Q1 Internal auditors are more likely to detect fraud by developing/strengthening their ability to
A. Recognize and question changes that occur in organizations. B. Develop internal controls to prevent the occurrence of fraud. C. Interrogate fraud perpetrators to discover why the fraud was committed. D. Document computerized operating system programs.
Answer (A) is correct.
An internal auditor’s responsibilities for detecting fraud include evaluating fraud indicators and deciding whether any additional action is necessary or whether an investigation should be recommended
Q2 The chief of an organization’s security received an anonymous call accusing a marketing manager of taking kickbacks from a media outlet. Thus, the marketing department is on the list of possible engagement clients for the coming year. The internal audit activity is assigned responsibility for investigating fraud by its charter. If obtaining access to outside media outlet records and personnel is not possible, the best action an internal auditor could take to investigate the allegation of marketing kickbacks is to
A. Obtain a list of approved media outlets.
B. Vouch any material past charge-offs of receivables.
C. Search for unrecorded liabilities from media outlets.
D. Develop a financial and behavioral profile of the suspect
Answer (D) is correct.
A common indicator of fraud by an employee is an unexplained change in his or her financial status. A
standard of living not commensurate with the employee’s income may signify wrongdoing. The
employee’s behavior may also be suspicious (for example, constant association with, and entertainment by, a member of the media outlet’s staff). The profile may help to corroborate illegal income and thereby provide a basis for tracing illegal payments to the employee
Q3 When comparing perpetrators who have embezzled an organization’s funds with perpetrators of financial statement fraud (falsified financial statements), those who have falsified financial statements are less likely to
A. Use organizational expectations as justification for the act.
B. Be living beyond their obvious means of support.
C. Have experienced an autocratic management style.
D. Rationalize the fraudulent behavior
Answer (B) is correct.
Living beyond one’s means has been linked to employee fraud (embezzlement), not to financial
statement fraud. Fraud perpetrated for the benefit of the organization ordinarily benefits the wrongdoer indirectly, whereas fraud that is detrimental to the organization provides immediate, direct benefits to the employee.
*Case 1*:
Internal auditor Sarah found her brother-in-law is CFO of a vendor under audit. She didn’t disclose this and proceeded with the audit of vendor contracts.
*Q*: Which Code of Ethics principle did Sarah violate?
A. Competency
B. Confidentiality
C. *Objectivity*
D. Integrity
*Answer: C*
*Trigger*: *Objectivity* – must not participate if impaired by family relationship. Standard 1120 requires disclosure. Integrity also breached, but objectivity is direct impairment.
*Case 2*:
During a consulting engagement, the CAE learns the client plans to hide losses via illegal accounting. Client asks CAE to keep silent due to engagement confidentiality.
*Q*: What should CAE do per IIA Code?
A. Remain silent due to confidentiality
B. Report to audit committee only
C. *Disclose to appropriate authorities as required by law*
D. Resign from engagement quietly
*Answer: C*
*Trigger*: *Confidentiality* principle: Do not disclose unless _legal or professional obligation_. Illegal acts = legal duty to report.
*Case 3*:
Auditor Tom accepted free golf club membership from auditee after issuing a favorable report. Value $2,000. Company policy allows gifts <$100.
*Q*: Which principle violated?
A. Competency
B. *Integrity*
C. Confidentiality
D. Objectivity
*Answer: B*
*Trigger*: *Integrity* – Rule 1.2: Shall not knowingly be party to illegal activity or accept gifts that impair judgment. Also impairs objectivity, but integrity is accepting improper gift
Case 4*:
Staff auditor is assigned to audit cybersecurity. She has no IT audit training but doesn’t tell the CAE because she fears losing her job.
*Q*: Which principle violated?
A. Objectivity B. Integrity
C. Confidentiality D. *Competency*
*Answer: D*
*Trigger*: *Competency* Rule 4.2: Shall perform only services for which they have knowledge, skills, experience
Q4 Which of the following would indicate that fraud may be taking place in a marketing department?
A. All of the answers are correct.
B. The control environment can best be described as “very loose.” However, this attitude is justified by management on the grounds that it is needed for creativity.
C. There is no documentation for some fairly large expenditures made to a new vendor.
D. A manager appears to be living a lifestyle that is in excess of what could be provided by a marketing manager’s salary.
Answer (A) is correct.
An internal auditor’s responsibilities for the detection of fraud include having sufficient knowledge to
identify indicators that fraud may have been committed; being alert to opportunities, such as control
weaknesses, that could allow fraud to occur; and evaluating the indicators of fraud sufficiently to
determine whether any further action is needed or whether a fraud investigation should be recommended. Among the many such indicators are lack of timely and appropriate documentation (including information about authorization) for material transactions, suspicious lifestyle characteristics of employees in a position to commit fraud, and management’s failure to display and communicate an appropriate attitude toward internal control
Q6 A medium-sized regional firm distributes packaged snack foods to convenience stores. A routine inventory has revealed significant amounts of inventory missing from the delivery trucks. Which of the
following suggests a control weakness that may provide an opportunity for fraud?
A. The policy and procedure manual clearly defines allowed and prohibited actions.
B. Access to the warehouse is restricted to a few trusted employees.
C. Careful counts are made as inventory is loaded on the trucks.
D. Truck drivers are allowed to use the trucks for personal reasons, including taking them home at night, as a benefit of employment.
Answer (D) is correct.
Unrestricted access to the trucks creates opportunities for theft of merchandise by the drivers
Q7 After noting some red flags, an internal auditor has an increased awareness that fraud may be present. Which of the following best describes the internal auditor’s responsibility?
A. Report the matter to the audit committee and request funding for outside service providers to help investigate the possible fraud.
B. Expand activities to determine whether an investigation is warranted.
C. Report the possibility of fraud to senior management and the board and ask them how they would like to proceed.
D. Consult with external legal counsel to determine the course of action to be taken, including the approval of the proposed engagement work program to make sure it is acceptable on legal grounds.
Answer (B) is correct.
An internal auditor’s responsibilities for detecting fraud include evaluating fraud indicators and deciding whether any additional action is necessary or whether an investigation should be recommended.
