Pre-Winter Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > IIA > CIA > IIA-CIA-Part1

IIA-CIA-Part1 Internal Audit Fundamentals Question and Answers

Question # 4

At a construction company, supervisors are entitled to bonus payments if there are no safety rule violations on their teams. There are several channels available for workers to report accidents and violations, and all reported violations are investigated. Bonus payment calculations are approved by managers and the head of safety. Which of the controls best addresses the risk that supervisors will conceal accidents on their teams in order to receive the bonus?

A.

The investigation of all reported violations

B.

The authorization process for bonus calculations

C.

The variety of reporting channels

D.

The presence of safety rules

Full Access
Question # 5

Which of the following situations violates The IIA’s principle on objectivity?

A.

Following the restructuring of the company, the chief audit executive now reports functionally to the chief financial officer.

B.

A new member of the internal audit function, who previously served as the company’s accounts payable supervisor for two years, advises on the implementation of a new accounts payable system.

C.

Believing there are errors in a given balance sheet account, an internal auditor decides to expand his testing without first obtaining approval from the board.

D.

An internal auditor avoids reporting material financial statement audit findings, as the accounting department is supervised by the chief audit executive.

Full Access
Question # 6

Which of the following options describes the reason that conformance with The IIA ' s Code of Ethics is mandatory for internal auditors?

A.

Ethical compliance provides the basis for stakeholder confidence in the competence of the internal audit activity and of professional internal auditors.

B.

Ethical compliance is necessary for internal auditors and the internal audit activity to accept responsibility for providing g absolute assurance about the organization ' s risk management.

C.

Ethical compliance provides the basis for stakeholder trust and confidence in the validity of the profession of internal auditing and the internal audit activity ' s findings.

D.

The internal audit activity ' s ethical compliance sets the tone for the ethical compliance by the organization ' s board, management, and employees.

Full Access
Question # 7

With regard to the internal audit activity ' s quality assurance and improvement program, which of the following must be reported to the board?

A.

A statement of independence of the organization ' s internal auditors.

B.

Meeting minutes with the assessment team, if key risks were identified and discussed.

C.

Frequency of the quality assessments being performed.

D.

Summary of previous internal assessments undertaken.

Full Access
Question # 8

While preparing the audit plan for an automobile manufacturing company, the chief audit executive (CAE) noted that the company ' s engineering department received a high risk ranking. However, the internal audit activity is understaffed, and current staff do not possess the necessary skills to adequately assess the effectiveness of the engineering department. What is the most appropriate course of action for the CAE to take?

A.

Include the engineering department on the audit plan, use the available internal audit resources to conduct the review, and exclude procedures that cannot be adequately assessed.

B.

Advise management to accept the assessed risk until the internal auditors are able to review the area adequately.

C.

Recruit internal auditors with the required competencies and wait until they are employed before including this audit on the internal audit plan.

D.

Proceed with a review of the engineering department but supplement the internal audit team with nonauditors from an external engineering company who have the required skills to assist

Full Access
Question # 9

Which of the following would likely have the greatest influence on the long-term quality of an organization’s control environment?

A.

Regulatory compliance.

B.

Business performance.

C.

Financial reconciliations.

D.

Accountability structure.

Full Access
Question # 10

An internal auditor in a newly established internal audit activity identifies many control weaknesses and raises a number of high-priority recommendations in her first few audit engagements. The internal auditor is concerned that there seems to be a poor understanding by management of risk and control. Which of the following is the most likely reason for this?

A.

Poor performance by individual operational managers in the areas audited.

B.

Unrealistic expectations by the internal audit activity on the quality of risk management and control.

C.

A lack of an effective organizational framework for risk management and control.

D.

A failure by the internal audit activity to identify and manage the organization ' s risks.

Full Access
Question # 11

Which of the following would be considered an indicator that an organization ' s ethics program is not yet well developed?

A.

Disciplinary actions for ethics compliance violations are reviewed by the internal audit activity for consistency.

B.

Communication of ethics compliance expectations is the responsibility of employees ' direct managers.

C.

The organization ' s code of ethics and related compliance policy are reviewed annually for potential updates.

D.

The board of directors reviews ethics oversight metrics for violations and compliance.

Full Access
Question # 12

An organization has limited resources to spend on corporate social responsibility initiatives. Which is the most suitable approach to determine how these resources should be used?

A.

Support a mix of environmental economic and social initiatives to ensure a balanced approach is taken

B.

Survey employees and external stakeholders to see which causes are best suited to the organization.

C.

Select corporate social responsibility initiatives that support the overall strategic goals of the organization

D.

Conduct a financial analysis to determine where the most impact can be made with the budget available

Full Access
Question # 13

What should be the first step for a newly hired chief audit executive to build and maintain the proficiency of the internal audit activity ' ?

A.

Incorporate the basic criteria of internal audit competency into job descriptions

B.

Complete a periodic skills assessment of the internal audit activity

C.

Develop a competency or skill assessment tool.

D.

Perform benchmarking with competitors to learn what other firms are doing related to this topic

Full Access
Question # 14

The board requested the chief audit executive (CAE) to provide consulting services for a new systems implementation project Which of the following statements is true regarding this scenario?

A.

The CAE should avoid making decisions on risk responses within risk management processes.

B.

The CAE may only provide consulting and not assurance services in risk management processes

C.

The CAE may manage the project risks on behalf of management in this particular situation

D.

The CAE should avoid giving assurance on risk management processes in this particular situation

Full Access
Question # 15

Which of the following documents would promote objectivity within an organization ' s internal audit activity?

A.

Internal audit charter.

B.

Internal audit manual.

C.

Audit committee charter

D.

Human resources employee handbook.

Full Access
Question # 16

Which statement is accurate regarding reporting on the quality assurance and improvement program (OAIP) to conform with the International Standards for the Professional Practice of Internal Auditing?

A.

The chief audit executive (CAE) should report all stages of the OAlP ' s development and key milestones.

B.

The CAE should report only corrective action plans that meet external assessor or stakeholder requirements.

C.

The CAE should establish the form and content of program communication so that it is in alignment with the internal audit activity charter.

D.

The CAE should disclose program details only after both internal and external assessments have been completed.

Full Access
Question # 17

Which type of engagement would be the most appropriate to assess the maturity and rigor of the organization wide risk management process of a target entity that management is considering acquiring?

A.

A due diligence engagement.

B.

An operational audit engagement.

C.

A feasibility study engagement.

D.

A risk and control self-assessment engagement.

Full Access
Question # 18

An organization grants its internal auditors authority to access sensitive confidential information so the auditors may analyze data and conduct effective assurance engagements.

This effectively demonstrates support for which of the following fundamental principles of internal auditing?

A.

Independence.

B.

Integrity.

C.

Confidentiality.

D.

Proficiency and due professional care.

Full Access
Question # 19

Which competency is required of all staff internal auditors prior to the commencement of an IT audit?

A.

The ability to assess IT governance.

B.

The ability to provide an explanation on the risk profile of the organization to the board and senior management.

C.

The ability to ensure that proposals for improvements to internal controls are balanced with organizational objectives and capabilities.

D.

The ability to assess the potential for fraud risk and identifying common types of fraud associated with the engagement.

Full Access
Question # 20

Which of the following disclosures must the chief audit executive (CAE) include when communicating the results of the quality assurance and improvement program to senior management and the board?

A.

Authority and responsibility of the internal audit activity

B.

Hours and sources of continuing professional education

C.

Scope and frequency of both the internal and external assessments

D.

independence and objectivity impairments of the CAE

Full Access
Question # 21

According to IIA guidance, which of the following best demonstrates due professional care?

A.

Staffing audit engagements with internal auditors who possess professional designations.

B.

Relying on prior audit work to save planning time and costs.

C.

Performing assurance procedures to guarantee all significant risks are identified.

D.

Assessing the cost of assurance in relation to the potential benefits.

Full Access
Question # 22

Which of the following is an example of a risk reduction strategy?

A.

Outsourcing the payroll function.

B.

Absorbing the cost of losses.

C.

Insuring fixed assets.

D.

Installing cameras around the plant

Full Access
Question # 23

Which of the following would the chief audit executive be required to disclose in the communication of quality assessment results to senior management and the board?

A.

The cost and frequency of both internal and external assessments.

B.

Any assumptions made by the assessment team

C.

A potential conflict of interest of the assessment team.

D.

The assessment team’s execution plan of relevant procedures.

Full Access
Question # 24

An internal auditor observed that sales staff are able to modify or cancel an order in the system prior to shipping* She wonders whether they can also modify orders after shipping. Which of the following types of controls should she examine?

A.

Batch controls.

B.

Application controls.

C.

General IT controls.

D.

Logical access controls

Full Access
Question # 25

An internal auditor is finding it difficult to get management to accept audit findings because of issues that management is having with how the information is presented. Management has expressed disagreement in the past about this auditor’s style in presenting complex findings and the general tone of the report.

Which of the following competencies or skills likely requires improvement on the auditor’s part?

A.

Communication.

B.

Critical thinking.

C.

Persuasion and negotiation.

D.

Business acumen.

Full Access
Question # 26

The internal audit activity audited an organization ' s risk management function multiple times, and the recommendations that were made remain unaddressed by the head of risk management. Which of the following would be the next step for the internal audit activity?

A.

The internal audit activity should add value by implementing the recommendations on management ' s behalf.

B.

The chief audit executive (CAE) must discuss this matter with senior management and the board

C.

The CAE should determine which recommendations to implement based on the severity of the associated risks.

D.

The internal audit activity, led by the CAE. should assume responsibility for risk management function.

Full Access
Question # 27

According to NA guidance which of the following should be documented in the internal audit chatter?

A.

The risk assessment process applied by the internal audit activity

B.

The organization ' s internal control framework used by the internal audit activity

C.

The nature of consulting services provided by the internal audit activity

D.

The performance evaluation process used by the internal audit activity

Full Access
Question # 28

According to NA guidance, which of the following conditions would enhance the independence of the internal audit activity?

A.

The organizational culture rewards critical and objective thinking.

B.

The quality of work performed by the internal audit activity is periodically reviewed,

C.

The organization establishes effective governing body oversight,

D.

Audit assignments are rotated among internal audit staff

Full Access
Question # 29

Which of the following is an example of a risk avoidance strategy?

A.

Outsourcing the payroll function

B.

Installing cameras in the mailroom

C.

Exiting a product line

D.

Insuring all fixed assets

Full Access
Question # 30

According to NA guidance, which of the following practices by the chief audit executive (CAE) best enhances the organizational independence of the internal audit activity?

A.

CAE reviews and approves the annual audit plan,

B.

CAE meets privately with the CEO at least annually.

C.

CAE meets privately with the board at least annually,

D.

CAE reports to the board regarding audit staff performance evaluation and compensation.

Full Access
Question # 31

Which of the following statements is true regarding the internal audit activity ' s quality assurance and improvement program (QAIP)?

A.

Internal assessments must be performed by the chief audit executive.

B.

An internal assessment must be performed at least once every five years.

C.

It Is permissible to share the results of the QAIP with the organization ' s external auditors.

D.

Results of ongoing monitoring must be validated annually by an independent external assessor.

Full Access
Question # 32

Which of the following statements about internal audit consulting engagements is true?

A.

The primary purpose of a consulting engagement is to assess evidence and provide conclusions.

B.

The internal audit activity determines the nature and scope of work for the specific consulting engagement

C.

Internal auditors may provide consulting services relating to operations for which they had previous responsibilities.

D.

It is not appropriate to communicate control issues identified during consulting engagements to the board

Full Access
Question # 33

Which of the following best demonstrates the application of due professional care?

A.

An engagement supervisor requests that the employment of a process owner be terminated due to a significant control failure.

B.

An audit lead establishes internal audit manuals to guide the internal audit activity on now to undertake audit engagements.

C.

An audit manager provides a guarantee to senior management that internal controls relating to an audited process operate effectively.

D.

An organization ' s internal audit activity operates under a direct reporting structure to tie audit committee of the board

Full Access
Question # 34

Which type(s) of assessments in an internal audit activity’s quality assurance and improvement program requires ongoing monitoring to evaluate internal audit activity ' s efficiency and effectiveness?

A.

Neither internal nor external assessment

B.

internal assessment

C.

Both internal and external assessment

D.

External assessment

Full Access
Question # 35

A new CEO authorizes a vendor’s access to the organization’s vendor payment and contracting database as part of a review to identify wasteful spending. An employee in the contracting department raised concerns to the internal audit function about potential fraud involving the vendor’s access to the database’s sensitive information, including that of the vendor’s competitors.

Which is a potential fraud risk that requires special consideration during an internal audit engagement?

A.

The new CEO hired the vendor to perform work that the internal audit function could have performed.

