Wednesday, September 9, 2026

Casebased MCQ questions on Accounting Information System,types of department in manufacturing business and its risk owner with their duties, documents and deliverables during revenue cycle payroll cycle & procurement cycle, internal control & AIS, internal control & control application etc from CIA Part 1 & from US CMA part 1 exam new syllabus


Casebased MCQ questions on Accounting Information System,types of department in manufacturing business and its risk owner with their duties, documents and deliverables during revenue cycle payroll cycle & procurement cycle, internal control & AIS, internal control & control application etc from CIA Part 1 & from US CMA part 1 exam new syllabus

 This is the MOST CONFUSING topic for CMA & CIA - But 6-8 Questions are 100% from here in both exams. Here is *Complete Case-Based Pack for AIS Cycles* as per CIA Part 1 + CMA Part 1 New Syllabus.


PART A: MANUFACTURING BUSINESS - DEPARTMENT, RISK OWNER, DUTIES

Department Risk Owner Main Duties Key Risk if fails

**Sales & Marketing** Sales Manager Takes customer order, credit check request, pricing Fictitious sales, wrong price

**Credit Dept** Credit Manager Approves credit limit - INDEPENDENT from Sales Bad debts, sales to bad customer

**Warehouse / Inventory** Warehouse Manager Stores, picks, packs, updates inventory records Theft, stock-out, obsolescence

**Shipping / Logistics** Shipping Manager Ships goods, prepares Bill of Lading Shipment error, revenue before shipment

**Production** Production Manager Manufacturing, Quality control, BOM Wastage, quality failure

**HR Department** HR Manager Hiring, termination, salary rate approval Ghost employees, wrong pay rate

**Timekeeping** Timekeeping Supervisor Records time worked - Independent from Payroll Buddy punching, inflated hours

**Payroll Dept** Payroll Manager Calculates payroll, deductions, prepares payroll register Miscalculation, unauthorized payments

**Purchasing** Purchasing Manager Issues PO, selects vendor, price negotiation Kickbacks, overpricing, fictitious vendors

**Receiving** Receiving Manager Counts, inspects goods, prepares Receiving Report - Independent from Purchasing Accepting damaged goods, collusion

**Accounts Payable** AP Manager 3-way match, processes payment Duplicate payment, paying for not received

**Accounts Receivable / Billing** AR Manager Invoicing, collections, AR ledger Lapping, misstatement of revenue

> *Golden Rule for EXAM: Authorization + Custody + Recording must be SEPARATE. That's SOD - Segregation of Duties.*


---


PART B: 35 CASE-BASED MCQs - CYCLES + DOCUMENTS + CONTROLS


*CYCLE 1: REVENUE CYCLE - O2C - Order to Cash*


*Documents Chain - MUST REMEMBER:* Customer PO -> Sales Order -> Credit Approval -> Pick List -> Shipping Doc/Bill of Lading -> Sales Invoice -> AR Ledger -> Cash Receipt


*Q1. Case:* Salesman takes order, approves credit of his friend, and also edits AR ledger to hide bad debt. Which control fails?

A) Input control

B) Segregation of Duties - Credit approval must be independent from Sales - P10 Control Activities - Risk Owner: Credit Manager, not Sales

C) Output control

D) No failure


*Ans: 


*Q2. Case:* Warehouse ships goods without approved Sales Order. Shipping clerk uses verbal instruction. Deliverable at risk?

A) No risk

B) Unauthorized shipment - Missing document: Approved Sales Order - Control: All shipments must match approved SO + Pick list

C) Payroll risk

D) Production risk


*Ans:


*Q3. Case:* Goods shipped on Dec 31, but invoice created on Jan 2 next year. Revenue recognized in Jan.

A) Correct - Invoice date matters

B) Wrong - Violation of Cut-off - Revenue must be recognized when shipment occurs - Document: Bill of Lading date is evidence of transfer of title - Risk Owner: AR/Billing Manager + Shipping

C) No control

D) Payroll cut-off


*Ans: 

*Q4. Case:* System allows invoice creation without matching shipping document.

A) Preventive control failure - Application Control - Must have automated 2-way match: Shipping doc vs Sales Order before invoicing - P11 General Controls

B) Detective control

C) No failure

D) Payroll control


*Ans


*Q5. Case:* Customer pays $10,000. Cashier pockets money and writes off as bad debt. Which control missing?

A) Segregation - Cash handling and AR write-off authorization must be separate - Cashier should not have access to AR ledger - Lapping risk - Risk Owners: Cashier vs AR Manager vs Credit Manager for write-off approval

B) Input control

C) No control

D) Payroll control


*Ans: 

*Q6. AIS Control Case:* Customer master file - Salesperson creates new customer "ABC Ltd" which is his own shell company. No approval workflow.

A) Failure of Master File Change Control - Application Control - New customer must be approved by Credit Manager independent - Document: Customer Master Change Request

B) Correct process

C) Input control only

D) No risk


*Ans: 

*CYCLE 2: PROCUREMENT CYCLE - P2P - Procure to Pay - HIGHEST FRAUD RISK*


*Documents Chain:* Purchase Requisition -> Purchase Order PO -> Vendor Selection -> Receiving Report / GRN -> Inspection Report -> Vendor Invoice -> 3-Way Match -> AP Ledger -> Payment Voucher -> Check / EFT


*Q7. Case:* Production dept needs raw material. Production supervisor directly calls vendor, receives goods, and asks AP to pay without PO.

A) Correct - Production needs material urgently

B) Control failure - No Purchase Requisition, No PO, No receiving segregation - Duties: Requester cannot be buyer. Must have approved PR -> PO by Purchasing Manager - Risk Owner: Purchasing Manager

C) No failure

D) Payroll issue


*Ans: 

*Q8. Case:* Same person in Purchasing creates vendor, issues PO to that vendor, and also is Receiving manager who confirms receipt.

A) No issue if trusted

B) Major SOD failure - Vendor creation must be independent from Purchasing + Receiving must be independent from Purchasing - Fictitious vendor fraud possible - Risk Owner: Vendor master = AP/Finance independent, Purchasing = Purchasing Manager, Receiving = Receiving Manager

C) Only payroll risk

D) Detective control enough


*Ans


*Q9. Case:* AP clerk pays invoice of $15,000 without checking Receiving Report. Later found goods never received.

A) Failure of 3-Way Match Control - Preventive Application Control - Must match PO + Receiving Report + Vendor Invoice - All 3 must agree in qty, price - Risk Owner: AP Manager owns 3-way match deliverable

B) No failure

C) Revenue control

D) Payroll control


*Ans:


*Q10. Case:* PO price is $10 per unit, but Vendor Invoice is $12 per unit, but AP pays $12 because vendor is relative of AP clerk.

