CCB Internal Auditing & Control Systems 4 — Questions and Answers
Question 1: A company requires two senior managers to approve wire transfers over $500,000. This is an example of:
- Dual control (Correct answer)
- Segregation of duties
- Reconciliation control
- Physical safeguard
Correct answer: Dual control
Dual control (also called dual authorization) requires two authorized individuals to approve a single transaction, reducing the risk of unauthorized transfers.
Question 2: In an IT environment, which control ensures that only authorized users can access sensitive financial data?
- Data encryption at rest
- User access management controls (Correct answer)
- Network perimeter firewall
- Backup and recovery procedures
Correct answer: User access management controls
User access management controls, including role-based access and periodic access reviews, ensure that only authorized individuals can view or modify sensitive data.
Question 3: The 'tone at the top' concept is MOST directly associated with which element of a strong control environment?
- Physical controls over assets
- Management's commitment to integrity and ethical values (Correct answer)
- Automated system access logs
- Frequency of external audits
Correct answer: Management's commitment to integrity and ethical values
Tone at the top refers to senior leadership's visible commitment to ethics and compliance, which sets the behavioral standard for the entire organization.
Question 4: Which internal audit technique compares financial ratios and trends over time to identify unusual fluctuations?
- Confirmations
- Analytical procedures (Correct answer)
- Physical inspection
- Attribute sampling
Correct answer: Analytical procedures
Analytical procedures involve evaluating financial information through analysis of relationships and trends, helping auditors identify areas requiring further investigation.
Question 5: An organization's internal audit charter should PRIMARILY:
- List all audit findings from the prior year
- Define the purpose, authority, and responsibility of the internal audit function (Correct answer)
- Specify the external audit fee schedule
- Outline employee performance evaluation criteria
Correct answer: Define the purpose, authority, and responsibility of the internal audit function
The internal audit charter is a formal document approved by the board that defines the function's purpose, authority, scope, and reporting relationships.
Question 6: Which of the following BEST describes a compensating control?
- A control that detects errors after the fact
- An alternative control that mitigates risk when an ideal control is not feasible (Correct answer)
- A control embedded within an IT system
- A management review performed annually
Correct answer: An alternative control that mitigates risk when an ideal control is not feasible
Compensating controls provide alternative risk mitigation when primary controls cannot be implemented, such as enhanced monitoring when segregation of duties is not practical in a small business.
Question 7: During an audit, the auditor discovers that account reconciliations have not been completed for three months. This is MOST likely a failure of:
- Physical safeguarding controls
- Monitoring controls (Correct answer)
- IT general controls
- Entity-level controls
Correct answer: Monitoring controls
Monitoring controls include regular reconciliations, reviews, and supervisory checks; failure to perform them indicates a breakdown in the monitoring component of COSO.
A company requires two senior managers to approve wire transfers over $500,000.
This is an example of: