Risk Assessment & Types of Risk
Q1: Which of the following best defines inherent risk?
· A) The risk remaining after management takes action to alter its likelihood or impact.
· B) The risk to an organization before management takes any action to alter its likelihood or impact.
· C) The risk that internal controls fail to prevent a material error.
· D) The level of risk an entity is willing to accept in pursuit of its objectives.
· · Answer: B
· · Explanation: Inherent risk is the baseline risk exposure an entity faces before any management intervention or control implementation
Q2: A disruption in supply chain vendor delivery due to an external hurricane falls primarily under which risk category?
· A) Strategic risk
· B) Financial risk
· C) Operational risk
· D) Compliance risk
- C (or External /Operational hybrid, depending on core process failure; operational processes deal with day-to-day execution failures).
Risk Matrix & Risk Strategy
Q3: How does a standard risk assessment matrix prioritize individual risks?
· A) By multiplying the cost of controls by the frequency of audits.
· B) By evaluating and plotting risks based on their likelihood and impact.
· C) By separating operational risks from financial reporting risks.
· D) By assigning risk ownership to senior executive committees.
· · Answer: B
· · Explanation: A risk matrix uses a grid system multiplying or mapping out likelihood (probability) and impact (severity) to score and prioritize risk levels.
·
Q4: Purchasing an insurance policy to cover potential facility damage is an example of which risk strategy?
· A) Risk avoidance
· B) Risk reduction/mitigation
· C) Risk transfer
· D) Risk acceptance
· · Answer: C
· · Explanation: Shifting the financial financial consequence of a risk to a third party (like an insurer) transfers the risk.
Risk Maturity Model & Risk Owner
Q5: In a high-level Risk Maturity Model (RMM), what characterizes an organization at the initial or lowest maturity level?
· A) Risk management processes are fully integrated into strategic planning.
· B) Risk management is ad hoc, unstructured, and reactive.
· C) Risk ownership is assigned to clear department process managers.
· D) Dynamic portfolio views are utilized for all operational decisions.
· · Answer: B
· · Explanation: Low maturity implies disorganized, ad-hoc awareness without formal enterprise frameworks.
Q6: Who is fundamentally responsible for acting as the "risk owner" for a specific operational process?
· A) The internal audit team
· B) The Chief Audit Executive (CAE)
· C) The operational manager or process owner
· D) The external auditor
· · Answer: C
· · Explanation: Under governance frameworks, operational line management owns and manages day-to-day risks (First Line).
Internal Control, Internal Auditor & Risk Assessment
Q7: Which control type is designed to discover an undesirable event after it has already occurred?
· A) Preventive control
· B) Directive control
· C) Detective control
· D) Compensating control
· · Answer: C
· · Explanation: Detective controls (such as monthly bank reconciliations) find errors or fraud post-occurrence.
Q8: What is the primary role of the internal audit activity regarding an organization's risk management process?
· A) Establish the organization’s overall risk appetite.
· B) Provide independent assurance on the effectiveness of risk management processes.
· C) Take ownership of operational risk registers.
· D) Make final management decisions on risk response strategies.
· · Answer: B
· · Explanation: Internal audit provides independent, objective evaluation (Third Line), but must never manage or own risks directly to preserve objectivity.
Control Application & Management Controls (MCQs)
1. Which type of control is designed to stop an error or fraud from occurring in the first place?
· A. Detective control
· B. Corrective control
· C. Preventive control
· D. Feedback control
· · Answer: C
· · Explanation: Preventive controls (like passwords or dual signatures) operate before an event to block unwanted outcomes.
2. In a well-designed purchasing process, which duty must be strictly segregated from the purchasing (ordering) function?
· A. Receiving goods B. Requisitioning goods
· C. General ledger posting D. Sales forecasting
· · Answer: A
· · Explanation: The receiving department must be independent of the purchasing department to verify that items ordered match items actually received
3. What is the primary objective of an accounting control within a transaction cycle?
· A. Enhancing brand reputation
· B. Ensuring the accurate and valid recording of all executed transactions
· C. Setting strategic management goals
· D. Predicting market trends
· · Answer: B
· · Explanation: Accounting controls focus on the integrity, completeness, and validity of financial record-keeping
4. Allowing an employee to both create a new vendor profile in the system and approve purchase invoices for that vendor violates which core internal control concept?