A) Failure of Price check - Processing control - System should flag price variance - Also conflict of interest - P1 Control Environment Ethics + P10 Control Activity

B) Correct

C) No control

D) Timekeeping control


*Ans:


*Q11. Case:* Receiving clerk receives 100 units but records 120 units to help vendor get more payment, and shares kickback.

A) Collusion + Need for independent inspection + Count - Control: Blind receiving - Receiving clerk should not know ordered qty - Document: Blind copy of PO - Risk Owner: Receiving Manager

B) No control can prevent

C) Correct

D) Only detective


*Ans: 

*Q12. Case:* Which document is evidence that liability should be recorded?

A) PO

B) Receiving Report / GRN - Once goods received and inspected, liability incurred - GRN triggers accrual

C) Purchase Requisition

D) Payment voucher


*Ans: 


*Q13. Case:* Vendor master file - Who should own / approve new vendor creation?

A) Purchasing

B) Independent from Purchasing - Finance / AP or Vendor Master team after due diligence - To prevent fictitious vendor

C) Receiving

D) Sales


*Ans:


*CYCLE 3: PAYROLL CYCLE - H2P - Hire to Pay*


*Documents Chain:* Hiring Authorization -> HR Master -> Time Card / Time Sheet -> Approved Time -> Payroll Rate Authorization -> Payroll Register -> Deduction Authorization -> Paycheck / Direct Deposit -> Payroll Tax Filing


*Q14. Case:* HR manager hires ghost employee "Ramesh Kumar", approves timecard, and also is payroll clerk who issues paycheck to his own account.

A) Major SOD failure - Hiring + Timekeeping + Payroll + Distribution must be separate - Duties: HR = Hiring, Timekeeping = Independent attendance, Payroll = Calculation, Treasurer = Distribution - Risk Owner: HR Manager, Timekeeping Supervisor, Payroll Manager

B) No failure if manager is senior

C) Only revenue risk

D) Correct process


*Ans: 


*Q15. Case:* Factory supervisor approves timecards of his team, inflates hours to earn overtime for friends.

A) SOD failure - Supervisor should not approve his own team's time without independent timekeeping check - Use biometric / Badge system + Timekeeping dept independent - Deliverable: Approved time sheet by Timekeeping, not just supervisor

B) Correct

C) No risk

D) Procurement control


*Ans:


*Q16. Case:* Payroll clerk changes pay rate from $20/hr to $30/hr without authorization, increases his own salary.

A) Failure of Pay Rate Authorization Control - Pay rate changes must be approved by HR Manager, not Payroll - HR owns HR Master deliverable - System should have access control - P11 IT Controls

B) No failure

C) Revenue control

D) Receiving control


*Ans: 


*Q17. Case:* Which is BEST control against ghost employees?

A) Reconciliation of payroll register to HR master by independent person + Surprise payroll distribution + Biometric attendance + Mandatory vacation

B) Only timecard

C) Only PO

D) No control needed


*Ans:


*Q18. Case:* Timecards are paper-based, no approval, payroll processes whatever is submitted.

A) Failure of Input Validation + Authorization - Need automated time system + Supervisor approval + Timekeeping approval

B) Correct

C) No risk

D) Procurement risk


*Ans


*Q19. Case:* Payroll taxes not deposited on time, penalty incurred. Whose duty?

A) Sales Manager

B) Payroll Manager owns compliance deliverable: Payroll Tax Filing + Deposit - Requires calendar control + Review by Finance Manager

C) Receiving

D) Purchasing


*Ans:


*Q20. Case:* Overtime not authorized in advance, but payroll pays it because timecard shows overtime.

A) Preventive control failure - Overtime must be pre-approved by Production Manager + HR - Document: Overtime Authorization Form

B) Correct

C) No control

D) 3-way match


*Ans: 


*CYCLE 4: AIS + INTERNAL CONTROL + CONTROL APPLICATION - COMMON FOR BOTH EXAMS*


*Q21. Case:* Which is Application Control vs General IT Control?

A) Input validation, sequence check, limit check, check digit = Application Control; Access to program, change management, backup = General IT Control - GITC affects all applications

B) Same

C) Application is general

D) None


*Ans:


*Q22. Case:* Check digit on customer account number - What control type?

A) Preventive Application - Input Control - Detects transposition errors

B) General control

C) Detective

D) Corrective


*Ans:


*Q23. Case:* Exception report of all payroll changes >10% - Reviewed by HR Manager weekly.

A) Detective Application Control + Monitoring - P16 - Review of exception report is monitoring

B) Preventive

C) No control

D) General control


*Ans: 


*Q24. Case:* System allows user to enter sales order date as Feb 30.

A) Failure of Format check / Validity check - Application Input Control - P10

B) Correct

C) General control

D) Monitoring


*Ans:


*Q25. Case:* Database administrator can directly edit payroll table in production to fix error.

A) Severe P11 violation - Direct data file change should NEVER be allowed - Must go through application with audit trail - Risk Owner: IT Manager / DBA

B) Allowed for efficiency

C) Application control

D) No risk


*Ans:


*Q26. Case:* During revenue cycle, which risk owner approves credit memo for returned goods?

A) Salesperson

B) Credit Manager + Receiving confirms goods returned + Inspection - Document: Credit Memo + Receiving Report for returns

C) Warehouse

D) Payroll clerk


*Ans: 


*Q27. Case:* Batch total of hours entered is 500 hrs, but system calculated payroll for 550 hrs. What control detects?

A) Batch total / Hash total / Record count - Input control that sums to ensure completeness

B) No control

C) General control

D) Monitoring


*Ans: 


*Q28. Case:* All 3 cycles: Who is ultimate owner of internal control?

A) Internal Auditor

B) Management - CEO owns, Board oversees, Internal Audit evaluates - As per COSO and IIA

C) External auditor

D) AP clerk


*Ans:


*Q29. Case:* In ERP, user has access to both create PO and approve payment - System shows SOD conflict but IT says "we have small team, can't segregate"

A) Must have compensating control - e.g., independent manager review of all transactions by that user + exception report review - P10 + P12 - Cannot just ignore - Must document compensating control

B) Acceptable to ignore

C) No control needed

D) Payroll control


*Ans: 


*Q30. Case:* Which cycle has highest inherent fraud risk per ACFE?

A) Revenue

B) Procurement/Purchasing - Corruption, kickbacks, fictitious vendors - Most common in manufacturing

C) Payroll

D) None


*Ans: 


*... And 5 more super exam-oriented cases:*


*Q31.* Document that triggers AP liability? *Ans: Receiving Report / GRN.*


*Q32.* Document that triggers revenue recognition? *Ans: Bill of Lading / Shipping Document, not Invoice.*


*Q33.* Risk owner for Vendor Master? *Ans: Finance / AP Manager independent of Purchasing.*


*Q34.* Payroll cycle - Best preventive for inflated hours? *Ans: Independent Timekeeping + Biometric + Pre-approved overtime.*


*Q35.* AIS - Which control ensures completeness of revenue? *Ans: Sequence check on pre-numbered shipping docs and invoices + Reconcile shipping log to invoice log daily - Deliverable: Daily Sales-Shipment Reconciliation by AR Manager.*


www.gmsisuccess.in


COSO Internal Control—Integrated Framework, COBIT 2019, governance, risk management, control, internal audit, and the distinction between governance and management.

COSO Internal Control—Integrated Framework, COBIT 2019, governance, risk management, control, internal audit, and the distinction between governance and management.

 high-difficulty 50-question CIA Part 1 case-based practice assessment, deliberately designed around the negative-question traps used in difficult exam questions: EXCEPT, NOT, LEAST likely, FALSE, and INCORRECT.

It integrates COSO Internal Control—Integrated Framework, COBIT 2019, governance, risk management, control, internal audit, and the distinction between governance and management.

CIA PART 1 — ADVANCED CASE-BASED PRACTICE EXAM

COSO + COBIT + Governance + Risk + Internal Control

50 Questions | High Difficulty | Negative-Style


SECTION A — COSO INTERNAL CONTROL + GOVERNANCE

Q1. COSO Control Environment — EXCEPT

A multinational company has experienced rapid growth. The board wants to strengthen the control environment. Which of the following is NOT an appropriate action?

A. Establishing clear accountability for internal-control responsibilities
B. Demonstrating management's commitment to integrity and ethical values
C. Ensuring appropriate oversight by those charged with governance
D. Allowing senior executives to override established controls whenever operational urgency exists


Q2. Risk Assessment — LEAST likely

A company is introducing an AI-based credit approval system. Management performs a risk assessment before implementation.

Which activity is LEAST likely to represent an appropriate COSO risk-assessment activity?

A. Identifying risks arising from changes in technology
B. Considering fraud risk separately from ordinary operational risks
C. Assessing whether identified risks could prevent achievement of objectives
D. Assuming existing controls remain effective because they worked under the previous system


Q3. Control Activities — EXCEPT

A manufacturing company introduces automated purchasing controls. Which of the following is NOT primarily a control activity?

A. Segregation of purchasing and payment responsibilities
B. Authorization of purchase orders above specified limits
C. Reconciliation of supplier statements
D. Establishing the organization's ethical tone at the top


Q4. Information & Communication — NOT

The internal audit director concludes that the organization has effective information and communication under COSO.

Which finding would NOT support that conclusion?

A. Relevant information reaches employees in sufficient time
B. Employees understand their control responsibilities
C. Critical control deficiencies are communicated to appropriate parties
D. Management restricts unfavorable information from reaching the audit committee


Q5. Monitoring Activities — LEAST likely

Which activity is LEAST likely to constitute a monitoring activity under COSO?

A. Management periodically evaluates whether controls continue to operate effectively
B. Internal audit performs an independent assessment of selected controls
C. A supervisor reviews exception reports generated by an automated system
D. The organization designs a new approval control after identifying a risk


Q6. COSO Principles — EXCEPT

Which of the following is NOT one of the fundamental COSO internal-control principles?

A. The organization demonstrates commitment to integrity and ethical values
B. The organization selects and develops competent individuals
C. The organization identifies and assesses risks to achievement of objectives
D. The organization guarantees that all identified risks will be completely eliminated


Q7. Fraud Risk — MOST appropriate exception

During a fraud-risk assessment, management identifies an incentive for sales managers to manipulate year-end revenue.

Which action is LEAST appropriate?

A. Assessing the opportunity to manipulate revenue
B. Considering management override
C. Evaluating pressures and incentives
D. Concluding that fraud cannot occur because the external auditor reviews revenue


Q8. Control Environment — NOT

Which statement is NOT consistent with a strong COSO control environment?

A. The board provides appropriate oversight
B. Management establishes accountability
C. Employees understand that ethical violations have consequences
D. Senior executives are exempt from control requirements applicable to other employees


Q9. COSO Change Management — EXCEPT

A company acquires a technology startup. Which activity would NOT normally be associated with COSO risk assessment?

A. Evaluating risks created by the acquisition
B. Assessing changes in personnel and systems
C. Reassessing existing control assumptions
D. Assuming that controls in the acquired company automatically align with the parent company's objectives


Q10. Internal Control Limitations — LEAST likely

Which of the following is LEAST likely to represent an inherent limitation of internal control?

A. Human judgment may be imperfect
B. Collusion can circumvent segregation of duties
C. Management may override controls
D. Properly designed controls provide absolute assurance against all risks


SECTION B — COBIT 2019 + GOVERNANCE/MANAGEMENT

Q11. COBIT Governance — EXCEPT

Which of the following is NOT a governance activity under COBIT?

A. Evaluate stakeholder needs
B. Direct through prioritization and decision-making
C. Monitor performance and compliance
D. Personally perform every IT management activity


Q12. Governance vs. Management — LEAST likely

The board wants to improve enterprise IT governance. Which activity is LEAST likely to be a governance responsibility?

A. Evaluating stakeholder needs
B. Directing priorities
C. Monitoring governance outcomes
D. Managing the organization's daily IT service desk


Q13. COBIT Governance System Principles — NOT

Which of the following is NOT a COBIT 2019 governance-system principle?

A. Provide stakeholder value
B. Dynamic governance system
C. Governance distinct from management
D. Eliminate all enterprise risk


Q14. COBIT Governance Framework — EXCEPT

Which statement is NOT consistent with COBIT 2019's governance framework principles?

A. The framework should be based on a conceptual model
B. The framework should be open and flexible
C. The framework should align with major standards and regulations
D. The framework should prescribe exactly the same governance design for every enterprise


Q15. COBIT Design Factors — LEAST likely

An organization is designing a customized governance system using COBIT.

Which factor is LEAST likely to be considered?

A. Enterprise strategy
B. Risk profile
C. Compliance requirements
D. The personal preference of the IT manager, regardless of enterprise objectives


Q16. COBIT Governance Components — EXCEPT

Which is NOT a typical component of a governance system?

A. Processes
B. Organizational structures
C. Information
D. Guaranteed achievement of every strategic objective


Q17. COBIT Governance Objective — NOT

A board establishes an enterprise governance objective for information and technology.

Which statement is NOT appropriate?

A. Governance should consider stakeholder needs
B. Governance should evaluate whether objectives are being achieved
C. Governance should provide direction
D. Governance should replace operational management completely


Q18. Governance Information — LEAST likely

Which information would be LEAST useful to the governing body when evaluating enterprise IT performance?

A. Significant technology risks
B. Achievement of strategic objectives
C. Major regulatory compliance issues
D. Every individual help-desk ticket regardless of significance


Q19. COBIT Performance Management — EXCEPT

Which statement about performance management under COBIT is INCORRECT?

A. Performance should be evaluated against objectives
B. Performance information supports decision-making
C. Performance measurement can help identify improvement opportunities
D. Performance measurement guarantees that management decisions will always be correct


Q20. COBIT + Enterprise Alignment — NOT

A company wants IT investments to support business strategy.

Which action is NOT consistent with effective governance?

A. Aligning IT objectives with enterprise objectives
B. Considering stakeholder needs
C. Prioritizing investments according to strategic value and risk
D. Allowing IT projects to proceed independently of enterprise strategy


SECTION C — COSO + COBIT INTEGRATION

Q21. Integrated Governance — EXCEPT

An organization uses COBIT for governance of information and technology and COSO for internal control.

Which statement is NOT correct?

A. COBIT can help address governance and management of enterprise information and technology
B. COSO provides a framework for internal control
C. The two frameworks can complement each other
D. COBIT completely replaces the need for an internal-control framework


Q22. Board vs. Management — LEAST likely

A board discovers that cybersecurity risk has increased significantly.

Which response is LEAST likely to represent the board's governance role?

A. Evaluating whether management's cybersecurity strategy addresses stakeholder needs
B. Directing management toward appropriate cybersecurity priorities
C. Monitoring significant cybersecurity risk indicators
D. Personally configuring firewalls for the organization


Q23. COSO + COBIT — NOT

Which statement is NOT accurate regarding the relationship between COSO and COBIT?

A. COSO focuses broadly on internal control
B. COBIT provides a framework focused on enterprise governance and management of information and technology
C. COBIT can support implementation of technology-related controls
D. COSO and COBIT are identical frameworks serving exactly the same purpose


Q24. Risk Alignment — EXCEPT

A bank uses COSO to assess enterprise risks and COBIT to govern technology.

Which activity would NOT demonstrate proper alignment?

A. Linking cybersecurity risks to business objectives
B. Evaluating technology risks in the enterprise risk context
C. Establishing technology objectives independent of business objectives
D. Monitoring significant risks and controls


Q25. Three Lines Model + COSO — LEAST likely

A CAE is evaluating the organization's internal-control structure.

Which activity is LEAST likely to be an internal-audit responsibility?

A. Providing independent assurance
B. Evaluating control effectiveness
C. Advising on improvements while maintaining objectivity
D. Assuming management's responsibility for designing and operating controls


Q26. Governance Information — EXCEPT

The audit committee requests information concerning the organization's IT governance.

Which item is LEAST appropriate as a primary governance-level indicator?

A. Major technology risks
B. Significant cybersecurity incidents
C. Progress toward strategic technology objectives
D. The exact number of keystrokes entered by each employee


Q27. Control Objective Alignment — NOT

A technology control is considered effective only when:

A. It addresses a relevant risk
B. It supports achievement of an objective
C. It operates as designed
D. It exists solely because the IT department considers it useful


Q28. Risk Response — LEAST likely

A company identifies a significant cloud-service risk.

Which response is LEAST likely to be appropriate?

A. Avoiding the activity when risk exceeds organizational tolerance
B. Reducing the risk through appropriate controls
C. Sharing/transferring certain risks through contractual arrangements
D. Automatically accepting every risk because technology is essential to operations


Q29. COSO Objectives — EXCEPT

Which of the following is NOT one of COSO's three broad categories of objectives?

A. Operations
B. Reporting
C. Compliance
D. Guaranteed profitability


Q30. COBIT and Stakeholders — NOT

Which statement is NOT consistent with the stakeholder-oriented nature of COBIT governance?

A. Stakeholder needs influence governance decisions
B. Different stakeholders may have different priorities
C. Governance should seek to balance stakeholder needs
D. Only the CIO's preferences should determine technology priorities


SECTION D — ADVANCED CASE-BASED QUESTIONS

Q31. Case: ERP Implementation — EXCEPT

A global manufacturer implements a new ERP system. The CIO reports that implementation was successful because the system went live on time.

Internal audit identifies:

  • No segregation of incompatible access privileges

  • Inadequate user access reviews

  • Poor change-management documentation

  • Strong project governance

  • Regular reporting to the steering committee

Which conclusion is LEAST justified?

A. The organization has significant control risks
B. Timely implementation alone does not establish control effectiveness
C. Governance oversight appears to have some strengths
D. The ERP implementation should automatically be considered successful because it met its deadline


Q32. Case: Cybersecurity — NOT

A financial institution experiences a ransomware incident.

Management argues that cybersecurity controls were effective because no incident occurred during the prior three years.

Which statement is NOT appropriate?

A. Historical absence of incidents does not prove control effectiveness
B. Threats and vulnerabilities can change
C. Monitoring should consider changing conditions
D. Prior success proves that the existing controls will remain effective indefinitely


Q33. Case: Management Override — EXCEPT

The CEO instructs the CFO to bypass a purchasing approval because a major supplier may cancel an important contract.

Which statement is NOT correct?

A. Management override represents an inherent limitation of internal control
B. The incident may increase fraud risk
C. The organization should consider whether compensating controls exist
D. The CEO's authority automatically makes the override an effective control


Q34. Case: Audit Committee — LEAST likely

The audit committee is reviewing the organization's governance system.

Which activity is LEAST likely to be an appropriate audit-committee responsibility?

A. Overseeing financial reporting
B. Considering significant risks and control issues
C. Providing oversight of internal audit
D. Operating the organization's daily accounting controls


Q35. Case: Cloud Computing — EXCEPT

A company moves critical applications to a cloud provider.

Which statement is NOT appropriate?

A. Management should assess third-party risks
B. Contractual controls should be evaluated
C. Security responsibilities should be clearly defined
D. Outsourcing automatically transfers ultimate accountability for enterprise risk to the cloud provider


Q36. Case: Data Governance — NOT

A company develops a data-governance program.

Which action would NOT strengthen governance?

A. Establishing data ownership
B. Defining data-quality responsibilities
C. Aligning data decisions with business objectives
D. Allowing every department to define conflicting data standards independently


Q37. Case: AI Decision System — LEAST likely

A bank uses AI to approve loans.

Which control is LEAST likely to be sufficient by itself?