B.

Vendor employees may not have been properly screened for database security clearance.

C.

The vendor has read-only access to all of the organization’s payments and contracting database.

D.

The vendor uses information from the database to gain information about services provided.

Full Access
Question # 36

A chief audit executive ensures that the internal audit activity provides annual training to management on internal controls. Where is the nature of these services defined?

A.

The annual audit plan.

B.

The audit report.

C.

The annual risk assessment.

D.

The audit charter.

Full Access
Question # 37

Which of the following tests would most likely help discover a fictitious invoice?

A.

Compare vendor addresses to employee addresses.

B.

Match cancelled checks to invoices.

C.

Search for duplicate payment amounts.

D.

Check employee bank records against invoice amounts.

Full Access
Question # 38

According to IIA guidance, which of the following activities would typically be examined when using the maturity model approach for assessing an organization ' s risk management program?

A.

Monitor and review.

B.

Performance measurement.

C.

Setting the context.

D.

Communication.

Full Access
Question # 39

According to IIA guidance, which of the following would be included in an internal audit charter to help establish the authority of the internal audit activity?

A.

Outline expectations for communicating the results of all aspects of the internal audit activity.

B.

Declare the internal audit activity’s accountability for safeguarding assets and confidentiality.

C.

Document the chief audit executive’s (CAE ' s) reporting line

D.

Document agreement between the CAE and the individual to whom the CAE reports

Full Access
Question # 40

An internal audit activity is performing a governance engagement. Which of the following would provide the best evidence for an internal auditor when evaluating the organization’s culture?

A.

Personnel and customer surveys, actual reports, and due diligence results regarding third-party governance practices.

B.

Details on mandatory reporting to third parties, disclosure committee charter and responsibilities, and the internal communication system.

C.

Succession plans, development programs, and job descriptions with responsibilities and authorities.

D.

Ethics and integrity policy; structured interviews with employees; and established and communicated values, mission, and vision.

Full Access
Question # 41

According to IIA guidance, which of the following is a required aspect of an internal audit charter?

A.

Management approval

B.

Independent review

C.

Reporting relationships

D.

Quarterly assessment

Full Access
Question # 42

Which of the following indicates that internal audit independence may be compromised?

A.

The internal auditor maintains a close personal relationship with operational management.

B.

Material observations were intentionally left out of the audit report.

C.

Internal auditors assigned to the audit engagement did not have the knowledge, skills, and competencies needed to perform their responsibilities.

D.

An internal auditor failed to apply professional skepticism while performing audit tests in an area overseen by an experienced, reputable manager

Full Access
Question # 43

An auditor for a large wholesaler is evaluating the controls over the approval and oversight of credit sales. Which of the following procedures would be a control weakness?

A.

The credit department is responsible for approving shipments to all customers

B.

The finance committee of the board of directors periodically reviews credit standards

C.

Customers who fail to meet credit requirements must pay cash for shipments upon delivery

D.

The sales department is responsible for determining the credit ratings of customers

Full Access
Question # 44

Which of the following is the most effective way for internal auditors to determine whether ethical values are followed throughout the organization?

A.

Review the organization ' s ethical value structure and reporting procedures.

B.

Review what the organization considers to be ethical behavior, such as the employee code of conduct.

C.

Review employee survey responses and follow up on those that suggest weaknesses in the ethical climate.

D.

Review the organization ' s records to ensure all employees have signed statements that they will follow ethical practices.

Full Access
Question # 45

An internal audit activity is taking steps to promote professional development among the staff, and is in the process of implementing a mentorship program. According to HA guidance, which of the following is important for a successful mentorship program?

A.

It is best if the mentor is the chief audit executive.

B.

Mentor meeting documentation should be retained in personnel files.

C.

It should target both new hires and highly experienced staff.

D.

Meetings with mentors should be formal and scheduled.

Full Access
Question # 46

Which of the following statements is true regarding managing an internal audit function?

A.

An internal audit function directed towards performing primarily operational activities becomes more effective in providing management with an objective opinion on the design of risk management and governance processes.

B.

An internal audit function is effectively managed when the results of its work achieve the purpose and responsibility included in its audit charter.

C.

The size of the internal audit function, as well as the complexity of its work, determines whether the chief audit executive should create policies and procedures to effectively manage the internal audit function.

D.

When an external service provider serves as the internal audit function, the provider assumes responsibility for maintaining an effective internal audit function.

Full Access
Question # 47

Which of the following best demonstrates the authority of the internal audit activity?

A.

Suggesting alternatives to decision makers.

B.

Improving the integrity of information.

C.

Determining the scope of internal audit services

D.

Achieving engagement objectives.

Full Access
Question # 48

Which of the following items related to the quality assurance and improvement program should the chief audit executive report to the board?

A.

Ongoing monitoring results

B.

Periodic management assessment results

C.

Annual risk assessment results

D.

Internal auditors ' training evaluation results

Full Access
Question # 49

After an engagement was completed and the final communication was issued, it came to the attention of the engagement supervisor that additional work was required to review some significant risks in the processes of the area under review.

How should the engagement supervisor proceed after completing the additional work?

A.

Update the final communications only if there are adverse findings stemming from the review.

B.

Update the report regardless of the additional findings to ensure senior management and risk owners are notified.

C.

Notify the chief audit executive of the findings, and allow her to determine whether communications are to be updated.

D.

Notify all parties of the errors and omissions from the original communications.

Full Access
Question # 50

An internal auditor found that his organization did not make a disclosure that is required by law. However, the auditor decided not to raise an audit finding. Which of the following Code of Ethics principles was violated?

A.

Objectivity.

B.

Integrity.

C.

Proficiency.

D.

Confidentiality.

Full Access
Question # 51

In an internal audit charter, which of the following statements regarding the chief audit executive (CAE) would be most directly related to describing the responsibilities of the internal audit activity*?

A.

The CAE shall report functionally to the board and administratively to the chief financial officer

B.

The CAE and the Internal audit activity shall have full access to any and all records and personnel of the organization that are relevant to audit engagements

C.

The CAE and the internal audit activity shall be independent and objective in performing their work.

D.

The CAE shall report periodically on the performance of the internal audit activity relative to its plan

Full Access
Question # 52

The chief audit executive (CAE) of a multinational corporation has been assigned to assist management in identifying an internal control framework for the organization. The CAE wants to ensure the framework is comprehensive and will effectively meet the needs of various stakeholders.

Which factor should the CAE primarily consider?

A.

The organization’s IT infrastructure and its alignment with business objectives.

B.

The CEO’s personal views on risk management.

C.

The organization’s strategic goals and risk appetite.

D.

The size and geographical dispersion of the organization.

Full Access
Question # 53

Which of the following would best describe a control implemented to detect cash register disbursement fraud in a large retail store?

A.

Separate the duties of processing and authorizing refunds on merchandise

B.

Post signs in the register area prompting customers to ask for and examine their sales receipts

C.

Periodically count the cash in the register and compare it to the expected amount

D.

Use cash registers with internal tapes that are tamper proof and that require a manager to process voids or refunds

Full Access
Question # 54

Prior to commencing a financial compliance engagement, the engagement supervisor reads the business plan for the finance department and meets informally with the director to learn more about any key issues. Which of the following competencies is the engagement supervisor demonstrating?

A.

The ability to inspire trust

B.

The ability to communicate effectively

C.

The ability to display courage

D.

The ability to understand the needs of stakeholders

Full Access
Question # 55

According to IIA guidance, a new internal auditor is expected to possess which of the following competencies?

A.

Technical industry-specific expertise.

B.

Expertise in cybersecurity, an area of increasing risk.

C.

Knowledge of IT risks and controls.

D.

Knowledge of forensic accounting.

Full Access
Question # 56

Which of the following is a typical characteristic of an organization ' s risk management framework?

A.

Risk tolerance may or may not align with risk appetite depending on whether the assessment is quantitative or qualitative

B.

Risk is assessed on both an inherent and a residual basis

C.

The framework addresses four organizational objective categories strategic, historical, operational, and investment

D.

External risks and internal opportunities are omitted from the risk assessment scope

Full Access
Question # 57

Which of the following describes a primary responsibility for the internal audit activity in helping management maintain effective controls?

A.

Promoting continuous evaluation

B.

Promoting continuous monitoring

C.

Promoting continuous improvement

D.

Promoting continuous reporting

Full Access
Question # 58

Nearing the completion of fieldwork, an internal auditor shared the draft report findings with management prior to the closing meeting. During the closing meeting, management expressed dissatisfaction in that they were not familiar with some of the findings. Management also noted that some aspects of the report seemed confusing. Which of the following competencies appears to have been lacking in this scenario?

A.

Communication.

B.

Business acumen.

C.

Persuasion.

D.

Critical thinking.

Full Access
Question # 59

Which of the following is the best reason why the engagement supervisor should take care in explaining to local management the criteria that will be used to measure the effectiveness of the control environment?

A.

The assessment will cover soft controls and company values.

B.

The assessment will focus on the policy for a particular process.

C.

The assessment will lack a defined scope

D.

The assessment will probably uncover fraud risks.

Full Access
Question # 60

An internal audit activity is using the auditing-by-element approach to audit the organization ' s controls around corporate social responsibility. Which of the following would be an element for the internal audit activity to consider?

A.

Working conditions.

B.

Employees ' families.

C.

Marketplace competition.

D.

Shareholders and investors

Full Access
Question # 61

Who is responsible for ensuring internal auditors’ continuing professional development?

A.

Individual internal auditors.

B.

Chief audit executive.

C.

The board.

D.

Engagement supervisors.

Full Access
Question # 62

An internal audit activity maintains a quality assurance and improvement program that includes annual self-assessments. The internal audit activity includes in each engagement report a clause that the engagement is conducted in conformance with the International! Standards for the Professional Practice of Internal Auditing (Standards). Which of the following justifies inclusion of this clause in the reports?

A.

Internal audit activity policies and engagement records provide relevant, sufficient, and competent evidence that the statement is correct.

B.

The audit committee has reviewed the annual self-assessment results and approved the use of the clause.

C.

The self-assessment results were validated by a qualified external review team three years prior.

D.

The internal audit charter, approved by the audit committee, requires conformance with the Standards

Full Access
Question # 63

Which of the following scenarios would most likely impair the independence of an internal audit activity?

A.

A relative of an internal audit team member works m a department being reviewed

B.

The internal audit budget is reduced by management requiring the removal of all lT-related engagements from the audit plan

C.

An audit manager removes a finding from the draft report due to disagreements with the chief financial officer

D.

The operating effectiveness of a control is reported as ' satisfactory. " because no concerns were identified during planning

Full Access
Question # 64

Which of the following activities would an internal auditor perform as a consulting engagement for an organization?

A.

Advising new internal auditors working for the organization on how to develop strategies on planning audits for the upcoming fiscal year

B.

Assessing whether the organization ' s corporate social responsibility program is meeting its yearly goals to reduce carbon emissions.

C.

Briefing the organization ' s department managers on how to implement risk management processes into their daily operations.

D.

Communicating with senior management to better understand how new purchasing controls will minimize payment processing time.

Full Access
Question # 65

Which of the following is an indicator of ineffective third-party risk management?

A.

Sourcing of third parties does not follow public procurement law.

B.

Violations of service conditions trigger either fines or termination.

C.

Due diligence of third parties is conducted only after contract signing.

D.

The right-to-audit clause is limited by personal data protection regulations.

Full Access
Question # 66

A whistleblower reveals to the chief audit executive (CAE) detailed allegations of potential fraud at the senior management level. Although the CAE has some experience in the area, she chooses to retain an external fraud expert to conduct the investigation. When asked by the director of finance to defend the expenditure, which of the following statements represents the CAE ' s best response?

A.

The CAE refers to the Standards and explains that to protect her independence, she needs to remain isolated from the investigation.

B.

The CAE refers to the Standards and explains that the internal audit activity must obtain competent assistance if needed.

C.

The CAE refers to the Standards and explains that to protect her objectivity, she needs to remain isolated from the investigation.

D.

The CAE describes the specifics of the allegation to underscore the importance of the situation and the need for expert investigation

Full Access
Question # 67

Which of the following scenarios would most likely impair the internal audit function’s independence?

A.

An internal auditor assisted external auditors with a review of the payables department. The auditor worked in the payables department a little over a year ago.

B.

The chief audit executive had responsibility for the risk management function and helped coordinate an audit of that area by a third-party consultant.

C.

The chief audit executive was urged by the chief financial officer to scale down an accounts payable audit due to limited funds to cover audit costs.

D.

A new internal auditor was part of a team reviewing an area for which she was responsible less than a year ago. The advisory engagement was requested by management.

Full Access
Question # 68

Which of the following scenarios represents a top-down flow of information regarding corporate governance?

