ACFE Auditing and Internal Controls 2 — Questions and Answers
Question 1: Under the Sarbanes-Oxley Act (SOX) Section 404, who is responsible for assessing the effectiveness of internal controls over financial reporting?
- Management and the external auditor (Correct answer)
- The internal audit department only
- The audit committee of the board
- The SEC directly
Correct answer: Management and the external auditor
SOX Section 404 requires both management to assess and report on internal controls over financial reporting and the external auditor to attest to that assessment.
Question 2: Which auditing standard requires external auditors to assess the risk of material misstatement due to fraud in every audit?
- AU-C Section 240 / ISA 240 (Correct answer)
- PCAOB AS 2201
- SAS No. 70
- ISAE 3402
Correct answer: AU-C Section 240 / ISA 240
AU-C 240 (US GAAS) and ISA 240 (international) require auditors to specifically consider and assess the risk of material misstatement arising from fraud in every financial statement audit.
Question 3: A 'compensating control' is best described as:
- A control that mitigates risk when the primary control cannot be implemented (Correct answer)
- A financial incentive paid to employees who report fraud
- A redundant control that duplicates the function of another control
- A corrective action taken after a fraud has been discovered
Correct answer: A control that mitigates risk when the primary control cannot be implemented
A compensating control is an alternative control that reduces risk to an acceptable level when the ideal primary control—such as segregation of duties—cannot be practically implemented.
Question 4: Which of the following best describes the purpose of a 'surprise audit' in a fraud prevention program?
- To deter fraud by introducing the unpredictability of detection (Correct answer)
- To replace the annual financial statement audit
- To satisfy SOX Section 302 certification requirements
- To train new auditors on fieldwork procedures
Correct answer: To deter fraud by introducing the unpredictability of detection
Surprise audits deter fraud by removing the predictability that allows fraudsters to conceal their schemes before a scheduled audit.
Question 5: The 'fraud triangle,' as described in the ACFE's guidance, consists of which three elements?
- Pressure, opportunity, and rationalization (Correct answer)
- Motive, means, and method
- Intent, capability, and concealment
- Risk, control, and detection
Correct answer: Pressure, opportunity, and rationalization
The fraud triangle identifies three conditions that are typically present when fraud occurs: perceived pressure (incentive/need), perceived opportunity, and the ability to rationalize the act.
Question 6: Which internal control procedure is most effective at detecting duplicate payments to vendors?
- Running automated data analytics to match invoice numbers, amounts, and vendor IDs (Correct answer)
- Requiring two approvals for all invoices over $10,000
- Conducting physical inventory counts quarterly
- Reconciling bank statements monthly
Correct answer: Running automated data analytics to match invoice numbers, amounts, and vendor IDs
Automated matching of invoice numbers, amounts, and vendor identifiers quickly flags duplicate submissions that might otherwise slip through manual review.
Under the Sarbanes-Oxley Act (SOX) Section 404, who is responsible for assessing the effectiveness of internal controls over financial reporting?