer based on business scenarios.
Q1. Risk Appetite
A manufacturing company has approved a strategy to enter an emerging market. Management estimates there is a 40% chance of moderate financial loss but expects substantial long-term growth. The board previously approved a moderate risk appetite.
What should management do FIRST?
A. Reject the project because losses are possible.
B. Compare the project's risk with the approved risk appetite.
C. Ask internal audit to approve the decision.
D. Purchase insurance immediately.
Answer b
Q2During an ERM review, the CEO asks internal audit to determine the organization's risk appetite.
What should the chief audit executive recommend?
A. Internal audit should establish the risk appetite.
B. Management should establish it without board involvement.
C. The board should approve the risk appetite proposed by management.
D. External auditors should determine it.
Answer c
Q3An organization launches an online payment platform. Before implementing controls, management evaluates possible cyberattacks and financial losses.
The organization is assessing:
A. Residual risk
B. Inherent risk
C. Detection risk
D. Audit risk
Answer: B
Q4. Residual Risk
After implementing multi-factor authentication, encryption, and continuous monitoring, cyber risk remains at a moderate level.
The remaining exposure is called:
A. Strategic risk
B. Residual risk
C. Detection risk
D. Fraud risk
Answer: B
Q5. Internal Audit Role
Senior management asks internal audit to become responsible for managing all operational risks.
The BEST response is:
A. Accept responsibility.
B. Manage only financial risks.
C. Decline because management owns risk management.
D. Ask external auditors to manage risks.
Answer: C
Q6. Risk Response
A logistics company purchases cargo insurance to reduce losses from transportation accidents.
This is an example of:
A. Risk acceptance
B. Risk transfer
C. Risk avoidance
D. Risk elimination
Answer: B
Q7. Risk Governance
Who has ultimate oversight responsibility for enterprise risk management?
A. Internal Audit
B. Chief Risk Officer
C. Board of Directors
D. External Auditor
Answer: C
Q8. Key Risk Indicators (KRIs)
A bank notices that unsuccessful customer login attempts have increased by 300% over two weeks.
This metric is BEST classified as:
A. Key Performance Indicator
B. Key Risk Indicator
C. Financial Ratio
D. Compliance Metric
Answer: B
Q9. Risk Register
During an audit, the auditor reviews a document listing risks, owners, controls, ratings, and planned responses.
This document is the:
A. Audit Charter
B. Strategic Plan
C. Risk Register
D. Fraud Report
Answer: C
Q10. Emerging Risk
A company heavily depends on artificial intelligence for customer service. New government regulations regarding AI are expected next year.
This represents:
A. Market Risk
B. Emerging Risk
C. Credit Risk
D. Liquidity Risk
Answer: B
Q11. Risk Monitoring
Management reviews KRIs every month to identify increasing cybersecurity threats.
This activity represents:
A. Risk Identification
B. Risk Monitoring
C. Risk Avoidance
D. Risk Transfer
Answer: B
Q12. Risk Acceptance
An organization decides not to install an expensive backup system because the probability of failure is extremely low and the possible loss is minimal.
Management has:
A. Reduced the risk
B. Accepted the risk
C. Avoided the risk
D. Transferred the risk
Answer: B
Q13. Preventive Controls
A company requires dual authorization before electronic payments above $50,000 are processed.
This is primarily a:
A. Detective Control
B. Preventive Control
C. Corrective Control
D. Monitoring Control
Answer: B
Q14. ERM Objective
What is the PRIMARY objective of Enterprise Risk Management?
A. Eliminate uncertainty.
B. Ensure achievement of organizational objectives within acceptable risk.
C. Reduce audit findings.
D. Increase profits every year.
Answer: B
Q15. Risk Assessment Priority
Which risk should management generally address FIRST?
A. Low likelihood, low impact
B. High likelihood, high impact
C. Low likelihood, high impact
D. High likelihood, low impact
Answer: B
Q16. Three Lines Model
According to the IIA Three Lines Model, who owns and manages risks?
A. Internal Audit
B. External Audit
C. Operational Management
D. Audit Committee
Answer: C
Q17. Internal Audit Assurance
Which activity BEST demonstrates internal audit's role in ERM?
A. Approving risk responses
B. Owning the risk register
C. Evaluating the effectiveness of risk management
D. Accepting residual risks
Answer: C
Q18. Reputation Risk
Following a major product defect, thousands of negative social media posts appear within hours.
This primarily represents:
A. Compliance Risk
B. Reputation Risk
C. Market Risk
D. Liquidity Risk
Answer: B
Q19. Risk Response Selection
A company discontinues manufacturing a hazardous chemical because safety risks cannot be adequately controlled.
This is:
A. Risk Reduction
B. Risk Transfer
C. Risk Acceptance
D. Risk Avoidance
Answer: D
Q20. Best Overall ERM Practice
During an audit, management demonstrates that risks are identified, assessed, assigned to owners, monitored using KRIs, and reported regularly to the board.
The internal auditor should conclude that:
A. ERM appears to be operating effectively.
B. Internal audit should own ERM.
C. No residual risks exist.
D. The organization has eliminated all risks.
Answer: A
CIA Exam Tip
In the new CIA Part 1 exam, many case-based questions can be answered by remembering these core principles:
- Board: Provides oversight and approves risk appetite.
- Management: Identifies, assesses, responds to, and monitors risks.
- Internal Audit: Provides independent assurance and advisory services; it does not own or manage risks.
- Inherent Risk: Risk before controls.
- Residual Risk: Risk remaining after controls.
- KRIs: Early warning indicators of increasing risk.
- Risk Register: Records risks, owners, controls, ratings, and responses.
- ERM Goal: Help the organization achieve objectives while operating within its approved risk appetite