To help you study for the US CMA Part 1 & CIA Part 1 Exam, here is a comprehensive questions with direct, one-line answers covering internal controls, risk management, governance, frameworks (COSO, COBIT), and Accounting Information Systems (AIS).
Corporate Governance & Internal Control Importance
1 What is corporate governance? ANSWER It is the system of rules, practices, and processes by which a firm is directed, controlled, and administered.
2 Who holds ultimate responsibility for corporate governance? ANSWER The Board of Directors holds ultimate accountability.
3What is the primary objective of internal control? ANSWER To provide reasonable assurance regarding the achievement of objectives related to operations, reporting, and compliance.
4 Why is good internal control important for financial reporting? ANSWER It ensures the accuracy, reliability, and timeliness of financial statements.
5 How do internal controls protect assets? ANSWER They safeguard assets from theft, fraud, unauthorized use, and inefficiencies.
6 What is the relationship between internal controls and operational efficiency? ANSWER Good internal controls streamline processes and optimize resource utilization to prevent waste.
7 What role does compliance play in internal control? ANSWER Internal controls ensure the organization adheres to relevant laws, regulations, and industry standards.
8 Who is responsible for designing and implementing internal controls? ANSWER Management is responsible for design, implementation, and maintenance.
9 What is the role of internal auditors regarding controls? ANSWER They independently evaluate the effectiveness of the internal control system.
10 What is the role of external auditors regarding controls? ANSWER They assess internal controls to determine the nature, timing, and extent of substantive audit procedures.
Inherent Limitations of Internal Control
11.Can internal controls provide absolute assurance?
ANSWER No, they can only provide reasonable assurance due to inherent limitations.
12 How does human error limit internal control? ANSWER Controls can fail due to simple mistakes, misunderstandings, or fatigue.
13 What is management override of controls? ANSWER It occurs when management bypasses established control policies for illegitimate gains or reporting manipulation.
14What is collusion in the context of internal controls?ANSWER It occurs when two or more individuals work together to circumvent segregation of duties.
15 How does cost-benefit constraint limit internal controls?
ANSWER The cost of implementing a control should not exceed the benefits expected to be derived from it.
16 How do changing business conditions affect controls? ANSWER Controls can become obsolete or ineffective due to shifts in technology, regulation, or business size.
17 What is a "breakdown" in internal control? ANSWER A temporary or permanent failure of a control policy to operate as designed.
18 Why can't controls prevent bad business judgments? ANSWER Controls ensure a process is followed but cannot stop management from making poor strategic decisions.
19 How does custom or culture limit controls? ANSWER A weak corporate ethical culture can lead employees to ignore or minimize control procedures.
20 What is the risk of poorly communicated control procedures? ANSWER Employees may fail to execute controls correctly if instructions are ambiguous.
Types of Internal Controls
21What is a preventive control? ANSWER A control designed to stop errors or fraud before they happen (e.g., locking a safe).
22 What is a detective control? ANSWER A control designed to discover errors or fraud after they have occurred (e.g., bank reconciliations).
23 What is a corrective control? ANSWER A control designed to remedy problems discovered by detective controls (e.g., restoring backups).
24 What are general IT controls (GITC)? ANSWER Controls that apply to all parts of the IT infrastructure and ensure its proper operation.
25 What are application IT controls? ANSWER Controls embedded within specific software applications to process transactions accurately (e.g., input validation).
26 What is a directive control? ANSWER A control designed to encourage a desirable event to occur (e.g., policy manuals, training).
27 What is a compensating control? ANSWER An alternative control used when a primary control is missing or cannot be implemented due to cost.
28 What are physical controls? ANSWER Tangible barriers and security measures used to protect assets (e.g., security cameras, badges).
29 What is segregation of duties (SOD)? ANSWER Dividing key transaction responsibilities (authorization, custody, recording, reconciliation) among different people.
30 What are independent verifications? ANSWER Reviews of performance or records conducted by individuals not involved in the original execution.
COSO Internal Control Integrated Framework
31.What are the three categories of objectives in the COSO framework? ANSWER Operations, Reporting, and Compliance.
32 How many components make up the COSO Internal Control Framework? ANSWER Five interrelated components.
33 How many total principles support the COSO framework? ANSWER Seventeen principles.
34 What is the "Control Environment" component? ANSWER The set of standards, processes, and structures that provide the basis for carrying out internal control across the organization.
