← All CBA Flashcard Decks

Audit Process and Management Flashcards

6 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Audit Process and Management flashcards as text
  1. The Chief Audit Executive (CAE) of a large commercial bank is developing the annual audit plan. Which of the following is the MOST critical first step in establishing the scope and priorities for the upcoming audit cycle?

    Answer: Conducting a comprehensive, bank-wide risk assessment to identify and rank high-risk areas.

    A risk-based approach is fundamental to modern internal auditing in banking. The initial step should be a comprehensive risk assessment to ensure that audit resources are focused on the areas that pose the greatest threat to the bank's objectives. While prior audit findings, board concerns, and staff capabilities are all important inputs, they are best considered within the context of the overall risk landscape identified by the assessment.

  2. During the fieldwork phase of an audit of a bank's lending department, an auditor discovers that a loan officer has been overriding system-based credit controls for several high-value loans without documented approval. What is the auditor's immediate responsibility?

    Answer: Document the finding and escalate it to the in-charge auditor or audit manager for further review.

    Standard audit procedures require that significant findings or potential irregularities discovered during fieldwork be properly documented and escalated to audit management promptly. This ensures the issue is addressed at the appropriate level, allows for a coordinated response (which may include expanding the audit scope), and maintains the objectivity of the audit process. Confronting the individual directly or waiting until the final report could compromise the investigation and allow the issue to persist.

  3. Which of the following BEST describes the primary purpose of the internal audit charter in a banking institution?

    Answer: To establish the internal audit function's purpose, authority, and responsibility, and its position within the organization.

    The internal audit charter is a formal document that defines the internal audit function's purpose, authority, and responsibility. It establishes the function's independence, authorizes its access to records, personnel, and physical properties relevant to the performance of engagements, and defines the scope of its activities. It is approved by the board of directors and senior management.

  4. A bank's internal audit department is assessing the effectiveness of its risk management processes. Which activity is LEAST likely to be a direct responsibility of the internal audit function?

    Answer: Setting the bank's overall risk appetite and tolerance levels.

    While internal audit plays a crucial role in evaluating risk management processes, it must maintain its independence and objectivity. Setting the bank's risk appetite and tolerance is a key governance responsibility of senior management and the Board of Directors, not the internal audit function. Internal audit's role is to provide assurance that the risk management framework established by management and the board is effective, not to set the risk strategy itself.

  5. In the context of managing an internal audit function, which of the following is a primary objective of a robust quality assurance and improvement program (QAIP)?

    Answer: To provide reasonable assurance that the audit function conforms with the Standards for the Professional Practice of Internal Auditing.

    A quality assurance and improvement program (QAIP) is essential for an internal audit function to evaluate its conformance with professional standards (such as those from The Institute of Internal Auditors), assess its efficiency and effectiveness, and identify opportunities for improvement. The QAIP helps ensure the credibility and quality of the audit work performed.

  6. An auditor is preparing for an audit of a bank's Anti-Money Laundering (AML) compliance program. During the planning phase, which of the following documents would be the MOST important to review first?

    Answer: The bank's most recent risk assessment of its money laundering and terrorist financing exposures.

    The foundation of a risk-based AML audit is understanding the bank's own assessment of its risks. The bank's formal risk assessment will identify high-risk products, services, customers, and geographic locations. Reviewing this document first allows the auditor to understand the bank's risk profile and evaluate whether the audit plan and control testing are appropriately focused on the most significant areas of AML risk.