Certified Internal Auditor Case Studies & Practical Application 3 — Questions and Answers
Question 1: An internal audit team is conducting a follow-up on prior audit recommendations. They find that management implemented a compensating control instead of the originally recommended primary control. What should the auditor conclude?
- The recommendation is not closed because the exact control was not implemented
- Assess whether the compensating control adequately mitigates the identified risk (Correct answer)
- Require management to implement the original recommendation exactly as written
- Escalate to the audit committee for non-compliance
Correct answer: Assess whether the compensating control adequately mitigates the identified risk
The auditor's goal is risk mitigation; a compensating control can close a recommendation if it adequately addresses the underlying risk.
Question 2: During a contract management audit, an auditor finds that a vendor's performance metrics consistently fall below SLA thresholds but no penalties have been assessed. The contract owner says the vendor 'always makes it up.' What risk does this represent?
- Vendor dependency risk only
- Financial loss, contractual rights waiver, and potential favoritism or conflict of interest (Correct answer)
- Operational risk from service disruption
- Reputational risk from poor vendor management
Correct answer: Financial loss, contractual rights waiver, and potential favoritism or conflict of interest
Failure to enforce SLA penalties risks financial loss, may legally waive contractual rights, and can indicate undisclosed conflicts of interest.
Question 3: An auditor reviewing capital project management finds that a $5M construction project has no change order log, and the final cost was $7.2M. What is the primary audit finding?
- The project cost overrun itself is the finding
- Lack of change order controls, preventing proper authorization and tracking of scope/cost changes (Correct answer)
- The project manager exceeded authority
- The budget was inadequately set at project initiation
Correct answer: Lack of change order controls, preventing proper authorization and tracking of scope/cost changes
The absence of a change order log is a control deficiency that prevented proper oversight of the $2.2M cost increase.
Question 4: An auditor is assessing a company's business continuity plan (BCP). They find that the plan was last tested 18 months ago and key personnel listed have since left the company. What is the most critical risk?
- The plan does not meet ISO 22301 certification requirements
- Critical recovery roles may be unfilled during an actual disruption, rendering the plan ineffective (Correct answer)
- The company's insurance coverage may be voided
- Testing frequency is below regulatory minimum
Correct answer: Critical recovery roles may be unfilled during an actual disruption, rendering the plan ineffective
An untested, outdated BCP with departed key personnel creates a high risk that recovery procedures will fail when actually needed.
Question 5: An auditor reviewing a bank's loan approval process finds that the same officer who approves loans also performs the annual credit reviews. What control deficiency does this represent?
- Insufficient training for loan officers
- Lack of segregation of duties, creating a self-review threat (Correct answer)
- Non-compliance with loan-to-value ratio requirements
- Inadequate loan documentation standards
Correct answer: Lack of segregation of duties, creating a self-review threat
Allowing the originating officer to also conduct credit reviews eliminates an independent check on the quality of lending decisions.
Question 6: During an environmental compliance audit, an auditor discovers that hazardous waste disposal records for one facility are missing for a six-month period. Management believes the records were lost in a system migration. What should the auditor recommend?
- Reconstruct records from vendor invoices and employee memory
- Assess regulatory notification obligations and implement controls to prevent future record loss during migrations (Correct answer)
- Report the facility to the EPA immediately
- Close the finding since the records were not intentionally destroyed
Correct answer: Assess regulatory notification obligations and implement controls to prevent future record loss during migrations
Missing compliance records may trigger mandatory regulatory notification obligations, and the auditor should address both the current exposure and prevent recurrence.
Question 7: An auditor finds that a company's travel and entertainment policy allows business class travel for flights over four hours but that 60% of business class tickets sampled were for shorter flights. What type of test would most efficiently identify the scope of this issue?
- Re-interview the employees who took the flights
- Data analytics on the full travel expense population to flag all flights under four hours booked as business class (Correct answer)
- A judgmental sample of the highest-spending executives
- A random sample of 25 additional expense reports
Correct answer: Data analytics on the full travel expense population to flag all flights under four hours booked as business class
Data analytics applied to the full population allows the auditor to quantify the complete scope of the policy violation efficiently.
An internal audit team is conducting a follow-up on prior audit recommendations.
They find that management implemented a compensating control instead of the originally recommended primary control.
What should the auditor conclude?