Sunday, September 20, 2026

To help you study for the US CMA Part 1 Exam, here is a comprehensive questions with direct, one-line answers covering internal controls, risk management, governance, frameworks (COSO, COBIT), and Accounting Information Systems (AIS).



To help you study for the US CMA Part 1 & CIA Part 1 Exam, here is a comprehensive questions with direct, one-line answers covering internal controls, risk management, governance, frameworks (COSO, COBIT), and Accounting Information Systems (AIS).


To help you study for the US CMA Part 1 & CIA Part 1 Exam, here is a comprehensive  questions with direct, one-line answers covering internal controls, risk management, governance, frameworks (COSO, COBIT), and Accounting Information Systems (AIS).

Corporate Governance & Internal Control Importance

1 What is corporate governance? ANSWER It is the system of rules, practices, and processes by which a firm is directed, controlled, and administered.

2 Who holds ultimate responsibility for corporate governance? ANSWER The Board of Directors holds ultimate accountability.

3What is the primary objective of internal control? ANSWER To provide reasonable assurance regarding the achievement of objectives related to operations, reporting, and compliance.

4 Why is good internal control important for financial reporting? ANSWER   It ensures the accuracy, reliability, and timeliness of financial statements.

5 How do internal controls protect assets? ANSWER They safeguard assets from theft, fraud, unauthorized use, and inefficiencies.

6 What is the relationship between internal controls and operational efficiency? ANSWER Good internal controls streamline processes and optimize resource utilization to prevent waste.

7 What role does compliance play in internal control? ANSWER Internal controls ensure the organization adheres to relevant laws, regulations, and industry standards.

8 Who is responsible for designing and implementing internal controls? ANSWER Management is responsible for design, implementation, and maintenance.

9 What is the role of internal auditors regarding controls? ANSWER   They independently evaluate the effectiveness of the internal control system.

10 What is the role of external auditors regarding controls? ANSWER They assess internal controls to determine the nature, timing, and extent of substantive audit procedures.

Inherent Limitations of Internal Control

11.Can internal controls provide absolute assurance?

ANSWER  No, they can only provide reasonable assurance due to inherent limitations.

12  How does human error limit internal control? ANSWER   Controls can fail due to simple mistakes, misunderstandings, or fatigue.

13 What is management override of controls? ANSWER   It occurs when management bypasses established control policies for illegitimate gains or reporting manipulation.

14What is collusion in the context of internal controls?ANSWER   It occurs when two or more individuals work together to circumvent segregation of duties.

15 How does cost-benefit constraint limit internal controls?

ANSWER  The cost of implementing a control should not exceed the benefits expected to be derived from it.

16  How do changing business conditions affect controls? ANSWER   Controls can become obsolete or ineffective due to shifts in technology, regulation, or business size.

17  What is a "breakdown" in internal control? ANSWER  A temporary or permanent failure of a control policy to operate as designed.

18  Why can't controls prevent bad business judgments? ANSWER  Controls ensure a process is followed but cannot stop management from making poor strategic decisions.

19 How does custom or culture limit controls? ANSWER   A weak corporate ethical culture can lead employees to ignore or minimize control procedures.

20  What is the risk of poorly communicated control procedures?  ANSWER Employees may fail to execute controls correctly if instructions are ambiguous.

Types of Internal Controls

21What is a preventive control? ANSWER   A control designed to stop errors or fraud before they happen (e.g., locking a safe).

22  What is a detective control? ANSWER   A control designed to discover errors or fraud after they have occurred (e.g., bank reconciliations).

23  What is a corrective control? ANSWER   A control designed to remedy problems discovered by detective controls (e.g., restoring backups).

24  What are general IT controls (GITC)? ANSWER   Controls that apply to all parts of the IT infrastructure and ensure its proper operation.

25  What are application IT controls?  ANSWER   Controls embedded within specific software applications to process transactions accurately (e.g., input validation).

26  What is a directive control? ANSWER   A control designed to encourage a desirable event to occur (e.g., policy manuals, training).

27  What is a compensating control? ANSWER   An alternative control used when a primary control is missing or cannot be implemented due to cost.

28  What are physical controls? ANSWER   Tangible barriers and security measures used to protect assets (e.g., security cameras, badges).

29  What is segregation of duties (SOD)? ANSWER   Dividing key transaction responsibilities (authorization, custody, recording, reconciliation) among different people.

30  What are independent verifications? ANSWER Reviews of performance or records conducted by individuals not involved in the original execution.

COSO Internal Control Integrated Framework

31.What are the three categories of objectives in the COSO framework? ANSWER   Operations, Reporting, and Compliance.

