Case-based multiple-choice questions (MCQs) for the
Certified Internal Auditor (CIA) Part 1 exam test your ability to apply fraud
risk concepts—such as the fraud triangle, control deficiencies, and red
flags—to real-world audit scenarios.
Section A…
Case 1: The Procurement Vulnerability
Scenario:During
a routine procurement engagement, an internal auditor discovers that a single
junior buyer has the authority to create new vendors in the vendor master file,
issue purchase orders, and approve corresponding vendor invoices below a
threshold of $10,000. Reviewing transactions under this threshold reveals
multiple payments made to a newly created consulting firm with an address
matching the junior buyer's residential address. No other supervisory reviews
or independent matching procedures exist for invoices under the $10,000 limit.
Question 1:
Which element of the Fraud Triangle
is most directly highlighted and enabled by the structural design of this
procurement process?
- A.
Pressure, because the buyer is living beyond their means due to personal
debt.
- B.
Opportunity, because weak segregation of duties allows one person to
originate, execute, and conceal transactions.
- C.
Rationalization, because the buyer feels underpaid compared to industry
peers.
- D.
Incentive, because management set aggressive cost-reduction targets for
the department.
Correct Answer: BRationale:
Opportunity arises when weak internal controls—such as a lack of segregation of
duties—allow an individual to commit and conceal fraud without immediate
detection. The other elements (pressure, rationalization) are internal
psychological drivers, whereas the system design flaw creates
the direct structural opportunity.
Case 2: The Overworked Controller
Scenario:An
internal audit team is assessing the overall control environment and fraud risk
governance of a mid-sized manufacturing division. Interviews and observations
reveal that the division’s controller works late evenings and weekends, refuses
to delegate core accounting tasks, and has not taken consecutive annual
vacations or time off in over two years. Furthermore, the controller handles
monthly bank reconciliations while simultaneously holding journal entry posting
access.
Question 2:
Which combination of behavioral red
flags and control risks is most evident in this scenario?
- A.
Management override of controls and aggressive revenue recognition.
- B.
Refusal to take vacation combined with inadequate segregation of duties
over cash.
- C.
Document falsification and dual-custody breakdown.
- D.
Lapping of accounts receivable and lifestyle changes.
Correct Answer: BRationale: An employee refusing to take
vacation or time off is a classic behavioral red flag, often because continuous
presence is required to maintain concealment of an ongoing misappropriation.
Combining this with custody of assets and record-keeping (bank reconciliations
plus journal entry access) violates basic segregation principles.
Case 3: Auditor's Responsibility upon Suspicion
Scenario:While
testing inventory receipts in a warehouse, an internal auditor notices that
several receiving reports show quantities significantly lower than the packing
slips, yet the full vendor invoices were paid in full. The warehouse supervisor
casually mentions that the missing inventory represents "defective scrap
written off," but there are no formal write-off documents, approval
signatures, or credit memos from the vendor.
Question 3:
According to IIA guidance and
professional standards, what is the internal auditor's most appropriate
immediate course of action?
- A.
Immediately confront the warehouse supervisor with accusations of asset
misappropriation.
- B. Expand
the sample size, gather sufficient preliminary evidence, and inform
management or the appropriate authorities as defined by the organization's
fraud program.
- C.
Disregard the discrepancy because the individual dollar amounts of missing
inventory appear immaterial to the financial statements as a whole.
- D.
Immediately halt the entire internal audit engagement and launch a
full-scale forensic criminal investigation.
Correct Answer: BRationale: Internal auditors must
evaluate indicators of fraud and expand procedures to determine if further
action is warranted. They should gather enough preliminary evidence and report
suspicions to the appropriate level of management or the board rather than immediately
accusing individuals or stepping out of their mandate into full police
investigations
Section B…
CIA Part 1: Fraud
Risk Management Case Quiz
1 / 5
1.
Sarah is the
accounting manager at a mid-sized manufacturing firm. The company is publicly
traded, and executive management's bonuses are tied strictly to achieving
aggressive quarterly net income targets. Sarah is personally facing foreclosure
on her home and massive medical debt. Under intense pressure from the CFO to
"find a way" to make the numbers work, Sarah capitalizes routine
operating expenses as capital assets to artificially inflate net income. Which
element of the fraud triangle does Sarah’s personal debt and the CFO’s bonus
structure primarily represent?
A.
Rationalization
B.
Opportunity
C.
