SECTION A: MCQ ON CONTROL SYSTEM,RISK ASSESSMENT,AIS ETC:
Directions for Questions 1 to 15:
Each question contains an Assertion (A) and a Reason (R). Evaluate both statements and select the correct option from the following choices:
· A) Both (A) and (R) are true, and (R) is the correct explanation of (A).
· B) Both (A) and (R) are true, but (R) is not the correct explanation of (A).
· C) (A) is true, but (R) is false.
· D) (A) is false, but (R) is true.
1. Corporate Governance & Audit Committee
· Assertion (A): The external auditors of a publicly traded company must report directly to the Audit Committee of the Board of Directors rather than the Chief Financial Officer (CFO).
· Reason (R): The Audit Committee consists entirely of independent, non-executive directors to ensure that financial reporting oversight remains free from management bias or conflicts of interest.
2. ERM vs. Traditional Risk Management
· Assertion (A): Enterprise Risk Management (ERM) is fundamentally superior to traditional siloed risk management because it evaluates risk at an aggregate portfolio level.
· Reason (R): Managing risks in individual operational silos often leads to a failure to recognize how separate risks interact or compound across the enterprise.
3. IT Governance & Strategic Alignment
· Assertion (A): Effective IT Governance, through frameworks like COBIT, requires the active involvement of business unit leaders, not just the Chief Information Officer (CIO).
· Reason (R): General IT Controls (GITCs) like change management and password complexity rules must be applied identically across every piece of software an organization uses.
4. Risk Assessment & Controls
· Assertion (A): An organization should never design or implement a control activity before completing a formal risk assessment.
· Reason (R): Internal controls are designed to mitigate identified risks, and implementing controls without assessing risk leads to inefficient resource allocation and over-controlling.
5. SOX 404 compliance
· Assertion (A): Under SOX Section 404, if management finds even a single material weakness in internal controls over financial reporting (ICFR), they must conclude that the company’s ICFR is ineffective.
· Reason (R): A material weakness implies that a material misstatement has already occurred in the current year's financial statements.
6. Segregation of Duties (SoD)
· Assertion (A): An employee who is responsible for authorizing credit limits for new customers should not be allowed to record cash receipts from those customers.
· Reason (R): Segregation of duties prevents a single individual from both committing fraud (e.g., creating a fake customer with a high credit limit) and concealing it in the accounting records.
7. COSO "Tone at the Top"
· Assertion (A): A company with highly sophisticated automated application controls can still fail a COSO internal control evaluation if its Control Environment is weak.
· Reason (R): The Control Environment sets the "tone at the top" and influences the control consciousness of the organization; a weak environment allows management to easily override automated controls.
8. Residual vs. Inherent Risk
· Assertion (A): Residual risk can occasionally be greater than inherent risk if an organization selects a flawed risk response strategy.
· Reason (R): Inherent risk represents the level of risk that exists before management implements any internal controls or mitigation strategies.
9. Monitoring Activities
· Assertion (A): Separate evaluations (such as periodic audits) are generally preferred over ongoing monitoring activities for detecting daily processing errors in real time.
· Reason (R): Ongoing monitoring is built directly into routine, recurring operating activities and operates continuously across business processes.
10. Foreign Corrupt Practices Act (FCPA)
· Assertion (A): A US-based multinational firm can be penalized under the FCPA for accounting failures even if no actual bribery of foreign officials took place.
· Reason (R): The FCPA's accounting provisions strictly require public companies to maintain accurate books and records and a robust system of internal accounting controls.
11. Risk Appetite vs. Risk Tolerance
· Assertion (A): Risk tolerance is typically narrower and more operational than risk appetite.
· Reason (R): Risk appetite represents the broad, high-level amount of risk an organization is willing to accept in pursuit of its strategic objectives.
12. General vs. Application IT Controls
· Assertion (A): If General IT Controls (GITCs) are deemed weak or ineffective by an auditor, the auditor cannot fully rely on automated application controls.
· Reason (R): Automated application controls rely on the underlying stability and security of the IT environment (e.g., unauthorized changes to code could compromise application controls).
13. Quantitative vs. Qualitative Risk Assessment
· Assertion (A): Organizations should always completely replace qualitative risk assessments with quantitative formulas like Annualized Loss Expectancy (ALE).
· Reason (R): Quantitative risk assessments rely heavily on precise historical data and financial estimates, which may not be available or reliable for emerging cyber threats.
