Audit & Risk Management Flashcards
7 cards from real CA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Audit & Risk Management flashcards as text
A risk heat map typically plots risks on two axes. What are those axes?
Answer: Likelihood of occurrence vs. impact/severity
A risk heat map plots each identified risk based on its likelihood of occurring and the severity of its potential impact, helping prioritize risk responses visually.
Which of the following BEST describes 'operational risk' as defined by Basel II/III?
Answer: The risk of loss resulting from inadequate or failed internal processes, people, systems, or external events
Basel II/III defines operational risk as the risk of loss from inadequate or failed internal processes, people, and systems, or from external events, including legal risk but excluding strategic and reputational risk.
During an audit of revenue recognition, the auditor is MOST concerned with which financial statement assertion?
Answer: Occurrence (existence)
For revenue, auditors are primarily concerned with the occurrence assertion — that recorded revenues represent genuine transactions that actually took place — since management may be motivated to inflate revenues.
What is the purpose of a 'walk-through' procedure in an internal control audit?
Answer: To trace a single transaction through each step of the relevant process to confirm that controls exist and operate as described
A walk-through traces one or a few transactions through the entire process from initiation to recording, confirming that documented controls exist and function as described in the narrative or flowchart.
The risk appetite of an organization is BEST defined as:
Answer: The amount and type of risk the organization is willing to accept in pursuit of its objectives
Risk appetite is the amount and type of risk an organization is willing to accept in pursuit of its strategic objectives, established by the board to guide risk-taking decisions.
Which of the following is an example of a 'preventive' internal control rather than a 'detective' control?
Answer: Segregation of duties between authorization and recording
Segregation of duties is a preventive control that stops errors or fraud from occurring in the first place, whereas reconciliations, variance analyses, and exception reports detect problems after they have occurred.
Under ISA 315, which element is NOT one of the components of an entity's system of internal control?
Answer: External audit opinion
ISA 315 identifies five components of internal control: control environment, entity's risk assessment process, control activities, information systems, and monitoring of controls — the external audit opinion is not a component.