32  How many components make up the COSO Internal Control Framework?  ANSWER   Five interrelated components.

33  How many total principles support the COSO framework?  ANSWER   Seventeen principles.

34  What is the "Control Environment" component? ANSWER   The set of standards, processes, and structures that provide the basis for carrying out internal control across the organization.

35  What is the "Tone at the Top"? ANSWER   The ethical atmosphere created by an organization's leadership regarding internal control and integrity.

36  What is the "Risk Assessment" component? ANSWER  The process of identifying and analyzing risks to achieving the entity's objectives.

37  What are "Control Activities"? ANSWER   The policies and procedures that help ensure management directives to mitigate risks are carried out.

38  What is the "Information and Communication" component?  ANSWER   The identification, capture, and exchange of information in a form and timeframe that enables people to carry out their responsibilities.

39  What is the "Monitoring Activities" component? ANSWER   Ongoing or separate evaluations used to ascertain whether internal control components are present and functioning.

40  What does "present and functioning" mean in COSO? ANSWER Components exist in the control design and are operating as intended to reduce risk to an acceptable level.

COSO Enterprise Risk Management (ERM) Framework

41.What is Enterprise Risk Management (ERM)? ANSWER   A culture, capabilities, and practices integrated with strategy-setting that organizations rely on to manage risk in creating value.

42  How many components are in the updated COSO ERM Framework?  ANSWER   Five components supported by twenty principles.

43  What are the five components of COSO ERM? ANSWER   Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; Information, Communication, and Reporting.

44  What is risk appetite?  ANSWER   The types and amount of risk an organization is willing to accept in pursuit of value.

45  What is risk tolerance?   ANSWER   The acceptable variation in performance relative to the achievement of specific objectives.

46  What is inherent risk? ANSWER   The risk to an entity in the absence of any actions management might take to alter its likelihood or impact.

47  What is residual risk? ANSWER   The risk remaining after management has taken action to mitigate or respond to the inherent risk.

48  What is a risk response of "Avoidance"? ANSWER   Choosing to exit the activity that gives rise to the risk entirely.

49  What is a risk response of "Reduction" or "Mitigation"? ANSWER   Taking action to reduce the likelihood or impact of the risk (e.g., implementing a control).

50  What is a risk response of "Sharing" or "Transfer"? ANSWER   Reducing risk likelihood or impact by transferring or sharing a portion of it (e.g., buying insurance).

51  What is a risk response of "Acceptance"? ANSWER   Taking no action to affect risk likelihood or impact because it falls within risk appetite.

52  What is the portfolio view of risk? ANSWER A composite view of risk the organization faces, evaluating how risks interact across the entire enterprise.

COBIT Framework (Control Objectives for Information and Related Technology)

53.What is COBIT? ANSWER   A framework created by ISACA for the governance and management of enterprise information and technology (IT).

54  What is the primary difference between COSO and COBIT?ANSWER   COSO focuses on general corporate internal controls, while COBIT specializes in IT governance and management.

55  What is the distinction between governance and management in COBIT? ANSWER  Governance ensures stakeholder needs are evaluated, while management plans, builds, runs, and monitors activities to align with governance goals.

56  What are the 5 governance domain objectives in COBIT? ANSWER  Evaluate, Direct, and Monitor (EDM).

57  What are the 4 management domain areas in COBIT? ANSWER   Align, Plan and Organize (APO); Build, Acquire and Implement (BAI); Deliver, Service and Support (DSS); Monitor, Evaluate and Assess (MEA).

58  What are COBIT focus areas? ANSWER  Specific governance topics, attributes, or contexts (e.g., cybersecurity, DevOps, small-to-medium enterprises) that can be tailored.

59  What is an IT governance framework meant to achieve? ANSWER Alignment of IT strategy with overall business strategy to maximize value and minimize IT-related risks.

Accounting Information Systems (AIS) & IT Risk

60.What is an Accounting Information System (AIS)?ANSWER   Collecting data, processing data into information, and providing controls to safeguard data.

61  What is Enterprise Resource Planning (ERP)? ANSWER   A centralized software system that integrates all functional areas of a business, including accounting, HR, and supply chain.

62  What is the main control advantage of an ERP system? ANSWER   It eliminates data redundancy and uses a single, centralized database for consistent reporting.

63  What is a relational database? ANSWER   A digital database architecture where data is organized into tables linked by defined relationships (primary and foreign keys).

64  What is data integrity? ANSWER  The accuracy, completeness, and consistency of data throughout its lifecycle.

65  What is an input control in an AIS? ANSWER   A control that ensures data entered into the system is accurate, complete, and valid (e.g., limit checks, field checks).

