AICPA Risk Management & Internal Control 2 — Questions and Answers
Question 1: Under COSO ERM, which component addresses the organization's philosophy about managing risk and its risk appetite?
- Control Activities
- Internal Environment (Correct answer)
- Event Identification
- Risk Response
Correct answer: Internal Environment
The Internal Environment component sets the foundation for how risk is viewed and addressed, including risk philosophy and appetite.
Question 2: A company implements a policy requiring two signatures on checks exceeding $10,000. This is an example of which type of control?
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Requiring dual signatures before a check is issued prevents unauthorized transactions from occurring, making it a preventive control.
Question 3: Which risk response strategy involves transferring risk to a third party through insurance or outsourcing?
- Risk avoidance
- Risk reduction
- Risk sharing (Correct answer)
- Risk acceptance
Correct answer: Risk sharing
Risk sharing (also called risk transfer) moves some or all of the risk to another party, such as through insurance contracts.
Question 4: The Sarbanes-Oxley Act Section 404 requires management to assess the effectiveness of internal controls over:
- Operational processes
- Financial reporting (Correct answer)
- IT systems exclusively
- Human resources
Correct answer: Financial reporting
SOX Section 404 mandates that management assess and report on the effectiveness of internal controls over financial reporting.
Question 5: When auditors test the same control at different points during the year, this is best described as:
- Substantive testing
- Roll-forward procedures
- Interim testing with update procedures (Correct answer)
- Year-end testing
Correct answer: Interim testing with update procedures
Interim testing with update procedures allows auditors to test controls mid-year and then perform limited procedures at year-end.
Question 6: Which element of the fraud triangle describes a person's ability to rationalize fraudulent behavior as acceptable?
- Pressure
- Opportunity
- Rationalization (Correct answer)
- Capability
Correct answer: Rationalization
Rationalization is when a fraudster justifies their actions as acceptable, such as believing they are simply 'borrowing' funds.
Question 7: An organization's risk appetite is best defined as:
- The maximum loss the company can survive
- The amount of risk an entity is willing to accept in pursuit of value (Correct answer)
- The residual risk remaining after controls are applied
- The probability that a risk event will occur
Correct answer: The amount of risk an entity is willing to accept in pursuit of value
Risk appetite is the broad amount of risk an entity is willing to accept while pursuing its strategy and objectives.
Under COSO ERM, which component addresses the organization's philosophy about managing risk and its risk appetite?