CCO Internal Controls and Audit 2 — Questions and Answers
Question 1: What is a control self-assessment (CSA)?
- An employee self-evaluation form
- A process where business units assess their own controls against defined criteria, often facilitated by internal audit or compliance (Correct answer)
- An external auditor assessment of management's controls
- A regulatory examination methodology
Correct answer: A process where business units assess their own controls against defined criteria, often facilitated by internal audit or compliance
CSAs engage business management and employees in evaluating the effectiveness of their own controls, building ownership and providing an early warning of control gaps.
Question 2: What is the difference between preventive and detective controls?
- Preventive controls are manual; detective controls are automated
- Preventive controls stop violations before they occur; detective controls identify violations after they have occurred (Correct answer)
- Preventive controls apply to finances; detective controls apply to IT systems
- Detective controls are more important than preventive controls
Correct answer: Preventive controls stop violations before they occur; detective controls identify violations after they have occurred
Preventive controls (e.g., approval requirements) block violations before they happen, while detective controls (e.g., reconciliations) identify them after the fact.
Question 3: What is an internal audit charter?
- A list of audit findings
- A formal document that defines the internal audit function's purpose, authority, responsibility, and independence within the organization (Correct answer)
- A contract with an external audit firm
- A regulatory requirement for financial institutions
Correct answer: A formal document that defines the internal audit function's purpose, authority, responsibility, and independence within the organization
The internal audit charter establishes the function's organizational authority, independence, scope, and accountability structure, typically approved by the Audit Committee.
Question 4: What does 'reasonable assurance' mean in the context of internal controls?
- That all errors and fraud will be detected
- That controls provide a high but not absolute level of assurance that objectives will be met, given inherent limitations of any control system (Correct answer)
- That management is satisfied with control outcomes
- That controls meet the minimum regulatory standard
Correct answer: That controls provide a high but not absolute level of assurance that objectives will be met, given inherent limitations of any control system
Reasonable assurance acknowledges that no control system is perfect and that there are inherent limitations — cost/benefit tradeoffs and human fallibility mean absolute assurance is unachievable.
Question 5: What is a management response to an audit finding?
- A rebuttal challenging the auditor's conclusions
- A formal response from management agreeing with or disputing the finding and committing to specific corrective actions with timelines (Correct answer)
- A press release about audit outcomes
- A regulatory notification of audit results
Correct answer: A formal response from management agreeing with or disputing the finding and committing to specific corrective actions with timelines
Management responses commit the business to remediation actions, owners, and deadlines for each audit finding, creating accountability for resolving control deficiencies.
Question 6: What is an audit risk model?
- A financial model estimating audit costs
- A framework combining inherent risk, control risk, and detection risk to determine the audit procedures needed to achieve acceptable assurance levels (Correct answer)
- A model for assessing auditor independence
- A risk rating system for regulatory violations
Correct answer: A framework combining inherent risk, control risk, and detection risk to determine the audit procedures needed to achieve acceptable assurance levels
The audit risk model helps auditors calibrate the nature, timing, and extent of procedures based on the combination of inherent, control, and detection risks in each area.
What is a control self-assessment (CSA)?