66  What is a processing control in an AIS? ANSWER   A control that ensures data is processed correctly without omission or duplication (e.g., run-to-run totals).

67  What is an output control in an AIS? ANSWER   A control that ensures system outputs are accurate, complete, and distributed only to authorized personnel.

68  What is a batch total? ANSWER   A control total used in batch processing to verify that all records in a group were processed correctly.

69  What is a hash total? ANSWER A batch total generated by summing non-financial numeric values (e.g., part numbers) to verify processing completeness.

Application of Controls (Cycles & Procedures)

70.What is the main risk in the Revenue/Sales cycle? ANSWER   Revenue being recognized prematurely, recorded inaccurately, or for fictitious sales.

71  What control prevents sales to un-creditworthy customers? ANSWER   Requiring independent credit approval before shipping goods.

72  What is the main risk in the Expenditure/Purchasing cycle? ANSWER   Making unauthorized purchases, paying for goods not received, or overpaying.

73  What is a "three-way match" control? ANSWER  Verifying that the Purchase Order, Receiving Report, and Vendor Invoice match before issuing payment.

74  What is a lockbox system? ANSWER   A control where customer payments are sent directly to a bank-managed mailbox to speed up deposits and reduce employee theft risk.

75  What control prevents the theft of inventory? ANSWER   Physical security, perpetual tracking systems, and periodic independent physical counts.

76  What control prevents payroll fraud (fictitious employees)? ANSWER  Segregation of duties between HR (hiring/rates) and payroll processing (payouts).

77  What control prevents unauthorized adjustments to accounting records?  ANSWER   Restricting journal entry capabilities to authorized personnel via system access levels.

78  What is a bank reconciliation? ANSWER  A detective control that explains the difference between the cash balance on the bank statement and the general ledger balance.

79  What is the purpose of an audit trail? ANSWER A chronological record that allows transactions to be traced from their source documents to the final financial statements and vice versa.

 

Systems Security, Business Continuity & Auditing

80.What is the principle of least privilege? ANSWER   Giving users only the minimum system access levels required to perform their job duties.

81  What is multi-factor authentication (MFA)? ANSWER   A security mechanism requiring two or more independent credentials to verify identity.

82  What is data encryption?ANSWER   Encoding information so that it can only be read by someone possessing the correct decryption key.

83  What is a firewall? ANSWER  A network security device that monitors and filters incoming and outgoing network traffic based on established rules.

84  What is a Disaster Recovery Plan (DRP)? ANSWER   A structured plan detailing how an organization restores its IT infrastructure and data following a disruptive event.

85  What is a Business Continuity Plan (BCP)? ANSWER   A broader plan designed to ensure that essential business functions can continue during and after a disaster.

86  What is a hot site? ANSWER  A fully equipped, operational backup facility that allows an organization to resume IT operations almost immediately.

87  What is a cold site? ANSWER  A backup facility that has physical space and electricity but lacks pre-installed computers and network configurations.

88  What is a grand-father, father, son backup strategy? ABSWER   A traditional backup rotation scheme involving daily (son), weekly (father), and monthly (grandfather) backups.

89  What is an access control list (ACL)? ANSWER   A list that specifies which users or system processes are granted access to specific data files or resources.

90  What is a digital signature? ANSWER   A mathematical scheme used to validate the authenticity and integrity of a digital message or document.

91  What is a penetration test? ANSWER   An authorized simulated cyberattack used to evaluate the security vulnerabilities of an IT system.

92  What is auditing "around" the computer? ANSWER  Auditing by processing source data manually and comparing results to computer outputs without testing internal system logic.

93  What is auditing "through" the computer? ANSWER   Auditing by directly examining and testing the internal logic, processing rules, and controls of the IT system.

94  What is an Integrated Test Facility (ITF)? ANSWER   An automated audit technique that inserts dummy transactions into an active system to test processing accuracy alongside live data.

95  What is parallel simulation?  ANSWER   An audit technique where the auditor writes a program to replicate the client's processing logic and compares the outputs.

96  What is Generalized Audit Software (GAS)? ANSWER   Software (like ACL or Idea) that allows auditors to extract, query, and analyze large datasets from a client's system.

97  What is an IT change management control?  ANSWER   A structured process ensuring all updates to software and systems are authorized, tested, and documented before deployment.

98  What is the role of a steering committee in IT governance? ANSWER   A high-level committee that ensures IT investments align with the organization's strategic business goals.

99  What is the purpose of a SOC 1 report? ANSWER   A report on controls at a service organization relevant to user entities' internal control over financial reporting.

100  What is the purpose of a SOC 2 report? ANSWER A report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy. 

No comments:

Post a Comment