CCB Internal Auditing & Control Systems 2 — Questions and Answers
Question 1: Which type of internal audit focuses on whether organizational resources are used efficiently and economically?
- Financial audit
- Compliance audit
- Performance audit (Correct answer)
- IT audit
Correct answer: Performance audit
Performance audits (also called operational or efficiency audits) assess whether resources are being used economically and efficiently to achieve organizational objectives.
Question 2: A control that prevents errors or fraud from occurring in the first place is classified as a:
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Preventive controls are designed to stop errors or irregularities before they occur, such as requiring dual authorization for large transactions.
Question 3: Under the COSO framework, which component addresses the organizational values and ethical tone set by leadership?
- Risk assessment
- Control activities
- Control environment (Correct answer)
- Information and communication
Correct answer: Control environment
The control environment is the foundation of COSO and includes the ethical values, management philosophy, and tone set by leadership.
Question 4: An auditor identifies that a single employee handles purchasing, receiving, and payment approval. This is best described as a:
- Segregation of duties weakness (Correct answer)
- Authorization control deficiency
- IT access control gap
- Monitoring control failure
Correct answer: Segregation of duties weakness
Segregation of duties requires that incompatible functions — such as authorizing, recording, and custody — be assigned to different individuals to reduce fraud risk.
Question 5: Which internal audit activity involves reviewing controls before a new system goes live?
- Post-implementation review
- Pre-implementation review (Correct answer)
- Substantive testing
- Walkthrough procedure
Correct answer: Pre-implementation review
Pre-implementation reviews assess the adequacy of controls in a new system before it becomes operational, reducing the risk of control gaps after launch.
Question 6: The primary purpose of a control self-assessment (CSA) is to:
- Replace external audit procedures
- Allow management and staff to evaluate their own controls (Correct answer)
- Satisfy regulatory reporting requirements
- Test the accuracy of financial statements
Correct answer: Allow management and staff to evaluate their own controls
CSA is a process where process owners and staff collaboratively assess the effectiveness of controls in their area, supplementing (not replacing) formal audits.
Question 7: When an auditor tests a sample of transactions and finds no exceptions, this provides:
- Absolute assurance that no errors exist
- Reasonable assurance based on the sample tested (Correct answer)
- Proof that all controls are operating effectively
- Grounds to eliminate future testing
Correct answer: Reasonable assurance based on the sample tested
Sampling provides reasonable, not absolute, assurance because only a subset of transactions is tested, leaving inherent sampling risk.
Which type of internal audit focuses on whether organizational resources are used efficiently and economically?