· A. Segregation of duties
· B. Strategic planning
· C. Risk sharing
· D. Batch processing
· · Answer: A
· · Explanation: Combining custody, authorization, or record-keeping enables fraud, such as creating fictitious vendors.
5. Which document is typically used by an internal auditor to graphically display the sequential flow of steps, responsibilities, and documents in an accounting process?
· A. Risk matrix
· B. Flowchart
· C. Narrative memo
· D. Questionnaire
· · Answer: B
· · Explanation: Flowcharts visually map out activities, inputs, outputs, and control points in business systems.
6. Management's tolerance of top-performing sales staff bypassing expense policy limits heavily undermines which COSO internal control component?
· A. Control environment
· B. Monitoring
· C. Information and communication
· D. Hardware security
· · Answer: A
· · Explanation: Tone at the top and management's enforcement of rules form the foundation of the control environment.
7. Which HR management control practice helps ensure that newly hired accounting staff possess the required competence?
· A. Automated continuous monitoring
· B. Background checks and structured skill testing during hiring
· C. Random physical inventory counts
· D. Dual signature mandates
· · Answer: B
· · Explanation: Hiring competent personnel through screening and testing is a foundational human resource control. [1]
8. A budget variance analysis that triggers management investigation after the month ends is an example of what kind of control?
· A. Feedforward control
· B. Concurrent control
· C. Feedback control
· D. Preventive control
· · Answer: C
· · Explanation: Feedback controls measure results after an activity is finished and prompt corrective action.
9. Which control activity is most effective in preventing duplicate payments of vendor invoices?
· A. Mailing checks via secure courier
· B. Canceling or stamping supporting documents (e.g., "Paid") upon check issuance
· C. Requiring a high school diploma for accounts payable clerks
· D. Performing background checks on suppliers
· · Answer: B
· · Explanation: Physically canceling invoices and supporting records prevents them from being re-submitted for subsequent payment.
10. In the payroll cycle, which function should ideally distribute paychecks or direct deposits?
· A. The payroll processing clerk
· B. The human resources manager who adds new employees
· C. An independent paymaster or treasurer with no role in timekeeping or hiring
· D. The departmental supervisor who assigns work hours
· · Answer: C
· · Explanation: Distributing pay through an independent party prevents "ghost employee" payroll scams
11. What is the primary purpose of a "horizontal flowchart" compared to other types?
· A. Showing computer code execution steps from top to bottom
· B. Depicting the separation and flow of responsibilities across different departments
· C. Illustrating raw electronic data transmission packets exclusively
· D. Tracking macro-economic data shifts
· · Answer: B
· · Explanation: Horizontal (or cross-functional) flowcharts highlight which department or role owns each step
12. Which management control assertion addresses whether recorded transactions actually took place during the specific accounting period?
· A. Completeness
· B. Valuation
· C. Occurrence
· D. Classification
· · Answer: C
· · Explanation: Occurrence verifies that recorded sales or expenses genuinely happened and were not fabricated.
13. What is the primary role of operational policies and procedures within management control?
· A. Guaranteeing zero operational mistakes
· B. Guiding daily employee behavior to align with strategic organizational objectives
· C. Replacing the need for internal audit oversight
· D. Eliminating all external market risk
· · Answer: B
· · Explanation: Policies set boundaries and expectations, while procedures give step-by-step instructions to hit objectives.
14. Which control weakness is present if warehouse staff have physical custody of inventory and also maintain the perpetual inventory subsidiary ledger?
· A. Lack of segregation between asset custody and accounting record-keeping
· B. Lack of proper executive oversight
· C. Inadequate budget allocations
· D. Failure to implement firewalls
· · Answer: A
· · Explanation: Custodians of physical inventory should not control inventory records, enabling hidden shrinkage or theft.
