CA Internal Controls & Governance 1 — Questions and Answers
Question 1: Which of the following is NOT one of the five components of the COSO Internal Control – Integrated Framework?
- Control Environment
- Risk Assessment
- Profit Optimization (Correct answer)
- Monitoring Activities
Correct answer: Profit Optimization
The five COSO components are Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring Activities; Profit Optimization is not a component.
Question 2: Segregation of duties is primarily designed to prevent which type of risk?
- Liquidity risk
- Fraud and error through collusion or unauthorized access (Correct answer)
- Interest rate risk
- Currency translation risk
Correct answer: Fraud and error through collusion or unauthorized access
Segregation of duties reduces the opportunity for any one individual to commit and conceal fraud or errors by dividing authorization, custody, and recordkeeping among different people.
Question 3: Under Sarbanes-Oxley (SOX) Section 404, management is required to:
- File quarterly tax returns with the SEC
- Assess and report on the effectiveness of internal controls over financial reporting (Correct answer)
- Publish an annual sustainability report
- Disclose all executive compensation to the IRS
Correct answer: Assess and report on the effectiveness of internal controls over financial reporting
SOX Section 404 requires management to assess the design and operating effectiveness of internal controls over financial reporting and have that assessment attested by the external auditor.
Question 4: A preventive control is best described as one that:
- Identifies errors after they have occurred
- Corrects errors once detected
- Stops errors or irregularities from occurring in the first place (Correct answer)
- Reports control failures to senior management
Correct answer: Stops errors or irregularities from occurring in the first place
Preventive controls are proactive measures designed to stop errors or fraud before they occur, such as requiring dual authorization on large payments.
Question 5: Which body is primarily responsible for overseeing a company's financial reporting and external auditor relationship in a U.S. public company?
- The CFO
- The Audit Committee of the Board of Directors (Correct answer)
- The Internal Audit Department
- The SEC Enforcement Division
Correct answer: The Audit Committee of the Board of Directors
The Audit Committee, composed of independent directors, is responsible for overseeing financial reporting integrity, hiring the external auditor, and reviewing audit findings.
Question 6: A 'material weakness' in internal controls over financial reporting is defined as:
- A minor clerical error in the trial balance
- A deficiency where there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis (Correct answer)
- Any control that has not been tested during the year
- An IT system outage lasting more than 24 hours
Correct answer: A deficiency where there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis
PCAOB and FASB define a material weakness as a significant deficiency, or combination of deficiencies, in ICFR such that there is a reasonable possibility of a material financial statement misstatement going undetected.
Question 7: The 'control environment' component of COSO is often referred to as the foundation of internal control because it:
- Establishes the physical security of assets
- Sets the tone at the top and influences the overall culture of integrity and ethical values (Correct answer)
- Defines the chart of accounts used in financial reporting
- Determines the interest rates charged on intercompany loans
Correct answer: Sets the tone at the top and influences the overall culture of integrity and ethical values
The control environment encompasses the organization's ethical values, management philosophy, organizational structure, and commitment to competence — elements that shape how employees regard internal controls.
Which of the following is NOT one of the five components of the COSO Internal Control – Integrated Framework?