14. Board Oversight & Strategic Risk
· Assertion (A): The Board of Directors is responsible for managing day-to-day operational risks within the organization.
· Reason (R): Governance frameworks dictate that the Board provides high-level oversight, strategy validation, and accountability, while execution is delegated to executive management.
15. Fraud Triangle & Risk Mitigation
· Assertion (A): From a risk assessment standpoint, internal controls are highly effective at eliminating an individual's rationalisation for committing fraud.
· Reason (R): Internal controls are primarily designed to reduce or eliminate the opportunity component of the Fraud Triangle.
section B:
multiple-choice practice questions aligned with the CIA Part 1 exam (2025 syllabus), focusing on ethics, professionalism, code of conduct, and core internal audit principles.
Questions 1–20
1. Assertion (A): An internal auditor must remain independent in fact and appearance at all times.Reason (R): Internal auditors cannot provide consulting services on operations they previously managed within the past year.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is true, but (R) is false.
- D. Both (A) and (R) are false.
- Answer: .
2. Which of the following is NOT a core principle of the IIA Code of Ethics?
- A. Integrity
- B. Objectivity
- C. Aggressiveness
- D. Competence
- Answer:
3. Neither of the following actions regarding the use of information gained during an engagement is permissible, EXCEPT:
- A. Using information for personal gain.
- B. Using information in a manner that would be contrary to the law.
- C. Disclosing confidential information required by a legal subpoena.
- D. Using information to disadvantage the organization for external profit.
- Answer:
4. Assertion (A): Internal auditors should decline an engagement if they lack the necessary knowledge and skills.Reason (R): The IIA Code of Ethics requires competence, meaning auditors should only perform services they are qualified to handle.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is true, but (R) is false.
- D. Both (A) and (R) are false.
- Answer:
5. All of the following constitute a threat to auditor objectivity, EXCEPT:
- A. Personal relationship with an operational manager being audited.
- B. Acceptance of a minor promotional item valued at less than $10 that does not impair judgment.
- C. Financial interest in the audited entity.
- D. Previous employment responsibilities in the area being reviewed within the last 12 months.
- Answer:
6. Assertion (A): Objectivity means an unbiased mental attitude that allows internal auditors to perform engagements with honest belief in their work.Reason (R): Quality assessments substitute for individual auditor objectivity.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is true, but (R) is false.
- D. Both (A) and (R) are false.
- Answer:
7. None of the following are violations of the IIA Code of Ethics concerning confidentiality, EXCEPT:
- A. Failing to reveal material facts that, if omitted, would distort reporting.
- B. Discussing audit findings with members of the executive board who have a legitimate need to know.
- C. Sharing engagement details with an external family member at dinner.
- D. Providing workpapers to an authorized regulatory body upon formal demand.
- Answer:
8. Inference regarding the internal audit function's organizational independence:If the chief audit executive (CAE) reports administratively to the Chief Financial Officer (CFO), which inference is most accurate?
- A. Independence is completely compromised with no safeguards possible.
- B. Functional reporting to the board mitigates administrative reporting constraints.
- C. The CAE cannot perform any financial audits whatsoever.
- D. The internal audit charter is rendered legally void.
- Answer:
9. Assertion (A): Internal auditors must respect the value and ownership of information they receive.Reason (R): Auditors should disclose information only when there is a legal or professional obligation to do so.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is true, but (R) is false.
- D. Both (A) and (R) are false.
- Answer:
10. All of the following describe expectations under the "Competence" rule of ethics, EXCEPT:
- A. Engaging only in services for which one has the necessary knowledge, skills, and experience.
- B. Performing internal audit services in accordance with the Global Internal Auditing Standards.
- C. Continuously improving proficiency and effectiveness of services.
- D. Guaranteeing that 100% of all organizational frauds will be detected during an assurance engagement.
- Answer:
11. Neither of these statements regarding the Global Internal Auditing Standards is correct, EXCEPT:
- A. They are optional guidelines that boards can choose to ignore entirely.
- B. They mandate adherence to principles of integrity, objectivity, competence, and confidentiality.
- C. They apply only to publicly traded manufacturing entities.
- D. They prohibit internal auditors from utilizing data analytics.
- Answer:
12. Assertion (A): An auditor who uncovers an illegal act must immediately notify local law enforcement before notifying organizational management.Reason (R): Confidentiality and reporting chains require internal escalation before external notification unless legally mandated otherwise.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is false, and (R) is true.
- D. Both (A) and (R) are false.
