AICPA Risk Management & Internal Control 3 — Questions and Answers
Question 1: Which control environment factor refers to the competence and ethical values demonstrated by top management?
- Tone at the top (Correct answer)
- Control activities
- Segregation of duties
- Information systems
Correct answer: Tone at the top
Tone at the top reflects the ethical values, integrity, and commitment to competence modeled by senior leadership.
Question 2: A key risk indicator (KRI) differs from a key performance indicator (KPI) in that a KRI:
- Measures past performance
- Signals potential future risk exposure (Correct answer)
- Tracks financial results only
- Is used exclusively by external auditors
Correct answer: Signals potential future risk exposure
KRIs are forward-looking metrics that provide early warning signals of increasing risk exposure before losses occur.
Question 3: Under COSO, 'monitoring' activities are designed to:
- Detect and correct control deficiencies over time (Correct answer)
- Set the organization's risk appetite
- Identify potential risk events
- Establish information flows
Correct answer: Detect and correct control deficiencies over time
Monitoring assesses the quality of internal control performance over time and corrects identified deficiencies.
Question 4: Which type of audit opinion indicates that one or more material weaknesses in internal control over financial reporting exist?
- Unqualified (clean) opinion
- Qualified opinion
- Adverse opinion (Correct answer)
- Disclaimer of opinion
Correct answer: Adverse opinion
An adverse opinion on internal controls means management's assessment is materially misstated or material weaknesses exist.
Question 5: The practice of limiting each employee's computer system access to only the functions needed for their job is known as:
- Access control
- Least privilege principle (Correct answer)
- Data encryption
- Logical security
Correct answer: Least privilege principle
The least privilege principle restricts user access rights to only what is necessary to perform their job functions.
Question 6: In enterprise risk management, 'inherent risk' is best described as:
- Risk after considering the effect of risk responses
- Risk in the absence of any management actions to alter its impact (Correct answer)
- Risk transferred to a third party
- Risk accepted by senior management
Correct answer: Risk in the absence of any management actions to alter its impact
Inherent risk is the raw risk facing an organization before management applies any controls or risk responses.
Question 7: A company's disaster recovery plan (DRP) primarily focuses on:
- Preventing cyberattacks
- Restoring IT systems and data after a disruption (Correct answer)
- Marketing strategy during a crisis
- Training employees on data privacy
Correct answer: Restoring IT systems and data after a disruption
A DRP provides documented procedures for recovering IT infrastructure and operations following a disaster or major disruption.
Which control environment factor refers to the competence and ethical values demonstrated by top management?