Q9An internal auditor who suspects fraud should
A. Determine that a loss has been incurred.
B. Recommend an investigation if appropriate.
C. Identify the employees who could be implicated in the case.
D. Interview those who have been involved in the control of assets
Answer (B) is correct.
An internal auditor’s responsibilities for detecting fraud include evaluating fraud indicators and deciding whether any additional action is necessary or whether an investigation should be recommended
*Case 8*:
Internal audit charter was approved by CFO only, not the Board.
*Q*: Which Standard is violated?
A. 1000 Purpose, Authority, Responsibility
B. *1010 Recognizing Mandatory Guidance*
C. 1100 Independence
D. 2010 Planning
*Answer: C*
*Trigger*: *1000.C1*: Nature of consulting services must be defined in charter.
*Case 10*:
Audit team rushed an audit to meet deadline and failed to test key controls.
*Q*: Which standard violated?
A. 1210 Proficiency
B. *1220 Due Professional Care*
C. 1230 Continuing Professional Development
D. 1311 Internal Assessments
*Answer: B*
*Trigger*: *1220*: Due professional care = adequate testing, skepticism. Rushing = lack of care
*Case 11*:
CAE has not had external quality assessment in 7 years.
*Q*: Violation of:
A. 1300 Quality Assurance B. 1310 Requirements
C. *1312 External Assessments* D. 1320 Reporting
*Answer: C*
*Trigger*: *1312*: External assessments at least *once every 5 years*.
*Case 12*:
CAE reports "Generally Conforms" to Standards but last EQA was 6 years ago.
*Q*: Is this allowed?
A. Yes, if internal assessment says so
B. Yes, if AC approves
C. *No, cannot use "conforms" if >5 years since EQA*
D. No, must say "does not conform
*Answer: C*
Q11 Auditors must always be alert for the possibility of fraud. Assume the controls over each risk listed below are marginal. Which of the following possible frauds or misuses of organization assets should be considered the area of greatest risk?
A. Purchases of supplies are made from fictitious vendors.
B. The president is using company travel and entertainment funds for activities that might be considered questionable.
C. Grants are made to organizations that might be associated with the president or are not for purposes dictated in the organization’s charter.
D. The payroll clerk has added ghost employees
Answer (C) is correct.
Grants represent 83.6% (US $418 ÷ $500) of current revenue. Consequently, fraudulent grants constitute a much greater risk exposure than any of the other items listed
Q12 Internal auditors have been advised to consider red flags to determine whether management is involved in a fraud. Which of the following does not represent a difficulty in using the red flags as fraud indicators?
A. Red flag information is not gathered as a normal part of an engagement.
B. The red flags literature is not well enough established to have a positive impact on internal auditing.
C. Some red flags are difficult to quantify or to evaluate.
D. Many common red flags are also associated with situations in which no fraud exists
Answer (B) is correct.
The state of red flags literature is an aid, not a difficulty, in internal auditing. It is well established and will be refined in the future as research is done
Q13 One factor that distinguishes fraud from other employee crimes is that fraud involves
A. Intentional deception.B. Malicious motives.
C. Collusion with a party outside the organization.
D. Personal gain for the perpetrator
Answer (A) is correct.
Fraud is defined in The IIA Glossary as “any illegal act characterized by deceit, concealment, or violation of trust. These acts are not dependent upon the threat of violence or physical force
Q14 An internal auditor is investigating the performance of a division with an unusually large increase in sales, gross margin, and profit. Which of the following indicators is least likely to indicate the
possibility of sales-related fraud in the division?
A. There is an unusually large amount of sales returns recorded after year end.
B. The internal auditor has taken a random sample of sales invoices but cannot locate a shipping document for a number of the sales transactions selected for November and December.
C. A significant portion of divisional management’s compensation is based on reported divisional profits.
D. One of the division’s major competitors went out of business during the year
Answer (D) is correct.
A decrease in the number of competitors during the year is a potential explanation for the increase in
sales and profits.
Q14 Internal auditors should have knowledge about factors (red flags) that have proven to be associated with management fraud. Which of the following factors have generally not been
associated with management fraud?
A. Regular comparison of actual results with budgets.
B. A domineering management.
C. A management preoccupation with increased financial performance.
D. Generous performance-based reward systems
Answer (A) is correct.
Regular comparison of actual results to budgets provides feedback and is a normal and necessary part of the control loop. Ineffective control is an indicator of possible fraud.
Q15 In an organization with a separate division that is primarily responsible for the prevention of fraud, the internal audit activity is responsible for
A. Establishing and maintaining that division’s system of internal control.
B. Controlling that division’s fraud prevention activities.
C. Planning that division’s fraud prevention activities.
D. Examining and evaluating the adequacy and effectiveness of that division’s actions taken to prevent fraud
Answer (D) is correct.
Control is the principal means of preventing fraud. Management is primarily responsible for the
establishment and maintenance of control. Internal auditors are primarily responsible for preventing fraud by examining and evaluating the adequacy and effectiveness of control
q17 Which of the following is most likely to be considered an indication of possible fraud?
A. Rapid turnover of the organization’s financial executives.
B. Rapid expansion into new markets.
C. The replacement of the management team after a hostile takeover.
D. A government audit of the organization’s tax returns.
Answer (A) is correct.
Even the most effective internal control can sometimes be circumvented, perhaps by collusion of two or more employees. Thus, an auditor must be sensitive to certain conditions that might indicate the
existence of fraud, including high personnel turnover. In the case of financial executives, high turnover
may suggest a pattern of inflation of profits to obtain bonuses or other benefits, to secure advantages in the marketplace, or to conceal incompetence or rash actions
q18 Which of the following wrongful acts committed by an employee constitutes fraud?
A. Embezzlement.
B. Harassment.
C. Libel.
D. Assault.
Answer (A) is correct.
Fraud is defined in The IIA Glossary as “any illegal act characterized by deceit, concealment, or violation of trust. These acts are not dependent upon the threat of violence or physical force. Frauds are perpetrated by parties and organizations to obtain money, property, or services; to avoid payment or loss of services; or to secure personal or business advantage.” Embezzlement is the intentional appropriation of property entrusted to one’s care. The embezzler converts property to his or her own use and conceals the theft.
