Internal Auditing & Control Systems Flashcards
9 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 9 Internal Auditing & Control Systems flashcards as text
What is the main goal of internal auditing?
Answer: To assess risks and improve processes
The main goal of internal auditing is to provide independent, objective assurance and consulting services designed to add value and improve an organization's operations. Internal auditors achieve this by evaluating the effectiveness of risk management, control, and governance processes. Their work helps identify weaknesses, recommend improvements, and ensure compliance, ultimately enhancing the organization's ability to achieve its objectives.
What is a control system?
Answer: A set of safeguards and process controls
A control system refers to the policies, procedures, and practices implemented by an organization to ensure that its objectives are met, risks are managed, and operations are conducted efficiently and ethically. These safeguards are designed to prevent errors, detect fraud, ensure compliance with regulations, and protect assets. Effective control systems are fundamental to good governance and operational reliability.
Which of the following is a key benefit of internal audits?
Answer: Improved efficiency and compliance
Internal audits systematically review an organization's operations, financial reporting, and compliance with laws and policies. By identifying inefficiencies, control weaknesses, and areas of non-compliance, internal audits provide recommendations for improvement. This leads to streamlined processes, better resource utilization, and stronger adherence to regulatory requirements, ultimately enhancing overall organizational performance and reducing risks.
What role does segregation of duties play in internal controls?
Answer: It ensures no single person controls all functions
Segregation of duties is a fundamental internal control principle designed to minimize the risk of error, fraud, and abuse. By dividing critical tasks and responsibilities among different individuals, it prevents any single person from having complete control over a transaction from beginning to end. This separation creates a system of checks and balances, making it much harder for unauthorized or fraudulent activities to occur undetected.
What is the purpose of audit documentation?
Answer: To provide proof of audit work and conclusions
Audit documentation serves as the official record of the audit work performed, the evidence gathered, and the conclusions reached by the auditor. It provides a basis for the auditor's report, demonstrating that the audit was conducted in accordance with professional standards and supporting the auditor's findings and recommendations. This documentation is crucial for accountability, quality review, and future reference.
How often should internal audits be conducted?
Answer: Periodically based on risk and schedule
The frequency of internal audits should not be fixed but rather determined by a risk-based approach and a predefined audit schedule. High-risk areas or processes with significant changes may require more frequent audits, while lower-risk areas might be audited less often. This approach ensures that audit resources are allocated effectively to areas that pose the greatest potential threat to the organization's objectives.
Why are control activities necessary?
Answer: To enforce policy and reduce risk
Control activities are specific actions taken by management to help ensure that management directives are carried out and that risks to the achievement of organizational objectives are mitigated. These activities include approvals, authorizations, reconciliations, and segregation of duties. They are essential for enforcing policies, preventing errors, detecting fraud, and safeguarding assets, thereby reducing overall operational and financial risks.
Which of the following is a limitation of internal control?
Answer: They may be overridden or bypassed
While internal controls are designed to mitigate risks, they are not foolproof. A significant limitation is the possibility of management override, where senior personnel intentionally circumvent established controls, or collusion among employees to bypass controls. Human error, misunderstanding, or resource constraints can also limit their effectiveness, meaning controls can reduce but not eliminate all risks.
Who is responsible for establishing internal controls?
Answer: Management
Management is primarily responsible for establishing, implementing, and maintaining an effective system of internal controls within an organization. They are accountable for designing controls that address identified risks, ensuring that employees understand and adhere to them, and regularly monitoring their effectiveness. While the board oversees, management is hands-on in their creation and daily operation.