15. Pre-numbering shipping documents and matching them sequentially to sales invoices tests for which transaction assertion?
· A. Occurrence
· B. Completeness
· C. Timeliness
· D. Authorization
· · Answer: B
· · Explanation: Sequence checks and matching ensure that all shipments made are completely billed and recorded.
16. Which of the following represents a "feedforward" control mechanism?
· A. Inspecting finished goods before packaging
· B. Reviewing monthly financial statements
· C. Inspecting raw materials quality with suppliers before purchase/production acceptance
· D. Performing a bank reconciliation
· · Answer: C
· · Explanation: Feedforward controls anticipate and prevent problems before the operational process begins.
17. Why is IT application input validation (such as range checks and limit checks) critical?
· A. It prevents unauthorized physical access to the server room.
· B. It stops incorrect or anomalous data from entering processing systems.
· C. It automatically fixes faulty management decisions.
· D. It removes the need for data backups.
· · Answer: B
· · Explanation: Input controls catch errors at the point of entry before data corrupts downstream records.
18. Who ultimately bears primary ownership and responsibility for designing and executing internal controls in an organization?
· A. The external auditor
· B. Management
· C. The internal audit activity
· D. Regulatory agencies
· · Answer: B
· · Explanation: Management designs, implements, and maintains the internal control structure
19. An internal auditor reviews a control matrix mapping risks to specific control activities. What is the main goal of this review?
· A. To confirm that every identified risk has a corresponding, active mitigation control
· B. To calculate net employee take-home pay
· C. To write annual financial statements
· D. To approve operational budgets
· · Answer: A
· · Explanation: A control matrix ensures coverage completeness—meaning no key risk remains unmitigated.
20. What is an intended benefit of maintaining a lean, unbureaucratic organizational structure?
· A. Elimination of all business errors
· B. Clearer lines of communication, easier oversight, and reduced monitoring costs
· C. Automatic segregation of all accounting duties
· D. Exemption from regulatory compliance rules
· · Answer: B
· · Explanation: Lean structures reduce red tape and make supervisory evaluation more direct and economical.
risk appetite is the broad amount of risk an organization wishes to pursue, while risk tolerance is the specific, measurable variance allowed.
1. What is the primary definition of risk appetite?
· A) The exact financial loss a company can take in a day.
· B) The broad amount of risk an organization is willing to accept in pursuit of its goals.
· C) The total capacity of risk before bankruptcy.
· D) The legal limit of risk allowed by regulators.
Answer B
2. How does risk tolerance differ from risk appetite?
· A) Risk tolerance is broader and less defined.
· B) Risk tolerance sets specific, measurable operational boundaries or acceptable deviations.
· C) Risk tolerance only applies to personal investments.
· D) Risk tolerance and risk appetite mean the exact same thing
· Correct Answer: B
3. Which statement best describes the hierarchy between the two?
· A) Risk tolerance sits at the top as a high-level strategic choice, and risk appetite is the operational limit.
· B) Risk appetite is a high-level strategic attitude, and risk tolerance defines the specific tactical limits within that appetite.
· C) They operate in completely separate departments with no relation.
· D) Risk tolerance dictates what the risk appetite should be.
Answer b
Casebased questions:
Case Scenario
TechNova, a financial technology company, has stated in its corporate charter that it has zero appetite for compliance violations. However, during a recent internal audit, the risk team discovered that 2% of transaction logs experienced a one-hour delay in encryption due to a software patch issue. The company’s policy explicitly allows a maximum 3% technical deviation for non-critical logs under emergency maintenance.
Question
Based on the scenario above, how should TechNova view the 2% encryption delay?
· A) It represents a breach of risk appetite, requiring an immediate shutdown of all transaction systems.
· B) It is completely aligned with the risk appetite since no actual financial fraud occurred.
· C) It falls within the company's defined risk tolerance, meaning it is an acceptable operational deviation under the circumstances.
· D) It exceeds the risk capacity of the organization and constitutes an automatic legal violation.