A.

The chief audit executive receives supply chain audit reports from an internal audit manager.

B.

The chief administrative officer reviews the payroll calendar prepared by the payroll manager.

C.

The chief information officer receives cybersecurity reports from the IT manager.

D.

The board approves the new annual budget prepared by the CEO.

Full Access
Question # 69

Which of the following options would include the policies and procedures that help ensure management’s risk responses are accomplished?

A.

Information and communication.

B.

Control activities.

C.

Risk assessment.

D.

Monitoring.

Full Access
Question # 70

An audit client who was unsatisfied with the audit report rating called the chief audit executive (CAE) and complained that the internal auditor who performed the audit was biased because his spouse, who worked in the area under review, was on a list of employees to be terminated. Which of the following measures would be most appropriate to prevent this situation from arising?

A.

Initiating an internal investigation to clarify whether a biased judgment took place.

B.

Requiring the internal auditors to disclose any potential conflicts of interest.

C.

Requiring that the audit client disclose any potential conflicts of interest with the auditor.

D.

Requiring human resources manager to submit all future job applicants ' data in order to identify relatives of auditors.

Full Access
Question # 71

A newly appointed chief audit executive (CAE) is tasked with creating a new internal audit activity within the organization. Which of the following would the CAE need to include in the new internal audit charter?

A.

The requirement to provide an annual cost analysis that justifies having an internal audit activity

B.

The specific engagements that the internal audit activity will perform for the organization

C.

The board s oversight role and responsibilities pertaining to the internal audit activity

D.

The relevant regulations that will guide the internal audit activity ' s regulatory compliance assessments

Full Access
Question # 72

Which of the following best describes the risk created when a manager bypasses organizational policies and procedures in order to meet an organization’s objective?

A.

Accountability/reward risk.

B.

Monitoring failure risk.

C.

Communication failure risk.

D.

Knowledge/skills risk

Full Access
Question # 73

Which of the following best demonstrates organizational independence of the internal audit activity?

A.

The chief audit executive reports directly to the board

B.

Internal auditors may not disclose personal data of the audit client

C.

Internal auditors may not accept gifts from management of the area under review

D.

Internal auditors must observe the law and make required disclosures

Full Access
Question # 74

Which of the following is the internal audit activity expected to do with respect to the organization ' s governance processes?

A.

Formally audit all governance activities.

B.

Provide strategic guidance on the organizational processes to senior management.

C.

Achieve agreement with the board regarding the range of activities, depth of review, and time period to include in the assessment.

D.

Audit against the governance structures and practices widely used in the industry.

Full Access
Question # 75

Which of the following describes an advisory service?

A.

Engagement results include conclusions, recommendations, and independent opinion based on an objective assessment of evidence.

B.

Internal auditors determine engagement objectives, scope, and the assessment techniques to be used.

C.

Internal auditors provided the assessment services requested by the engagement client.

D.

The parties involved in the engagement process are the internal auditor, the owner of the assessed activity, and the user of the engagement results.

Full Access
Question # 76

Which of the following frauds is most likely to occur in the accounts payable function?

A.

Factitious vendors are entered into the system, possibly resulting in improper disbursements.

B.

Bad debt expense is intentionally omitted from the financial statements.

C.

Certain costs are capitalized, rather than expensed.

D.

A related party receives benefits not appropriate in an arm ' s-length transaction.

Full Access
Question # 77

Which of the following is a primary benefit of implementing a governance, risk management, and compliance framework within an organization?

A.

Fewer internal audits.

B.

More effective interviews.

C.

Automated risk management strategy tools.

D.

Reduced assurance costs.

Full Access
Question # 78

Which of the following best demonstrates that the internal audit activity is using due professional care?

A.

The internal audit activity reports directly to the board on the engagements it performs.

B.

Internal auditors undertake the necessary training to complete their audit work.

C.

The completion of engagements is based on the assumption that fraudulent activities may exist.

D.

Internal auditors consider the use of technology-based audit and other data analysts techniques

Full Access
Question # 79

A financial institution intends to contract a data center management service provider to host and manage the data in its custody as a response to data security and protection risks.

What technique is being adopted by this organization?

A.

Risk acceptance.

B.

Risk avoidance.

C.

Risk sharing.

D.

Risk reduction.

Full Access
Question # 80

The internal audit activity was denied access to expenditure and budget reports because they were considered to be confidential. This situation would result in which of the following limitations of the internal audit activity?

A.

Independence

B.

Integrity

C.

objectivity

D.

Authority

Full Access
Question # 81

An internal auditor at a multinational organization is reviewing the effectiveness of the organization ' s risk management framework. In this scenario, which of the following statements is true?

A.

The auditor should consider local cultures and customs in various regions when assessing control effectiveness.

B.

Regardless of their location, employees at all levels share responsibility for designing effective controls to mitigate risks.

C.

To achieve an effective internal control environment, the organization ' s risk management plan must be documented and communicated to all levels throughout each region.

D.

Setting clear objectives is a precondition to effectively identifying, assessing, and responding to the organization ' s risks.

Full Access
Question # 82

An internal auditor has documented several instances in which management asked employees to ad against the policies and procedures. Which of the following is the most appropriate next step?

A.

Report the non-compliance cases to the board of directors.

B.

Recommend that management update its policies and procedures based on the circumstances.

C.

Investigate the rationale for management ' s actions.

D.

Recommend those employees to report the cases through the designed whistleblowing channel for the appropriate treatment.

Full Access
Question # 83

Tr» chiet audit executive (CAE) of large organization is preparing job descriptions to hire five new general internal audit staff, two new IT auditors and a senior auditer how is the CAE likely to describe IT requirements for me general internal audit statt positions?

A.

The candidate must be able to apply data analytics tolls methodologies

B.

The candidate must be able to evaluate IT governance and cybersecurity frameworks.

C.

The candidate must be able to understand IT-elated risk and general controls

D.

The candidate must be able to execute web servers, applications, and databases testing procedures.

Full Access
Question # 84

An internal auditor is assessing fraud risks and creating a fraud risk matrix for a particular branch location. Which of the following is most likely to be included in the matrix?

A.

Risks and relevant mitigating controls.

B.

Business processes and relevant fraud risks.

C.

Fraud scenarios and relevant risks.

D.

Opportunity, rationalization, and pressure to commit fraud.

Full Access
Question # 85

Which of the following would best illustrate to the chief audit executive that due professional care was exercised by internal auditors during an engagement?

A.

Internal auditors gave assurance that no irregularities existed.

B.

Internal auditors had the knowledge and skills needed.

C.

Internal auditors assigned were sufficient and appropriate.

D.

Internal auditors considered the use of data analysis techniques.

Full Access
Question # 86

An organization allows the same individual to physically access inventory and purchase new assets when supplies are depleted. Which of the following would best help the organization manage the risk of fraud?

A.

Accounting personnel should regularly perform a reconciliation between invoices and purchase orders.

B.

Accounting personnel should conduct a periodic inventory count and reconcile all inventory movements.

C.

Internal auditors should review the frequency and volume of purchased assets to detect trends in the inventory levels.

D.

Management should establish a policy requiring new inventory asset purchases to be made on serialized order forms with copies retained.

Full Access
Question # 87

Which type of engagement requires that the client agrees with the techniques used by the internal audit activity?

A.

A performance audit.

B.

A sensitive fraud investigation.

C.

A compliance audit

D.

A consulting service.

Full Access
Question # 88

Which of the following describes the primary objective when implementing a risk management framework?

A.

To achieve planned profitability for business expansion.

B.

To enhance an organization ' s confidence in achieving strategy.

C.

To strengthen corporate governance standards.

D.

To eliminate business risks and uncertainties.

Full Access
Question # 89

Which of the following should catch the internal auditor ' s attention as a potential red flag for fraud?

A.

The accounting unit keeps detailed records and preserves supporting documentation in excess of company requirements

B.

One of the subsidiaries has more bank accounts than any other comparable subsidiary

C.

The same external audit firm has been with the company for three years without rotation

D.

The arithmetic median tenure of employees working at production facilities is 15 years

Full Access
Question # 90

The internal audit activity completed its analysis of sample transactions to determine occurrences of double billings According to If A guidance, which of the following best demonstrates that internal auditors exercised due professional care during the review?

A.

Internal auditors found no instances of double billing and concluded there were no significant risks in this area.

B.

Internal auditors documented the scope and methodology of the data testing.

C.

Internal auditors discussed with management how data is safeguarded.

D.

Internal auditors received formal performance feedback from the engagement supervisor.

Full Access
Question # 91

According to IIA guidance, which of the following is the primary reason the chief audit executive discusses the internal audit charter with senior management and the board?

A.

To provide guidance and solicit feedback on managing the internal audit activity as expected by various stakeholders.

B.

To provide an understanding of the Mission of Internal Audit and The IIA ' s mandatory guidance elements.

C.

To provide an update on the internal audit activity ' s quality of engagement supervision.

D.

To provide information on existing internal audit planning, changes to the internal audit plan, and the rationale for the changes

Full Access
Question # 92

Which of the following is a detective control strategy against fraud?

A.

Requiring employees to attend ethics training.

B.

Performing background checks on employees.

C.

Implementing a control self-assessment.

D.

Performing a surprise audit

Full Access
Question # 93

A company selling electronic devices has a satisfaction guaranteed policy allowing customers to return devices within 30 calendar days, no questions asked.

Which of the following would be most concerning for an internal auditor regarding the possibility of fraud?

A.

Company policy does not involve any bonuses for shop managers who surpass sales quotas.

B.

Shop managers are paid a bonus for sales over a monthly quota at the end of each month.

C.

Sales are evenly distributed throughout the year except for high sales and returns during holiday periods.

D.

Shop managers are paid a bonus for net sales over a yearly quota on the first day of March each year.

Full Access
Question # 94

A chief audit executive (CAE) was asked by senior management to establish and manage a risk management function. A new chief risk officer was hired a year later to assume these responsibilities. As this function was included in the current annual audit plan, the CAE engaged an external resource for a risk management engagement. Which of the following potential threats to objectivity was the CAE likely addressing?

A.

Self-review threat.

B.

Advocacy threat.

C.

Familiarity threat.

D.

Personal relationship threat.

Full Access
Question # 95

Which of the following statements is most likely to be true regarding a consulting engagement involving an organization ' s new payroll system?

A.

The internal auditor and engagement client established an understanding that the scope would include the new payroll system project.

B.

The payroll system engagement was scheduled as a result of internal audit ' s risk-based annual planning process.

C.

The internal auditor concluded that the engagement objectives would include assessing the effectiveness of the payroll process controls.

D.

The internal auditor acknowledged the engagement client’s satisfactory performance in the final engagement results that were communicated to senior management and the board.

Full Access
Question # 96

A significant number of employees expressed concerns of a hostile work environment within a large manufacturing plant, which is in contrast to the organization ' s stated culture of tolerance and open communication. Which of the following approaches would be most effective for an internal auditor to assess whether the organization supports a culture of tolerance and open communication?

A.

Assess plant employees ' social media activity for specific messages related to tolerance and open communication

B.

Compare plant employees’ compensation and benefits with those at similar sized organizations that have a stated culture of tolerance and open communication.

C.

Evaluate organization policies and procedures for references related to encouraging tolerance and open communication.

D.

Conduct a meeting with all plant employees and management to discuss tolerance and open communication

Full Access
Question # 97

Which of the following statements regarding corporate governance is true?

A.

The governance process centers on management’s role in risk management.

B.

Senior management is primarily responsible for understanding and focusing on the needs of key stakeholders.

C.

Internal and external assurance providers are an integral part of the governance process.

D.

The governance process begins after setting the organization’s strategic objectives.

Full Access
Question # 98

Which of the following is an appropriate role for the internal audit activity?

A.

Ensuring the organization ' s key risks are managed through appropriate controls.

B.

Assisting the organization in maintaining effective controls.

C.

Implementing new controls to promote continuous improvement.

D.

Validating control assessments performed by the external auditor.

Full Access
Question # 99

Which of the following should play a leading role in overseeing ihe ethical atmosphere of an organization?

A.

Internal audit activity.

B.

Operating management.

C.

Senior management.

D.

Board of directors.

Full Access
Question # 100

In an environment where employees are frequently penalized for mistakes and the organizational culture is one of fear and blame which of the following is an internal auditor most likely to find?

A.

Management regularly overrides key controls

B.

Employee turnover is tow

C.

Careless behavior becomes normal

D.

Employee morale is low

Full Access
Question # 101

With regard to governance, which of the following is a board-level responsibility rather than a management responsibility?

A.

Obtaining assurance on external financial, regulatory, and internal audits.

B.

Complying with laws, regulations, and codes.

C.