- Answer:
13. Which of the following is NOT an attribute of integrity in internal auditing?
- A. Performing work with honesty and responsibility.
- B. Observing the law and making disclosures expected by the profession.
- C. Knowingly being a party to any illegal activity for the benefit of the employer.
- D. Respected for the trust and credibility established.
- Answer:
14. Inference regarding conflict of interest:An internal auditor's brother is the sales director of a division scheduled for audit. What is the logical inference?
- A. A clear potential impairment to objectivity exists and must be disclosed.
- B. The audit can proceed normally without disclosure as long as they are siblings, not spouses.
- C. The auditor must immediately resign from the entire internal audit department.
- D. Familial relations never affect professional judgment.
- Answer:
15. None of the following practices enhance auditor independence, EXCEPT:
- A. Direct functional reporting to the board of directors.
- B. Board approval of the internal audit charter.
- C. Board approval of the appointment and removal of the CAE.
- D. All of the above.
- Answer:
16. Assertion (A): Internal auditors may accept small tokens of appreciation from clients during holiday seasons without restriction.Reason (R): Token gifts that do not impair or presume impairment of professional judgment are acceptable under ethics rules, though organizational policy may be stricter.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is false, but (R) is true.
- D. Both (A) and (R) are false.
- Answer:
17. All of the following are key responsibilities of the board regarding internal audit, EXCEPT:
- A. Approving the internal audit risk-based plan.
- B. Executing day-to-day audit field testing and sampling.
- C. Receiving regular communications from the CAE on audit performance.
- D. Ensuring the function is free from resource limitations that impede independence.
- Answer:
18. Neither of the following conditions ensures absolute assurance, EXCEPT that:
- A. Internal audit provides reasonable assurance, not absolute assurance, due to inherent limitations.
- B. Internal audit guarantees zero errors in financial statements.
- C. Testing 100% of transactions eliminates all risks.
- D. Competent auditors never miss a misstatement.
- Answer:
19. Assertion (A): The internal audit charter is a formal document that defines the mandate, scope, and authority of the internal audit activity.Reason (R): The charter must be approved by executive management alone to ensure operational flexibility.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is true, but (R) is false.
- D. Both (A) and (R) are false.
- Answer:
20. None of the following statements about continuous professional development (CPD) are false, EXCEPT:
- A. CPD is irrelevant once the CIA designation is achieved.
- B. Maintaining competence requires ongoing fulfillment of CPE/CPD credit requirements.
- C. Reading a novel satisfies technical CPE requirements.
- D. Ethics training has no place in continuing education.
- Answer:
ANSWERS:
SECTION A: MCQ ON CONTROL SYSTEM,RISK ASSESSMENT,AIS ETC:
Directions for Questions 1 to 15:
Each question contains an Assertion (A) and a Reason (R). Evaluate both statements and select the correct option from the following choices:
· A) Both (A) and (R) are true, and (R) is the correct explanation of (A).
· B) Both (A) and (R) are true, but (R) is not the correct explanation of (A).
· C) (A) is true, but (R) is false.
· D) (A) is false, but (R) is true.
1. Corporate Governance & Audit Committee
· Assertion (A): The external auditors of a publicly traded company must report directly to the Audit Committee of the Board of Directors rather than the Chief Financial Officer (CFO).
· Reason (R): The Audit Committee consists entirely of independent, non-executive directors to ensure that financial reporting oversight remains free from management bias or conflicts of interest.
2. ERM vs. Traditional Risk Management
· Assertion (A): Enterprise Risk Management (ERM) is fundamentally superior to traditional siloed risk management because it evaluates risk at an aggregate portfolio level.
· Reason (R): Managing risks in individual operational silos often leads to a failure to recognize how separate risks interact or compound across the enterprise.
3. IT Governance & Strategic Alignment
· Assertion (A): Effective IT Governance, through frameworks like COBIT, requires the active involvement of business unit leaders, not just the Chief Information Officer (CIO).
· Reason (R): General IT Controls (GITCs) like change management and password complexity rules must be applied identically across every piece of software an organization uses.
4. Risk Assessment & Controls
· Assertion (A): An organization should never design or implement a control activity before completing a formal risk assessment.
· Reason (R): Internal controls are designed to mitigate identified risks, and implementing controls without assessing risk leads to inefficient resource allocation and over-controlling.
5. SOX 404 compliance
· Assertion (A): Under SOX Section 404, if management finds even a single material weakness in internal controls over financial reporting (ICFR), they must conclude that the company’s ICFR is ineffective.