Answer & Explanation
· Correct Answer: C
· Why it is correct: Risk tolerance represents the acceptable variation or deviation from a goal. While TechNova's broad strategic appetite is zero compliance violations, its operational tolerance explicitly permits up to a 3% technical deviation during emergency maintenance. Because the 2% delay falls under this threshold, it is within the allowed tolerance limit.
· Why the others are incorrect:
o A is incorrect because a minor, tolerated operational deviation does not constitute a catastrophic breach that requires shutting down operations.
o B is incorrect because risk appetite focuses on compliance and standards, not just financial fraud.
o D is incorrect because risk capacity is the absolute maximum risk an organization can bear before failing, which a minor logging delay does not threaten.
Case Scenario
Apex Telecom is planning a major infrastructure expansion costing ₹500 crores. Financial analysis shows that if the expansion fails completely, a loss exceeding ₹350 crores will cause the company to breach its debt covenants, triggering immediate loan acceleration and forcing corporate bankruptcy. The Board of Directors states they are only comfortable risking up to ₹150 crores on new ventures this fiscal year.
Question
In this scenario, what does the ₹350 crore threshold represent for Apex Telecom?
· A) The company's risk appetite for strategic expansion.
· B) The operational risk tolerance for project budget overruns.
· C) The absolute risk capacity of the organization.
· D) The risk target for annual capital expenditure.
Answer & Explanation
· Correct Answer: C
· Why it is correct: Risk capacity is the maximum amount of risk an organization can physically or financially bear before facing catastrophic failure or bankruptcy. Since crossing the ₹350 crore loss threshold triggers insolvency, it represents the absolute boundary of Apex Telecom's capacity. [1]
· Why the others are incorrect:
o A is incorrect because the board's stated comfort zone of ₹150 crores represents their risk appetite (what they choose to risk).
o B is incorrect because risk tolerance deals with acceptable operational deviations around specific targets, not the ultimate survival threshold.
o D is incorrect because a risk target is a planned risk level, not a hard line for corporate survival
Case Scenario
GlobalTrust Bank operates under a strict regulatory framework where losing its "Tier-1 Integrity Rating" results in the automatic revocation of its banking license by the Central Bank. The bank's executive committee is currently debating whether to launch an aggressive marketing campaign that borders on controversial. While the marketing team believes the campaign will boost engagement, the chief risk officer warns that a negative public backlash could trigger a regulatory audit, endangering their Tier-1 rating and threatening the bank's legal existence.
Question
In the context of risk management, the potential loss of the Tier-1 Integrity Rating and the subsequent loss of the banking license represents a breach of what boundary?
· A) The bank's operational risk tolerance for marketing expenses.
· B) The bank's reputational risk capacity.
· C) The bank's strategic risk appetite for market share.
· D) The bank's compliance risk target for customer acquisition
Answer & Explanation
· Correct Answer: B
· Why it is correct: Reputational risk capacity is the limit beyond which reputational damage threatens the very survival, viability, or legal existence of an organization. Since losing the Tier-1 rating leads to an automatic loss of the banking license, it is the absolute maximum reputational risk the bank can survive.
· Why the others are incorrect:
o A is incorrect because this scenario is about survival and public perception, not standard operational variations in marketing budgets.
o C is incorrect because risk appetite represents what the bank is willingly prepared to accept for growth, and no bank intentionally appetites its own liquidation.
o D is incorrect because a risk target is an optimal level of risk aimed for during regular operations, not a catastrophic boundary line.
Case Scenario
Vanguard Airlines operates with a slim cash reserve of ₹100 crores. A major safety audit reveals that a critical fleet component requires an immediate overhaul costing ₹90 crores. Concurrently, if this safety flaw becomes public knowledge, the airline's primary corporate clients—who contribute 80% of its regular revenue—have clauses in their contracts allowing immediate termination for safety failures. The Chief Financial Officer notes that the combined financial cost of the repairs and the instant loss of corporate client trust would completely deplete their capital and trigger immediate liquidation.
