Certified Fraud Examiner Corporate Governance Questions and Answers — Questions and Answers
Question 1: Which of the following represents the clearest distinction between the responsibilities of the board of directors and senior management in the context of fraud risk management?
- The board is responsible for designing internal controls, while management is responsible for testing their effectiveness.
- The board has the ultimate responsibility for fraud risk oversight, while management is responsible for the day-to-day implementation of anti-fraud programs. (Correct answer)
- Management is responsible for setting the 'tone at the top,' while the board is responsible for communicating it to employees.
- Management is responsible for hiring external auditors, while the board is responsible for overseeing the internal audit function.
Correct answer: The board has the ultimate responsibility for fraud risk oversight, while management is responsible for the day-to-day implementation of anti-fraud programs.
Corporate governance principles separate the roles of oversight and execution. The board of directors is responsible for overseeing the organization's strategic direction and governance, which includes the oversight of fraud risk management. Senior management, led by the CEO, is tasked with the operational responsibility of designing, implementing, and maintaining the specific anti-fraud programs and internal controls.
Question 2: A company's CEO consistently dismisses the importance of the corporate code of conduct during meetings, often stating, "We need to do whatever it takes to meet our quarterly numbers." This attitude has led middle managers to approve questionable expense reports and ignore inventory control weaknesses. This scenario is a prime example of a failure in what aspect of corporate governance?
- Audit committee independence
- Segregation of duties
- The 'tone at the top' (Correct answer)
- Whistleblower protection policy
Correct answer: The 'tone at the top'
The 'tone at the top' refers to the ethical atmosphere created by an organization's leadership. When senior management demonstrates a disregard for ethical standards and internal controls, it creates a culture where such behavior is implicitly condoned, increasing the risk of fraud throughout the organization.
Question 3: Under the Sarbanes-Oxley Act of 2002 (SOX), which of the following is a key requirement for the audit committees of publicly traded companies?
- All members of the audit committee must be Certified Public Accountants (CPAs).
- The committee must be directly responsible for the appointment, compensation, and oversight of the external auditor. (Correct answer)
- The Chief Financial Officer (CFO) must serve as the chairperson of the audit committee.
- The audit committee must meet on a daily basis to review all financial transactions.
Correct answer: The committee must be directly responsible for the appointment, compensation, and oversight of the external auditor.
Section 301 of the Sarbanes-Oxley Act mandates that the audit committee of a public company shall be directly responsible for appointing, compensating, and overseeing the work of the external audit firm. This provision is crucial for ensuring auditor independence from management. While financial literacy is required and having a financial expert is encouraged, not all members must be CPAs. The CFO, being part of management, cannot be an independent member of the committee.
Question 4: The primary role of a corporate board's audit committee in preventing and detecting fraud is to:
- Conduct detailed fraud investigations of all employee tips.
- Design and implement the company's internal control system.
- Provide active oversight of the financial reporting process, internal controls, and the external audit function. (Correct answer)
- Personally approve every significant financial transaction.
Correct answer: Provide active oversight of the financial reporting process, internal controls, and the external audit function.
The audit committee's role is one of oversight, not direct management or execution. Its key responsibilities include overseeing the financial reporting process, the effectiveness of internal controls, the performance and independence of the external auditor, and the internal audit function. Management is responsible for designing and implementing controls, and while the committee oversees investigations, it does not typically conduct them directly.
Question 5: A Certified Fraud Examiner is reviewing the governance structure of a privately-held company. The CFE notes that the board of directors consists of the CEO, the CEO's brother (who is the COO), the company's long-time external lawyer, and two retired executives who are close personal friends of the CEO. Which corporate governance weakness is MOST apparent from this structure?
- Lack of a formal whistleblower policy.
- Absence of a designated financial expert.
- Insufficient segregation of accounting duties.
- A significant lack of independent directors. (Correct answer)
Correct answer: A significant lack of independent directors.
An effective board of directors requires independence to provide objective oversight and challenge management's decisions. A board composed of insiders (CEO, COO) and individuals with close personal or business relationships with the CEO (lawyer, friends) lacks the independence necessary for effective governance and creates a higher risk of management override and unchecked authority.
Question 6: What is the primary purpose of a formal corporate Code of Conduct within a company's overall governance and anti-fraud framework?
- To satisfy the minimum requirements of government regulations.
- To provide a detailed procedures manual for every job function.
- To set clear expectations for ethical behavior and provide guidance for employees on how to act with integrity. (Correct answer)
- To guarantee that no fraud will ever occur within the organization.
Correct answer: To set clear expectations for ethical behavior and provide guidance for employees on how to act with integrity.
A Code of Conduct is a cornerstone of an ethical culture and serves as a formal declaration of the organization's values and principles. Its primary purpose is to clearly communicate the expected standards of behavior to all employees, directors, and agents, and to provide a framework for making ethical decisions. While it helps meet regulatory expectations, its main function is to guide behavior and establish a culture of integrity.
Which of the following represents the clearest distinction between the responsibilities of the board of directors and senior management in the context of fraud risk management?