· Reason (R): A material weakness implies that a material misstatement has already occurred in the current year's financial statements.
6. Segregation of Duties (SoD)
· Assertion (A): An employee who is responsible for authorizing credit limits for new customers should not be allowed to record cash receipts from those customers.
· Reason (R): Segregation of duties prevents a single individual from both committing fraud (e.g., creating a fake customer with a high credit limit) and concealing it in the accounting records.
7. COSO "Tone at the Top"
· Assertion (A): A company with highly sophisticated automated application controls can still fail a COSO internal control evaluation if its Control Environment is weak.
· Reason (R): The Control Environment sets the "tone at the top" and influences the control consciousness of the organization; a weak environment allows management to easily override automated controls.
8. Residual vs. Inherent Risk
· Assertion (A): Residual risk can occasionally be greater than inherent risk if an organization selects a flawed risk response strategy.
· Reason (R): Inherent risk represents the level of risk that exists before management implements any internal controls or mitigation strategies.
9. Monitoring Activities
· Assertion (A): Separate evaluations (such as periodic audits) are generally preferred over ongoing monitoring activities for detecting daily processing errors in real time.
· Reason (R): Ongoing monitoring is built directly into routine, recurring operating activities and operates continuously across business processes.
10. Foreign Corrupt Practices Act (FCPA)
· Assertion (A): A US-based multinational firm can be penalized under the FCPA for accounting failures even if no actual bribery of foreign officials took place.
· Reason (R): The FCPA's accounting provisions strictly require public companies to maintain accurate books and records and a robust system of internal accounting controls.
11. Risk Appetite vs. Risk Tolerance
· Assertion (A): Risk tolerance is typically narrower and more operational than risk appetite.
· Reason (R): Risk appetite represents the broad, high-level amount of risk an organization is willing to accept in pursuit of its strategic objectives.
12. General vs. Application IT Controls
· Assertion (A): If General IT Controls (GITCs) are deemed weak or ineffective by an auditor, the auditor cannot fully rely on automated application controls.
· Reason (R): Automated application controls rely on the underlying stability and security of the IT environment (e.g., unauthorized changes to code could compromise application controls).
13. Quantitative vs. Qualitative Risk Assessment
· Assertion (A): Organizations should always completely replace qualitative risk assessments with quantitative formulas like Annualized Loss Expectancy (ALE).
· Reason (R): Quantitative risk assessments rely heavily on precise historical data and financial estimates, which may not be available or reliable for emerging cyber threats.
14. Board Oversight & Strategic Risk
· Assertion (A): The Board of Directors is responsible for managing day-to-day operational risks within the organization.
· Reason (R): Governance frameworks dictate that the Board provides high-level oversight, strategy validation, and accountability, while execution is delegated to executive management.
15. Fraud Triangle & Risk Mitigation
· Assertion (A): From a risk assessment standpoint, internal controls are highly effective at eliminating an individual's rationalisation for committing fraud.
· Reason (R): Internal controls are primarily designed to reduce or eliminate the opportunity component of the Fraud Triangle.
Detailed Answer Key & Logical Inferences
1. A) Both (A) and (R) are true, and (R) is the correct explanation of (A).
o Inference: Independence is crucial for corporate governance. Reporting to the CFO creates a conflict of interest because the auditor would be reporting to the very person whose financial work they are reviewing.
2. A) Both (A) and (R) are true, and (R) is the correct explanation of (A).
o Inference: Traditional risk management handles risks in isolation. ERM's main value proposition is aggregating these risks to see the bigger picture, preventing unexpected compounding effects.
3. B) Both (A) and (R) are true, but (R) is not the correct explanation of (A).
o Inference: Both statements are factually true. However, (R) describes the nature of GITCs, which does not explain why business leaders need to participate in governance (they participate to align IT goals with business strategy).
4. A) Both (A) and (R) are true, and (R) is the correct explanation of (A).
o Inference: Controls do not exist in a vacuum; they exist to mitigate risk. Without a risk assessment, you are guessing what needs protection, leading to waste or security gaps.
5. C) (A) is true, but (R) is false.
o Inference: A material weakness means there is a reasonable possibility that a material misstatement will occur and go undetected. It does not mean a misstatement has actually happened yet.
6. A) Both (A) and (R) are true, and (R) is the correct explanation of (A).
o Inference: Combining authorization (credit limits) and recording (cash receipts) allows an employee to write off balances or create fake accounts and pocket the cash without being caught.