A. Monitoring model performance
B. Reviewing significant exceptions
C. Establishing accountability for model decisions
D. Assuming the AI system is objective because it is automated


Q38. Case: Risk Appetite — EXCEPT

The board establishes a risk appetite statement.

Which statement is NOT correct?

A. Risk appetite provides direction for risk-taking
B. Risk appetite should relate to organizational objectives
C. Risk appetite can support management decision-making
D. Risk appetite means management must eliminate every identified risk


Q39. Case: Internal Audit Independence — NOT

The CAE reports functionally to the audit committee and administratively to the CEO.

Which action would NOT support organizational independence?

A. Audit committee approval of the internal audit charter
B. Direct access to the audit committee chair
C. Management approval of every individual audit conclusion before reporting
D. Periodic communication with the audit committee


Q40. Case: Control Deficiency — LEAST likely

An internal auditor discovers that employees can modify vendor bank-account information without independent review.

Which response is LEAST likely to be appropriate?

A. Assessing the risk of unauthorized payments
B. Determining whether compensating controls exist
C. Evaluating the design and operating effectiveness of related controls
D. Assuming the control is effective because no fraudulent payment has yet been detected


SECTION E — ULTRA-CHALLENGING NEGATIVE QUESTIONS

Q41. Which is NOT a Governance Question?

During an enterprise technology strategy meeting, which question is LEAST likely to be a governance-level question?

A. Does the technology strategy support stakeholder needs?
B. Are technology investments aligned with enterprise objectives?
C. Are significant technology risks within acceptable boundaries?
D. Which individual employee should reset a user's password today?


Q42. COSO Principle — EXCEPT

Which statement is NOT consistent with COSO's approach to risk assessment?

A. Risks are assessed in relation to objectives
B. Fraud risk is specifically considered
C. Significant changes are evaluated
D. Risk assessment occurs only once when the organization is established


Q43. COBIT — LEAST likely

Which statement is LEAST likely to be consistent with COBIT's governance philosophy?

A. Governance evaluates stakeholder needs
B. Governance provides direction
C. Management executes the direction established through governance
D. Governance and management are interchangeable terms


Q44. Internal Control — NOT

Which statement is NOT an appropriate conclusion when an organization has well-designed internal controls?

A. Controls can provide reasonable assurance
B. Controls cannot guarantee achievement of objectives
C. Human error remains possible
D. Well-designed controls eliminate the possibility of fraud


Q45. Technology Risk — EXCEPT

An organization identifies a critical cybersecurity vulnerability.

Which action would NOT be appropriate?

A. Assessing the likelihood and impact
B. Considering risk treatment options
C. Monitoring remediation
D. Assuming the vulnerability is immaterial because no breach has occurred yet


Q46. Governance vs. Management — LEAST likely

A board has approved a technology governance framework.

Which activity should LEAST likely be performed by the board?

A. Establishing broad direction
B. Evaluating whether stakeholder needs are addressed
C. Monitoring significant outcomes
D. Managing individual software-development tasks


Q47. COSO Monitoring — NOT

Which statement about monitoring is NOT correct?

A. Monitoring can involve ongoing evaluations
B. Separate evaluations can provide assurance
C. Deficiencies should be communicated to appropriate parties
D. Monitoring is unnecessary once controls have initially been tested


Q48. Integrated Frameworks — EXCEPT

A company uses COSO, COBIT, ISO 27001 and its own internal policies.

Which statement is NOT correct?

A. Multiple frameworks can coexist
B. Frameworks can complement one another
C. Management should map overlapping requirements where appropriate
D. Using multiple frameworks automatically guarantees effective governance


Q49. MOST DIFFICULT — Negative Case

A technology company has:

  • Excellent cybersecurity controls

  • Strong IT policies

  • Effective automated controls

  • Regular internal audits

  • Significant misalignment between technology investments and corporate strategy

The board claims that IT governance is effective because controls are strong.

Which statement is LEAST likely to support the board's conclusion?

A. Effective controls do not automatically establish strategic alignment
B. Governance includes evaluating whether stakeholder needs are addressed
C. IT governance involves alignment with enterprise objectives
D. Strong operational controls prove that technology governance is effective


Q50. MASTER INTEGRATION CASE — EXCEPT

A multinational organization has implemented COSO and COBIT. The board establishes strategic objectives, management develops operating plans, IT implements technology solutions, and internal audit provides independent assurance.

Internal audit discovers that:

  • The board receives insufficient information regarding emerging technology risks.

  • Management has implemented several controls without linking them to identified risks.

  • IT objectives are not fully aligned with enterprise objectives.

  • Internal audit independently evaluates the control environment.

  • The audit committee regularly communicates with the CAE.

Which statement is NOT correct?

A. The information deficiency may represent a governance concern
B. Controls should be linked to relevant risks and objectives
C. Misalignment between IT objectives and enterprise objectives can indicate a governance weakness
D. Because internal audit performs independent evaluations, governance and management responsibilities are automatically fulfilled


🔥 CIA NEGATIVE-QUESTION TRAP SHEET

When you see these words, slow down:

Exam wordingWhat you should do
EXCEPTFind the one that does NOT belong
NOTIdentify the incorrect/non-applicable statement
LEAST likelyFind the weakest/least appropriate option
MOST likely NOTFind the strongest exception
INCORRECTLook for the false statement
TRUE EXCEPTThree are true; one is false
PRIMARILYIdentify the principal responsibility
BESTSeveral may be reasonable; select the strongest
FIRSTThink sequence/prioritization
MOST appropriateSelect the answer most aligned with the governing principle

The BIG CIA distinction

COSO → Internal Control

COBIT → Governance & Management of Information and Technology

Board → Governance / oversight

Management → Execution / management

Internal Audit → Independent assurance + advisory role

Controls → Address risks

Objectives → Drive risk assessment

Risk → Does NOT necessarily mean eliminate

Framework → Does NOT guarantee effectiveness

Automation → Does NOT eliminate risk

Outsourcing → Does NOT eliminate accountability

Strong controls → Do NOT automatically mean strong governance

Internal audit → Does NOT own management's controls

Saturday, September 5, 2026

answers: US CMA Part 1 – Internal Control, SOX, FCPA, COSO & COBIT

 

answers: US CMA Part 1 – Internal Control, SOX, FCPA, COSO & COBIT

answers:

US CMA Part 1 – Internal Control, SOX, FCPA, COSO & COBIT

50  MCQs (Exam-Oriented)



1. Which of the following is NOT an objective of an effective internal control system?

A. Safeguarding assets
B. Ensuring reliable financial reporting
C. Guaranteeing that fraud will never occur
D. Promoting operational efficiency

Answer: C


2. Internal control does NOT provide reasonable assurance regarding:

A. Achievement of objectives
B. Reliability of financial reporting
C. Absolute prevention of all errors
D. Compliance with laws and regulations

Answer: C


3. Which of the following is NOT one of the five components of the COSO Internal Control Framework?

A. Control environment
B. Risk assessment
C. Risk transfer
D. Monitoring activities

Answer: C


4. Which is NOT considered a limitation of internal control?

A. Collusion among employees
B. Management override
C. Human error
D. Absolute guarantee of achieving objectives

Answer: D


5. Which of the following is NOT primarily the responsibility of management?

A. Establishing internal controls
B. Maintaining internal controls
C. Designing appropriate controls
D. Providing an external audit opinion

Answer: D


6. Which activity would NOT normally be considered a preventive control?

A. Segregation of duties
B. Password authorization
C. Bank reconciliation
D. Physical access restrictions

Answer: C


7. Which of the following is NOT a detective control?

A. Bank reconciliation
B. Physical inventory count
C. Exception reports
D. Employee authorization limits

Answer: D


8. Segregation of duties is designed primarily to reduce the risk of all of the following EXCEPT:

A. Fraud
B. Errors
C. Unauthorized transactions
D. Natural disasters

Answer: D


9. Which of the following duties should NOT normally be performed by the same employee?

A. Authorization and custody of assets
B. Recording and reconciliation
C. Authorization and recording
D. Custody and authorization

Answer: A


10. A properly designed internal control system does NOT necessarily:

A. Reduce the risk of fraud
B. Improve reliability of information
C. Eliminate all business risks
D. Support achievement of objectives

Answer: C


COSO FRAMEWORK

11. Which of the following is NOT a COSO component?

A. Control environment
B. Information and communication
C. Monitoring activities
D. Strategic planning

Answer: D


12. The COSO control environment does NOT primarily include:

A. Integrity and ethical values
B. Organizational structure
C. Management's philosophy
D. Detailed transaction processing

Answer: D


13. Which is NOT normally included in the COSO risk assessment component?

A. Identification of risks
B. Analysis of risks
C. Consideration of fraud risk
D. Preparation of journal entries

Answer: D


14. Control activities do NOT generally include:

A. Authorizations
B. Verifications
C. Reconciliations
D. Establishing corporate objectives only

Answer: D


15. Which of the following is NOT an example of information and communication?

A. Reporting control deficiencies
B. Communicating policies
C. Sharing relevant information
D. Performing physical inventory counts

Answer: D


16. Monitoring activities do NOT primarily involve:

A. Ongoing evaluations
B. Separate evaluations
C. Identification of deficiencies
D. Daily authorization of every transaction

Answer: D


17. Which COSO component is most directly concerned with identifying and analyzing threats to objectives?

A. Control environment
B. Risk assessment
C. Monitoring
D. Information and communication

Answer: B


18. Which of the following is NOT a principle associated with the COSO control environment?

A. Demonstrates commitment to integrity
B. Exercises board oversight
C. Establishes appropriate structure and authority
D. Guarantees profitability

Answer: D


GOVERNANCE

19. Corporate governance does NOT primarily focus on:

A. Accountability
B. Oversight
C. Ethical conduct
D. Guaranteeing business success

Answer: D


20. The board of directors should NOT:

A. Provide oversight
B. Monitor management
C. Establish governance direction
D. Perform all day-to-day management functions

Answer: D


21. Which is NOT generally a responsibility of the audit committee?

A. Overseeing financial reporting
B. Monitoring internal controls
C. Overseeing external auditors
D. Preparing daily accounting entries

Answer: D


22. An independent board member is generally expected to NOT:

A. Exercise objective judgment
B. Provide oversight
C. Have excessive conflicts of interest
D. Challenge management decisions

Answer: C


23. Which of the following is NOT a major objective of corporate governance?

A. Accountability
B. Transparency
C. Ethical behavior
D. Elimination of all financial risks

Answer: D


24. The audit committee should NOT compromise its independence by:

A. Meeting external auditors
B. Reviewing financial reporting
C. Excessively depending on management without independent evaluation
D. Monitoring internal control

Answer: C


SARBANES-OXLEY ACT (SOX)

25. The Sarbanes-Oxley Act (SOX) does NOT primarily apply to:

A. Publicly traded companies in the United States
B. Companies subject to SEC reporting requirements
C. Management of covered companies
D. Every private business worldwide

Answer: D


26. Section 302 of SOX does NOT require CEOs and CFOs to certify:

A. Accuracy of financial reports
B. Responsibility for disclosure controls
C. Knowledge of material weaknesses
D. Guaranteed future profitability

Answer: D


27. SOX Section 404 primarily deals with:

A. Executive compensation
B. Internal control over financial reporting
C. Foreign bribery
D. Income tax calculation

Answer: B


28. Section 404 does NOT require management to:

A. Assess internal controls
B. Report on internal control effectiveness
C. Maintain adequate internal control over financial reporting
D. Guarantee that no accounting error exists

Answer: D


29. SOX Section 302 certification is primarily made by:

A. Internal auditor and external auditor
B. CEO and CFO
C. Audit committee chairperson only
D. All accounting employees

Answer: B


30. SOX was enacted primarily in response to concerns about:

A. Corporate financial reporting and governance failures
B. Weather-related business risks
C. International trade restrictions
D. Employee productivity only

Answer: A


31. Which of the following is NOT a purpose of SOX?

A. Improving corporate governance
B. Enhancing financial reporting reliability
C. Strengthening internal controls
D. Eliminating the need for external auditors

Answer: D


32. Under SOX, management is NOT relieved from responsibility for internal control because:

A. External auditors conduct an audit
B. Internal audit performs testing
C. An audit committee exists
D. All of the above

Answer: D


SECTION 302 & SECTION 404

33. Which statement about SOX Section 302 is INCORRECT?

A. CEO and CFO certifications are required
B. Officers accept responsibility for financial reports
C. The section requires management to guarantee future results
D. Disclosure controls are relevant

Answer: C


34. SOX Section 404 focuses primarily on:

A. Internal control over financial reporting
B. Foreign political contributions
C. Personal income taxes
D. Product quality management

Answer: A


35. Which is NOT required for effective internal control assessment under Section 404?

A. Identification of relevant controls
B. Evaluation of control effectiveness
C. Documentation of significant deficiencies
D. Guarantee of zero fraud

Answer: D


36. A material weakness in internal control does NOT mean:

A. There is a reasonable possibility of material misstatement
B. Internal controls have a serious deficiency
C. Management should evaluate the issue
D. Every financial statement amount is incorrect

Answer: D


FCPA – FOREIGN CORRUPT PRACTICES ACT

37. The FCPA does NOT permit:

A. Accurate books and records
B. Adequate internal accounting controls
C. Bribery of foreign officials to obtain business
D. Compliance monitoring

Answer: C


38. The anti-bribery provisions of the FCPA primarily prohibit:

A. Accurate accounting
B. Improper payments to foreign officials for business advantage
C. Internal control testing
D. Employee training

Answer: B


39. Which of the following is NOT a major requirement associated with the FCPA?

A. Maintaining accurate books and records
B. Maintaining adequate internal accounting controls
C. Preventing improper foreign bribery
D. Guaranteeing that every foreign transaction is profitable

Answer: D


40. Under the FCPA, a company should NOT:

A. Maintain accurate records
B. Establish internal accounting controls
C. Conceal improper payments
D. Monitor foreign operations

Answer: C


41. The books and records provisions of the FCPA do NOT encourage:

A. Accurate transaction recording
B. Proper accounting records
C. Concealment of transactions
D. Reasonable internal accounting controls

Answer: C


COBIT

42. COBIT is primarily associated with governance and management of:

A. Information and technology
B. Human resource recruitment only
C. Manufacturing machinery only
D. Personal taxation

Answer: A


43. COBIT does NOT primarily focus on:

A. IT governance
B. Information management
C. Alignment of IT with business objectives
D. Preparing individual tax returns

Answer: D


44. Which of the following is NOT a primary objective of IT governance?

A. Value delivery
B. Risk management
C. Resource optimization
D. Guaranteeing that all IT projects succeed

Answer: D


45. COBIT helps an organization EXCEPT:

A. Align IT with business objectives
B. Manage IT-related risks
C. Establish IT governance frameworks
D. Eliminate all cybersecurity threats permanently

Answer: D


46. Which statement is NOT correct regarding COBIT?

A. It supports IT governance
B. It can help manage IT risks
C. It provides a framework for information and technology governance
D. It guarantees that IT systems will never fail

Answer: D


INTEGRATED INTERNAL CONTROL QUESTIONS

47. Which of the following is NOT an effective response to a significant control deficiency?

A. Investigating the root cause
B. Communicating the deficiency to appropriate parties
C. Taking corrective action
D. Ignoring the deficiency because controls cannot be perfect

Answer: D


48. An effective internal control system should NOT be designed solely to:

A. Prevent fraud
B. Support reliable reporting
C. Help achieve organizational objectives
D. Provide reasonable assurance

Answer: A


49. Which of the following is NOT an appropriate control over cash disbursements?

A. Segregating authorization and custody duties
B. Requiring supporting documentation
C. Performing independent bank reconciliations
D. Allowing one employee to authorize, record, and reconcile all payments

Answer: D


50. Which statement about internal control is INCORRECT?

A. Internal control is a process
B. Internal control provides reasonable assurance
C. Internal control is affected by people at all organizational levels
D. Internal control guarantees achievement of all organizational objectives

Answer: D


www.gmsisuccess.in




Practice Quiz... The content comprehensively tests Corporate Governance, Internal Controls, COSO, COBIT, SOX Sections 302 & 404, and the FCPA.

 



US CMA Part 1/CIA PART,1: Internal Control, Governance, SOX, FCPA, COSO, and COBIT Practice Quiz... The content comprehensively tests Corporate Governance, Internal Controls, COSO, COBIT, SOX Sections 302 & 404, and the FCPA

    

US CMA Part 1 – Internal Control, SOX, FCPA, COSO & COBIT

50 MCQs (Exam-Oriented)

1. Which of the following is NOT an objective of an effective internal control system?

A. Safeguarding assets
B. Ensuring reliable financial reporting
C. Guaranteeing that fraud will never occur
D. Promoting operational efficiency

Answer: 

2. Internal control does NOT provide reasonable assurance regarding:

A. Achievement of objectives
B. Reliability of financial reporting
C. Absolute prevention of all errors
D. Compliance with laws and regulations

Answer: 

3. Which of the following is NOT one of the five components of the COSO Internal Control Framework?

A. Control environment
B. Risk assessment
C. Risk transfer
D. Monitoring activities

Answer:

4. Which is NOT considered a limitation of internal control?

A. Collusion among employees
B. Management override
C. Human error
D. Absolute guarantee of achieving objectives

Answer: 

5. Which of the following is NOT primarily the responsibility of management?

A. Establishing internal controls
B. Maintaining internal controls
C. Designing appropriate controls
D. Providing an external audit opinion

Answer: 

6. Which activity would NOT normally be considered a preventive control?

A. Segregation of duties
B. Password authorization
C. Bank reconciliation
D. Physical access restrictions

Answer:

7. Which of the following is NOT a detective control?

A. Bank reconciliation
B. Physical inventory count
C. Exception reports
D. Employee authorization limits

Answer: 

8. Segregation of duties is designed primarily to reduce the risk of all of the following EXCEPT:

A. Fraud
B. Errors
C. Unauthorized transactions
D. Natural disasters

Answer: 

9. Which of the following duties should NOT normally be performed by the same employee?

A. Authorization and custody of assets
B. Recording and reconciliation
C. Authorization and recording
D. Custody and authorization

Answer:

10. A properly designed internal control system does NOT necessarily:

A. Reduce the risk of fraud
B. Improve reliability of information
C. Eliminate all business risks
D. Support achievement of objectives

Answer: 

COSO FRAMEWORK

11. Which of the following is NOT a COSO component?

A. Control environment
B. Information and communication
C. Monitoring activities
D. Strategic planning

Answer: 

12. The COSO control environment does NOT primarily include:

A. Integrity and ethical values
B. Organizational structure
C. Management's philosophy
D. Detailed transaction processing

Answer:

13. Which is NOT normally included in the COSO risk assessment component?

A. Identification of risks
B. Analysis of risks
C. Consideration of fraud risk
D. Preparation of journal entries

Answer: 

14. Control activities do NOT generally include:

A. Authorizations
B. Verifications
C. Reconciliations
D. Establishing corporate objectives only

Answer: 

15. Which of the following is NOT an example of information and communication?

A. Reporting control deficiencies
B. Communicating policies
C. Sharing relevant information
D. Performing physical inventory counts

Answer: 

16. Monitoring activities do NOT primarily involve:

A. Ongoing evaluations
B. Separate evaluations
C. Identification of deficiencies
D. Daily authorization of every transaction

Answer: 

17. Which COSO component is most directly concerned with identifying and analyzing threats to objectives?

A. Control environment
B. Risk assessment
C. Monitoring
D. Information and communication

Answer: 

18. Which of the following is NOT a principle associated with the COSO control environment?

A. Demonstrates commitment to integrity
B. Exercises board oversight
C. Establishes appropriate structure and authority
D. Guarantees profitability

