CCA Internal Controls & Risk Management 3 — Questions and Answers
Question 1: Which of the following is an example of a preventive control rather than a detective control?
- Monthly bank reconciliations
- Variance analysis reports
- Password authentication requirements (Correct answer)
- Internal audit reviews
Correct answer: Password authentication requirements
Preventive controls like password authentication stop errors or fraud before they occur, unlike detective controls that identify issues after the fact.
Question 2: Enterprise Risk Management (ERM) under COSO 2017 is organized around how many components?
- 5
- 8 (Correct answer)
- 17
- 20
Correct answer: 8
COSO's 2017 ERM framework is organized around 5 components and 20 principles, with 8 being associated with the older 2004 framework components.
Question 3: A key risk indicator (KRI) differs from a key performance indicator (KPI) in that a KRI:
- Measures past financial results
- Signals the likelihood of future adverse events (Correct answer)
- Tracks employee productivity
- Reports budget variance
Correct answer: Signals the likelihood of future adverse events
KRIs are forward-looking metrics that provide early warning signals of increasing risk exposure before issues materialize.
Question 4: Which control environment factor relates to management's demonstrated commitment to competence and ethical values?
- Tone at the top (Correct answer)
- Control consciousness
- Risk appetite statement
- Monitoring protocol
Correct answer: Tone at the top
Tone at the top reflects the ethical values, integrity, and commitment to internal control demonstrated by senior leadership.
Question 5: When assessing internal control effectiveness, an auditor identifies a deficiency where controls might not prevent or detect a material misstatement. This is classified as a:
- Control deficiency
- Significant deficiency
- Material weakness (Correct answer)
- Reportable condition
Correct answer: Material weakness
A material weakness is a deficiency or combination of deficiencies in internal control where there is a reasonable possibility that a material misstatement will not be prevented or detected.
Question 6: Operational risk is best described as the risk of loss resulting from:
- Interest rate fluctuations
- Inadequate internal processes, people, or systems (Correct answer)
- Credit counterparty defaults
- Foreign exchange movements
Correct answer: Inadequate internal processes, people, or systems
Operational risk arises from failures in internal processes, human errors, system failures, or external events affecting business operations.
Question 7: Which approach to risk assessment involves quantifying risk by assigning numerical probabilities and financial impact estimates?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Inherent risk mapping
- Control gap analysis
Correct answer: Quantitative risk assessment
Quantitative risk assessment uses statistical models and numerical data to estimate the probability and financial magnitude of risks.
Which of the following is an example of a preventive control rather than a detective control?