Wednesday, September 9, 2026

COSO Internal Control—Integrated Framework, COBIT 2019, governance, risk management, control, internal audit, and the distinction between governance and management.

COSO Internal Control—Integrated Framework, COBIT 2019, governance, risk management, control, internal audit, and the distinction between governance and management.

 high-difficulty 50-question CIA Part 1 case-based practice assessment, deliberately designed around the negative-question traps used in difficult exam questions: EXCEPT, NOT, LEAST likely, FALSE, and INCORRECT.

It integrates COSO Internal Control—Integrated Framework, COBIT 2019, governance, risk management, control, internal audit, and the distinction between governance and management.

CIA PART 1 — ADVANCED CASE-BASED PRACTICE EXAM

COSO + COBIT + Governance + Risk + Internal Control

50 Questions | High Difficulty | Negative-Style


SECTION A — COSO INTERNAL CONTROL + GOVERNANCE

Q1. COSO Control Environment — EXCEPT

A multinational company has experienced rapid growth. The board wants to strengthen the control environment. Which of the following is NOT an appropriate action?

A. Establishing clear accountability for internal-control responsibilities
B. Demonstrating management's commitment to integrity and ethical values
C. Ensuring appropriate oversight by those charged with governance
D. Allowing senior executives to override established controls whenever operational urgency exists


Q2. Risk Assessment — LEAST likely

A company is introducing an AI-based credit approval system. Management performs a risk assessment before implementation.

Which activity is LEAST likely to represent an appropriate COSO risk-assessment activity?

A. Identifying risks arising from changes in technology
B. Considering fraud risk separately from ordinary operational risks
C. Assessing whether identified risks could prevent achievement of objectives
D. Assuming existing controls remain effective because they worked under the previous system


Q3. Control Activities — EXCEPT

A manufacturing company introduces automated purchasing controls. Which of the following is NOT primarily a control activity?

A. Segregation of purchasing and payment responsibilities
B. Authorization of purchase orders above specified limits
C. Reconciliation of supplier statements
D. Establishing the organization's ethical tone at the top


Q4. Information & Communication — NOT

The internal audit director concludes that the organization has effective information and communication under COSO.

Which finding would NOT support that conclusion?

A. Relevant information reaches employees in sufficient time
B. Employees understand their control responsibilities
C. Critical control deficiencies are communicated to appropriate parties
D. Management restricts unfavorable information from reaching the audit committee


Q5. Monitoring Activities — LEAST likely

Which activity is LEAST likely to constitute a monitoring activity under COSO?

A. Management periodically evaluates whether controls continue to operate effectively
B. Internal audit performs an independent assessment of selected controls
C. A supervisor reviews exception reports generated by an automated system
D. The organization designs a new approval control after identifying a risk


Q6. COSO Principles — EXCEPT

Which of the following is NOT one of the fundamental COSO internal-control principles?

A. The organization demonstrates commitment to integrity and ethical values
B. The organization selects and develops competent individuals
C. The organization identifies and assesses risks to achievement of objectives
D. The organization guarantees that all identified risks will be completely eliminated


Q7. Fraud Risk — MOST appropriate exception

During a fraud-risk assessment, management identifies an incentive for sales managers to manipulate year-end revenue.

Which action is LEAST appropriate?

A. Assessing the opportunity to manipulate revenue
B. Considering management override
C. Evaluating pressures and incentives
D. Concluding that fraud cannot occur because the external auditor reviews revenue


Q8. Control Environment — NOT

Which statement is NOT consistent with a strong COSO control environment?

A. The board provides appropriate oversight
B. Management establishes accountability
C. Employees understand that ethical violations have consequences
D. Senior executives are exempt from control requirements applicable to other employees


Q9. COSO Change Management — EXCEPT

A company acquires a technology startup. Which activity would NOT normally be associated with COSO risk assessment?

A. Evaluating risks created by the acquisition
B. Assessing changes in personnel and systems
C. Reassessing existing control assumptions
D. Assuming that controls in the acquired company automatically align with the parent company's objectives


Q10. Internal Control Limitations — LEAST likely

Which of the following is LEAST likely to represent an inherent limitation of internal control?

A. Human judgment may be imperfect
B. Collusion can circumvent segregation of duties
C. Management may override controls
D. Properly designed controls provide absolute assurance against all risks


SECTION B — COBIT 2019 + GOVERNANCE/MANAGEMENT

Q11. COBIT Governance — EXCEPT

Which of the following is NOT a governance activity under COBIT?

A. Evaluate stakeholder needs
B. Direct through prioritization and decision-making
C. Monitor performance and compliance
D. Personally perform every IT management activity


Q12. Governance vs. Management — LEAST likely

The board wants to improve enterprise IT governance. Which activity is LEAST likely to be a governance responsibility?

