CCM Compliance Monitoring & Auditing 3 — Questions and Answers
Question 1: Under COSO's Internal Control framework, which component specifically addresses the policies and procedures that help ensure management directives are carried out?
- Control Environment
- Risk Assessment
- Control Activities (Correct answer)
- Monitoring Activities
Correct answer: Control Activities
Control Activities are the policies and procedures that ensure management directives are implemented and risks are mitigated.
Question 2: A compliance officer wants to measure how quickly issues identified in audits are resolved. Which KPI is MOST appropriate?
- Number of audits completed per year
- Average days to close audit findings (Correct answer)
- Total number of open regulatory requirements
- Percentage of employees trained on compliance
Correct answer: Average days to close audit findings
Average days to close audit findings directly measures remediation speed and helps identify bottlenecks in the corrective action process.
Question 3: Which audit technique involves tracing a transaction from its origin through all processing steps to the final output?
- Flowcharting
- Vouching
- Walkthrough (Correct answer)
- Analytical review
Correct answer: Walkthrough
A walkthrough traces a single transaction end-to-end through the process to confirm controls operate as designed.
Question 4: A compliance team uses data analytics to flag 100% of transactions for review. This approach is BEST described as:
- Statistical sampling
- Judgmental sampling
- Full population testing (Correct answer)
- Risk-based sampling
Correct answer: Full population testing
Full population testing examines every transaction rather than a sample, which is increasingly feasible with automated data analytics tools.
Question 5: Which regulatory concept requires organizations to demonstrate that their compliance controls are working, rather than simply having them documented?
- Compliance by design
- Evidence of effectiveness (Correct answer)
- Policy attestation
- Regulatory safe harbor
Correct answer: Evidence of effectiveness
Evidence of effectiveness requires organizations to show through testing and documentation that controls are actually operating as intended.
Question 6: An internal audit finds a 'significant deficiency' in a compliance control. How does this differ from a 'material weakness'?
- A significant deficiency always requires immediate regulatory reporting; a material weakness does not
- A significant deficiency is less severe and may not prevent detection of a major violation; a material weakness indicates a higher probability of a major failure (Correct answer)
- They are synonymous terms used interchangeably in compliance auditing
- A material weakness applies only to financial audits, not compliance audits
Correct answer: A significant deficiency is less severe and may not prevent detection of a major violation; a material weakness indicates a higher probability of a major failure
A significant deficiency is less severe than a material weakness; a material weakness represents a higher probability that a significant compliance failure will go undetected.
Question 7: What is the MAIN benefit of using automated compliance monitoring tools over purely manual reviews?
- They eliminate the need for a compliance department entirely
- They provide consistent, scalable, and timely detection of control failures across large data sets (Correct answer)
- They guarantee zero compliance violations
- They replace the need for regulatory reporting
Correct answer: They provide consistent, scalable, and timely detection of control failures across large data sets
Automated tools apply rules consistently across large volumes of data and flag exceptions faster than manual review, reducing human error and lag time.
Under COSO's Internal Control framework, which component specifically addresses the policies and procedures that help ensure management directives are carried out?