CBA Audit Process and Management Questions and Answers — Questions and Answers
Question 1: The Chief Audit Executive (CAE) of a large commercial bank is developing the annual audit plan. Which of the following is the MOST critical first step in establishing the scope and priorities for the upcoming audit cycle?
- Reviewing the findings and recommendations from the prior year's audit reports.
- Conducting a comprehensive, bank-wide risk assessment to identify and rank high-risk areas. (Correct answer)
- Meeting with the Board of Directors' Audit Committee to understand their primary concerns.
- Evaluating the current staffing levels and technical expertise of the internal audit department.
Correct answer: Conducting a comprehensive, bank-wide risk assessment to identify and rank high-risk areas.
A risk-based approach is fundamental to modern internal auditing in banking. The initial step should be a comprehensive risk assessment to ensure that audit resources are focused on the areas that pose the greatest threat to the bank's objectives. While prior audit findings, board concerns, and staff capabilities are all important inputs, they are best considered within the context of the overall risk landscape identified by the assessment.
Question 2: During the fieldwork phase of an audit of a bank's lending department, an auditor discovers that a loan officer has been overriding system-based credit controls for several high-value loans without documented approval. What is the auditor's immediate responsibility?
- Include the finding in the final audit report to be presented to the audit committee.
- Confront the loan officer directly to request an explanation for the overrides.
- Discontinue the audit of the lending department until management resolves the issue.
- Document the finding and escalate it to the in-charge auditor or audit manager for further review. (Correct answer)
Correct answer: Document the finding and escalate it to the in-charge auditor or audit manager for further review.
Standard audit procedures require that significant findings or potential irregularities discovered during fieldwork be properly documented and escalated to audit management promptly. This ensures the issue is addressed at the appropriate level, allows for a coordinated response (which may include expanding the audit scope), and maintains the objectivity of the audit process. Confronting the individual directly or waiting until the final report could compromise the investigation and allow the issue to persist.
Question 3: Which of the following BEST describes the primary purpose of the internal audit charter in a banking institution?
- To outline the annual audit plan, including the specific departments and processes to be reviewed.
- To detail the specific testing procedures and methodologies that auditors must follow during engagements.
- To establish the internal audit function's purpose, authority, and responsibility, and its position within the organization. (Correct answer)
- To list the professional qualifications and continuing education requirements for the internal audit staff.
Correct answer: To establish the internal audit function's purpose, authority, and responsibility, and its position within the organization.
The internal audit charter is a formal document that defines the internal audit function's purpose, authority, and responsibility. It establishes the function's independence, authorizes its access to records, personnel, and physical properties relevant to the performance of engagements, and defines the scope of its activities. It is approved by the board of directors and senior management.
Question 4: A bank's internal audit department is assessing the effectiveness of its risk management processes. Which activity is LEAST likely to be a direct responsibility of the internal audit function?
- Evaluating the design and operating effectiveness of risk mitigation controls.
- Providing independent assurance on the accuracy of risk management reporting to the board.
- Setting the bank's overall risk appetite and tolerance levels. (Correct answer)
- Auditing the processes for identifying, assessing, and monitoring key business risks.
Correct answer: Setting the bank's overall risk appetite and tolerance levels.
While internal audit plays a crucial role in evaluating risk management processes, it must maintain its independence and objectivity. Setting the bank's risk appetite and tolerance is a key governance responsibility of senior management and the Board of Directors, not the internal audit function. Internal audit's role is to provide assurance that the risk management framework established by management and the board is effective, not to set the risk strategy itself.
Question 5: In the context of managing an internal audit function, which of the following is a primary objective of a robust quality assurance and improvement program (QAIP)?
- To guarantee that all audits are completed within their allocated budget and timeframe.
- To ensure the audit team receives favorable performance reviews from auditees.
- To provide reasonable assurance that the audit function conforms with the Standards for the Professional Practice of Internal Auditing. (Correct answer)
- To focus exclusively on identifying and disciplining underperforming audit staff members.
Correct answer: To provide reasonable assurance that the audit function conforms with the Standards for the Professional Practice of Internal Auditing.
A quality assurance and improvement program (QAIP) is essential for an internal audit function to evaluate its conformance with professional standards (such as those from The Institute of Internal Auditors), assess its efficiency and effectiveness, and identify opportunities for improvement. The QAIP helps ensure the credibility and quality of the audit work performed.
Question 6: An auditor is preparing for an audit of a bank's Anti-Money Laundering (AML) compliance program. During the planning phase, which of the following documents would be the MOST important to review first?
- The previous year's AML audit report and management's response.
- The bank's most recent risk assessment of its money laundering and terrorist financing exposures. (Correct answer)
- A detailed list of all Suspicious Activity Reports (SARs) filed in the last quarter.
- The training records and certifications of the bank's AML compliance staff.
Correct answer: The bank's most recent risk assessment of its money laundering and terrorist financing exposures.
The foundation of a risk-based AML audit is understanding the bank's own assessment of its risks. The bank's formal risk assessment will identify high-risk products, services, customers, and geographic locations. Reviewing this document first allows the auditor to understand the bank's risk profile and evaluate whether the audit plan and control testing are appropriately focused on the most significant areas of AML risk.
The Chief Audit Executive (CAE) of a large commercial bank is developing the annual audit plan.
Which of the following is the MOST critical first step in establishing the scope and priorities for the upcoming audit cycle?