Pressure/Incentive
D.
Collusion
Answer C…
A.
Rationalization
Incorrect. Rationalization
involves the mindset or justification the individual uses to make the unethical
act feel acceptable, rather than the external or internal driving force.
B.
Opportunity
Incorrect. Opportunity
relates to weaknesses in internal control that allow a person to commit and
conceal fraud, not the incentive or need that motivates them.
C.
Pressure/Incentive
Correct! Both personal
financial distress (foreclosure/debt) and unrealistic performance goals/bonuses
create the incentive or pressure that drives an individual to commit fraud.
D.
Collusion
Incorrect. Collusion refers
to cooperation between two or more individuals to bypass controls, which is a
structural aspect rather than the primary motivational driver described.
2.
David has worked
as the sole accounts payable clerk at a wholesale distributor for 15 years. He
is universally trusted by management, never takes consecutive days off, and
processes all vendor invoices, inputs banking details, and performs monthly
bank reconciliations without review or secondary authorization. An internal
auditor discovers multiple payments made to a shell company owned by David.
Which condition of the fraud triangle enabled David to execute this scheme?
A.
Ineffective internal controls
creating an Opportunity
B.
An overwhelming Financial
Pressure due to personal debts
C.
A robust Rationalization that
the company owes him for years of low pay
D.
External market incentives
forcing the behavior
Answer A…
A.
Ineffective internal controls
creating an Opportunity
Correct! A lack of
segregation of duties and lack of independent supervisory review create a
massive window of opportunity for an employee to commit and conceal fraud.
B.
An overwhelming Financial
Pressure due to personal debts
Incorrect. While David may
have had financial motivations, the scenario highlights his total control over
incompatible duties, which directly addresses the structural ease of committing
the fraud.
C.
A robust Rationalization that
the company owes him for years of low pay
Incorrect. Although
rationalization likely existed, the absence of segregation of duties is the
primary environmental factor that physically allows the execution of the
scheme.
D.
External market incentives
forcing the behavior
Incorrect. External market
incentives do not explain an internal AP clerk embezzling through shell
companies; internal control failure is the core facilitator here.
3.
During an
operational audit of the procurement department, the internal auditor notices
that the senior buyer of IT equipment drives a luxury sports car far exceeding
his salary level, refuses to take annual vacations, and consistently awards
contracts to a vendor whose primary contact shares the same last name and home
address as the buyer. How should the internal auditor classify these
observations?
A.
Normal operational
efficiencies and personal wealth accumulation
B.
Behavioral and operational
red flags indicating potential conflict of interest and fraud
C.
Evidence of effective
segregation of duties within procurement
D.
Compliance indicators that
vendor selection is objective
Answer B…
A.
Normal operational
efficiencies and personal wealth accumulation
Incorrect. Awarding contracts
to family members and refusing vacations are classic danger signs, not normal
operating behavior or simple wealth building.
B.
Behavioral and operational
red flags indicating potential conflict of interest and fraud
Correct! Living beyond one's
means, refusing to take vacations (which hides concealment), and familial ties
to a vendor are textbook behavioral and operational red flags for procurement
fraud.
C.
Evidence of effective
segregation of duties within procurement
Incorrect. Awarding contracts
to a related party without proper disclosure or competitive bidding
demonstrates a complete breakdown of procurement controls.
D.
Compliance indicators that
vendor selection is objective
Incorrect. Selecting a vendor
with the same last name and home address strongly indicates non-objective,
biased selection and potential kickbacks.
4.
An internal
auditor is conducting a routine review of general ledger journal entries. She
identifies several large, non-standard manual journal entries posted on New
Year’s Eve with descriptions like "miscellaneous accrual" that lack
supporting documentation or required supervisory sign-offs. According to IIA
standards, what is the internal auditor's immediate responsibility?
A.
Ignore the entries since they
are standard year-end closing adjustments
B.
Automatically assume
management is committing fraud and immediately notify local law enforcement
C.
Delete the entries to protect
the integrity of the financial records
D.
Exercise professional
skepticism, investigate the business rationale of these entries, and report the
control deficiency
Answer D..
A.
Ignore the entries since they
are standard year-end closing adjustments
Incorrect. Manual entries
without documentation or sign-offs are major warning signs of potential
manipulation and should never be ignored.
B.