Q19 The most common motivation for management fraud is the existence of
A. Job dissatisfaction.
B. Financial pressures on the organization.
C. The challenge of committing the perfect crime.
D. Vices, such as a gambling habit.
Answer (B) is correct.
Management fraud benefits organizations rather than individuals, so the existence of financial pressures is the most common motivation. Management perpetrators attempt to make their financial statements appear more attractive because of the financial pressures of restrictive loan covenants, a poor cashposition, loss of significant customers, etc
Q20 An engagement had been scheduled by the chief audit executive to address unusual inventory shortages revealed in the annual physical inventory process at a large consumer goods warehouse
operation. A cycle count program had been installed in the storeroom at the beginning of the year in place of the disruptive process of counting one entire product line at the end of each month. The cycle count program appeared effective because only nine minor adjustments had been made for the entire year on the several thousand different products located in the storeroom. The storeroom supervisor explained that each of the 15 stockroom personnel selected one item each day for cycle
count based on how efficiently the item could be counted. The opportunity for control-related problems including fraud has been increased in the stockroom because
A. Stockroom personnel record cycle count information.
B. Items for cycle count are selected by stockroom personnel.
C. A cycle count program has been installed in place of a less efficient program.
D. Only nine minor adjustments have been recorded as a result of the cycle count process
Answer (B) is correct.
The opportunity for fraud has been increased because stockroom personnel select the items for cycle
count (poor internal control). Selection of items should be based on relative values or the relationship of an item to the total volume of transactions. Moreover, personnel who do not have custodial or
recordkeeping responsibilities should control the counts.
*Scenario:*
You are a senior internal auditor at Zenith Bank. Your spouse was just hired as Accounts Payable Manager. Next week you’re assigned to audit the AP cycle, including vendor master file controls. Your CAE says “You know the process best, so you should lead it.”
*Q1.* What is your FIRST action under IIA Code of Ethics – Objectivity?
A. Disclose the relationship to CAE and request reassignment from the AP audit
B. Proceed with audit but have another auditor review your workpapers
C. Audit only non-AP areas like travel expenses to avoid conflict
D. Resign from the engagement team to maintain independence
*Answer: A*
*Rationale:* Standard 1120 – Individual Objectivity. Impairment exists due to familial relationship. Per Implementation Guide 1120, _disclosure + reassignment_ is required before audit starts. B is insufficient because impairment cannot be “reviewed away”. C creates scope limitation. D is extreme
*Q2.* If CAE insists you perform the audit due to staff shortage, which Principle is violated?
A. Integrity
B. Competency
C. Confidentiality
D. Objectivity
*Answer: D*
*Rationale:* Principle of Objectivity requires freedom from conflicts. CAE forcing audit violates Std 1110 – Organizational Independence and 1120.
*CASE 2: Confidentiality vs Legal Obligation*
*Scenario:*
During a payroll audit at MedTech Inc., you discover the CFO created fictitious employees and embezzled $400,000. The CFO asks to meet privately and says, “If you report this, the company will collapse and 200 people lose jobs. I’ll repay in 6 months. Let’s keep this between us for now.”
*Q3.* Under IIA Code of Ethics – Confidentiality, what must you do?
A. Keep information confidential until CFO repays, per Principle of Confidentiality
B. Report to CAE immediately, as illegal acts are not protected by confidentiality
C. Confront the Board directly to maintain Integrity
D. Document in workpapers but delay reporting to give CFO chance to correct
*Answer: B*
*Rationale:* Confidentiality does NOT cover illegal acts. Standard 2440 + Code of Ethics: Must disclose to appropriate parties. CAE is first escalation. Delay violates Integrity + Due Professional Care 1220.
*Scenario:*
You’re assigned to audit IT general controls for a new ERP. You have no IT audit experience or CISA. The CAE says, “Just use last year’s checklist. It’s the same system.” You notice the ERP was upgraded to cloud SaaS with new access controls not covered in checklist.
*Q5.* What does Std 1210 – Proficiency require you to do?
A. Decline the engagement due to lack of competency
B. Proceed using checklist, noting limitation in report
C. Obtain necessary competencies through training/consult expert before performing audit
D. Outsource entire audit without informing CAE
*Answer: C*
*Rationale:* Std 1210.A1: Must have knowledge, skills, experience OR obtain them. Std 1220 – Due Professional Care requires assessing complexity. Using outdated checklist = failure of care. A is only if competence cannot be obtained
*Q6.* If you proceed without IT knowledge and miss a critical SaaS misconfiguration, which principle is breached?
A. Objectivity
B. Confidentiality
C. Competency
D. Objectivity & Confidentiality
*Answer: C*
*Rationale:* Principle of Competency + Std 1220.A2 due professional care. Auditor must apply knowledge and skills expected of prudent auditor.
*Scenario:*
While auditing procurement at AutoParts Ltd., the vendor you’re reviewing offers you tickets to the F1 Grand Prix worth $1,200 “as appreciation for your fairness”. Company policy allows gifts < $100. Your CAE is on vacation.
*Q7.* What is the most ethical action per IIA Code of Ethics?
A. Accept tickets but disclose in workpapers to maintain transparency
B. Decline tickets and report offer to CAE/Compliance upon return
C. Accept tickets because vendor is not asking for favorable report
D. Donate tickets to charity to avoid personal benefit
*Answer: B*
*Rationale:* Principle of Objectivity + Integrity. Gifts impair independence or create appearance of impairment. IIA Implementation Guide: decline + report. Company policy $100 limit also breached. A/D still create conflict.
*Q8.* If you accepted the tickets, which Standard is violated?
A. 1100 – Independence and Objectivity
B. 1200 – Proficiency and Due Professional Care
C. 1300 – Quality Assurance
D. 2000 – Managing Internal Audit Activity
*Answer: A*
*Rationale:* Std 1120 Objectivity and 1130 Impairment to Independence. Accepting significant gifts impairs actual or perceived objectivity.
Q21 What is the responsibility of the internal auditor with respect to fraud?
A. The internal auditor should have sufficient knowledge to identify the indicators of fraud but is not expected to be an expert.
B. An internal auditor should have sufficient knowledge and training so that (s)he is able to detect fraud.
C. The internal auditor should have the same ability to detect fraud as a person whose primary responsibility is detecting and investigating fraud.