7. A) Both (A) and (R) are true, and (R) is the correct explanation of (A).
o Inference: The Control Environment is the foundation of COSO. If the leadership doesn't value integrity, they can force overrides on automated software, making tech-side controls useless.
8. D) (A) is false, but (R) is true.
o Inference: Residual risk is the risk left after controls are applied. It cannot mathematically be higher than inherent risk (the raw risk before controls), even if a control is poorly designed (though a poor control can introduce new separate inherent risks).
9. D) (A) is false, but (R) is true.
o Inference: Separate evaluations happen periodically (after the fact). Ongoing monitoring is what catches operational processing errors in real time.
10. A) Both (A) and (R) are true, and (R) is the correct explanation of (A).
o Inference: The FCPA is designed to stop bribery by making it impossible to hide. Therefore, bad accounting and poor control systems are independent violations of the act, regardless of whether a bribe occurred.
11. A) Both (A) and (R) are true, and (R) is the correct explanation of (A).
o Inference: Appetite is the macro-level goal (e.g., "We accept moderate volatility for growth"). Tolerance is the micro-level boundary (e.g., "This project cannot exceed budget by more than 5%").
12. A) Both (A) and (R) are true, and (R) is the correct explanation of (A).
o Inference: Application controls live inside a program. If the general controls (like change management) are broken, a malicious actor could alter the program's code, rendering its application controls unreliable.
13. D) (A) is false, but (R) is true.
o Inference: Organizations should use a mix of both. Qualitative assessment is essential when data is scarce or when evaluating subjective risks like reputation or corporate culture.
14. D) (A) is false, but (R) is true.
o Inference: The Board does not handle day-to-day operations; that is management's job. The Board strictly provides governance, strategy oversight, and policy approval.
15. D) (A) is false, but (R) is true.
o Inference: Internal controls cannot control what is inside a person's head (rationalisation). They can only put up barriers to eliminate the physical or systemic opportunity to steal or commit fraud
section B:
multiple-choice practice questions aligned with the CIA Part 1 exam (2025 syllabus), focusing on ethics, professionalism, code of conduct, and core internal audit principles.
Questions 1–20
1. Assertion (A): An internal auditor must remain independent in fact and appearance at all times.Reason (R): Internal auditors cannot provide consulting services on operations they previously managed within the past year.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is true, but (R) is false.
- D. Both (A) and (R) are false.
- Answer: C (Cooling-off period for previous operations is typically one year under standard guidance, but R misstates the absolute rule or time frame universally applied across all frameworks).
2. Which of the following is NOT a core principle of the IIA Code of Ethics?
- A. Integrity
- B. Objectivity
- C. Aggressiveness
- D. Competence
- Answer: C
3. Neither of the following actions regarding the use of information gained during an engagement is permissible, EXCEPT:
- A. Using information for personal gain.
- B. Using information in a manner that would be contrary to the law.
- C. Disclosing confidential information required by a legal subpoena.
- D. Using information to disadvantage the organization for external profit.
- Answer: C
4. Assertion (A): Internal auditors should decline an engagement if they lack the necessary knowledge and skills.Reason (R): The IIA Code of Ethics requires competence, meaning auditors should only perform services they are qualified to handle.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is true, but (R) is false.
- D. Both (A) and (R) are false.
- Answer: A
5. All of the following constitute a threat to auditor objectivity, EXCEPT:
- A. Personal relationship with an operational manager being audited.
- B. Acceptance of a minor promotional item valued at less than $10 that does not impair judgment.
- C. Financial interest in the audited entity.
- D. Previous employment responsibilities in the area being reviewed within the last 12 months.
- Answer: B
6. Assertion (A): Objectivity means an unbiased mental attitude that allows internal auditors to perform engagements with honest belief in their work.Reason (R): Quality assessments substitute for individual auditor objectivity.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is true, but (R) is false.
- D. Both (A) and (R) are false.
- Answer: C
7. None of the following are violations of the IIA Code of Ethics concerning confidentiality, EXCEPT:
- A. Failing to reveal material facts that, if omitted, would distort reporting.
- B. Discussing audit findings with members of the executive board who have a legitimate need to know.
- C. Sharing engagement details with an external family member at dinner.
- D. Providing workpapers to an authorized regulatory body upon formal demand.
- Answer: C
8. Inference regarding the internal audit function's organizational independence:If the chief audit executive (CAE) reports administratively to the Chief Financial Officer (CFO), which inference is most accurate?