35 What is the "Tone at the Top"? ANSWER The ethical atmosphere created by an organization's leadership regarding internal control and integrity.
36 What is the "Risk Assessment" component? ANSWER The process of identifying and analyzing risks to achieving the entity's objectives.
37 What are "Control Activities"? ANSWER The policies and procedures that help ensure management directives to mitigate risks are carried out.
38 What is the "Information and Communication" component? ANSWER The identification, capture, and exchange of information in a form and timeframe that enables people to carry out their responsibilities.
39 What is the "Monitoring Activities" component? ANSWER Ongoing or separate evaluations used to ascertain whether internal control components are present and functioning.
40 What does "present and functioning" mean in COSO? ANSWER Components exist in the control design and are operating as intended to reduce risk to an acceptable level.
COSO Enterprise Risk Management (ERM) Framework
41.What is Enterprise Risk Management (ERM)? ANSWER A culture, capabilities, and practices integrated with strategy-setting that organizations rely on to manage risk in creating value.
42 How many components are in the updated COSO ERM Framework? ANSWER Five components supported by twenty principles.
43 What are the five components of COSO ERM? ANSWER Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; Information, Communication, and Reporting.
44 What is risk appetite? ANSWER The types and amount of risk an organization is willing to accept in pursuit of value.
45 What is risk tolerance? ANSWER The acceptable variation in performance relative to the achievement of specific objectives.
46 What is inherent risk? ANSWER The risk to an entity in the absence of any actions management might take to alter its likelihood or impact.
47 What is residual risk? ANSWER The risk remaining after management has taken action to mitigate or respond to the inherent risk.
48 What is a risk response of "Avoidance"? ANSWER Choosing to exit the activity that gives rise to the risk entirely.
49 What is a risk response of "Reduction" or "Mitigation"? ANSWER Taking action to reduce the likelihood or impact of the risk (e.g., implementing a control).
50 What is a risk response of "Sharing" or "Transfer"? ANSWER Reducing risk likelihood or impact by transferring or sharing a portion of it (e.g., buying insurance).
51 What is a risk response of "Acceptance"? ANSWER Taking no action to affect risk likelihood or impact because it falls within risk appetite.
52 What is the portfolio view of risk? ANSWER A composite view of risk the organization faces, evaluating how risks interact across the entire enterprise.
COBIT Framework (Control Objectives for Information and Related Technology)
53.What is COBIT? ANSWER A framework created by ISACA for the governance and management of enterprise information and technology (IT).
54 What is the primary difference between COSO and COBIT?ANSWER COSO focuses on general corporate internal controls, while COBIT specializes in IT governance and management.
55 What is the distinction between governance and management in COBIT? ANSWER Governance ensures stakeholder needs are evaluated, while management plans, builds, runs, and monitors activities to align with governance goals.
56 What are the 5 governance domain objectives in COBIT? ANSWER Evaluate, Direct, and Monitor (EDM).
57 What are the 4 management domain areas in COBIT? ANSWER Align, Plan and Organize (APO); Build, Acquire and Implement (BAI); Deliver, Service and Support (DSS); Monitor, Evaluate and Assess (MEA).
58 What are COBIT focus areas? ANSWER Specific governance topics, attributes, or contexts (e.g., cybersecurity, DevOps, small-to-medium enterprises) that can be tailored.
59 What is an IT governance framework meant to achieve? ANSWER Alignment of IT strategy with overall business strategy to maximize value and minimize IT-related risks.
Accounting Information Systems (AIS) & IT Risk
60.What is an Accounting Information System (AIS)?ANSWER Collecting data, processing data into information, and providing controls to safeguard data.
61 What is Enterprise Resource Planning (ERP)? ANSWER A centralized software system that integrates all functional areas of a business, including accounting, HR, and supply chain.
62 What is the main control advantage of an ERP system? ANSWER It eliminates data redundancy and uses a single, centralized database for consistent reporting.
63 What is a relational database? ANSWER A digital database architecture where data is organized into tables linked by defined relationships (primary and foreign keys).
64 What is data integrity? ANSWER The accuracy, completeness, and consistency of data throughout its lifecycle.
65 What is an input control in an AIS? ANSWER A control that ensures data entered into the system is accurate, complete, and valid (e.g., limit checks, field checks).
66 What is a processing control in an AIS? ANSWER A control that ensures data is processed correctly without omission or duplication (e.g., run-to-run totals).