Question
In risk management terms, what do the combined threats of the ₹90 crore repair cost and the total loss of corporate client trust represent?
· A) The airline's tactical risk tolerance for operational maintenance overruns.
· B) The airline's strategic risk appetite for rapid market expansion.
· C) The airline's compliance risk target for regulatory safety standards.
· D) The organization's aggregate risk capacity, where overlapping financial and reputational limits threaten core survival
Answer & Explanation
· Correct Answer: D
· Why it is correct: Aggregate risk capacity represents the total, combined limit of risk across multiple categories (like financial and reputational) that an organization can survive. Because the simultaneous financial hit (₹90 crores out of ₹100 crores) and the reputational hit (loss of 80% of revenue) will push Vanguard Airlines into liquidation, it represents the absolute boundary of their aggregate capacity.
· Why the others are incorrect:
o A is incorrect because tolerance deals with manageable deviations in daily operations, not existential threats that cause company liquidation.
o B is incorrect because risk appetite is what the company willingly seeks to take for profit. No company actively desires or appetites total insolvency.
o C is incorrect because a risk target is an optimal level of risk aimed for during regular business planning, not a catastrophic breaking point.
Multiple-choice questions (MCQs) for testing knowledge on risk appetite, risk tolerance, and risk capacity focus on strategic willingness, operational boundaries, and absolute limit
1. Which term defines the maximum amount of risk an organization can absorb before its survival or ability to function is compromised? [1]
· A) Risk appetite
· B) Risk tolerance
· C) Risk capacity
· D) Risk threshold
Answer C (Risk capacity is the absolute hard ceiling.
2. An organization states it wants to pursue high-growth tech investments but prefers low exposure to compliance failures. This high-level strategic stance describes: [1, 2]
· A) Risk capacity
· B) Risk appetite
· C) Risk tolerance
· D) Operational limit
Answer B (Risk appetite defines the types and broad levels of risk an organization is willing to take.
3. What is the main difference between risk appetite and risk tolerance?
· A) Risk appetite is a hard financial ceiling, while tolerance is flexible.
· B) Risk appetite is broad and strategic, whereas risk tolerance sets specific, measurable operational thresholds.
· C) Risk tolerance is set by the board of directors, while appetite is set by middle management.
· D) There is no difference; the terms are completely interchangeable
Answer B (Appetite is high-level/strategic; tolerance is granular/measurable
Risk appetite is set by the board of directors, while risk tolerance (the measurable operational boundaries) is typically set by management and approved by the board
Risk Appetite vs. Risk Tolerance
· Risk Appetite (Board level):
o Defines the broad amount and type of risk an organization is willing to accept to reach its goals.
o Expressed as a high-level, qualitative statement (e.g., "low," "moderate," or "high").
o Owned and approved directly by the board of directors.
· Risk Tolerance (Management level):
o Defines the specific, measurable thresholds or acceptable deviations for individual risks.
o Expressed using quantitative metrics (e.g., "downtime cannot exceed 30 minutes" or "budget variance up to 5%").
o Operationalized and drafted by management and risk owners within the boundaries set by the board's appetite.
4. If a company sets its target downtime to zero, but allows a maximum deviation of up to 3 hours per month before taking corrective action, those 3 hours represent:
· A) Risk capacity
· B) Risk appetite
· C) Risk tolerance
· D) Risk avoidance
Answer C (Tolerance defines the acceptable variation or deviation from the target.
5. In a proper governance hierarchy, which of the following statements is true regarding the relationship between the three concepts?
· A) Risk appetite can safely exceed risk capacity during a growth phase.
· B) Risk capacity must always be lower than risk appetite and tolerance.
· C) Risk appetite and tolerance must always remain equal to or less than risk capacity.
· D) Risk tolerance is decided before establishing the risk appetite
Answer c (Appetite and tolerance must stay within the bounds of total capacity.)