Automatically assume
management is committing fraud and immediately notify local law enforcement
Incorrect. Internal auditors
must evaluate findings and perform further procedures first, rather than
escalating directly outside the organization without proper internal
investigation and reporting protocols.
C.
Delete the entries to protect
the integrity of the financial records
Incorrect. Deleting ledger
entries destroys audit trails and violates fundamental accounting and auditing
principles.
D.
Exercise professional
skepticism, investigate the business rationale of these entries, and report the
control deficiency
Correct! The internal auditor
must exercise professional skepticism, evaluate the lack of
controls/documentation, extend procedures to see if fraud indicators exist, and
report the control breakdown to appropriate management.
5.
The Chief
Executive Officer (CEO) of a retail company routinely bypasses
dual-authorization controls for wire transfers exceeding $100,000, instructing
the treasurer to execute payments directly. When questioned by the internal
audit activity, the CEO dismisses the concern, stating, "I founded this
company; the rules are meant for junior employees, and I need to move fast to
seize market opportunities." This attitude exemplifies which element of
the fraud triangle and organizational risk?
A.
Rationalization and
tone-at-the-top risk leading to management override
B.
Financial pressure caused by
declining retail sales
C.
Lack of technological
opportunity to perform authorized sign-offs
D.
Standard operational
delegation of authority
Answer A….
A.
Rationalization and
tone-at-the-top risk leading to management override
Correct! The CEO's belief
that rules do not apply to leadership represents a toxic tone-at-the-top and an
inherent rationalization that bypasses controls, creating profound risk through
management override.
B.
Financial pressure caused by
declining retail sales
Incorrect. The prompt does
not state sales are declining; the rationale given is entitlement and speed,
not financial hardship.
C.
Lack of technological
opportunity to perform authorized sign-offs
Incorrect. The issue is a
behavioral disregard for established controls by leadership, not a
technological limitation.
D.
Standard operational
delegation of authority
Incorrect. Bypassing
dual-authorization controls explicitly meant for high-value financial transfers
is an override of controls, not a standard delegation process.
Section C…
Case-based multiple-choice questions (MCQs) for CIA Part
1 (Essentials of Internal Auditing) focus on the application of the Fraud Triangle,
control evaluations, indicators (red flags), and auditor responsibilities
regarding fraud.
Case 1: Procurement and Segregation
of Duties
Scenario:During
a routine operational audit of the procurement department, an internal auditor
observes that a single senior buyer has the authority to create new vendor
profiles in the enterprise system, issue purchase orders up to $50,000, and
approve the resulting vendor invoices for payment matching the receiving slips.
Management notes this flexibility is required to maintain operational
efficiency during peak manufacturing cycles.
Question:
Which of the following actions
exposes the organization to the highest fraud risk under this operating
condition?
- A.
Purchase orders are issued sequentially and matched to receiving reports.
- B. The
procurement policy manual was last updated twenty-four months ago.
- C. A
single individual maintains the vendor master file and approves payment
invoices below the review threshold.
- D. Vendor
payment terms are renegotiated annually following a competitive bidding
round.
Correct Answer: CRationale:
Fraud risk is heavily concentrated where a single person holds incompatible
duties, creating the opportunity to both originate and conceal a scheme (e.g.,
setting up a fictitious vendor and authorizing payments). Options A, B, and D
describe standard administrative conditions or ordinary controls rather than a
direct breakdown in segregation of duties.
Case 2: Concealment and Journal
Entry Red Flags
Scenario:An
internal audit team is examining inventory management controls at a regional
distribution center. The warehouse manager recently purchased a luxury sports
car and took no annual leave over a three-year period. The financial statement
review reveals an unusual pattern: inventory counts match physical stock, but
several non-routine manual journal entries were posted at the end of each
quarter, debiting operating expense accounts and crediting inventory values to
absorb unexplained shrinkage.
Question:
To conceal the ongoing theft of
physical inventory assets, which type of accounting entry did the perpetrator
most likely execute through these manual overrides?
- A. Debit
an asset account and credit another asset account.
- B. Debit
an expense account and credit the asset account.
- C. Debit
revenue and credit the asset account.
- D. Debit
the asset account and credit an income statement liability.
Correct Answer: BRationale:
Perpetrators typically conceal asset thefts (like inventory) by writing them
off directly to operating expenses. This debits the expense account (increasing
expenses) and credits the asset account (reducing the recorded balance to match
the stolen reality).