- A. Independence is completely compromised with no safeguards possible.
- B. Functional reporting to the board mitigates administrative reporting constraints.
- C. The CAE cannot perform any financial audits whatsoever.
- D. The internal audit charter is rendered legally void.
- Answer: B
9. Assertion (A): Internal auditors must respect the value and ownership of information they receive.Reason (R): Auditors should disclose information only when there is a legal or professional obligation to do so.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is true, but (R) is false.
- D. Both (A) and (R) are false.
- Answer: A
10. All of the following describe expectations under the "Competence" rule of ethics, EXCEPT:
- A. Engaging only in services for which one has the necessary knowledge, skills, and experience.
- B. Performing internal audit services in accordance with the Global Internal Auditing Standards.
- C. Continuously improving proficiency and effectiveness of services.
- D. Guaranteeing that 100% of all organizational frauds will be detected during an assurance engagement.
- Answer: D
11. Neither of these statements regarding the Global Internal Auditing Standards is correct, EXCEPT:
- A. They are optional guidelines that boards can choose to ignore entirely.
- B. They mandate adherence to principles of integrity, objectivity, competence, and confidentiality.
- C. They apply only to publicly traded manufacturing entities.
- D. They prohibit internal auditors from utilizing data analytics.
- Answer: B
12. Assertion (A): An auditor who uncovers an illegal act must immediately notify local law enforcement before notifying organizational management.Reason (R): Confidentiality and reporting chains require internal escalation before external notification unless legally mandated otherwise.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is false, and (R) is true.
- D. Both (A) and (R) are false.
- Answer: C
13. Which of the following is NOT an attribute of integrity in internal auditing?
- A. Performing work with honesty and responsibility.
- B. Observing the law and making disclosures expected by the profession.
- C. Knowingly being a party to any illegal activity for the benefit of the employer.
- D. Respected for the trust and credibility established.
- Answer: C
14. Inference regarding conflict of interest:An internal auditor's brother is the sales director of a division scheduled for audit. What is the logical inference?
- A. A clear potential impairment to objectivity exists and must be disclosed.
- B. The audit can proceed normally without disclosure as long as they are siblings, not spouses.
- C. The auditor must immediately resign from the entire internal audit department.
- D. Familial relations never affect professional judgment.
- Answer: A
15. None of the following practices enhance auditor independence, EXCEPT:
- A. Direct functional reporting to the board of directors.
- B. Board approval of the internal audit charter.
- C. Board approval of the appointment and removal of the CAE.
- D. All of the above.
- Answer: D
16. Assertion (A): Internal auditors may accept small tokens of appreciation from clients during holiday seasons without restriction.Reason (R): Token gifts that do not impair or presume impairment of professional judgment are acceptable under ethics rules, though organizational policy may be stricter.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is false, but (R) is true.
- D. Both (A) and (R) are false.
- Answer: A
17. All of the following are key responsibilities of the board regarding internal audit, EXCEPT:
- A. Approving the internal audit risk-based plan.
- B. Executing day-to-day audit field testing and sampling.
- C. Receiving regular communications from the CAE on audit performance.
- D. Ensuring the function is free from resource limitations that impede independence.
- Answer: B
18. Neither of the following conditions ensures absolute assurance, EXCEPT that:
- A. Internal audit provides reasonable assurance, not absolute assurance, due to inherent limitations.
- B. Internal audit guarantees zero errors in financial statements.
- C. Testing 100% of transactions eliminates all risks.
- D. Competent auditors never miss a misstatement.
- Answer: A
19. Assertion (A): The internal audit charter is a formal document that defines the mandate, scope, and authority of the internal audit activity.Reason (R): The charter must be approved by executive management alone to ensure operational flexibility.
- A. Both (A) and (R) are true, and (R) is the correct explanation of (A).
- B. Both (A) and (R) are true, but (R) is not the correct explanation of (A).
- C. (A) is true, but (R) is false.
- D. Both (A) and (R) are false.
- Answer: C (Charter must be approved by the board, not just executive management).
20. None of the following statements about continuous professional development (CPD) are false, EXCEPT:
- A. CPD is irrelevant once the CIA designation is achieved.
- B. Maintaining competence requires ongoing fulfillment of CPE/CPD credit requirements.
- C. Reading a novel satisfies technical CPE requirements.
- D. Ethics training has no place in continuing education.
- Answer: B