A. Evaluating stakeholder needs
B. Directing priorities
C. Monitoring governance outcomes
D. Managing the organization's daily IT service desk


Q13. COBIT Governance System Principles — NOT

Which of the following is NOT a COBIT 2019 governance-system principle?

A. Provide stakeholder value
B. Dynamic governance system
C. Governance distinct from management
D. Eliminate all enterprise risk


Q14. COBIT Governance Framework — EXCEPT

Which statement is NOT consistent with COBIT 2019's governance framework principles?

A. The framework should be based on a conceptual model
B. The framework should be open and flexible
C. The framework should align with major standards and regulations
D. The framework should prescribe exactly the same governance design for every enterprise


Q15. COBIT Design Factors — LEAST likely

An organization is designing a customized governance system using COBIT.

Which factor is LEAST likely to be considered?

A. Enterprise strategy
B. Risk profile
C. Compliance requirements
D. The personal preference of the IT manager, regardless of enterprise objectives


Q16. COBIT Governance Components — EXCEPT

Which is NOT a typical component of a governance system?

A. Processes
B. Organizational structures
C. Information
D. Guaranteed achievement of every strategic objective


Q17. COBIT Governance Objective — NOT

A board establishes an enterprise governance objective for information and technology.

Which statement is NOT appropriate?

A. Governance should consider stakeholder needs
B. Governance should evaluate whether objectives are being achieved
C. Governance should provide direction
D. Governance should replace operational management completely


Q18. Governance Information — LEAST likely

Which information would be LEAST useful to the governing body when evaluating enterprise IT performance?

A. Significant technology risks
B. Achievement of strategic objectives
C. Major regulatory compliance issues
D. Every individual help-desk ticket regardless of significance


Q19. COBIT Performance Management — EXCEPT

Which statement about performance management under COBIT is INCORRECT?

A. Performance should be evaluated against objectives
B. Performance information supports decision-making
C. Performance measurement can help identify improvement opportunities
D. Performance measurement guarantees that management decisions will always be correct


Q20. COBIT + Enterprise Alignment — NOT

A company wants IT investments to support business strategy.

Which action is NOT consistent with effective governance?

A. Aligning IT objectives with enterprise objectives
B. Considering stakeholder needs
C. Prioritizing investments according to strategic value and risk
D. Allowing IT projects to proceed independently of enterprise strategy


SECTION C — COSO + COBIT INTEGRATION

Q21. Integrated Governance — EXCEPT

An organization uses COBIT for governance of information and technology and COSO for internal control.

Which statement is NOT correct?

A. COBIT can help address governance and management of enterprise information and technology
B. COSO provides a framework for internal control
C. The two frameworks can complement each other
D. COBIT completely replaces the need for an internal-control framework


Q22. Board vs. Management — LEAST likely

A board discovers that cybersecurity risk has increased significantly.

Which response is LEAST likely to represent the board's governance role?

A. Evaluating whether management's cybersecurity strategy addresses stakeholder needs
B. Directing management toward appropriate cybersecurity priorities
C. Monitoring significant cybersecurity risk indicators
D. Personally configuring firewalls for the organization


Q23. COSO + COBIT — NOT

Which statement is NOT accurate regarding the relationship between COSO and COBIT?

A. COSO focuses broadly on internal control
B. COBIT provides a framework focused on enterprise governance and management of information and technology
C. COBIT can support implementation of technology-related controls
D. COSO and COBIT are identical frameworks serving exactly the same purpose


Q24. Risk Alignment — EXCEPT

A bank uses COSO to assess enterprise risks and COBIT to govern technology.

Which activity would NOT demonstrate proper alignment?

A. Linking cybersecurity risks to business objectives
B. Evaluating technology risks in the enterprise risk context
C. Establishing technology objectives independent of business objectives
D. Monitoring significant risks and controls


Q25. Three Lines Model + COSO — LEAST likely

A CAE is evaluating the organization's internal-control structure.

Which activity is LEAST likely to be an internal-audit responsibility?

A. Providing independent assurance
B. Evaluating control effectiveness
C. Advising on improvements while maintaining objectivity
D. Assuming management's responsibility for designing and operating controls


Q26. Governance Information — EXCEPT

The audit committee requests information concerning the organization's IT governance.

Which item is LEAST appropriate as a primary governance-level indicator?

A. Major technology risks
B. Significant cybersecurity incidents
C. Progress toward strategic technology objectives
D. The exact number of keystrokes entered by each employee


Q27. Control Objective Alignment — NOT

A technology control is considered effective only when:

A. It addresses a relevant risk
B. It supports achievement of an objective
C. It operates as designed
D. It exists solely because the IT department considers it useful


Q28. Risk Response — LEAST likely

A company identifies a significant cloud-service risk.

Which response is LEAST likely to be appropriate?

A. Avoiding the activity when risk exceeds organizational tolerance
B. Reducing the risk through appropriate controls
C. Sharing/transferring certain risks through contractual arrangements
D. Automatically accepting every risk because technology is essential to operations


Q29. COSO Objectives — EXCEPT

Which of the following is NOT one of COSO's three broad categories of objectives?

A. Operations
B. Reporting
C. Compliance
D. Guaranteed profitability


Q30. COBIT and Stakeholders — NOT

Which statement is NOT consistent with the stakeholder-oriented nature of COBIT governance?

A. Stakeholder needs influence governance decisions
B. Different stakeholders may have different priorities
C. Governance should seek to balance stakeholder needs
D. Only the CIO's preferences should determine technology priorities


SECTION D — ADVANCED CASE-BASED QUESTIONS

Q31. Case: ERP Implementation — EXCEPT

A global manufacturer implements a new ERP system. The CIO reports that implementation was successful because the system went live on time.

Internal audit identifies:

  • No segregation of incompatible access privileges

  • Inadequate user access reviews

  • Poor change-management documentation

  • Strong project governance

  • Regular reporting to the steering committee

Which conclusion is LEAST justified?

A. The organization has significant control risks
B. Timely implementation alone does not establish control effectiveness
C. Governance oversight appears to have some strengths
D. The ERP implementation should automatically be considered successful because it met its deadline


Q32. Case: Cybersecurity — NOT

A financial institution experiences a ransomware incident.

Management argues that cybersecurity controls were effective because no incident occurred during the prior three years.

Which statement is NOT appropriate?

A. Historical absence of incidents does not prove control effectiveness
B. Threats and vulnerabilities can change
C. Monitoring should consider changing conditions
D. Prior success proves that the existing controls will remain effective indefinitely


Q33. Case: Management Override — EXCEPT

The CEO instructs the CFO to bypass a purchasing approval because a major supplier may cancel an important contract.

Which statement is NOT correct?

A. Management override represents an inherent limitation of internal control
B. The incident may increase fraud risk
C. The organization should consider whether compensating controls exist
D. The CEO's authority automatically makes the override an effective control


Q34. Case: Audit Committee — LEAST likely

The audit committee is reviewing the organization's governance system.

Which activity is LEAST likely to be an appropriate audit-committee responsibility?

A. Overseeing financial reporting
B. Considering significant risks and control issues
C. Providing oversight of internal audit
D. Operating the organization's daily accounting controls


Q35. Case: Cloud Computing — EXCEPT

A company moves critical applications to a cloud provider.

Which statement is NOT appropriate?

A. Management should assess third-party risks
B. Contractual controls should be evaluated
C. Security responsibilities should be clearly defined
D. Outsourcing automatically transfers ultimate accountability for enterprise risk to the cloud provider


Q36. Case: Data Governance — NOT

A company develops a data-governance program.

Which action would NOT strengthen governance?

A. Establishing data ownership
B. Defining data-quality responsibilities
C. Aligning data decisions with business objectives
D. Allowing every department to define conflicting data standards independently


Q37. Case: AI Decision System — LEAST likely

A bank uses AI to approve loans.

Which control is LEAST likely to be sufficient by itself?

A. Monitoring model performance
B. Reviewing significant exceptions
C. Establishing accountability for model decisions
D. Assuming the AI system is objective because it is automated


Q38. Case: Risk Appetite — EXCEPT

The board establishes a risk appetite statement.

Which statement is NOT correct?

A. Risk appetite provides direction for risk-taking
B. Risk appetite should relate to organizational objectives
C. Risk appetite can support management decision-making
D. Risk appetite means management must eliminate every identified risk


Q39. Case: Internal Audit Independence — NOT

The CAE reports functionally to the audit committee and administratively to the CEO.

Which action would NOT support organizational independence?

A. Audit committee approval of the internal audit charter
B. Direct access to the audit committee chair
C. Management approval of every individual audit conclusion before reporting
D. Periodic communication with the audit committee


Q40. Case: Control Deficiency — LEAST likely

An internal auditor discovers that employees can modify vendor bank-account information without independent review.

Which response is LEAST likely to be appropriate?

A. Assessing the risk of unauthorized payments
B. Determining whether compensating controls exist
C. Evaluating the design and operating effectiveness of related controls
D. Assuming the control is effective because no fraudulent payment has yet been detected


SECTION E — ULTRA-CHALLENGING NEGATIVE QUESTIONS

Q41. Which is NOT a Governance Question?

During an enterprise technology strategy meeting, which question is LEAST likely to be a governance-level question?

