CA Internal Controls & Governance 2 — Questions and Answers
Question 1: IT General Controls (ITGCs) differ from IT Application Controls in that ITGCs:
- Validate individual transactions within a specific application
- Apply broadly to the IT environment supporting multiple applications, such as access management and change management (Correct answer)
- Are configured by end-users in spreadsheets
- Are only relevant for cloud-based systems
Correct answer: Apply broadly to the IT environment supporting multiple applications, such as access management and change management
ITGCs govern the overall IT environment — including logical access, program change management, and computer operations — and their effectiveness underpins the reliability of application-level controls.
Question 2: Under the Three Lines of Defense model, the internal audit function represents which line?
- First line
- Second line
- Third line (Correct answer)
- Fourth line
Correct answer: Third line
The third line (internal audit) provides independent assurance to the board and senior management about the effectiveness of governance, risk management, and controls established by the first and second lines.
Question 3: Which of the following best describes a 'significant deficiency' in internal controls?
- A control deficiency less severe than a material weakness, but important enough to merit attention by those charged with governance (Correct answer)
- A control that has never been tested
- Any error exceeding $1,000 in a single transaction
- A breach of the code of conduct by a non-executive employee
Correct answer: A control deficiency less severe than a material weakness, but important enough to merit attention by those charged with governance
A significant deficiency is a control shortcoming that, while not rising to a material weakness, still warrants the attention of the audit committee due to its potential impact on financial reporting.
Question 4: Corporate governance principles generally require that a majority of board members be:
- Current executives of the company
- Independent directors with no material relationship to management (Correct answer)
- Certified Public Accountants
- Shareholders owning more than 5% of outstanding shares
Correct answer: Independent directors with no material relationship to management
Independence is fundamental to effective board oversight; stock exchange listing rules and governance best practices require a majority of directors to be independent to avoid conflicts of interest.
Question 5: Management override of internal controls is considered a significant inherent risk because:
- It is prohibited under GAAP
- Even well-designed controls can be circumvented by senior management, making fraud possible regardless of the control system (Correct answer)
- Override automatically triggers an SEC investigation
- It only affects public companies with more than 500 employees
Correct answer: Even well-designed controls can be circumvented by senior management, making fraud possible regardless of the control system
Because management has the authority and knowledge to bypass controls, auditing standards treat management override as an inherent risk that must always be addressed, regardless of the control environment.
Question 6: A whistleblower policy is an example of which COSO component?
- Risk Assessment
- Control Activities
- Information & Communication (Correct answer)
- Control Environment
Correct answer: Information & Communication
Whistleblower hotlines and reporting mechanisms fall under the Information & Communication component because they facilitate the flow of relevant information — including concerns about misconduct — to appropriate parties.
Question 7: Which regulatory body issues auditing standards for public company auditors in the United States regarding internal controls?
- FASB
- AICPA
- PCAOB (Correct answer)
- COSO
Correct answer: PCAOB
The Public Company Accounting Oversight Board (PCAOB) was established by SOX to issue auditing standards for registered public accounting firms, including AS 2201 on ICFR audits.
IT General Controls (ITGCs) differ from IT Application Controls in that ITGCs: