CAT Internal Controls & Risk Assessment 2 — Questions and Answers
Question 1: Which control activity ensures that no single employee can both authorize a transaction and record it in the accounting system?
- Reconciliation
- Segregation of duties (Correct answer)
- Physical safeguards
- Independent verification
Correct answer: Segregation of duties
Segregation of duties divides authorization, recording, and custody functions among different employees to prevent fraud and error.
Question 2: An organization's risk appetite is BEST described as:
- The total amount of risk the organization faces
- The level of risk the organization is willing to accept in pursuit of its objectives (Correct answer)
- The risk remaining after controls are applied
- The probability that a risk event will occur
Correct answer: The level of risk the organization is willing to accept in pursuit of its objectives
Risk appetite defines how much risk management is prepared to accept when pursuing strategic objectives.
Question 3: Which type of control is designed to discover errors or irregularities AFTER they have occurred?
- Preventive control
- Detective control (Correct answer)
- Corrective control
- Directive control
Correct answer: Detective control
Detective controls identify problems that have already happened, such as bank reconciliations or exception reports.
Question 4: A company requires two authorized signatures on all checks exceeding $10,000. This is an example of:
- Compensating control
- Dual authorization (Correct answer)
- Physical safeguard
- Audit trail
Correct answer: Dual authorization
Dual authorization requires more than one person to approve high-value transactions, reducing the risk of unauthorized payments.
Question 5: Residual risk is defined as the risk that remains:
- Before any controls are implemented
- After management has responded to the risk (Correct answer)
- When a risk cannot be identified
- Only in financial reporting processes
Correct answer: After management has responded to the risk
Residual risk is the exposure that still exists after management applies controls or other risk responses.
Question 6: Which component of the COSO Internal Control framework addresses the organization's commitment to integrity and ethical values?
- Risk Assessment
- Control Activities
- Control Environment (Correct answer)
- Monitoring Activities
Correct answer: Control Environment
The Control Environment sets the tone at the top, including ethical values, governance structure, and management's commitment to competence.
Question 7: A purchasing manager who also approves invoices from the same vendor presents which type of risk?
- Credit risk
- Liquidity risk
- Conflict of interest risk (Correct answer)
- Market risk
Correct answer: Conflict of interest risk
When the same person selects vendors and approves their invoices, there is a conflict of interest that may lead to fraudulent or biased payments.
Which control activity ensures that no single employee can both authorize a transaction and record it in the accounting system?