Answer: 

GOVERNANCE

19. Corporate governance does NOT primarily focus on:

A. Accountability
B. Oversight
C. Ethical conduct
D. Guaranteeing business success

Answer: 

20. The board of directors should NOT:

A. Provide oversight
B. Monitor management
C. Establish governance direction
D. Perform all day-to-day management functions

Answer:

21. Which is NOT generally a responsibility of the audit committee?

A. Overseeing financial reporting
B. Monitoring internal controls
C. Overseeing external auditors
D. Preparing daily accounting entries

Answer: 

22. An independent board member is generally expected to NOT:

A. Exercise objective judgment
B. Provide oversight
C. Have excessive conflicts of interest
D. Challenge management decisions

Answer: 

23. Which of the following is NOT a major objective of corporate governance?

A. Accountability
B. Transparency
C. Ethical behavior
D. Elimination of all financial risks

Answer:

24. The audit committee should NOT compromise its independence by:

A. Meeting external auditors
B. Reviewing financial reporting
C. Excessively depending on management without independent evaluation
D. Monitoring internal control

Answer: 

SARBANES-OXLEY ACT (SOX)

25. The Sarbanes-Oxley Act (SOX) does NOT primarily apply to:

A. Publicly traded companies in the United States
B. Companies subject to SEC reporting requirements
C. Management of covered companies
D. Every private business worldwide

Answer: 

26. Section 302 of SOX does NOT require CEOs and CFOs to certify:

A. Accuracy of financial reports
B. Responsibility for disclosure controls
C. Knowledge of material weaknesses
D. Guaranteed future profitability

Answer: 

27. SOX Section 404 primarily deals with:

A. Executive compensation
B. Internal control over financial reporting
C. Foreign bribery
D. Income tax calculation

Answer:

28. Section 404 does NOT require management to:

A. Assess internal controls
B. Report on internal control effectiveness
C. Maintain adequate internal control over financial reporting
D. Guarantee that no accounting error exists

Answer: 

29. SOX Section 302 certification is primarily made by:

A. Internal auditor and external auditor
B. CEO and CFO
C. Audit committee chairperson only
D. All accounting employees

Answer: 

30. SOX was enacted primarily in response to concerns about:

A. Corporate financial reporting and governance failures
B. Weather-related business risks
C. International trade restrictions
D. Employee productivity only

Answer: 

31. Which of the following is NOT a purpose of SOX?

A. Improving corporate governance
B. Enhancing financial reporting reliability
C. Strengthening internal controls
D. Eliminating the need for external auditors

Answer: 

32. Under SOX, management is NOT relieved from responsibility for internal control because:

A. External auditors conduct an audit
B. Internal audit performs testing
C. An audit committee exists
D. All of the above

Answer: 

SECTION 302 & SECTION 404

33. Which statement about SOX Section 302 is INCORRECT?

A. CEO and CFO certifications are required
B. Officers accept responsibility for financial reports
C. The section requires management to guarantee future results
D. Disclosure controls are relevant

Answer: 

34. SOX Section 404 focuses primarily on:

A. Internal control over financial reporting
B. Foreign political contributions
C. Personal income taxes
D. Product quality management

Answer: 

35. Which is NOT required for effective internal control assessment under Section 404?

A. Identification of relevant controls
B. Evaluation of control effectiveness
C. Documentation of significant deficiencies
D. Guarantee of zero fraud

Answer: 

36. A material weakness in internal control does NOT mean:

A. There is a reasonable possibility of material misstatement
B. Internal controls have a serious deficiency
C. Management should evaluate the issue
D. Every financial statement amount is incorrect

Answer:

FCPA – FOREIGN CORRUPT PRACTICES ACT

37. The FCPA does NOT permit:

A. Accurate books and records
B. Adequate internal accounting controls
C. Bribery of foreign officials to obtain business
D. Compliance monitoring

Answer:

38. The anti-bribery provisions of the FCPA primarily prohibit:

A. Accurate accounting
B. Improper payments to foreign officials for business advantage
C. Internal control testing
D. Employee training

Answer: 

39. Which of the following is NOT a major requirement associated with the FCPA?

A. Maintaining accurate books and records
B. Maintaining adequate internal accounting controls
C. Preventing improper foreign bribery
D. Guaranteeing that every foreign transaction is profitable

Answer: 

40. Under the FCPA, a company should NOT:

A. Maintain accurate records
B. Establish internal accounting controls
C. Conceal improper payments
D. Monitor foreign operations

Answer: 

41. The books and records provisions of the FCPA do NOT encourage:

A. Accurate transaction recording
B. Proper accounting records
C. Concealment of transactions
D. Reasonable internal accounting controls

Answer:

COBIT

42. COBIT is primarily associated with governance and management of:

A. Information and technology
B. Human resource recruitment only
C. Manufacturing machinery only
D. Personal taxation

Answer:

43. COBIT does NOT primarily focus on:

A. IT governance
B. Information management
C. Alignment of IT with business objectives
D. Preparing individual tax returns

Answer: 

44. Which of the following is NOT a primary objective of IT governance?

A. Value delivery
B. Risk management
C. Resource optimization
D. Guaranteeing that all IT projects succeed

Answer: 

45. COBIT helps an organization EXCEPT:

A. Align IT with business objectives
B. Manage IT-related risks
C. Establish IT governance frameworks
D. Eliminate all cybersecurity threats permanently

Answer: 

46. Which statement is NOT correct regarding COBIT?

A. It supports IT governance
B. It can help manage IT risks
C. It provides a framework for information and technology governance
D. It guarantees that IT systems will never fail

Answer:

INTEGRATED INTERNAL CONTROL QUESTIONS

47. Which of the following is NOT an effective response to a significant control deficiency?

A. Investigating the root cause
B. Communicating the deficiency to appropriate parties
C. Taking corrective action
D. Ignoring the deficiency because controls cannot be perfect

Answer: 

48. An effective internal control system should NOT be designed solely to:

A. Prevent fraud
B. Support reliable reporting
C. Help achieve organizational objectives
D. Provide reasonable assurance

Answer:

49. Which of the following is NOT an appropriate control over cash disbursements?

A. Segregating authorization and custody duties
B. Requiring supporting documentation
C. Performing independent bank reconciliations
D. Allowing one employee to authorize, record, and reconcile all payments

Answer:

50. Which statement about internal control is INCORRECT?

A. Internal control is a process
B. Internal control provides reasonable assurance
C. Internal control is affected by people at all organizational levels
D. Internal control guarantees achievement of all organizational objectives

Answer: 

www.gmsisuccess.in


answers:

US CMA Part 1,CIA Part 1– Internal Control, SOX, FCPA, COSO & COBIT