Assigning authority and responsibilities organization wide.

D.

Monitoring and measuring performance.

Full Access
Question # 102

A technology company recently hired an entry-level internal auditor. To achieve conformance with the Standards, which of the following must the newly hired internal auditor possess?

A.

An understanding of fraud and fraud risk.

B.

IT audit expertise.

C.

Industry-specific knowledge

D.

At least one audit-related certification

Full Access
Question # 103

To encourage internal audit objectivity, which of the following is an appropriate policy the chief audit executive should establish?

A.

Internal auditors should report their audit findings directly to the audit committee.

B.

To receive an outstanding performance rating, internal auditors are required to generate audit findings.

C.

Prior to hiring a new internal auditor, the chief audit executive must determine whether the auditor owns stock in the organization.

D.

Internal auditors are permitted to audit an entity managed by a close friend or relative, as long as they notify the chief audit executive.

Full Access
Question # 104

While conducting an engagement in the procurement department, the internal auditor noticed that the department head’s travel reports showed minor travel expenses, and there were no charges for hotels, meals, or transportation. However, the auditor knew that the department head frequently traveled worldwide to meet with suppliers and visit their production sites. Which of the following would be the most appropriate next step for the auditor?

A.

The auditor should make a note of the issue for follow-up when employee travel expenses are audited.

B.

The auditor should analyze trends and changes among the organization’s suppliers over the past few years.

C.

The auditor should investigate whether there are any special arrangements regarding senior management travel.

D.

The auditor should analyze the list of destinations the department head visited to estimate typical costs.

Full Access
Question # 105

Which of the following should be considered in developing a risk and control model for use in an engagement?

A.

The risk and control model should be globally accepted by the profession.

B.

The risk and control model should be strictly adhered to in performing the engagement.

C.

The risk and control model should be tailored to the organization that will be the subject of the engagement.

D.

The risk and control model should be developed individually by the auditor for use on individual audit projects within the planned engagement.

Full Access
Question # 106

In an assurance engagement focused on the adequacy of organizationwide risk management practices, which of the following best describes a primary area of interest for the engagement?

A.

The effectiveness of process-level and transaction-level controls.

B.

Conflicts of interest within the organizational structure of the senior management.

C.

The alignment of management decisions with the level of risk the organization is willing to accept.

D.

The actions of upper management in response to the internal audit activity ' s reporting

Full Access
Question # 107

Senior management requests that the chief audit executive nominate an internal auditor to observe the bid opening process and offer advice on any improvement opportunities.

How would this requested assignment differ from a typical assurance engagement?

A.

The nature of this type of engagement would not need to be included in the charter.

B.

The auditor would be able to assume some management responsibilities for this particular type of engagement.

C.

The results would not need to be communicated in writing.

D.

The scope of the engagement would be determined in agreement with senior management.

Full Access
Question # 108

According to IIA guidance, the internal audit activity must be free from interference in which of the following areas in order to maintain organizational independence?

A.

Monitoring resources.

B.

Compensating the chief audit executive.

C.

Determining scope.

D.

Allocating internal costs.

Full Access
Question # 109

Which of the following statements is true regarding the use of risk frameworks?

A.

They are only effective at the strategic level in managing key external and internal risks.

B.

They are jointly managed by the board and senior management to create a consensus for key risks.

C.

They are usually implemented as an automated methodology to identify and manage key risks at the process level.

D.

They are flexible in addressing and linking objectives and related risks across the organization.

Full Access
Question # 110

Which of the following activities best ensures that internal auditors grow professionally in alignment with current industry trends to meet the expectations of primary stakeholders?

A.

Deploying self-assessments against a competency benchmark.

B.

Acquiring memberships in professional organizations.

C.

Developing professional succession plans.

D.

Obtaining subscriptions to professional journals in their area of interest.

Full Access
Question # 111

An internal audit activity includes in its audit reports the assertion that its work is performed in conformance with the International Standards for the Professional Practice of Internal Auditing ( Standards). A recent external quality assessment concluded that the internal audit activity had substantial deficiencies that impact its overall operations.

According to IIA guidance, which of the following is the most appropriate action for issuing future audit reports?

A.

Refrain from indicating that the internal audit activity operates in conformance with the Standards until the chief audit executive confirms that the internal audit activityhas addressed all areas of nonconformance and the audit committee has been notified.

B.

Refrain from indicating that the internal audit activity operates in conformance with the Standards until another external assessment confirms that the significant areas of nonconformance have been addressed.

C.

Indicate that the internal audit activity operates in partial conformance with the Standards t as the internal audit activity has a quality assurance and improvement program in place to address deficiencies and has met the requirement for conducting an external assessment.

D.

Update and reissue previous audit reports, removing the assertion that the internal audit activity operates in conformance with the Standards, and distribute them to ail parties who received the original reports.

Full Access
Question # 112

Upon completion of an external quality assessment, which of the following would the chief audit executive be required to report to the board?

A.

The total time spent to accomplish the external assessment

B.

The detailed evaluation results of the external assessment

C.

The competency and independence of the external assessment team

D.

The timetable and schedule of the next external assessment

Full Access
Question # 113

Management decided to post the organization ' s newly established code of conduct on its website. This decision is primarily intended to mitigate which of the following risks?

A.

Accountability risk.

B.

Communication risk.

C.

Knowledge risk.

D.

Cultural risk.

Full Access
Question # 114

Which of the following best describes why a chief audit executive might obtain the services of a fraud specialist to assist in a major fraud investigation ' ?

A.

Fraud specialists are better at using computer-assisted audit techniques

B.

Fraud specialists are better equipped to act as an expert witness in court

C.

Fraud specialists are better able to properly apply due professional care

D.

Fraud specialists are better at using crime scene investigation techniques

Full Access
Question # 115

An organization ' s fraud policies and procedures dictate that the internal audit activity does not have primary responsibility for conducting fraud investigations and should, in fact, refrain from involvement in investigations. Which of the following activities would be considered acceptable for internal auditors to perform of this organization?

A.

Evaluate the effectiveness of fraud investigations

B.

Oversee and monitor senior management s approach to manage fraud risks

C.

Set the tone for fraud risk management within an organization

D.

Evaluate whether the financial statements are free of material misstatement due to fraud

Full Access
Question # 116

According to The IIA’s Code of Ethics, which of the following statements is true?

A.

When an internal auditor releases required information to a regulator, resulting in a significant loss through fines and penalties for the organization, he fails to add value.

B.

When an internal auditor limits the scope of the audit engagement after learning that management is hiding relevant information, he demonstrates integrity.

C.

When an internal auditor disagrees with the treatment received by workers in the organization’s foreign subsidiary and alters the audit program to highlight the issue, the fails to demonstrate objectivity.

D.

When an internal auditor continues with an audit engagement, despite the audit client’s claims that the work performed is unnecessary and redundant, he fails to demonstrate competency.

Full Access
Question # 117

Which of the following actions by an internal auditor would be the most relevant to determine the effectiveness of controls?

A.

Participate in a fraud risk-assessment session as an in-house facilitator.

B.

Send regular written updates to senior management on new control-related regulations.

C.

Lead a seminar on internal controls and provide numerous examples to the audience.

D.

Conduct a surprise inventory count at the raw materials warehouse.

Full Access
Question # 118

Due to extreme liquid fuel price fluctuations, management decided to designate a specific price below which liquid fuel shall not be sold to customers, but instead shall be pumped into storage tanks. Which of the following risk responses has management selected?

A.

Risk reduction.

B.

Risk transfer.

C.

Risk acceptance.

D.

Risk avoidance.

Full Access
Question # 119

Which principle of the HA Code of Ethics focuses on continuing education and professional development?

A.

Due professional care

B.

Professionalism

C.

Proficiency

D.

Competency

Full Access
Question # 120

Which level of corporate social responsibility does whistleblowing in companies primarily support?

A.

Ethical responsibility.

B.

Economic responsibility.

C.

Legal responsibility.

D.

Discretionary responsibility.

Full Access
Question # 121

The internal audit activity was asked to conduct an investigation for potential fraud in the treasury department and subsequently contracted with a forensic accountant to join the team for the engagement. Which of the following parties has the primary responsibility for resolving any fraud incidents found as a result of this investigation?

A.

Chief audit executive.

B.

Senior management.

C.

The forensic accountant.

D.

The legal department.

Full Access
Question # 122

An internal auditor extended the scope of testing for a disbursements engagement following a fraud risk assessment Despite the investment of additional audit resources no significant issues were found Unfortunately a major payment fraud was discovered several

months later According to IIA guidance which of the following statements is true regarding the internal auditor ' s application of due professional care?

A.

Due professional care was not applied because no additional work should have been performed unless there was actual evidence of fraud

B.

Due professional care was not applied because the extended scope resulted in no issues being identified, while fraud actually existed

C.

Due professional care was applied as the internal auditor modified the scope based on reasonable judgment, despite the additional cost of resources

D.

Due professional care was applied as the cost of audit resources should not be a determining factor in the degree of testing undertaken

Full Access
Question # 123

Which of the following is a preventive control the organization could implement to mitigate fraudulent activity in the accounts payable department?

A.

Delivering fraud awareness training to employees in the department.

B.

Segregating duties between employees in the department.

C.

Requesting the internal audit activity perform an independent evaluation of fraud risk in the department.

D.

Requiring accounts payable employees to sign a code of conduct awareness confirmation.

Full Access
Question # 124

Which of the following organizations is adopting an acceptance technique in terms of its risk response?

A.

An organization that takes no action in managing the possible exposure to an earthquake.

B.

An organization that opts out of investing in a new region due to volatility in foreign exchange rates.

C.

An organization that takes out insurance policies to protect its property and equipment.

D.

An organization that deploys policies and procedures to guide business activities and practices

Full Access
Question # 125

Which of the following is most important for an internal auditor to consider when developing an approach for an audit engagement in a foreign country?

A.

Currency exchange rates, as they relate to internal audit-related expenses.

B.

Differences in typical working hours, compared to other countries.

C.

The effects of subtle language nuances on translations.

D.

Accepted practices that may be illegal in other countries.

Full Access
Question # 126

Due to the increased operational responsibility of the CEO the chief audit executive (CAE) of an organization currently reports to the chief financial officer (CFO) What is the likely impact of such a situation?

A.

There may be limitation in the scope of engagements that can be undertaken

B.

The CFO could provide expert advice when auditing areas under his purview

C.

The internal audit activity is adequately positioned when the CAE reports to a member of executive management

D.

The expertise of finance staff can be called upon during an audit of finance-related areas

Full Access
Question # 127

The chief audit executive (CAE) annually develops a budget and resource plan and submits it to the board for approval. This action best fulfills which of the following responsibilities of the CAE?

A.

The responsibility to maintain organizational independence.

B.

The responsibility to perform engagements with due professional care.

C.

The responsibility to communicate corrective action plans to the board.

D.

The responsibility to define the purpose of the internal audit activity.

Full Access
Question # 128

During an audit of company expenses, the internal auditor performed a test using data analytics and identified a violation of the company ' s expenses policy. The auditor who discovered the issue considered it a potential fraudulent transaction and informed the chief financial officer (CFO). The CFO dismissed the concern because he did not understand the data analytics test that was performed and the transaction was of a low value. Given this situation, which skills or competencies should this internal auditor seek to improve?

A.

Skills in evaluating the risk of fraud.

B.

Knowledge of key IT risks and controls

C.

Soft skills such as communication and negotiation.

D.

Knowledge and understanding of the company ' s expenses policy

Full Access
Question # 129

What is expected of internal auditors in regards to due professional care?

A.

Auditors perform assurance services without regard to cost

B.

Auditors perform assurance services effectively to identify all risks

C.

Auditors perform assurance services needed to achieve the engagement ' s objectives

D.

Auditors perform assurance services to guarantee all significant risks will be addressed

Full Access
Question # 130

Which of the following best describes the internal audit activity ' s contribution to the implementation of the risk management framework?

A.

Internal audit identifies key risk areas during assurance reviews and provides audit findings.

B.

Internal audit assists with the prioritization of identified risks.

C.

Internal audit participates in setting the risk appetite.

D.

Internal audit takes part in the design of risk mitigation measures.

Full Access
Question # 131

Which of the following accurately describes the concept of inherent risk?

A.

Risk factors that exist when controls are in place and operating effectively

B.

Internal risk factors assuming no controls are in place

C.

Risk factors that cannot be mitigated because they are innate to a process

D.

Combination of internal and external risk factors in their pure state assuming no controls are in place

Full Access
Question # 132

Which of the following statements best demonstrates application of due professional care during an assurance engagement?

A.

The engagement detected irregularities and noncompliance instances.

B.

The engagement supervisor had no significant comments in the supervisory review.

C.

The audit procedures were systematically planned, executed, and documented.

D.

The engagement objectives were designed to assist the engagement client.

Full Access
Question # 133

According to IIA guidance, an internal audit charter should detail which of the following?

A.

The objectives and goals of management

B.

The process used by the CAE to manage the organization ' s internal controls

C.

The nature of services that the internal audit activity will provide to external third parties

D.

The responsibilities of the audit committee

Full Access
Question # 134

Once an organization ' s risks are identified, what would be the next step to ensure resources are properly allocated to manage those risks?

A.

Risk responses must be selected.

B.

Risks must be assessed.

C.

The risk universe must be established.

D.

Risk responses must be aligned.

Full Access
Question # 135

Internal controls belong to which risk response category?

A.

Reduction.

B.

Avoidance.

C.

Sharing.

D.

Acceptance.

Full Access
Question # 136

An internal auditor notes that inventory counts are conducted on Mondays only and that all documentation is on paper as there are no computers in the underground warehouses. Also she notices that the person responsible for receiving the goods is the same one who distributes materials and spare parts Finally, she sees that spare parts are written off and taken by the heads of mining units to different underground locations to wait for their turn to be installed. Which of the described findings requires more consideration from a fraud risk perspective?

A.

The job responsibilities of the warehouse employee compromise segregation of duties

B.

Spare parts are written off before their actual usage and installation

C.

Warehouse management is conducted on paper and requires further investigation

D.

The inventory counts take place on specific days of the week for no apparent reason

Full Access
Question # 137

A global manufacturing company has three regional offices. The chief audit executive (CAE) is concerned about the cost of an upcoming external quality assessment of the internal audit activity. The last external assessment was performed six years ago. Recently, the internal audit staff at one of the regional offices performed an internal assessment. To ensure conformance with the Standards, what is the most appropriate action for the CAE to take?

A.

Request from the audit committee an additional budget and an extension so that the external assessment could be performed next year.

B.

Review the results of the internal assessment, identify weaknesses, and implement improvements at the remaining offices.

C.

Request the regional office that performed the internal assessment to perform an assessment of the remaining offices.

D.

Request that an external assessor validate the results of the internal assessment and review the remaining offices.

Full Access
Question # 138

How can internal auditors best enhance the credibility and value of their work?

A.

By prioritizing management’s advisory requests over assurance engagements.

B.

By documenting workpapers after engagements are completed.

C.

By following audit programs from previous assurance engagements.

D.

By providing risk-based advice.

Full Access
Question # 139

An internal auditor is trying to evaluate what could go wrong after determining that a risk management technique is operating effectively. What type of risk is the auditor assessing?

A.

Inherent risk.

B.

Residual risk.

C.

Impact risk.

D.

Detection risk.

Full Access
Question # 140

During an audit engagement, a junior staff internal auditor begins to suspect a fraud may have occurred involving a friend of the engagement supervisor. He reports his concerns to the engagement supervisor, who disagrees with his suspicions and directs him to continue with the engagement as planned. Given the circumstance, what is the most appropriate action for the junior auditor to take?

A.

Document in the workpapers and expand testing.

B.

Continue with the engagement as planned, per the more senior auditor.

C.

Report the suspected fraud to law enforcement officials and seek financial restitution.

D.

Escalate the concern to the chief audit executive.

Full Access
Question # 141

Which of the following statements is true regarding the importance of risk management?

A.

Risk management ensures the ability to eliminate potential hazards to the organization.

B.

Risk management includes consideration of potential opportunities for the organization.

C.

Risk management aids with the establishment of appropriate key performance indicators.

D.

Risk management increases employees ' commitment and belief in strategic goals.

Full Access
Question # 142

Which of the following statements is true regarding an organization ' s code of ethics?

A.

It should be written with primary consideration given to using a rule-based approach.

B.

It should be of two variations: one applicable internally and one applicable for third parties.

C.

Its operational effectiveness cannot be tested using traditional audit and rating systems such as maturity models.

D.

It should require an annual attestation of compliance with the code of conduct by all employees.

Full Access
Question # 143

Wi ch of the following circumstances would most likely be considered a potential red flag for fraud by the internal audit activity?

A.

The monthly payroll reports are not vetted to ensure terminated employees have been removed from the payroll system

B.

The volume of nonroutine journal entries has steadily increased over time.

C.

The database of approved suppliers has not been reviewed the last year

D.

The recent employee survey indicates that some employees remain unaware of the organization’s whistieblower hotline.

Full Access
Question # 144

What must a chief audit executive do if significant changes to regulations may affect the nature of internal audit services?

A.

Discuss the changes with the external auditors.

B.

Discuss the changes with the CEO, who is responsible for escalating to the board.

C.

Discuss the changes with the board and senior management.

D.

No action is needed because the changes are unlikely to affect the work of internal auditors.

Full Access
Question # 145

Which of the following best demonstrates the board of directors ' governance over internal control?

A.

The board bears direct responsibility for developing and implementing the internal control system.

B.

The majority of board members are experienced and qualified members of the organization ' s executive management team.

C.

The board may be assisted by an audit committee, chaired by the chief audit executive.

D.

The board is responsible for succession planning for the CEO and other key members of the executive management team.

Full Access
Question # 146

An internal auditor is performing testing to gather evidence regarding an organization’s inventory account balance and is mindful of the possibility that the sample used might support the conclusion that the recorded account balance is not materially misstated when, in fact, it is. The auditor ' s concern best describes which of the following risks?

A.

incorrect rejection risk

B.

Incorrect acceptance risk.

C.

Tolerable misstatement risk.

D.

Anticipated misstatement risk

Full Access
Question # 147

Which of the following is an example of an entity-level control pertaining to the finance area of an organization ' ?

A.

Key account reconciliation such as bank reconciliation

B.

Segregation of duties between posting and reviewing journal entnes

C.

A signing authority matrix for spending approvals

D.

The establishment of a finance and audit committee

Full Access
Question # 148

To achieve conformance with the Standards, the chief audit executive must include which of the following activities in the quality assurance and improvement program (QAIP)?

A.

Require board oversight of the QAIP.

B.

Assess Standards conformance for each individual engagement.

C.

Conduct a self assessment at least once every five years.

D.

Report the results of the QAIP to senior management

Full Access
Question # 149

To comply with the proficiency standard, which of the following would the chief audit executive likely consider as the primary hiring criterion when choosing a new internal auditor?

A.

The auditor ' s demonstrated problem-solving skills.

B.

The auditor ' s skills compared to those already possessed by other audit staff.

C.

The auditor ' s ability to be self-motivated and a good team player.

D.

The length and consistency of the auditor ' s work experience.

Full Access
Question # 150

Which of the following most accurately describes corporate social responsibility at an organization?

A.

An organizational locus on improving the overall environment, even it is to the detriment of the local community.

B.

A philosophy driven by employees that flows up to senior management and the board of directors.

C.

An overall commitment of the organization to improve the quality of life for not only the employees but the community at large.

D.

A policy of ensuring that the organization is socially responsible, even if it leads to unprofitability due to increased costs.

Full Access
Question # 151

An internal auditor is providing consulting services on an area he was responsible for three years ago. Part of the consulting scope covers a review of a performance measuring system that the auditor helped to develop. What is the best course of action for the auditor to take concerning the consulting service?

A.

Accept the consulting services only after receiving approval to do so from the board.

B.

Accept the consulting services. The objectivity won ' t be impaired if it has been more than a year since he last worked in the area under review.

C.

Refrain from providing the consulting service because he was responsible for that area and his objectivity will be impaired,

D.

Disclose the potential impairment to the customer before accepting the consulting engagement

Full Access
Question # 152

Which of the following is (he most effective way any organization can ensure proper governance over its internal controls?

A.

By adopting the best practices of similar organizations in the industry.

B.

By adjusting their internal control framework as business practices evolve.

C.

By introducing the universally accepted COSO internal control framework.

D.

By encouraging the internal audit activity to provide training on internal controls.

Full Access
Question # 153

Which statement accurately describes the authority of the internal audit activity as outlined in the audit charter?

A.

The chief audit executive (CAE) shall report directly to the board and administratively to the CEO.

B.

The CAE shall provide senior management and the board with performance updates quarterly.

C.

The internal audit team shall have full access to the organization ' s records, physical property, and personnel required to conduct audit engagements.

D.

The internal audit activity shall maintain a quality assurance and improvement program in conformance with the Standards.

Full Access
Question # 154

An organization allows the same individuals to physical access inventory and purchase new assets when supplies are depleted. Which of the following would best help the organization manage the risk of fraud?

A.

Accounting personnel should regularly perform reconciliation between invoices and purchase orders

B.

Accounting personnel should conduct a periodic inventory count and reconcile inventory movements

C.

internal auditors should review Vie frequency and volume of purchased assets to detect trends in the inventory levels

D.

Management should established a policy requiring new inventory asset purchases to be made on serialized order forms with copies retained

Full Access
Question # 155

Which of the following is a limitation of detective internal controls in fraud management?

A.

Implementation costs tend to be higher than the expected benefits.

B.

They tend to be easy for fraudsters to circumvent.

C.

They are not designed to improve efficiency of operations.

D.

They are not effective in preventing fraud.

Full Access
Question # 156

The internal audit activity is performing an assessment of an organization ' s ethics program, and the engagement scope specifies a focus on the training program ' s design. According to IIA guidance, which of the following questions would be the most relevant?

1. Does the training include situations that require an ethical decision?

2. What percentage of employees have taken the training?

3. What are the results of the employee assessment of the organization ' s ethical climate?

4. Does the instructor provide feedback on the thought process to reach an ethical resolution?

A.

1 and 2.

B.

1 and 4.

C.

2 and 3.

D.

3 and 4.

Full Access
Question # 157

There is a growing perception that employees generally evade their responsibilities. What impact will an internal auditor most likely see during an engagement?

A.

Supervisors are likely to reduce their level of supervision and increase span of control.

B.

Employees are likely to be supervised closely and given little freedom.

C.

Peer employees are likely to trust one another, but distrust management.

D.

Employees are likely to join forces to accomplish their duties as teams.

Full Access
Question # 158

Which of the following would be considered an impairment to an internal auditor ' s objectivity when performing a review of the organization ' s procurement function ' ?

A.

The internal auditor worked on the implementation of the accounting system within the organization before joining the internal audit activity last year

B.

The internal auditor is part of a multidisciplinary team tasked to assist with a new project implementation checklist within the organization

C.

The internal auditor worked as a sourcing specialist before joining the internal audit activity last year

D.

The internal auditor participates in a cross-departmental team for information and data security within the organization

Full Access
Question # 159

Which of the following statements best illustrates why internal auditors assess soft controls?

A.

Assessing soft controls are an effective method of assessing risk related to personnel.

B.

Assessing soft controls, as opposed to hard controls, makes it easier to evaluate operating effectiveness.

C.

Assessing soft controls can help internal auditors in undertaking root-cause analysis.

D.

Assessing soft controls provides more objective information than assessing hard controls.

Full Access
Question # 160

According to The IIA ' s Competency Framework, which competency is considered the mandatory minimum for internal auditors to possess when performing internal audit engagements?

A.

To recognize red flags that indicate fraud.

B.

To recommend controls to prevent fraud.

C.

To apply forensic auditing techniques to detect fraud.

D.

To evaluate the potential for fraud.

Full Access
Question # 161

An executive responsible for the implementation of an expensive asset management system reported the project to be a success in cost optimization, although the opposite was true. During an interview, the executive admitted that he knew the actual outcome of the project but did not want to admit failure because he was being considered for a promotion.

Which of the following common fraud factors is most likely represented by the executive’s behavior?

A.

The executive felt that his decision was justifiable in this situation.

B.

The executive was fearful of retaliation.

C.

The executive had the opportunity to exploit his position.

D.

The executive felt pressure to succeed.

Full Access
Question # 162

According to IIA guidance, which of the following conditions would enhance the independence of the internal audit activity?

A.

The organizational culture rewards critical and objective thinking.

B.

The quality of work performed by the internal audit activity is periodically reviewed.

C.

The organization establishes effective governing body oversight.

D.

Audit assignments are rotated among internal audit staff.

Full Access
Question # 163

An organization is implementing a new cybersecurity policy and has established a committee to ensure stakeholder alignment across the organization ' s infrastructure, network, and security teams. The head of the committee has asked the chief audit executive if the internal audit activity could play a role in these efforts. According to HA guidance, which of the following is the most appropriate response?

A.

It is not appropriate for the internal audit activity to play a role because its independence must be protected.

B.

The internal audit activity should not participate because there are no IT auditors on staff.

C.

The internal audit activity is knowledgeable about risk and therefore should prioritize the organization ' s responses and control activities for the committee.

D.