Scenario-Based Practice Questions
1. A fintech startup has $10 million in total capital. If it loses more than $8 million, it will face mandatory regulatory shutdown. The startup’s board decides it is comfortable risking up to $2 million to develop a new cryptocurrency app. In this scenario, what does the $8 million figure represent?
· A) Risk Appetite
· B) Risk Tolerance
· C) Risk Capacity
· D) Risk Indicator
Answer C (The $8 million is the absolute limit before regulatory bankruptcy, making it the capacity. The $2 million is their appetite.)
2. A global logistics company aims to deliver 98% of its packages on time. However, senior management explicitly states that a drop down to 95% due to extreme winter weather is acceptable before emergency backup fleets are deployed. The variance between 98% and 95% represents:
· A) Risk Appetite
· B) Risk Tolerance
· C) Risk Capacity
· D) Risk Exposure
Answer B (The acceptable variance around their target delivery goal represents their risk tolerance.)
3. An online retailer operates a server setup that can handle up to 500,000 simultaneous users before crashing. Marketing plans a massive flash sale. They target an influx of 300,000 users, but state they are willing to push promotions to hit 400,000 users. Which number represents the retailer's risk capacity?
· A) 300,000 users
· B) 400,000 users
· C) 500,000 users
· D) 100,000 users
Answer C (The absolute physical breaking point of the system is 500,000 users, which defines its capacity.)
4. A hospital’s board states: "We have zero willingness to compromise on patient data privacy." Despite this, the IT department sets a target that no more than 5 minor, non-malicious policy exceptions (like a delayed log-out) should occur per department per month. The board's statement is an expression of:
· A) Risk Capacity
· B) Risk Tolerance
· C) Risk Appetite
· D) Risk Threshold
Answer C (A high-level statement of willingness or unwillingness regarding a specific risk type is a risk appetite statement.)
5. A commercial bank finds that due to a new economic recession, its maximum bearable loss has dropped from $50 million to $30 million. However, its current strategic growth plan involves actively pursuing aggressive loans that could risk up to $35 million in defaults. What is the immediate risk governance issue here?
· A) Risk tolerance is too far below risk appetite.
· B) Risk appetite has exceeded risk capacity.
· C) Risk capacity has grown larger than risk appetite.
· D) Risk appetite and risk tolerance are perfectly aligned.
Answer B (The bank's appetite ($35M) is now higher than its actual capacity to absorb losses ($30M), creating a critical governance violation.) pursuing aggressive risk=risk apetite =35 , max loss= risk capacity=now 30
case-study scenario to evaluate a risk statement based on the standard Cause-Event-Impact structure.
Case Study Scenario
A retail bank is launching a new mobile banking app. The risk manager writes a risk statement to describe a potential problem with data security during the launch.
Options for the Risk Statement:
· A) Because of weak encryption standards, unauthorized third parties may intercept customer login credentials, leading to financial loss, regulatory fines, and severe reputational damage.
· B) Our mobile app might get hacked by bad actors and ruin our brand.
· C) Financial loss and regulatory fines will happen because the mobile app is bad.
· D) Hackers will steal data because we have poor security.
Evaluation
· Option A (Correct): Follows the standard Cause (weak encryption standards) -> Event (unauthorized third parties intercept customer login credentials) -> Impact (financial loss, regulatory fines, and severe reputational damage) format clearly and professionally.
· Option B: Too vague; lacks a precise cause and clear business impact.
· Option C: Puts the impact before the cause and lacks a specific event description.
· Option D: Too brief and informal; lacks a detailed description of the event and comprehensive impacts.
The COSO and ACFE Fraud Risk Management Guide is built on five key principles that match the core components of internal control. Below are multiple-choice questions testing your knowledge of these principles, governance policies, and fraud risk programs. [1, 2, 3, 4]
Multiple-Choice Questions
1. How many core principles form the foundation of the COSO Fraud Risk Management Guide?
· A. Three B. Five C. Seventeen D. Twenty
Correct Answer: c.