D. An internal auditor’s primary role is to detect and investigate fraud
Answer (A) is correct.
Internal auditors must have sufficient knowledge to evaluate the risk of fraud and the manner in which it is managed by the organization. They are not expected to have the expertise of a person whose primary responsibility is detecting and investigating fraud (Impl. Std. 1210.A2).
*CASE 1: Prior Role Impairment*
You transferred to Internal Audit 8 months ago. Before that, you were Payroll Manager for 3 years. CAE assigns you to audit payroll processing controls.
*Q1.* Per Std 1130.A1, what must you do?
A. Disclose prior role but proceed since 8 months passed
B. Decline audit due to impairment; 1-year cooling period required
C. Perform audit but exclude transactions from your tenure
D. Ask a co-sourced firm to review your work only
*Answer: B*
*Rationale:* Std 1130.A1 – Impairment if auditor audited activity where they had responsibility within previous year. Must wait 12 months. A/C still impair objectivity. D doesn’t cure impairment.
Q22 An internal auditor’s field work uncovers a series of transactions that indicate a possible embezzlement. Which of the following actions should the chief audit executive take?
A. Decide whether to recommend an investigation.
B. Review the finding with the suspect’s fellow workers to see whether the workers can furnish additional evidence.
C. Confront the suspected embezzler to determine that the facts are correct.
D. Discuss the case with the board.
Answer (A) is correct.
An internal auditor’s responsibilities for detecting fraud include evaluating fraud indicators and deciding whether any additional action is necessary or whether an investigation should be recommended
*CASE 2: Consulting vs Assurance Conflict*
You provided consulting to design a new procurement approval workflow last quarter. Now CAE asks you to provide assurance on that same workflow’s effectiveness.
*Q2.* What does Std 1130.A2 require?
A. Accept if management understands it’s not independent assurance
B. Decline, as prior consulting impairs objectivity for 12 months
C. Proceed but disclose prior consulting in audit report
D. Have another auditor sign report while you do fieldwork
*Answer: B*
*Rationale:* Std 1130.A2 – Auditors who previously designed controls cannot audit them for 12 months. Impairment exists. C violates impairment rule even with disclosure
Q1Which of the following can help determine whether an organization's risk management framework is current and complete?
A.Risk volatility
B.Risk discovery
C.Risk maturity
D.Risk agility
The Answer C is Correct.
Risk maturity deals with whether an organization is using a proper risk management framework to
manage organization's risks. It seeks to determine whether that framework is old or new, complete or
incomplete, mature or immature, fully implemented or partially implemented. Moreover, it asks
whether the current maturity fits with the current business
Q2 Internal auditors would be more likely to detect fraud if they developed/strengthened their ability to:
a) Recognize and question changes that occur in organizations.
b) Interrogate fraud perpetrators to discover why the fraud was committed.
c) Develop internal controls to prevent the occurrence of fraud.
d) Document computerized operating system programs
Answer (A) is Correct.
The recognition and questioning of change is critical to the detection of fraud
Q3 According to the IIA Standards, which of the following best describes the two general categories or types of fraud that concern most internal auditors?
A.Improper payments (i.e., bribes and kickbacks) and tax fraud.
B.Fraud designed to benefit the organization and fraud perpetrated to the detriment of the organization.
C.Acceptance of bribes or kickbacks and improper related-party transactions.
D.Acceptance of kickbacks or embezzlement and misappropriation of assets.
Answer (B) is Correct.
These are the two overall categories or types of fraud given in the IIA Standards (IIA Standard
1220—Due Professional Care).
Q4 A company hired a highly qualified accounts payable manager who had been terminated from another company for alleged wrongdoing. Six months later the manager diverted $12,000 by sending duplicate payments of invoices to a relative. A control that might have prevented this situation would be to:
a) Adequately check prior employment backgrounds for all new employees.
b) Not hire individuals who appear overqualified for a job.
c) Verify educational background for all new employees.
d) Check to see if close relatives work for vendors
Answer (A) is correct.
This practice might give some leads to previous shortcomings
Q5 Red flags are conditions that indicate a higher likelihood of fraud. Which of the following would not be considered a red flag?
a) Management has delegated the authority to make purchases under a certain dollar
limit to subordinates.
b) An individual has held the same cash-handling job for an extended period without
any rotation of duties.
c) An individual handling marketable securities is responsible for making the
purchases, recording the purchases, and reporting any discrepancies and
gains/losses to senior management.
d) The assignment of responsibility and accountability in the accounts receivable
department is not clear.
Answer (A) is Correct.
This is an acceptable control procedure aimed at limiting risk while promoting efficiency. It is not, by
itself, considered a red flag
Q6 Internal auditors and management have become increasingly concerned about computer fraud.
Which of the following control procedures would be least important in preventing computer fraud?
A.Program change control that requires a distinction between production programs and test programs.
B.Testing of new applications by users during the systems development process.
C.Segregation of duties between the applications programmer and the program librarian function.
D.Segregation of duties between the programmer and systems analyst
Answer (D) is Correct.
This is one of the elements of good program change control
Q7 Which of the following statements correctly characterize(s) the red flags literature that has recently developed in the auditing profession?
I. Red flags are items or actions that have been associated with fraudulent conduct.
II. The auditor should document all red flags that may have been noted on an audit engagement.
III. Many red flags are subjective in nature and might not come to the auditor's attention during the course of an audit that is properly planned and conducted in accordance with the Standards.
a) I and II b) I and III c) II and III d) III only
Answer (B) is Correct.
Red flags are associated with fraudulent conduct. However, many red flags are personal in nature and
would not necessarily come to the attention of the auditor. These would include items such as an
excessive living style by a manager, excessive gambling, and so on
Q8 An employee of an insurance company processed a fraudulent policy loan application for an amount less than the established level requiring supervisory review. The employee then obtained
the check and cashed it by forging the endorsement. To prevent the loan’s appearance on a subsequent policyholder statement, the loan amount was transferred to a suspense account. Which
of the following should expose this situation at the earliest date?
a) A computer report identifying unusual entries to the suspense account.
b) The use of prenumbered checks that are periodically accounted for.
c) An annual internal audit.
d) Regular reconciliation of the suspense account performed by an independent employee.
Answer (A) is Correct.