The internal audit activity may assist the committee and consult with management on the organization ' s responses and control activities.

Full Access
Question # 164

An internal auditor assessed that the risk of steel theft at a plant is high. In response, the plant ' s management introduced a number of controls, including fences around the facility, a metal detector at the entrance, and monthly steel inventory counts. If the controls operate as intended, which of the following outcomes would the internal auditor hope to see?

A.

The inherent risk will be mitigated to a level lower than the residual risk.

B.

The inherent risk will be reduced to an acceptable level.

C.

The residual risk will be reduced to an acceptable level.

D.

The residual risk will be eliminated

Full Access
Question # 165

A chief audit executive (CAE) has been asked by the board to evaluate the effectiveness of ethical programs created by management. Which of the following would be the most appropriate action for the CAE to take?

A.

Compare the design of the organization ' s ethical programs with best practices.

B.

Verify that a code of conduct and related policies exist and are communicated.

C.

Use employee surveys to assess whether ethical programs are achieving desired outcomes.

D.

Compare the cost of the ethical programs with the achieved outcomes.

Full Access
Question # 166

Which of the following statements is true regarding reporting results of the quality assurance and improvement program to senior management and the board?

A.

Internal assessments must be reported to the board at least every five years

B.

If supported by assessment results, reporting provides assurance that internal auditors demonstrate conformance with the Code of Ethics

C.

Following the reporting the board must give the internal audit activity five years to correct any deviations

D.

A report, including the results of both internal and external assessments must be provided to the board annually

Full Access
Question # 167

A series of incidents over the past year reveals several members of senior management possess a limited understanding of the concept and impact of fraud. Which of the following would be the most effective way to approach this issue?

A.

The board should ask the internal audit activity to perform additional assurance engagements.

B.

A comprehensive fraud risk assessment and management program should be carried out.

C.

The organization should conduct training sessions on fraud, which should be attended by senior management and staff.

D.

Anti-fraud and whistleblowing policies should be implemented and their importance should be clearly stated.

Full Access
Question # 168

Which of the following best demonstrates that an internal auditor is applying due professional care when planning an assurance engagement?

A.

Assessing the risk of noncompliance with laws and regulations

B.

Following the policies as prescribed by the internal audit manual.

C.

Advising management of the area under review on how to mitigate internal control risks.

D.

Conducting the engagement on the presupposition that fraud exists.

Full Access
Question # 169

A new company’s risk management function is developing its cybersecurity risk management program Which of the following actions should be the first priority when developing the program?

A.

Start building a cybersecurity culture and set the desired behavior using a bottom-up approach

B.

Determine the cybersecurity framework that will establish and report on the effectiveness of the program

C.

Define the cybersecurity risk appetite and perform a cost-benefit analysis of the program

D.

Raise cybersecurity awareness across various departments outside of the IT department

Full Access
Question # 170

An internal auditor has completed an assurance engagement. Which of the following is most likely true regarding the engagement?

A.

During audit planning the auditor provided the client with the scope of the engagement for their agreement

B.

The results of tie engagement were included m a written report mat was issued to the cleint who requested me engagement

C.

During audit planning the auditor determined that the engagement scope would include a review of the security and privacy of payroll records

D.

The client requested the review of a new payroll system in order to improve the security of fie system

Full Access
Question # 171

Which of the following is a legitimate requirement for an internal audit activity’s quality assurance and improvement program (QAIP)?

A.

Quality assessments should be performed by individuals with sufficient knowledge of the internal audit practices

B.

External quality assessments should be conducted every seven years

C.

All quality assessments should be either conducted or validated by an independent assessment team

D.

The results of the QAIP should be communicated to shareholders annually

Full Access
Question # 172

According to IIA guidance, which of the following best describes expense reimbursement fraud?

A.

Theft of cash after it is recorded in the books

B.

Theft of cash before it is recorded in the books

C.

Theft of assets through fictitious or inflated invoices

D.

Theft of assets through false mileage travel logs and meal charges

Full Access
Question # 173

The board asked the chief audit executive (CAE) to assume responsibility for a newly formed risk management function while retaining responsibility for the internal audit function. The new function is comprised of both risk and compliance activities.

How should next year’s internal audit of the risk management function be performed?

A.

It should be performed by a competent assurance provider external to the internal audit function.

B.

It should be performed by a qualified audit team in the internal audit function and overseen by the most senior auditor other than the CAE.

C.

It should be conducted by a team of internal auditors under the supervision of risk and compliance managers.

D.

It should be performed by a team of the most experienced internal auditors, without oversight or direct involvement from the CAE.

Full Access
Question # 174

What is an appropriate first step in an internal auditor’s fraud risk assessment to evaluate how the organization manages such risk?

A.

Develop preventive and detective controls

B.

Identify potential fraud scenarios

C.

Assess the impact and likelihood of fraud risks

D.

Determine fraud risk responses

Full Access
Question # 175

How do assurance services and consulting services differ?

A.

There is less variety of consulting services that an internal audit activity might provide compared to assurance services

B.

Assurance services are limited to financial events or actions, and consulting services are not limited in this way

C.

Consulting services do not have to be included in the internal audit charter

D.

Other employees in an organization can provide consulting services but only an internal audit activity can provide assurance services

Full Access
Question # 176

According to IIA guidance, which of the following best demonstrates how the chief audit executive may ensure that due professional care is applied?

A.

Establish policies and procedures concerning the engagement process

B.

Develop a strategy for recruiting assigning, and training staff

C.

Outsource complex engagements to an external service provider

D.

Base the auditor evaluation process on the number of observations

Full Access
Question # 177

Which data analytics competency is critical for new internal auditors to possess in order to plan and perform internal audit engagements in conformance with the Standards?

A.

Describe data analytics and the application of data analytics methods in internal auditing.

B.

Apply data analytics methods in internal auditing.

C.

Evaluate the use of data analytics in an internal audit.

D.

Understand the definition of data analytics only.

Full Access
Question # 178

Which of the following represents an example of an ethical issue that the organization should address ' ?

A.

An employee discovered that there is no personal protective equipment at a temporary construction site

B.

An employee saw that a group of other employees were smoking in close proximity to petrol distribution tanks

C.

A supervisor insists that an employee complete time sheets regularly

D.

An employee received concert tickets from a vendor and asked whether she could keep them

Full Access
Question # 179

A snow removal company is conducting a scenario planning exercise where participating employees consider the potential impacts of a significant reduction in annual snowfall for the coming winter. Which of the following best describes this type of risk?

A.

Residual.

B.

Net.

C.

Inherent.

D.

Accepted.

Full Access
Question # 180

An internal auditor failed to identify transactions between the parent organization and a subsidiary. What is the most likely reason for the failure?

A.

The auditor misunderstood the audit objectives.

B.

The auditor lacked professional skepticism.

C.

The auditor ' s fieldwork was not properly supervised.

D.

The auditor lacked an understanding of the organization.

Full Access
Question # 181

An internal auditor was assigned to work in the procurement department for six months to gam m-depth knowledge about the procurement process. Which of the following personnel development practices was applied in this situation?

A.

Cosourcing

B.

Inbound rotation

C.

Guest auditor

D.

Outbound rotation

Full Access
Question # 182

Which of the following would best assist the internal audit activity in assessing whether an organization ' s responses to risk are aligned with its risk appetite?

A.

Analyzing the results of successful testing of controls and monitoring procedures implemented by management

B.

Determining that there are no gaps between the internal auditors ' risk assessment and the risk assessment performed by the organization

C.

Obtaining evidence that employees throughout the organization are aware of the organization s risk appetite

D.

Verifying that previously identified organizational risks were documented in board meeting minutes

Full Access
Question # 183

According to MA guidance, which of the following gives the internal audit activity the authority to request supporting documentation for the invoices of a third-party service provider?

A.

The internal audit policy manual.

B.

The internal audit charter.

C.

The board of directors.

D.

The quality assurance and improvement program.

Full Access
Question # 184

Due to toe increased operational responsibility of the CEO. The chief audit executive (CAE) of an organization currently reports to the chief financial officer (CFO). What is the likely imped of such a situation?

A.

There may be limitation m the scope of engagements that can be undertaken

B.

The CPO could provide expert advice when auditing areas under his purview

C.

The internal audit activity is adequately positioned when the CAE reports to a member of executive management

D.

The expense of finance staff can be catted upon during an audit of finance-related areas

Full Access
Question # 185

Which of the following best describes the risk contained in an initial public offering for a new stock?

A.

Residual risk.

B.

Net risk.

C.

Inherent risk.

D.

Underlying risk.

Full Access
Question # 186

Which of the following would be the most appropriate first step for the board to take when developing an effective system of governance?

A.

Determine the organization’s overall risk appetite.

B.

Establish a governance committee.

C.

Delegate authority to members of senior management.

D.

Identify key stakeholders and their expectations

Full Access
Question # 187

The chief audit executive (CAE) of a new internal audit activity is creating an internal audit charter According to IIA guidance, which of the following terms is most likely to

be included in the charter?

A.

Senior management will be present whenever the CAE interacts with the board, to ensure effective communication among all three parties.

B.

Internal auditors will advise on the design of control policies and procedures in any area where the organization does not possess the requisite expertise,

C.

Internal auditors will demonstrate competence, concern, and the dedication expected of a professional,

D.

Internal auditors will receive performance-based compensation, including bonuses for reporting more than a stipulated number of observations.

Full Access
Question # 188

A chief audit executive (CAE) identifies that the internal audit activity lacks a necessary skill to perform a management request for a consulting engagement. According to IIA guidance, which of the following is the most appropriate action the CAE should take regarding the request?

A.

Assign the engagement to a more senior internal auditor.

B.

Decline the engagement request.

C.

Allow the internal auditors to acquire the needed skills while performing the engagement.

D.

Supervise the assigned internal auditors throughout the engagement.

Full Access
Question # 189

What would be the proper sequence of steps for an internal auditor to take in order to draw a conclusion on internal control effectiveness and adequacy after ascertaining the key controls?

A.

Evaluate the adequacy of the controls and then test the controls for effectiveness.

B.

Test the controls for effectiveness and then evaluate the adequacy of the controls.

C.

Identify risks and then evaluate the controls for effectiveness.

D.

Evaluate the controls for effectiveness and then assess the risks in the area.

Full Access
Question # 190

Which of the following describes the internal audit activity ' s most appropriate role in an organization ' s risk management process?

A.

Reporting to the board on management ' s assessment of current risks

B.

Establishing a risk management policy and framework for the organization

C.

Assigning responsibility for identifying and managing significant risks

D.

Developing key controls to mitigate risks across the organization

Full Access
Question # 191

Which of the following threatens internal audit objectivity ' ?

A.

Internal auditors are expected by senior management to identify a minimum of five major control weaknesses in each area audited

B.

Internal auditors are prevented from accessing information necessary to undertake their audit engagements

C.

The chief audit executive reports directly to the chief financial officer who previously led the internal audit activity

D.

The CEO requests the internal audit activity develop a charter that clearly delineates its purpose and responsibilities within the organization

Full Access
Question # 192

In which of the following scenarios would it be appropriate for the chief audit executive (CAE) to report that the internal audit activity conforms with the Standards?

A.

It A new internal audit activity was formed four years ago. An external assessment was never performed, but successive internal assessments were performed and support the conclusion that the internal audit activity conforms with the Standards

B.

An internal self-assessment completed yesterday found that the internal audit activity did not conform with the Standards when carrying out its work. However, the preceding independent external assessment supports the conclusion that the internal audit activity conforms with the Standards.

C.

To reduce costs, the CAE excluded the use of external assessors from the internal audit activity ' s quality assurance and improvement program for the past seven years.However, the CAE concluded that the internal audit activity conforms with the Standards because all internal assessments over the period have supported this conclusion.

D.

The results of the last external assessment of the internal audit activity, performed a little over five years ago, indicated that the internal audit activity conforms with the Standards. The most recent internal assessment performed within the past year also indicates conformance.

Full Access
Question # 193

According to The IIA’s Code of Ethics, which of the following scenarios offers the best example of violating the principle of integrity?

A.

An internal audit manager collaborates with senior management to provide misleading information to government authorities.

B.

An internal audit manager provides sample audit reports and workpapers to a friend without obtaining prior approval

C.

An internal audit manager carries out a technical audit request without seeking expert opinion, despite a lack of the requisite skills.

D.

An internal audit manager assigned to audit a sales process failed to reveal that the process owner is a relative

Full Access
Question # 194

Who is primarily responsible for an organization’s culture?

A.

All employees.

B.

The internal audit function.

C.

Senior management.

D.

The board.

Full Access
Question # 195

IT management requires all employees in the IT department to attend annual training on the department ' s mission, values, and key performance measures. This activity is designed to prevent which of the following conditions?