67 What is an output control in an AIS? ANSWER A control that ensures system outputs are accurate, complete, and distributed only to authorized personnel.
68 What is a batch total? ANSWER A control total used in batch processing to verify that all records in a group were processed correctly.
69 What is a hash total? ANSWER A batch total generated by summing non-financial numeric values (e.g., part numbers) to verify processing completeness.
Application of Controls (Cycles & Procedures)
70.What is the main risk in the Revenue/Sales cycle? ANSWER Revenue being recognized prematurely, recorded inaccurately, or for fictitious sales.
71 What control prevents sales to un-creditworthy customers? ANSWER Requiring independent credit approval before shipping goods.
72 What is the main risk in the Expenditure/Purchasing cycle? ANSWER Making unauthorized purchases, paying for goods not received, or overpaying.
73 What is a "three-way match" control? ANSWER Verifying that the Purchase Order, Receiving Report, and Vendor Invoice match before issuing payment.
74 What is a lockbox system? ANSWER A control where customer payments are sent directly to a bank-managed mailbox to speed up deposits and reduce employee theft risk.
75 What control prevents the theft of inventory? ANSWER Physical security, perpetual tracking systems, and periodic independent physical counts.
76 What control prevents payroll fraud (fictitious employees)? ANSWER Segregation of duties between HR (hiring/rates) and payroll processing (payouts).
77 What control prevents unauthorized adjustments to accounting records? ANSWER Restricting journal entry capabilities to authorized personnel via system access levels.
78 What is a bank reconciliation? ANSWER A detective control that explains the difference between the cash balance on the bank statement and the general ledger balance.
79 What is the purpose of an audit trail? ANSWER A chronological record that allows transactions to be traced from their source documents to the final financial statements and vice versa.
Systems Security, Business Continuity & Auditing
80.What is the principle of least privilege? ANSWER Giving users only the minimum system access levels required to perform their job duties.
81 What is multi-factor authentication (MFA)? ANSWER A security mechanism requiring two or more independent credentials to verify identity.
82 What is data encryption?ANSWER Encoding information so that it can only be read by someone possessing the correct decryption key.
83 What is a firewall? ANSWER A network security device that monitors and filters incoming and outgoing network traffic based on established rules.
84 What is a Disaster Recovery Plan (DRP)? ANSWER A structured plan detailing how an organization restores its IT infrastructure and data following a disruptive event.
85 What is a Business Continuity Plan (BCP)? ANSWER A broader plan designed to ensure that essential business functions can continue during and after a disaster.
86 What is a hot site? ANSWER A fully equipped, operational backup facility that allows an organization to resume IT operations almost immediately.
87 What is a cold site? ANSWER A backup facility that has physical space and electricity but lacks pre-installed computers and network configurations.
88 What is a grand-father, father, son backup strategy? ABSWER A traditional backup rotation scheme involving daily (son), weekly (father), and monthly (grandfather) backups.
89 What is an access control list (ACL)? ANSWER A list that specifies which users or system processes are granted access to specific data files or resources.
90 What is a digital signature? ANSWER A mathematical scheme used to validate the authenticity and integrity of a digital message or document.
91 What is a penetration test? ANSWER An authorized simulated cyberattack used to evaluate the security vulnerabilities of an IT system.
92 What is auditing "around" the computer? ANSWER Auditing by processing source data manually and comparing results to computer outputs without testing internal system logic.
93 What is auditing "through" the computer? ANSWER Auditing by directly examining and testing the internal logic, processing rules, and controls of the IT system.
94 What is an Integrated Test Facility (ITF)? ANSWER An automated audit technique that inserts dummy transactions into an active system to test processing accuracy alongside live data.
95 What is parallel simulation? ANSWER An audit technique where the auditor writes a program to replicate the client's processing logic and compares the outputs.
96 What is Generalized Audit Software (GAS)? ANSWER Software (like ACL or Idea) that allows auditors to extract, query, and analyze large datasets from a client's system.
97 What is an IT change management control? ANSWER A structured process ensuring all updates to software and systems are authorized, tested, and documented before deployment.
98 What is the role of a steering committee in IT governance? ANSWER A high-level committee that ensures IT investments align with the organization's strategic business goals.
99 What is the purpose of a SOC 1 report? ANSWER A report on controls at a service organization relevant to user entities' internal control over financial reporting.
100 What is the purpose of a SOC 2 report? ANSWER A report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy.

No comments:
Post a Comment