CCS Internal Controls & Auditing 2 — Questions and Answers
Question 1: Which COSO component addresses the organization's values, ethics, and commitment to competence?
- Risk Assessment
- Control Environment (Correct answer)
- Monitoring Activities
- Information & Communication
Correct answer: Control Environment
The Control Environment is the foundation of COSO's Internal Control framework and sets the tone at the top regarding ethics, integrity, and competence.
Question 2: A compliance officer discovers that a control designed to prevent duplicate payments has a 15% failure rate. What should be the FIRST step?
- Immediately report to regulators
- Perform a root cause analysis (Correct answer)
- Terminate the responsible employees
- Implement a compensating control without further investigation
Correct answer: Perform a root cause analysis
Root cause analysis should precede corrective action to ensure the remediation addresses the actual source of the control failure.
Question 3: Under the Sarbanes-Oxley Act Section 404, management is required to:
- Hire external auditors to design internal controls
- Assess and report on the effectiveness of internal controls over financial reporting (Correct answer)
- Eliminate all material weaknesses within 30 days
- File quarterly control assessments with the SEC
Correct answer: Assess and report on the effectiveness of internal controls over financial reporting
SOX Section 404 requires management to assess and report on the effectiveness of internal controls over financial reporting as part of the annual report.
Question 4: Which type of audit evidence is generally considered MOST reliable?
- Oral representations from management
- Documents created internally and retained within the organization
- Documents obtained directly from independent third parties (Correct answer)
- Copies of documents provided by the auditee
Correct answer: Documents obtained directly from independent third parties
Evidence obtained directly from independent third parties is most reliable because it is least susceptible to management influence or manipulation.
Question 5: In the context of internal auditing, 'inherent risk' refers to:
- Risk remaining after management applies controls
- Risk that auditors will fail to detect a material misstatement
- Risk existing before any controls are applied (Correct answer)
- Risk introduced by the audit process itself
Correct answer: Risk existing before any controls are applied
Inherent risk is the susceptibility of an assertion or process to material error before considering any related controls.
Question 6: Which sampling technique gives every item in a population an equal chance of being selected?
- Judgmental sampling
- Stratified sampling
- Systematic sampling
- Random sampling (Correct answer)
Correct answer: Random sampling
Random sampling ensures each item in the population has an equal and independent probability of selection, supporting statistically valid conclusions.
Question 7: An auditor finds that the same employee who approves purchase orders also processes the payment. This is an example of:
- Adequate segregation of duties
- A compensating control
- A segregation of duties weakness (Correct answer)
- An acceptable dual-control procedure
Correct answer: A segregation of duties weakness
Combining authorization and custody/payment functions in one person violates segregation of duties principles and creates an opportunity for fraud.
Which COSO component addresses the organization's values, ethics, and commitment to competence?