A.

Knowledge/skills gap.

B.

Monitoring gap.

C.

Accountability/reward failure.

D.

Communication failure.

Full Access
Question # 196

Which of the following is an example of impairment to an internal auditor’s independence?

A.

Due to his prior position as the accounts payable supervisor for two years, a new member of the internal audit function is assigned to audit accounts payable.

B.

An internal auditor delays reporting her findings to management until after a friend transfers from the department under review.

C.

The senior internal auditor utilizes the chief financial officer’s recommended sample selections to perform detailed testing.

D.

Believing there must be errors in a given balance sheet account, the internal auditor decides to expand her testing.

Full Access
Question # 197

Which of the following is included in the risk identification process?

A.

Screening for the impact and likelihood or whether the risk is controllable.

B.

Weighing the likelihood that an event or condition will happen.

C.

Disclosing all plausible events or conditions that could occur.

D.

Determining controllability of an event or condition.

Full Access
Question # 198

A chief audit executive (CAE) has just joined an organization with an existing internal audit activity. Based on her review of the current organizational structure, the CAE determines that the internal audit activity lacks adequate independence. Which of the following actions is the CAE ' s best step to take next to move the internal audit activity toward organizational independence?

A.

Ensure the limitations are disclosed through communication with the board and senior management, so that the internal audit activity can continue operating under the same organizational structure.

B.

Request that the board restructure the reporting line of the internal audit activity to ensure the CAE has unrestricted access to the board.

C.

Rotate internal audit assignments among members of the internal audit activity to minimize the effects of the current structure.

D.

Train internal auditors about organizational independence and have them sign an acknowledgment of understanding.

Full Access
Question # 199

During an audit of an organization ' s accounts payable area, an internal auditor identified anomalies in the information examined that may indicate potential fraud. Which test should the auditor perform first to verify this?

A.

Verify the completeness and integrity of the data being analyzed.

B.

Identify duplicated organizational transactions.

C.

Analyze all transactions within the targeted area.

D.

Check control totals that have may have been falsified.

Full Access
Question # 200

Which of the following scenarios best demonstrates the application of internal audit proficiency?

A.

Management requests that the internal audit activity review and provide feedback on its strategic plans for a merger, but the chief audit executive (CAE) declines the engagement due to the team ' s lack of experience with mergers.

B.

A CAE reassigns auditors from other audits to perform testing on all of the fixed asset additions for a period, including amounts below the materiality level stated by external auditors.

C.

Due to the routine and recurring nature of bank branch audits, an audit manager often excludes detailed planning at the beginning of the audit and immediately performs fieldwork.

D.

During fieldwork, an auditor observed a lack of segregation of duties over cash management. The auditor reported this observation to his supervisor, who decided that the area should be examined in a subsequent audit.

Full Access
Question # 201

Which of the following requests, if accepted by the internal audit activity, would impair its independence?

A.

A request to develop workshops on corporate governance for management.

B.

A request to act as liaison with external auditors.

C.

A request to determine appropriate risk management responses for management.

D.

A request to provide counseling services on ethical matters.

Full Access
Question # 202

Which of the following statements related to organization wide risk management and control is true?

A.

Organizationwide risk management is a function or department.

B.

Organizationwide risk management addresses more than internal control.

C.

Organizationwide risk management sets adequate controls to ensure all risks are avoided.

D.

Organizationwide risk management is the checklist used during the risk and control self-assessment exercise.

Full Access
Question # 203

Which of the following situations would best indicate to the chief audit executive that one of the audit team members is struggling with application of due professional care?

A.

The engagement supervisor requests that an auditor carry out improvements to workpapers to address numerous problems: evidence is missing, references are incorrect, and conclusions are superfluous

B.

Audit work was completed m accordance with the established goals; however, a material misstatement was later uncovered in the audited area by another assurance provider.

C.

According to the audit report, several control failures occurred due to irresponsible behavior of local management, who was consequently deprived of bonuses and wrote a negative feedback to the auditor

D.

The delivery of audit results was several weeks late because the internal auditor had to spend additional time trying to understand the nature of certain transactions with derivation.

Full Access
Question # 204

An Internal auditor accepted a role as an engagement supervisor on a highly specialized and technical engagement for which she did not have the expertise. Which of the following fundamental principles of The IIA ' s Code of Ethics did she violate?

A.

Objectivity.

B.

Confidentiality.

C.

Competency.

D.

Due professional care.

Full Access
Question # 205

At the beginning of an IT development project, key risks were identified and assessed, and risk owners were appointed. Six months later, the IT development team reported that the project is significantly over budget, it will not be completed on time, and key personnel had left the organization. Which of the following risk management practices should be improved for future projects?

A.

Risk response

B.

Risk assessment

C.

Risk monitoring

D.

Risk avoidance

Full Access
Question # 206

Which of the following is the primary benefit of establishing a formal training program for the internal audit activity?

A.

It is useful to reinforce the independence of the internal audit activity.

B.

It is useful to guide internal auditors as they perform specific engagements.

C.

It is useful to maintain the skills and competencies of internal audit staff.

D.

It is useful to measure the effectiveness and maturity of the internal audit activity.

Full Access
Question # 207

A senior executive at a government-owned organization received an invitation to attend a public exhibition where he can learn about new trucks relevant to the organization ' s business. As a special perk, the executive is offered an opportunity to drive a luxury vehicle manufactured by one of the exhibiting companies. Prior to the event, the executive asked for the chief audit executive s (CAE’s) advice. What should the CAE recommend as the most appropriate course of action for the executive?

A.

Attend the event, but decline the offer to use the luxury vehicle

B.

Decline the invitation to the exhibition.

C.

Ask the board to decide on the issue.

D.

Select a lower-level employee to enjoy the luxury vehicle instead

Full Access
Question # 208

During an audit of the purchasing department, an internal auditor identifies significant issues that could affect the organization ' s financial reporting. Management disagrees with the audit results. Which of the following responses best demonstrates the internal auditor has the necessary competencies related to professional Judgment and conflict management?

A.

The auditor maintains his convictions and continues to proceed with the review process despite management ' s concerns related to the results.

B.

The auditor bypasses management, discusses the results with the board, and seeks the board ' s input on how best to address the recommendations.

C.

The auditor consults with other members of the audit team, and together they develop alternative recommendations that management may be more likely to accept.

D.

The auditor meets with management to discuss the results and obtain a better understanding of the specific concerns.

Full Access
Question # 209

According to IIA guidance, which of the following would the internal audit activity examine in order to evaluate the organization ' s governance process for strategic and operational decisions ' ?

A.

The risk assessment process including interviews with senior management.

B.

The organization’s mission and value statements, code of conduct, and whistleblowing policy

C.

Board meeting minutes the board policy manual, and past audit reports

D.

Staff compensation objective setting and the performance evaluation policy and process

Full Access
Question # 210

An IT contractor applied for an internal audit position at a bank. The contractor worked for the bank ' s IT security manager two years ago. If the audit manager interviewed the contractor and wants to extend a job offer, which of the following actions should the chief audit executive pursue?

A.

Allow the audit manager to hire the contractor and state that the individual is free to perform IT audits, including security.

B.

Not allow the audit manager to hire the contractor, as it would be a conflict of interest

C.

Allow the audit manager to hire the contractor, but state that the individual is not allowed to work on IT security audits for one year.

D.

Not allow the audit manager to hire the contractor and ask the individual to apply again in one year.

Full Access
Question # 211

Which of the following conditions classifies an engagement as a consulting service provided by the internal audit activity?

A.

The internal auditor assigned to the engagement previously worked in the area under review and lacks objectivity.

B.

The internal audit engagement will involve providing an opinion on the effectiveness of controls.

C.

The internal auditor assigned to the engagement was specifically requested by management of the area under review.

D.

he internal audit engagement involves only two parties: the internal auditor and the engagement client.

Full Access
Question # 212

Which of the following would be most helpful to measure whether an internal audit activity successfully provides risk-based assurance?

A.

Percentage of highly significant risks covered by internal audit plan.

B.

Percentage of previously unknown risks identified per engagement.

C.

Percentage of internal audit staff skilled in alignment with the organization ' s structure and key risks.

D.

Percentage of observations made in assurance engagements compared to advisory engagements.

Full Access
Question # 213

An internal auditor identified an inefficiency in a control and made recommendations to strengthen the control environment, but senior management was reluctant to adopt the recommendations because there were concerns regarding staff acceptance of the change of processes. Consequently, the auditor agreed to remove the observation from the audit report.

Which of the following competencies does the auditor lack?

A.

Connectivity.

B.

Strategic thinking.

C.

Influence.

D.

Collaboration.

Full Access
Question # 214

Which of the following is the most appropriate reason for a chief audit executive to conduct an external assessment more frequently than five years?

A.

Significant changes in the organization ' s accounting policies or procedures would warrant timely analysis and feedback.

B.

More frequent external assessments can serve as an equivalent substitute for internal assessments.

C.

The parent organization ' s internal audit activity agreed to perform biennial reciprocal external assessments to provide greater assurance at a reduced cost.

D.

A change in senior management or internal audit leadership may change expectations and commitment to conformance.

Full Access
Question # 215

Which of the following can be used to integrate cultural risk factors into testing for an audit engagement?

A.

Results of employee surveys.

B.

Process maps.

C.

The organizational chart.

D.

The documented governance structure.

Full Access
Question # 216

Which of the following statements is correct regarding disclosure of conformance or Standards?

A.

An internal audit activity that has been in existence fewer than five years cannot Indicate that it is operating in conformance with the Standards because it has not yet undergone an external assessment.

B.

Once an external assessment validates conformance with the Standards, the internal audit activity may continue to use the statement until the next external assessment.

C.

If it has been more than five years since the last external assessment was conducted, the Internal audit activity must cease indicating that it operates in conformance with the Standards.

D.

The chief audit executive must disclose every instance of noncompliance with the Code of Ethics or the Standards.

Full Access
Question # 217

A chief audit executive (CAE) recruited a few new internal auditors to reduce the resource gaps identified in this year ' s internal audit plan. One of the new recruits has several years of experience with the organization. Ten months ago. she served as a senior supervisor in the finance department. However, for the past 10 months, she has been helping the organization with implementing a new IT system. What approach should the CAE take for the upcoming financial statement controls audit?

A.

Assign the new auditor to assist with conducting the fieldwork. but ensure that her work is reviewed by the CAE.

B.

Assign the new auditor to assist with developing the audit program, but ensure that the audit program is executed by other audit staff.

C.

Ensure that the new auditor ' s previous manager, and other close former coworkers, are excused during the audit.

D.

Ensure that the new auditor is responsible only for the supervisory review, but not the execution of the audit field work.

Full Access
Question # 218

An organization established 20 years ago has had its internal audit activity in place for the last three years. Which of the following would allow the internal audit activity to accurately state that it is in conformance with the Standards ' ?

A.

Documented assessment was performed by the audit committee and confirmed conformance.

B.

Internal and external assessments are performed annually, and nonconformance results are reported to the board.

C.

The independent and objective judgement of the chief audit executive confirmed conformance with the Standards.

D.

Documented internal assessments are performed periodically and confirm conformance.

Full Access
Question # 219

During an assurance engagement, an internal auditor uses benchmarking research to support preparation of a report to stakeholders that contains significant findings about control deficiencies. Which of the following skills did the auditor demonstrate?

A.

Internal audit management.

B.

Conflict negotiation.

C.

Critical thinking.

D.

Persuasion and collaboration.

Full Access
Question # 220

What is the primary reason a chief audit executive should dedicate time and resources to support continuing professional development of internal audit staff?

A.

To ensure that internal audit staff maintains high overall job satisfaction.

B.

To ensure that internal audit staff acquired continuing professional education credits timely.

C.

To ensure that top risks are mitigated to an acceptance level.

D.

To ensure that internal audit staff have the competency to address high-priority risks.

Full Access
Question # 221

Which of the following statements best describes how the internal audit activity obtains reasonable assurance that significant risks in the organization are identified and assessed?

A.

The internal auditors review the organization ' s strategic plan, business plan, and policies, and have discussions with the board and senior management.

B.

The internal auditors evaluate the adequacy and timeliness of management ' s reporting of risk management results.

C.

The internal auditors interview staff at various levels and determine whether the organization ' s objectives, significant risks, and risk appetite are articulated sufficiently.

D.

The internal auditors review recently completed risk assessments and related reports issued by senior management, external auditors, and other sources.

Full Access
Question # 222

During a payroll audit, the internal auditor discovered that several individuals who have the same position classification as he are earning a significantly higher salary. The auditor noted the names and amounts of each, and he planned to prepare a request to the chief audit executive for a salary increase based on this information. Which of the following IIA Code of Ethics principles was violated in this scenario?