A programmed computer output notification identifying unusual entries would identify the write‐off
of the payee’s account to suspense as an unusual item immediately when it occurs.
*CASE 3: Confidentiality & Subpoena*
During audit you learn of an unreported environmental spill. You’re later subpoenaed by EPA. Company legal says “Code of Ethics requires confidentiality, so don’t testify.”
*Q3.* Correct action under Code of Ethics?
A. Refuse to testify, citing Principle of Confidentiality
B. Testify truthfully, as legal requirement overrides confidentiality
C. Ask CAE to testify instead to protect auditor-client privilege
D. Provide only documents, not verbal testimony
*Answer: B*
*Rationale:* Confidentiality does NOT apply when legally required. IIA Code: “shall not disclose…unless legal or professional responsibility”. Std 2440
Q9The primary purpose of operating a fraud hotline within a company is to:
a) Reduce total costs of operating the company.
b) Measure how well organizational units are achieving the organization’s goals.
c) Establish channels of communication for people to report suspected improprieties.
d) Concentrate on areas that deserve attention and to place less attention on areas operating as expected.
Answer (C) is Correct.
Fraud hotlines may identify areas where existing internal controls need to be modified or enhanced.
Q10A programmer accumulating round‐off errors into one account that is later accessed by the programmer is a type of computer fraud. The best way to prevent this type of fraud is to:
a) Build in judgment with reasonableness tests.
b) Independently test programs during development and limit access to the programs.
c) Segregate duties of systems development and programming.
d) Use control totals and check the results of the computer
Answer (B) is Correct.
The accumulation of round‐off errors into one person’s account is a procedure written into the
program. Independent testing of a program will lead to discovery of this programmed fraud. If access
to programs was not limited, it would be possible for a programmer to change a program without
approval.
Q11Which of the following statements is (are) correct regarding the deterrence of fraud?
I. The primary means of deterring fraud is through an effective control system initiated by top management.
II. Internal auditors are responsible for assisting in the deterrence of fraud by examining and evaluating the adequacy of the control system.
III. Internal auditors should determine whether communication channels provide management with adequate and reliable information regarding the effectiveness of the control system and the occurrence of unusual transactions.
A.I only B.I and II only C.II only D.I, II, and III
Answer (D) is Correct.
All three items are correct statements according to the IIA Standards
Q12 A significant employee fraud took place shortly after an internal audit. The internal auditor may not have properly fulfilled the responsibility for the deterrence of fraud by failing to note and report that:
A.Policies, practices, and procedures to monitor activities and safeguard assets were less extensive in low-risk areas than in high-risk areas.
B.A system of control that depended on separation of duties could be circumvented by collusion among three employees.
C.There were no written policies describing prohibited activities and the action required whenever violations are discovered.
D.Divisional employees had not been properly trained to distinguish between bona fide signatures and cleverly forged ones on authorization forms
Answer (C) is Correct.
In carrying out its responsibility for the deterrence of fraud, internal auditing should determine
whether such written policy statements exist
Q13 Fraudulent use of corporate credit cards would be minimized by which of the following internal control procedures?
A.Establishing a corporate policy on the issuance of credit cards to authorized employees.
B.Reviewing the validity of credit card need at executive and operating levels on a periodic basis.
C.Reconciling the monthly statement from the credit card company with the submitted copies of the cardholders’ charge slips.
D.Subjecting credit card charges to the same expense controls as those used on regular company expense forms.
Answer (D) is Correct.
Subjecting credit card expenses to the same controls used in processing similar expense reports. In
this way, per diems and authorization limits would be reviewed
Section b
*CASE 1: Objectivity Impairment*
*Scenario:*
You are a senior internal auditor at Zenith Bank. Your spouse was just hired as Accounts Payable Manager. Next week you’re assigned to audit the AP cycle, including vendor master file controls. Your CAE says “You know the process best, so you should lead it.”
*Q1.* What is your FIRST action under IIA Code of Ethics – Objectivity?
A. Disclose the relationship to CAE and request reassignment from the AP audit
B. Proceed with audit but have another auditor review your workpapers
C. Audit only non-AP areas like travel expenses to avoid conflict
D. Resign from the engagement team to maintain independence
*Answer: A*
*Rationale:* Standard 1120 – Individual Objectivity. Impairment exists due to familial relationship. Per Implementation Guide 1120, _disclosure + reassignment_ is required before audit starts. B is insufficient because impairment cannot be “reviewed away”. C creates scope limitation. D is extreme.
*Q2.* If CAE insists you perform the audit due to staff shortage, which Principle is violated?
A. Integrity
B. Competency
C. Confidentiality
D. Objectivity
*Answer: D*
*Rationale:* Principle of Objectivity requires freedom from conflicts. CAE forcing audit violates Std 1110 – Organizational Independence and 1120.
*CASE 2: Confidentiality vs Legal Obligation*
*Scenario:*
During a payroll audit at MedTech Inc., you discover the CFO created fictitious employees and embezzled $400,000. The CFO asks to meet privately and says, “If you report this, the company will collapse and 200 people lose jobs. I’ll repay in 6 months. Let’s keep this between us for now.”
*Q3.* Under IIA Code of Ethics – Confidentiality, what must you do?
A. Keep information confidential until CFO repays, per Principle of Confidentiality
B. Report to CAE immediately, as illegal acts are not protected by confidentiality
C. Confront the Board directly to maintain Integrity
D. Document in workpapers but delay reporting to give CFO chance to correct
*Answer: B*
*Rationale:* Confidentiality does NOT cover illegal acts. Standard 2440 + Code of Ethics: Must disclose to appropriate parties. CAE is first escalation. Delay violates Integrity + Due Professional Care 1220.
*Q4.* Which action best demonstrates “Integrity” in this case?
A. Accepting CFO’s promise because saving jobs is ethical
B. Reporting facts objectively without bias, regardless of consequences
C. Anonymously leaking to press to protect employees
D. Ignoring it because materiality is below audit threshold
*Answer: B*
*Rationale:* Integrity = honesty, not distorting facts. Performance Standard 2320 requires sufficient, reliable evidence and unbiased reporting. A & D violate integrity. C violates confidentiality + proper channels.