Case 3: Auditor Due Professional
Care and Scope Limitations
Scenario:An
internal auditor finishes an engagement covering cash operations and
disbursements. Two months later, management uncovers a sophisticated skimming
scheme perpetrated through collusion between the cashier and the assistant
controller. The working papers prove that the auditor tested a statistically
valid sample of material transactions, none of which included the fraudulent
items because they were concealed beneath testing materiality thresholds.
Question:
How does this discovery impact the
evaluation of the internal auditor's performance?
- A. The
internal auditors failed to exercise due professional care because fraud
occurred during the active review period.
- B. The
internal auditor acted with due professional care by testing an
appropriate statistical sample of material transactions.
- C. The
internal audit department is legally responsible for guaranteeing 100%
detection in high-risk cash cycles.
- D.
Internal audit standards completely exempt staff from considering fraud
risk in operational environments.
Correct Answer: BRationale:
Internal auditors are not expected to detect every single instance of
sophisticated collusive fraud if they apply due professional care, design
appropriate statistical samples, and execute standard testing. Absolute
assurance is unattainable.
Here
are more case-based practice questions for the CIA Part 1 exam, focusing on preventive
vs. detective controls and behavioral red flags of fraud.
Case 4: Preventive vs. Detective Controls in E-Commerce
Scenario:
An international retailer experiences an incident where an IT systems
administrator uses elevated database privileges to modify customer shipping
addresses on high-value orders right before shipment. This allowed the
administrator to redirect goods to an off-site locker. The fraud was uncovered
three weeks later when customers complained about missing orders, prompting a
forensic review of system access logs.
Question:
Which
of the following modifications represents the most effective preventive
control to mitigate this specific risk in the future?
- A. Implementation of an
automated script that emails a weekly summary of all address changes to
the internal audit team.
- B. Enforcement of
dual-authorization or "four-eyes" approval within the system
before any administrative change to an active order's shipping address
takes effect.
- C. A daily reconciliation
report comparing customer-entered addresses against the final carrier
shipping manifests.
- D. Periodic mandatory
rotation of IT administrators' assigned accounts and system
responsibilities.
Correct Answer: B
Rationale: A preventive control stops fraud before
it occurs. Requiring a second authorized user to approve the change actively
blocks a single rogue administrator from completing the fraudulent alteration
alone. Options A and C are detective controls because
they identify the anomaly after the fact. Option D is an administrative control
that might disrupt ongoing fraud but does not strictly prevent a specific
transaction.
Case 5: Behavioral Red Flags and the Fraud Triangle
Scenario:
During an audit of the accounts payable function, an internal auditor reviews
employee performance data and files. The auditor notes that the department
manager has refused to take a vacation for four consecutive years, insists on
personally picking up and opening all mail from a specific geographic region,
and frequently overrides system alerts regarding duplicate invoice numbers,
claiming "system glitches."
Question:
According
to the Fraud Triangle, which element is most strongly indicated by the
manager's refusal to take vacations and isolation of incoming mail?
- A. Rationalization
- B. Pressure
- C. Capability
- D. Opportunity
(Concealment)
Correct Answer: D
Rationale: Refusing to take vacation and strictly controlling work
inputs (like mail) are classic behavioral red flags of an employee trying to
maintain the opportunity to conceal an active fraud scheme. If they take
time off, a replacement worker would likely uncover the irregularities.
Case 6: Assessing Management Pressure and Financial
Statement Fraud
Scenario:
A manufacturing company's executive bonuses are heavily tied to meeting a
strict 15% year-over-year revenue growth target. During the fourth quarter,
market demand drops sharply. Internal audit reviews late-quarter transactions
and discovers that management pressured the shipping department to record
"bill-and-hold" transactions for goods that have not yet been
manufactured or legally transferred to customers.
Question:
In
analyzing fraud risk factors, the pressure placed on the shipping department to
record unearned revenue is a direct manifestation of which dynamic?
- A. A breakdown in
detective transactional controls within logistics.
- B. An incentive/pressure
risk factor originating from corporate compensation structures.
- C. A lack of technical
capability within the internal accounting team.
- D. A rationalization that
the market downturn is temporary.
Correct Answer: B
Rationale: The scenario explicitly links management's fraudulent behavior
to executive bonus structures tied to aggressive targets. This represents the Incentive/Pressure
component of the Fraud Triangle, which often drives management override of
controls.
www.gmsisuccess.in

No comments:
Post a Comment