A.

Competency.

B.

Objectivity,

C.

Integrity.

D.

Confidentiality

Full Access
Question # 223

Which of the following specifications in an internal audit charter is the most important factor in the internal audit activity’s independence?

A.

Description of internal audit activity ' s responsibilities

B.

Definition of internal auditing

C.

Statement of internal audit activity ' s authority

D.

Description of internal audit activity ' s reporting structure

Full Access
Question # 224

According to IIA guidance, which of the following statements is true regarding the internal audit activity ' s quality assurance and improvement program (QAIP)?

A.

Internal assessments rely solely on the review of completed audit engagements for demonstrated performance

B.

The chief audit executive is responsible for assessing the suitability and competence of an external assessor.

C.

QAIP results must first be discussed with the board and approval obtained for distribution to senior management

D.

At the board ' s discretion, the frequency of external assessments can exceed the five-year guideline

Full Access
Question # 225

The CEO of an organization expresses his opinion clearly and confidently, and others in the organization do not dare to challenge his opinion. In fact, members of the senior management team communicate support for the CEO’s viewpoints even when they personally disagree.

Which of the following cultural success factors seems to be missing in this organization?

A.

Open dialogue.

B.

Clear communication.

C.

Positive incentives.

D.

Code of conduct.

Full Access
Question # 226

Which of the following strategies for professional development best demonstrates an internal auditor’s competency ' ?

A.

Completed education credits

B.

Membership in professional organizations

C.

Subscriptions to sources of relevant professional information

D.

Professional development and training plans

Full Access
Question # 227

Which of the following documents are internal auditors most likely to be asked to sign as a demonstration of due professional care?

A description of their job responsibilities,

A.

A non-disclosure agreement.

B.

An annual declaration of commitment to

C.

The IIA s Code of Ethics.

D.

The internal audit charter.

Full Access
Question # 228

An organization has discovered that an excessive number of labor hours has been entered into a costing system.

Which of the following controls should the organization implement to prevent this issue from reoccurring?

A.

Program input fields with maximum attributes.

B.

Perform recalculation tests during processing.

C.

Reconcile input control totals.

D.

Check data in input fields for consistency.

Full Access
Question # 229

An engagement supervisor noted that an internal auditor ' s personal relationship with a process owner resulted in the auditor providing a favorable and partial assessment during an audit within that process owner ' s area. According to MA guidance, which of the following should be used to manage this impairment?

A.

An internal audit charter.

B.

An employee disciplinary policy.

C.

A functional audit committee.

D.

A functional reporting placement.

Full Access
Question # 230

Which of the following internal control components has COSO identified as the most important?

A.

Information and communication

B.

Risk assessment

C.

Control activities

D.

Control environment

Full Access
Question # 231

Which of the following statements is true regarding how the scope of a consulting engagement should be established?

A.

The engagement client should be able to determine the scope to be applied to the engagement

B.

The internal auditor should establish a scope that does not impair her objectivity

C.

Any attempts by the engagement client to limit the scope should be considered a scope limitation

D.

The scope should include reviewing the effectiveness of the internal control environment

Full Access
Question # 232

During fieldwork, an internal auditor located a significant internal control issue. Without identifying the origins of the issue, the auditor concluded the engagement and included the issue in the final audit report. To enhance audit quality, which of the following skills should the internal auditor improve?

A.

Business acumen.

B.

Critical thinking.

C.

Communication.

D.

Audit report writing.

Full Access
Question # 233

When dealing with various stakeholders which of the following is true regarding an internal auditor ' s responsibility to remain objective and independent?

A.

When deciding between conflicting reports of a control ' s performance from a control operator and the operator ' s manager the internal auditor should generally believe the manager

B.

Some audit issues may remain unremediated and unreported if management will accept recommendations that the internal auditor deems more important

C.

The internal auditor may initially disagree with management s acceptance of a risk, but reevaluate and agree with management’s judgment after further discussion

D.

When working on business unit audits it is sometimes sufficient for the internal auditor to report deficiencies only to the unit manager when remediation is not complex

Full Access
Question # 234

Which of the following describes an ongoing monitoring activity that could be performed as part of an internal assessment for a quality assurance and improvement program (QAIP)?

A.

Planning and supervising engagements

B.

Evaluating the quality of supervision

C.

Identifying opportunities for improvement m internal audit ' s processes and procedures

D.

Determining if the objectives of QAIP are current

Full Access
Question # 235

Which of the following would best preserve the organizational independence of the internal audit activity?

A.

The internal audit charter is approved by the chief audit executive (CAE).

B.

The CAE reports functionally to the CEO.

C.

The CAE ' s internal audit plan is endorsed by the board.

D.

The chief financial officer determines the appointment of the CAE.

Full Access
Question # 236

Which of the following statements is true regarding the role of the internal audit activity in the organization ' s risk management process?

A.

The internal audit activity should not be responsible for developing the organization ' s risk management framework, even with appropriate safeguards.

B.

The internal audit activity is typically responsible for alerting operational management to emerging risks and changes in regulatory scenarios

C.

The internal audit activity may coach management on risk response scenarios if safeguards have been implemented.

D.

The internal audit activity should avoid giving assurance regarding the accuracy of risk evaluations if safeguards have not been implemented.

Full Access
Question # 237

After the final audit report was issued, the engagement supervisor received an expensive gift from management recognizing her assistance in improving the business, if the gift is accepted, which of the following would be true?

A.

The engagement supervisor violated The IIA ' s Code of Ethics principle of integrity.

B.

The engagement supervisor violated The IIA ' s Code of Ethics principle of objectivity.

C.

The engagement supervisor violated The IIA’s Code of Ethics principle of confidentiality.

D.

The engagement supervisor did not violate any principles of The IIA’s Code of Ethics.

Full Access
Question # 238

In which of the following situations would an internal audit function most likely experience impairments to its independence?

A.

The chief audit executive (CAE) regularly conducts undocumented private meetings with the chair of the board.

B.

The CAE participates as a non-voting member in key strategic initiatives and board meetings.

C.

The CAE’s communications with the board are reviewed and preapproved by senior management.

D.

The CAE has monthly meetings with the CEO.

Full Access
Question # 239

When issuing his department’s performance report, a sales director in an insurance company knowingly fails to correct the reserves for unearned income that resulted from cancellations of policy subscriptions. This could be considered which of the following types of fraud?

A.

Asset misappropriation

B.

Skimming

C.

Disbursement fraud

D.

Information misrepresentation

Full Access
Question # 240

In which of the following ways could stakeholders be engaged in corporate social responsibility efforts?

A.

Investigation of health and safety incidents.

B.

Auditing of controls and management systems.

C.

Communication of disclosures and external reporting,

D.

Involvement in focus groups and complaint management

Full Access
Question # 241

What controls could be implemented as a preventive measure against malicious insider threats, such as an unauthorized employee obtaining electronic customer sales information and later selling them to a competitor?

A.

Role-based access controls.

B.

Visitor management system controls.

C.

Network firewall prevention controls.

D.

Information classification controls.

Full Access
Question # 242

Which of the following is the appropriate next step after management identifies and implements risk responses?

A.

Prioritize risks.

B.

Assess the severity of risks.

C.

Develop a portfolio view of risks.

D.

Measure the velocity of risks.

Full Access
Question # 243

An organization ' s board has approved an expansion plan into a new market. The board acknowledged that if the expansion is not successful, the organization would encounter large monetary losses consisting of legal fees, research and development costs, rent expenses, and labor fees. Which of the following has the board approved?

A.

The risk response.

B.

The risk tolerance.

C.

The residual risk.

D.

The inherent risk.

Full Access
Question # 244

A medical clinic has developed a policy that prohibits its doctors from performing certain high-risk optional medical procedures.

Which of the following best describes this risk management technique?

A.

Reduction.

B.

Mitigation.

C.

Transfer.

D.

Avoidance.

Full Access
Question # 245

During an audit of a foreign subsidiary an internal audit team discovered that products were sold to a prohibited country due to sanctions. What is the best course of action for the internal audit team?

A.

Include the facts m the engagement communications

B.

Inform me external auditors of the violation.

C.

Report the violation to the government regulators

D.

Consult with the legal department

Full Access
Question # 246

It is important for the chief audit executive to consider the level of competence of the internal audit staff because their competence influences which of the following?

A.

The cost-benefit relationship of planned audits.

B.

Proficiency needed to carry out engagements.

C.

Achievement of the objectives of internal control.

D.

Quantity of the audits performed.

Full Access
Question # 247

Which of the following are considered root causes of fraud?

A.

Rationalization and corruption

B.

Corruption and opportunity

C.

Opportunity and perceived need

D.

Perceived need and weak internal controls

Full Access
Question # 248

Which of the following best describes the internal audit activity’s responsibility within a risk and control framework?

A.

The internal audit activity constitutes the first line of defense in effective risk management.

B.

The internal audit activity provides direction regarding internal controls implementation.

C.

The internal audit activity verifies that management has met its responsibility for implementing effective controls.

D.

The internal audit activity implements the internal control framework and advises management regarding best practices.

Full Access
Question # 249

Which of the following preventative controls would be most effective for organizations facing business disruptions and respective financial losses?

A.

Develop a business continuity plan for contingent situations,

B.

Insure the organization against financial losses.

C.

Rely on third-party cloud solution providers for the organization ' s systems.

D.

Hedge company assets via purchasing derivatives.

Full Access
Question # 250

During a quality assessment of the internal audit activity an auditor is assessing whether the independence of the internal audit activity is at risk of being compromised. According to IIA guidance, which of the following would provide the best source of evidence for such an assessment?

A.

An organizational chart showing the reporting line of the chief audit executive to the CEO

B.

The internal audit charter as endorsed by the organization’s governing body

C.

A review of the audit opinions issued from a sample of recent audit engagements

D.

An assessment of the scope of the audit work performed by the internal au < M activity

Full Access
Question # 251

Management of an area under review is aggressive, upset, and questioning the knowledge and experience of the organization ' s internal auditors, as the audit results highlight critical findings. The relationship between the internal audit activity and management has continued to degenerate. as previous audit reports also showed a large number of issues. What would be the best strategy for working through the current audit results while also attempting to repair the relationship with management?

A.

Take an accommodating approach and change the overall rating of the audit report.

B.

Take a compromising approach by modifying the tone of the report, while maintaining the critical findings.

C.

Take an assertive approach and be persistent in attempting to convince the director.

D.

Take an assisting approach and offer to assist with the implementation of action plans.

Full Access
Question # 252

According to IIA guidance, which of the following statements is true regarding the internal audit activity’s responsibilities in providing consulting services?

A.

The chief audit executive is responsible for deciding the priority of consulting services in the internal audit plan

B.

The scope of consulting services is determined primarily by the internal auditor with input from management of the area under review

C.

The board defines the internal audit activity’s responsibilities over consulting activities

D.

Adding value to an organization requires the internal audit activity to initiate a consulting engagement

Full Access
Question # 253

Which of the following actions, if taken by a chief audit executive, aligns with a successful continuing professional development program?

A.

Adoption of a collaborative initiative with the organization’s human resources function to identify potential talent for the internal audit function.

B.

Introduction of a challenge that encourages internal auditors to volunteer with their respective professional bodies on advocacy.

C.

Implementation of biannual reporting to the board on the freedom of the internal audit function from undue influence from senior management.

D.

Deployment of an electronic platform for disclosing potential impairments to the objectivity of individual internal auditors.

Full Access
Question # 254

Which of the following activities is most likely to require a fraud specialist to supplement the knowledge and skills of the internal audit activity?

A.

Planning an engagement of the area in which fraud is suspected.

B.

Employing audit tests to detect fraud.

C.

Interrogating a suspected fraudster

D.

Completing a process review to improve controls to prevent fraud

Full Access
Question # 255

Which of the following statements is true regarding the quality assurance and improvement program (QAIP)?

A.

Reporting on the QAIP to the board should occur at least once every five years

B.

The responsibility for the selection of an external assessor rests with the board

C.

The qualifications of the assessors must be communicated to the board

D.

The reporting of outcomes of the QAIP can be delegated to senior audit staff

Full Access
Question # 256

An employee accepts cash payments from customers and does not record the sale. This is an example of which of the following types of fraud?

A.

Asset misappropriation.

B.

Skimming

C.

Corruption.

D.

Lapping.

Full Access
Question # 257

Which of the following activities should the chief audit executive perform to ensure compliance with an organization ' s code of conduct?

A.

Act as an advisor to the committee responsible for reviewing violations of the code.

B.

Review and adjudicate all violations of the code of conduct.

C.

Lead the committee responsible for the oversight of the code.

D.

Implement a system of procedures to inform all employees of the code.

Full Access