*CASE 3: Competency & Due Professional Care*
*Scenario:*
You’re assigned to audit IT general controls for a new ERP. You have no IT audit experience or CISA. The CAE says, “Just use last year’s checklist. It’s the same system.” You notice the ERP was upgraded to cloud SaaS with new access controls not covered in checklist.
*Q5.* What does Std 1210 – Proficiency require you to do?
A. Decline the engagement due to lack of competency
B. Proceed using checklist, noting limitation in report
C. Obtain necessary competencies through training/consult expert before performing audit
D. Outsource entire audit without informing CAE
*Answer: C*
*Rationale:* Std 1210.A1: Must have knowledge, skills, experience OR obtain them. Std 1220 – Due Professional Care requires assessing complexity. Using outdated checklist = failure of care. A is only if competence cannot be obtained.
*Q6.* If you proceed without IT knowledge and miss a critical SaaS misconfiguration, which principle is breached?
A. Objectivity
B. Confidentiality
C. Competency
D. Objectivity & Confidentiality
*Answer: C*
*Rationale:* Principle of Competency + Std 1220.A2 due professional care. Auditor must apply knowledge and skills expected of prudent auditor.
*CASE 4: Conflict of Interest & Gifts*
*Scenario:*
While auditing procurement at AutoParts Ltd., the vendor you’re reviewing offers you tickets to the F1 Grand Prix worth $1,200 “as appreciation for your fairness”. Company policy allows gifts < $100. Your CAE is on vacation.
*Q7.* What is the most ethical action per IIA Code of Ethics?
A. Accept tickets but disclose in workpapers to maintain transparency
B. Decline tickets and report offer to CAE/Compliance upon return
C. Accept tickets because vendor is not asking for favorable report
D. Donate tickets to charity to avoid personal benefit
*Answer: B*
*Rationale:* Principle of Objectivity + Integrity. Gifts impair independence or create appearance of impairment. IIA Implementation Guide: decline + report. Company policy $100 limit also breached. A/D still create conflict.
*Q8.* If you accepted the tickets, which Standard is violated?
A. 1100 – Independence and Objectivity
B. 1200 – Proficiency and Due Professional Care
C. 1300 – Quality Assurance
D. 2000 – Managing Internal Audit Activity
*Answer: A*
*Rationale:* Std 1120 Objectivity and 1130 Impairment to Independence. Accepting significant gifts impairs actual or perceived objectivity.
Section c….
*CASE 1: Prior Role Impairment*
You transferred to Internal Audit 8 months ago. Before that, you were Payroll Manager for 3 years. CAE assigns you to audit payroll processing controls.
*Q1.* Per Std 1130.A1, what must you do?
A. Disclose prior role but proceed since 8 months passed
B. Decline audit due to impairment; 1-year cooling period required
C. Perform audit but exclude transactions from your tenure
D. Ask a co-sourced firm to review your work only
*Answer: B*
*Rationale:* Std 1130.A1 – Impairment if auditor audited activity where they had responsibility within previous year. Must wait 12 months. A/C still impair objectivity. D doesn’t cure impairment.
*CASE 2: Consulting vs Assurance Conflict*
You provided consulting to design a new procurement approval workflow last quarter. Now CAE asks you to provide assurance on that same workflow’s effectiveness.
*Q2.* What does Std 1130.A2 require?
A. Accept if management understands it’s not independent assurance
B. Decline, as prior consulting impairs objectivity for 12 months
C. Proceed but disclose prior consulting in audit report
D. Have another auditor sign report while you do fieldwork
*Answer: B*
*Rationale:* Std 1130.A2 – Auditors who previously designed controls cannot audit them for 12 months. Impairment exists. C violates impairment rule even with disclosure.
*CASE 3: Confidentiality & Subpoena*
During audit you learn of an unreported environmental spill. You’re later subpoenaed by EPA. Company legal says “Code of Ethics requires confidentiality, so don’t testify.”
*Q3.* Correct action under Code of Ethics?
A. Refuse to testify, citing Principle of Confidentiality
B. Testify truthfully, as legal requirement overrides confidentiality
C. Ask CAE to testify instead to protect auditor-client privilege
D. Provide only documents, not verbal testimony
*Answer: B*
*Rationale:* Confidentiality does NOT apply when legally required. IIA Code: “shall not disclose…unless legal or professional responsibility”. Std 2440.
*CASE 4: Due Professional Care – Scope Limitation*
Audit Committee demands you finish AP audit in 2 days vs planned 2 weeks due to IPO. You cannot test key vendor controls.
*Q4.* To comply with Std 1220 – Due Professional Care, you must:
A. Complete in 2 days and issue report with scope limitation
B. Refuse engagement if adequate work cannot be done
C. Use prior year workpapers to fill gap
D. Issue clean report based on limited testing to meet deadline
*Answer: B*
*Rationale:* Std 1220.A1 – Due care means consider extent of work needed. If scope imposed prevents conclusion, must decline or qualify. A without qualifying = wrong. D violates integrity.
*CASE 5: Integrity – Pressure to Omit Finding*
You find $2M revenue overstatement. CFO says “Board will fire me. It’s immaterial to $5B company. Remove it or you’re off future audits.”
*Q5.* Principle of Integrity requires:
A. Remove finding since it’s < 0.1% materiality
B. Report finding; materiality doesn’t override fraud
C. Report to Audit Committee only, not in final report
D. Negotiate with CFO to adjust in next quarter
*Answer: B*
*Rationale:* Integrity = honesty. Fraud is always material qualitatively. Std 2060 + 2320. Materiality thresholds don’t apply to intentional misstatement.
### Question
An internal auditor becomes aware that a comment made in a draft engagement report would seriously damage the reputation of a senior manager, even though the finding is factually accurate and supported by sufficient evidence. The auditor’s supervisor pressures the auditor to soften the wording, but the auditor knows the change would misrepresent the risk to the organization.
According to The IIA’s Code of Ethics, which of the following actions is **most appropriate** for the auditor to take?
