CCA Internal Controls & Risk Management 2 — Questions and Answers
Question 1: Which COSO framework component addresses how an organization communicates information necessary for employees to carry out their internal control responsibilities?
- Control Activities
- Information & Communication (Correct answer)
- Monitoring Activities
- Risk Assessment
Correct answer: Information & Communication
The Information & Communication component ensures relevant information is identified, captured, and communicated in a timely manner to support internal control.
Question 2: A company discovers that a single employee can both approve purchase orders and authorize payments. This represents a failure in which internal control principle?
- Physical safeguards
- Segregation of duties (Correct answer)
- Independent verification
- Documentation procedures
Correct answer: Segregation of duties
Segregation of duties requires that no single employee controls all phases of a transaction to reduce fraud and error risk.
Question 3: Under the ERM framework, 'residual risk' is best defined as:
- Risk that has been transferred to a third party
- Risk remaining after management has applied controls (Correct answer)
- Risk identified but not yet assessed
- Risk arising from new business activities
Correct answer: Risk remaining after management has applied controls
Residual risk is the level of risk that remains after management implements risk responses and controls.
Question 4: Which internal control technique involves comparing recorded amounts with independently determined amounts such as bank statements?
- Reconciliation (Correct answer)
- Authorization
- Physical counts
- Budgetary control
Correct answer: Reconciliation
Reconciliation is the process of comparing two sets of records to ensure they are consistent and accurate.
Question 5: A company's board audit committee is primarily responsible for:
- Day-to-day operational risk management
- Overseeing financial reporting and internal audit functions (Correct answer)
- Approving all capital expenditures
- Managing the company's cybersecurity program
Correct answer: Overseeing financial reporting and internal audit functions
The audit committee oversees financial reporting integrity, internal audit activities, and compliance with regulatory requirements.
Question 6: Which risk response strategy involves sharing risk exposure with another party, such as through insurance?
- Risk avoidance
- Risk acceptance
- Risk transfer (Correct answer)
- Risk mitigation
Correct answer: Risk transfer
Risk transfer shifts the financial consequences of risk to another party, most commonly through insurance or contractual arrangements.
Question 7: The 'three lines of defense' model assigns internal audit to which line?
- First line
- Second line
- Third line (Correct answer)
- Fourth line
Correct answer: Third line
Internal audit serves as the third line of defense, providing independent assurance over the effectiveness of governance, risk management, and control.
Which COSO framework component addresses how an organization communicates information necessary for employees to carry out their internal control responsibilities?