Certified Internal Auditor Case Studies & Practical Application 2 — Questions and Answers
Question 1: An internal auditor discovers that a regional manager has been approving vendor invoices that exceed her authorization limit by routing them through a subordinate with higher limits. What should the auditor do first?
- Immediately report the manager to law enforcement
- Document the finding and assess whether it constitutes a control override requiring escalation (Correct answer)
- Inform the subordinate they are violating policy
- Close the finding since the invoices were ultimately approved by someone with authority
Correct answer: Document the finding and assess whether it constitutes a control override requiring escalation
The auditor should document the control override finding and evaluate its significance before determining the appropriate escalation path per IIA standards.
Question 2: During a procurement audit, an auditor finds that 80% of purchase orders over $50,000 were awarded to a single vendor without competitive bidding. Management states the vendor provides unique services. What is the auditor's most appropriate response?
- Accept management's explanation and close the finding
- Verify whether the sole-source justifications were documented and approved per policy (Correct answer)
- Recommend immediate contract termination with the vendor
- Expand the audit scope to include all vendor contracts
Correct answer: Verify whether the sole-source justifications were documented and approved per policy
The auditor should verify whether required sole-source documentation and approvals exist rather than accepting an undocumented verbal explanation.
Question 3: A company's IT general controls audit reveals that privileged user access reviews are performed annually. Industry best practice recommends quarterly reviews. How should the auditor classify this finding?
- Not a finding, since annual reviews are better than no reviews
- A significant deficiency requiring immediate remediation
- A control gap with risk rated based on the sensitivity of systems and data accessed (Correct answer)
- A material weakness automatically because it deviates from best practice
Correct answer: A control gap with risk rated based on the sensitivity of systems and data accessed
The severity of a control gap should be assessed based on actual risk exposure, not simply deviation from best practice.
Question 4: An auditor is reviewing expense reimbursements and notices that a senior executive submitted $12,000 in meal receipts over three months, all just below the $500 per-event threshold requiring additional approval. What fraud scheme does this pattern suggest?
- Skimming
- Structuring (threshold avoidance) (Correct answer)
- Lapping
- Ghost employee fraud
Correct answer: Structuring (threshold avoidance)
Consistently submitting expenses just below approval thresholds is a classic structuring scheme designed to avoid control triggers.
Question 5: During a payroll audit, the auditor finds 15 employees whose direct deposit accounts were changed in the two weeks before payroll processing, with no corresponding HR change requests. What is the most likely risk indicated?
- System configuration error in payroll software
- Unauthorized redirection of payroll funds, possibly via compromised credentials (Correct answer)
- Normal employee banking changes during open enrollment
- Duplicate payment processing error
Correct answer: Unauthorized redirection of payroll funds, possibly via compromised credentials
Bank account changes without HR authorization are a strong indicator of payroll fraud through unauthorized account redirection.
Question 6: An auditor is testing controls over financial statement close. She finds that journal entries posted after period-end cutoff lack supporting documentation 40% of the time. Management says this is due to time pressure. What is the primary audit concern?
- Staff training on documentation requirements
- Risk of unsupported or fraudulent manual journal entries manipulating reported results (Correct answer)
- Whether the close timeline should be extended
- Whether the auditor's sample size was large enough
Correct answer: Risk of unsupported or fraudulent manual journal entries manipulating reported results
Unsupported post-close journal entries represent a high risk for earnings manipulation and are a key fraud indicator in financial reporting audits.
Question 7: A healthcare organization's auditor reviews patient billing and finds that claims for a specific procedure code increased 300% in one quarter with no corresponding increase in patient volume. What should the auditor do?
- Note the finding and schedule a follow-up audit next year
- Investigate whether the code is being upcoded or applied to ineligible services (Correct answer)
- Report directly to CMS without informing management
- Conclude that billing productivity improved
Correct answer: Investigate whether the code is being upcoded or applied to ineligible services
A dramatic increase in a specific billing code without corresponding patient volume growth is a red flag for upcoding fraud requiring immediate investigation.
An internal auditor discovers that a regional manager has been approving vendor invoices that exceed her authorization limit by routing them through a subordinate with higher limits.
What should the auditor do first?