The Principles and Components
· Fraud Risk Governance (Control Environment):
o Sets ethical tone and board oversight
o Defines anti-fraud policies and roles
· Fraud Risk Assessment (Risk Assessment):
o Identifies specific fraud schemes
o Estimates likelihood and significance
· Fraud Control Activities (Control Activities):
o Deploys preventive and detective controls
o Uses technology and data analytics
· Fraud Investigation and Correction (Information & Communication):
o Operates whistleblower reporting systems
o Conducts investigations and applies corrective actions
· Fraud Risk Monitoring (Monitoring Activities):
o Evaluates program effectiveness over time
o Communicates control deficiencies promptly
2. Which principle of the COSO Fraud Risk Management Guide relates directly to establishing governance policies and an anti-fraud tone at the top?
· A. Principle 1: Fraud Risk Governance
· B. Principle 2: Fraud Risk Assessment
· C. Principle 3: Fraud Control Activities
· D. Principle 4: Investigation and Monitoring
Correct Answer: A. Principle 1: Fraud Risk Governance
3. What is the primary purpose of performing a periodic fraud risk assessment under industry standards?
· A. To eliminate all organizational risks completely
· B. To identify specific fraud schemes, assess their likelihood and significance, and map controls
· C. To satisfy external tax audits only
· D. To replace the need for an internal audit department
Correct Answer: B. To identify specific fraud schemes, assess their likelihood and significance, and map control
4. Preventive and detective fraud control activities should be designed primarily to:
· A. Punish employees after a loss occurs
· B. Mitigate identified high-priority fraud risks to an acceptable level
· C. Increase the speed of daily financial transactions
· D. Hide minor financial discrepancies from stakeholders
B. Mitigate identified high-priority fraud risks to an acceptable level
5. Which element is essential for an effective reporting and investigation process under the COSO framework?
· A. Anonymous and robust whistleblower reporting channels
· B. Immediate public disclosure of unverified allegations
· C. Outsourcing all management decisions to external legal counsel
· D. Ignoring low-level red flags to save time
A. Anonymous and robust whistleblower reporting channels
COSO Principle-Based Practice Questions
Question 1: Control Environment
An audit committee actively reviews management's choices in accounting policy and challenges key operational assumptions. Which specific COSO principle does this action best demonstrate?
· A) Principle 1: Commitment to integrity and ethical values
· B) Principle 2: Independence of the board of directors and oversight of internal control
· C) Principle 3: Establishment of structure, authority, and responsibility
· D) Principle 5: Enforcement of accountability
· Answer b
Question 2: Risk Assessment
A company reviews how a dishonest employee might bypass payroll controls to issue fake bonus checks. Which COSO principle is the organization applying?
· A) Principle 6: Specification of suitable objectives
· B) Principle 7: Identification and analysis of risk
· C) Principle 8: Assessment of potential fraud risk
· D) Principle 9: Identification and analysis of significant change
Answer c
Question 3: Control Activities
Management requires dual authorization for any wire transfer exceeding $50,000, aiming to reduce the risk of asset loss. This control relates directly to which principle?
· A) Principle 10: Selection and development of control activities that mitigate risks
· B) Principle 11: Selection and development of general controls over technology
· C) Principle 12: Deployment through policies and procedures
· D) Principle 14: Internal communication of control information
Answer A
Question 4: Information and Communication
A retail firm publishes an open compliance hotline on its website for external vendors to report bribery or unethical conduct by company buyers. This channel supports which COSO principle?
· A) Principle 13: Use of relevant, quality information
· B) Principle 14: Internal communication of information
· C) Principle 15: Communication with external parties regarding internal control matters
· D) Principle 16: Conducting ongoing and separate evaluations
ANSWER C
Question 5:
An internal audit team finds a recurring weakness in inventory count procedures, rates its severity, and reports the finding directly to executive management and the audit committee for correction. Which principle is applied here?
· A) Principle 16: Conducting ongoing and separate evaluations
· B) Principle 17: Evaluation and communication of internal control deficiencies
· C) Principle 9: Identification of significant change
· D) Principle 4: Commitment to competence
ANSWER B Monitoring Activities (Principle 17 - Evaluating Deficiencie