Audit & Risk Management Flashcards
7 cards from real CA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Audit & Risk Management flashcards as text
In a scenario where an auditor identifies a related-party transaction not previously disclosed by management, the FIRST step should be to:
Answer: Communicate the finding to management and those charged with governance and assess its impact on the financial statements
Upon discovering an undisclosed related-party transaction, the auditor must communicate it to management and those charged with governance and evaluate whether the financial statements require amendment or additional disclosure.
A 'residual risk' is BEST described as:
Answer: The risk remaining after management has implemented its risk responses and controls
Residual risk is the level of risk that remains after management applies controls and other risk responses to address the inherent risk.
Which of the following scenarios would MOST likely result in a disclaimer of opinion?
Answer: The auditor is unable to obtain sufficient appropriate audit evidence due to a pervasive scope limitation imposed by management
A disclaimer of opinion is issued when the auditor cannot obtain sufficient appropriate evidence and the possible effects are both material and pervasive, making it impossible to express any opinion.
The primary purpose of a risk register in enterprise risk management is to:
Answer: Record identified risks, their likelihood and impact assessments, risk owners, and planned responses in a single repository
A risk register is a centralized document that captures identified risks, their assessed likelihood and impact, assigned owners, and the controls or actions planned to manage each risk.
When evaluating the appropriateness of using the work of an internal auditor, the external auditor MUST consider:
Answer: The objectivity, technical competence, and due professional care of the internal audit function
ISA 610 requires external auditors to evaluate the internal audit function's objectivity, technical competence, and whether it applies due professional care before relying on its work.
Which of the following BEST describes 'business continuity risk'?
Answer: The risk that disruptions to critical operations prevent an organization from delivering products or services within acceptable timeframes
Business continuity risk refers to the potential that an unexpected disruption — such as a natural disaster, cyberattack, or supply chain failure — prevents the organization from maintaining critical operations within defined recovery time objectives.
Under the fraud triangle model, which three conditions are necessary for fraud to occur?
Answer: Pressure, opportunity, and rationalization
The fraud triangle, developed by Donald Cressey, identifies pressure (incentive), opportunity (weak controls), and rationalization (justification) as the three conditions that together enable fraud.