A. Does the technology strategy support stakeholder needs?
B. Are technology investments aligned with enterprise objectives?
C. Are significant technology risks within acceptable boundaries?
D. Which individual employee should reset a user's password today?


Q42. COSO Principle — EXCEPT

Which statement is NOT consistent with COSO's approach to risk assessment?

A. Risks are assessed in relation to objectives
B. Fraud risk is specifically considered
C. Significant changes are evaluated
D. Risk assessment occurs only once when the organization is established


Q43. COBIT — LEAST likely

Which statement is LEAST likely to be consistent with COBIT's governance philosophy?

A. Governance evaluates stakeholder needs
B. Governance provides direction
C. Management executes the direction established through governance
D. Governance and management are interchangeable terms


Q44. Internal Control — NOT

Which statement is NOT an appropriate conclusion when an organization has well-designed internal controls?

A. Controls can provide reasonable assurance
B. Controls cannot guarantee achievement of objectives
C. Human error remains possible
D. Well-designed controls eliminate the possibility of fraud


Q45. Technology Risk — EXCEPT

An organization identifies a critical cybersecurity vulnerability.

Which action would NOT be appropriate?

A. Assessing the likelihood and impact
B. Considering risk treatment options
C. Monitoring remediation
D. Assuming the vulnerability is immaterial because no breach has occurred yet


Q46. Governance vs. Management — LEAST likely

A board has approved a technology governance framework.

Which activity should LEAST likely be performed by the board?

A. Establishing broad direction
B. Evaluating whether stakeholder needs are addressed
C. Monitoring significant outcomes
D. Managing individual software-development tasks


Q47. COSO Monitoring — NOT

Which statement about monitoring is NOT correct?

A. Monitoring can involve ongoing evaluations
B. Separate evaluations can provide assurance
C. Deficiencies should be communicated to appropriate parties
D. Monitoring is unnecessary once controls have initially been tested


Q48. Integrated Frameworks — EXCEPT

A company uses COSO, COBIT, ISO 27001 and its own internal policies.

Which statement is NOT correct?

A. Multiple frameworks can coexist
B. Frameworks can complement one another
C. Management should map overlapping requirements where appropriate
D. Using multiple frameworks automatically guarantees effective governance


Q49. MOST DIFFICULT — Negative Case

A technology company has:

  • Excellent cybersecurity controls

  • Strong IT policies

  • Effective automated controls

  • Regular internal audits

  • Significant misalignment between technology investments and corporate strategy

The board claims that IT governance is effective because controls are strong.

Which statement is LEAST likely to support the board's conclusion?

A. Effective controls do not automatically establish strategic alignment
B. Governance includes evaluating whether stakeholder needs are addressed
C. IT governance involves alignment with enterprise objectives
D. Strong operational controls prove that technology governance is effective


Q50. MASTER INTEGRATION CASE — EXCEPT

A multinational organization has implemented COSO and COBIT. The board establishes strategic objectives, management develops operating plans, IT implements technology solutions, and internal audit provides independent assurance.

Internal audit discovers that:

  • The board receives insufficient information regarding emerging technology risks.

  • Management has implemented several controls without linking them to identified risks.

  • IT objectives are not fully aligned with enterprise objectives.

  • Internal audit independently evaluates the control environment.

  • The audit committee regularly communicates with the CAE.

Which statement is NOT correct?

A. The information deficiency may represent a governance concern
B. Controls should be linked to relevant risks and objectives
C. Misalignment between IT objectives and enterprise objectives can indicate a governance weakness
D. Because internal audit performs independent evaluations, governance and management responsibilities are automatically fulfilled


🔥 CIA NEGATIVE-QUESTION TRAP SHEET

When you see these words, slow down:

Exam wordingWhat you should do
EXCEPTFind the one that does NOT belong
NOTIdentify the incorrect/non-applicable statement
LEAST likelyFind the weakest/least appropriate option
MOST likely NOTFind the strongest exception
INCORRECTLook for the false statement
TRUE EXCEPTThree are true; one is false
PRIMARILYIdentify the principal responsibility
BESTSeveral may be reasonable; select the strongest
FIRSTThink sequence/prioritization
MOST appropriateSelect the answer most aligned with the governing principle

The BIG CIA distinction

COSO → Internal Control

COBIT → Governance & Management of Information and Technology

Board → Governance / oversight

Management → Execution / management

Internal Audit → Independent assurance + advisory role

Controls → Address risks

Objectives → Drive risk assessment

Risk → Does NOT necessarily mean eliminate

Framework → Does NOT guarantee effectiveness

Automation → Does NOT eliminate risk

Outsourcing → Does NOT eliminate accountability

Strong controls → Do NOT automatically mean strong governance

Internal audit → Does NOT own management's controls

No comments:

Post a Comment