CDFM Auditing and Internal Controls 3 — Questions and Answers
Question 1: Which OMB circular specifically requires federal agencies to assess and report on internal controls over financial reporting using a recognized framework such as COSO?
- OMB Circular A-11
- OMB Circular A-123 (Correct answer)
- OMB Circular A-136
- OMB Circular A-76
Correct answer: OMB Circular A-123
OMB Circular A-123 (Management's Responsibility for Enterprise Risk Management and Internal Control) requires agencies to establish, assess, and report on internal controls.
Question 2: In the context of DoD audits, what is the purpose of a corrective action plan (CAP)?
- To document audit findings before they are reported
- To describe management's planned actions to remediate identified control weaknesses (Correct answer)
- To authorize new spending authorities for remediation
- To transfer audit responsibility to the Inspector General
Correct answer: To describe management's planned actions to remediate identified control weaknesses
A CAP documents the specific steps management will take to remediate control deficiencies or audit findings, including timelines and responsible officials.
Question 3: A preventive internal control is best described as a control that:
- Identifies errors after they have occurred
- Stops errors or irregularities from occurring in the first place (Correct answer)
- Corrects errors after detection
- Reports errors to senior management
Correct answer: Stops errors or irregularities from occurring in the first place
Preventive controls are designed to deter or stop errors and fraud before they occur, such as authorization requirements and access restrictions.
Question 4: Under GAGAS, a performance audit that evaluates whether a program is achieving its intended outcomes is classified as what type of objective?
- Attestation engagement
- Effectiveness objective (Correct answer)
- Economy objective
- Compliance objective
Correct answer: Effectiveness objective
Effectiveness objectives in performance audits assess the extent to which a program achieves its intended results or outcomes.
Question 5: Which of the following best describes 'segregation of duties' as an internal control in DoD financial operations?
- Assigning one person to handle all aspects of a transaction to ensure accountability
- Dividing transaction responsibilities so no single individual controls all phases (Correct answer)
- Rotating auditors annually to prevent familiarity
- Requiring dual signatures only for transactions above $10,000
Correct answer: Dividing transaction responsibilities so no single individual controls all phases
Segregation of duties divides authorization, custody, and recording functions among different personnel to reduce the risk of error and fraud.
Question 6: The audit risk model expresses audit risk as a function of which three components?
- Inherent risk, Control risk, and Detection risk (Correct answer)
- Business risk, Fraud risk, and Compliance risk
- Sampling risk, Non-sampling risk, and Projection risk
- Material weakness risk, Significant deficiency risk, and Control deficiency risk
Correct answer: Inherent risk, Control risk, and Detection risk
Audit risk = Inherent Risk × Control Risk × Detection Risk; auditors manage detection risk to achieve an acceptable overall audit risk level.
Question 7: In DoD, which office is primarily responsible for conducting independent evaluations of internal controls and financial management practices within a military department?
- Defense Finance and Accounting Service (DFAS)
- Inspector General (IG) (Correct answer)
- Under Secretary of Defense (Comptroller)
- Defense Contract Management Agency (DCMA)
Correct answer: Inspector General (IG)
The Inspector General conducts independent audits and investigations to evaluate internal controls, financial management, and program integrity within DoD components.
Which OMB circular specifically requires federal agencies to assess and report on internal controls over financial reporting using a recognized framework such as COSO?