A. Modify the wording as requested by the supervisor to maintain a positive working relationship.
B. Omit the finding entirely to avoid conflict with management.
C. Report the situation to the chief audit executive or audit committee, and ensure the accurate wording is retained.
D. Resign from the internal audit activity to avoid being associated with an unfair report.
*Correct answer:** **C**
### Explanation (rationale)
- The IIA’s **Code of Ethics** requires internal auditors to act with **integrity** and **objectivity**, and to disclose all material facts that, if omitted, could distort the engagement communication. [1][2]
- Softening or omitting a fact‑based finding under pressure would violate **objectivity** and the requirement to communicate truthfully. [1][3]
- The appropriate course is to escalate the matter to a higher authority (CAE or audit committee) while preserving the accuracy of the report, which upholds the principles of **ethics**, **professionalism**, and **independence** under the Global Internal Audit Standards.
Section d…..
1. **Which of the following best describes the purpose of The IIA’s Code of Ethics?**
A. A guide for external audit only
B. A set of enforceable behavioral expectations for internal auditors
C. A marketing brochure for internal audit
D. A framework for IT‑only audits
**Answer: B**
2. **An internal auditor uses confidential information to buy shares in a supplier. This action most directly violates:**
A. Competency
B. Objectivity
C. Integrity
D. Confidentiality
**Answer: D**
3. **An internal auditor is asked to audit a department where a close relative is the manager. The best action is to:**
A. Proceed because the auditor knows the environment well
B. Disclose the relationship and withdraw from the engagement
C. Limit the scope to financial data only
D. Ask the relative to sign the report
**Answer: B**
4. **Which of the following is a core principle of the Code of Ethics?**
A. Profit maximization
B. Objectivity
C. Operational speed
D. Confidentiality (only)
**Answer: B**
5. **An auditor receives an expensive gift from a client being audited. Accepting this gift primarily threatens which principle?**
A. Competency B. Objectivity
C. Integrity D. Confidentiality
**Answer: C**
6. **An internal auditor is pressured to soften a fact‑based negative finding. The auditor should:**
A. Delete the finding to please management
B. Refuse and, if necessary, escalate to the CAE or audit committee
C. Move it to an appendix
D. Change the wording to be vague
**Answer: B**
7. **An internal auditor discovers that a policy is violated but the practice is “common.” The auditor should:**
A. Ignore it because it is widespread
B. Document and communicate the violation
C. Discuss it only with the violator
D. Amend the policy to match practice
*Answer: B**
8. **Which of the following best describes “objectivity” in internal auditing?**
A. Auditing only highly profitable areas
B. Avoiding bias and conflicts of interest
C. Avoiding documentation
D. Following management directions without question
*Answer: B**
9. **An internal auditor is asked to provide both consulting and then audit services on the same project. This arrangement most directly threatens:**
A. Competency
B. Objectivity
C. Confidentiality
D. Independence
*Answer: B**
10. **An auditor uses audit information to gain a personal financial advantage. This violates:**
A. Integrity only
B. Confidentiality only
C. Both integrity and confidentiality
D. Competency only
**Answer: C**
11. **An internal auditor is told not to report “mildly unfavorable” findings. This pressure most directly threatens:**
A. Competency
B. Objectivity
C. Confidentiality
D. Integrity
**Answer: D**
12. **Which of the following is required under the “Competency” principle?**
A. Internal auditors must have a degree in every subject
B. Internal auditors must perform services only when they have the necessary knowledge and skills
C. Internal auditors must avoid all training
D. Internal auditors must complete all engagements in one day
*Answer: B**
13. **An internal auditor is asked to sign a report that contains a false statement. The auditor should:**
A. Sign it to avoid conflict
B. Refuse to sign and escalate
C. Soften the wording and sign
D. Ask the client to sign instead
*Answer: B**
14. **An internal auditor overhears a confidential discussion about a merger. The best action is to:**
A. Use the information to buy shares
B. Share it with family members
C. Treat it as confidential and not use it personally
D. Post it on social media
**Answer: C**
15. **Which of the following is correct about organizational independence of the internal audit function?**
A. It reports only to the CFO
B. It is overseen by the audit committee and has direct access to the board
C. It is funded only by the department being audited
D. It evaluates only external auditors
**Answer: B**
16. **An auditor is asked to audit a system they themselves implemented. This threatens:**
A. Competency
B. Objectivity
C. Confidentiality
D. Independence
**Answer: B**
17. **An internal auditor is offered a job promotion contingent on deleting negative findings. The auditor should:**
A. Delete the findings and take the promotion
B. Document the pressure and refuse to delete findings
C. Seek the opinion of the external auditor
D. Redistribute the findings to another unit
**Answer: B**
18. **An internal auditor is asked to “go easy” on a favorite department. The auditor should:**
A. Reduce the sample size
B. Apply the same procedures and standards as to all departments
C. Avoid the department entirely
D. Ignore all findings
**Answer: B**
19. **Which of the following supports due professional care?**
A. Using only prior‑year checklists
B. Applying appropriate professional skepticism and judgment
C. Minimizing sample sizes
D. Avoiding communication with stakeholders
**Answer: B**
20. **An internal auditor is asked to perform both internal audit and operational management for the same unit. This primarily threatens:**
A. Competency
B. Objectivity
C. Confidentiality
D. Independence
**Answer: B**
21. **An internal auditor is uncertain about the legality of a transaction. The best action is to:**
A. Assume it is legal
B. Ignore it if not material
C. Seek legal or compliance advice and document the steps
D. Disclose it to the media
**Answer: C**
22. **An internal auditor is asked to keep a negative finding confidential from the audit committee. This request primarily threatens:**
A. Integrity
B. Objectivity
C. Competency
D. Confidentiality
*Answer: A**
23. **Which of the following best describes the relationship between the Code of Ethics and the Global Internal Audit Standards?**
A. The Standards override the Code
B. The Code provides ethical expectations; the Standards provide structural and procedural guidance
C. The Code is optional
D. The Code applies only to external auditors
**Answer: B**
24. **An internal auditor is asked to provide consulting advice and then to audit the same advice. This is most likely to impair:**
A. Competency
B. Objectivity
C. Confidentiality
D. Independence
*Answer: B**
25. **An internal auditor is asked to provide a written opinion on a matter outside their expertise. The auditor should:**
A. Issue an opinion anyway
B. Decline or seek appropriate expertise
C. Copy another auditor’s opinion
D. Wait until the next training cycle
*Answer: B**
26. **An auditor discovers that a prior‑year deficiency still exists. The auditor should:**
A. Ignore it because it is old
B. Re‑assess it based on current evidence
C. Delete all references
D. Not document it
*Answer: B**
27. **An internal auditor is offered a small gift from a client. The best practice is to:**
A. Keep it because it is small
B. Decline or follow organizational policy on gifts
C. Exchange it for cash
D. Accept it but not tell anyone
*Answer: B**
28. **An internal auditor is asked to “not reopen” a prior‑year issue. The auditor should:**
A. Ignore the prior‑year issue
B. Re‑evaluate the issue based on current conditions
C. Delete all references to it
D. Agree verbally but not in writing
**Answer: B**
29. **Which of the following demonstrates professionalism in internal auditing?**
A. Avoiding all documentation
B. Acting in the best interest of the organization while upholding ethical standards
C. Focusing only on financial statements
D. Avoiding interaction with the audit committee
*Answer: B**
30. **An internal auditor is asked to prepare financial statements for a client. This activity is most closely related to:**
A. Integrity
B. Competency
C. Objectivity
D. Independence
**Answer: B**
31. **An internal auditor is asked to not disclose a material fact in a report. This action violates:**
A. The Standards only
B. The Code of Ethics only
C. Both the Standards and the Code
D. Neither
**Answer: C**
32. **An internal auditor is asked to audit a project where they have a significant financial interest. The auditor should:**
A. Proceed because they are honest
B. Disclose the interest and withdraw or have an independent lead
C. Limit the scope to non‑financial areas
D. Store all data on a personal device
*Answer: B**
33. **Which of the following is a requirement under the “Confidentiality” principle?**
A. Auditors may share information freely with colleagues
B. Auditors shall not disclose information without appropriate authority unless legally or professionally required
C. Auditors must publish all findings publicly
D. Auditors must store all information on personal devices
*Answer: B**
34. **An internal auditor is asked to use sensitive data for a non‑audit purpose. The auditor should:**
A. Agree because it is “for the good of the organization”
B. Only use it if the senior manager says it is okay
C. Refuse unless there is proper authorization and it aligns with policy
D. Share it with the external auditor
**Answer: C**
35. **An internal auditor is asked to provide a favorable opinion on a weakly controlled process. The auditor should:**
A. Issue a favorable opinion to support management
B. Express an opinion based on evidence and professional judgment
C. Refuse to issue any opinion
D. Ask the process owner to sign the report
**Answer: B**
36. **An internal auditor is considering accepting a consulting role with a major vendor. The auditor should:**
A. Accept because it is outside office hours
B. Check for conflicts of interest and policy compliance
C. Ask the vendor to pay for the audit
D. Do the work only if the vendor is foreign
Answer: B**
37. **An internal auditor is asked to keep evidence from a finding out of the report. This primarily threatens:**
A. Integrity
B. Objectivity
C. Competency
D. All of the above
**Answer: A**
38. **An internal auditor believes their judgment is impaired due to a personal relationship with a client. The auditor should:**
A. Continue but document the concern
B. Disclose the impairment and withdraw from the engagement
C. Transfer the impairment to a colleague
D. Ask the client to certify the report
**Answer: B**
39. **Which of the following is a key ethical behavior when communicating audit results?**
A. Avoiding all negative findings
B. Communicating findings clearly, factually, and without bias
C. Sending reports only by email
D. Sharing findings only with the CEO
*Answer: B**
40. **An internal auditor is asked to perform an audit shortly after designing a control for the same area. The auditor should:**
A. Proceed because they know the control well
B. Decline or ensure independence and objectivity are preserved
C. Limit the scope to non‑control areas
D. Ask the vendor to review the report
*Answer: B**
41. **An internal auditor is offered a bribe to change an audit opinion. The auditor should:**
A. Accept if the bribe is large
B. Report the incident to appropriate authorities
C. Accept but reduce the scope
D. Change the opinion only if the finding is not material
Answer: B**
42. **Which of the following is correct about the Code of Ethics?**
A. It applies only to staff‑level auditors
B. It applies to all internal auditors regardless of level
C. It is a guideline but not important for the CIA exam
D. It applies only to for‑profit entities
*Answer: B**
43. **An internal auditor is asked to “not pursue” a finding in exchange for improvement. This action threatens:**
A. Competency
B. Objectivity
C. Integrity
D. Confidentiality
*Answer: C**
44. **An auditor discovers evidence of fraud involving a senior executive. The auditor should:**
A. Keep it confidential to avoid embarrassment
B. Discuss it only with the executive
C. Report it to appropriate parties within the organization
D. Wait until the annual report cycle
*Answer: C**
45. **Which of the following is a key element of “professionalism” in internal auditing?**
A. Avoiding documentation
B. Upholding ethical standards and acting in the organization’s best interest
C. Focusing only on financial statement audits
D. Avoiding the audit committee
*Answer: B**
46. **An internal auditor is asked to accept a paid speaking engagement related to a client’s industry. The auditor should:**
A. Accept without disclosure
B. Accept only if the client pays
C. Disclose any potential conflicts and ensure neutrality
D. Refuse all speaking engagements
*Answer: C**
47. **An internal auditor is asked to reuse last‑year’s working papers without updating them. This threatens:**
A. Integrity
B. Objectivity
C. Competency
D. Confidentiality
*Answer: C**
48. **An internal auditor is asked to not document a finding verbally discussed with management. The auditor should:**
A. Comply to avoid conflict
B. Ensure the finding is properly documented
C. Move it to an appendix
D. Send it by text message
*Answer: B**
49. **An internal auditor is asked to provide a written assurance opinion on a matter they have not audited. The auditor should:**
A. Issue the opinion anyway
B. Issue the opinion only if management wants it
C. Refuse or clearly state the limitation
D. Delegate it to a junior auditor
**Answer: C**
50. **An internal auditor discovers that their own prior audit opinion may have been incorrect. The auditor should:**
A. Ignore it because it is too late
B. Keep it confidential to avoid embarrassment
C. Communicate the issue to the CAE and appropriate parties
D. Blame the prior‑year team
**Answer: C**
www.gmsisuccess.in
www.finzo.pw for online exam mocktest
No comments:
Post a Comment