Certified Internal Auditor Case Studies & Practical Application 4 — Questions and Answers
Question 1: An internal auditor learns through an anonymous tip that the CFO may be manipulating revenue recognition. The CAE informs the board audit committee chair privately. What is the most appropriate next step?
- Proceed with a standard financial audit of the revenue cycle
- The audit committee should engage outside counsel and forensic auditors to investigate independently of management (Correct answer)
- The CAE should confront the CFO directly with the allegation
- File an SEC whistleblower report on behalf of the organization
Correct answer: The audit committee should engage outside counsel and forensic auditors to investigate independently of management
Allegations involving senior management require independent investigation under the audit committee's direction, typically with outside experts, to avoid conflicts of interest.
Question 2: An auditor is evaluating a company's anti-money laundering (AML) program and finds that 200 currency transaction reports (CTRs) were filed late over the past year. What is the primary concern?
- The filing system needs a software upgrade
- Regulatory non-compliance that may result in significant fines and potential criminal liability (Correct answer)
- CTR filing staff need additional training
- The late filings should be restated with corrected data
Correct answer: Regulatory non-compliance that may result in significant fines and potential criminal liability
Late CTR filings violate Bank Secrecy Act requirements and can result in substantial civil and criminal penalties for the organization.
Question 3: A manufacturing company's auditor reviews inventory controls and finds that cycle count adjustments average 8% of inventory value per month. What does this pattern indicate?
- The cycle count program is working effectively by catching discrepancies
- Significant control weaknesses in receiving, storage, or recording that require root cause investigation (Correct answer)
- Normal inventory shrinkage within acceptable industry ranges
- The inventory valuation method needs to be changed to FIFO
Correct answer: Significant control weaknesses in receiving, storage, or recording that require root cause investigation
Persistent high-value cycle count adjustments signal systematic control failures in inventory management processes, not a healthy counting program.
Question 4: During a cybersecurity audit, an auditor finds that 35 former employees still have active network credentials 90 days after termination. What is the most significant risk?
- Violation of password complexity standards
- Unauthorized access to systems and data by individuals with no legitimate business need (Correct answer)
- License compliance issues with user-based software
- Audit trail gaps from unattributed logins
Correct answer: Unauthorized access to systems and data by individuals with no legitimate business need
Active credentials for terminated employees represent an immediate unauthorized access risk and are a common source of insider threat and data breaches.
Question 5: An auditor reviewing a government contractor's cost accounting finds that the company is allocating 100% of executive salaries to government contracts. The executives also work on commercial contracts. What is the primary concern?
- The salaries exceed the compensation cap under FAR
- Unallowable cost allocation that inflates charges to the government by attributing costs not exclusively incurred for government work (Correct answer)
- Executive compensation is not an allowable cost category under any government contract
- The allocation method was not pre-approved by the DCAA
Correct answer: Unallowable cost allocation that inflates charges to the government by attributing costs not exclusively incurred for government work
Allocating shared costs entirely to government contracts when executives support commercial work violates cost accounting standards and FAR, constituting potential false claims.
Question 6: An internal auditor is observing a cash count at a retail branch. The branch manager asks the auditor to initial a preliminary count sheet before the final reconciliation is done. What should the auditor do?
- Initial the sheet to be cooperative with branch staff
- Decline to initial and explain that the auditor is an observer, not a participant, to maintain independence (Correct answer)
- Leave the cash count and report the request as an interference
- Initial only after confirming the count matches the register
Correct answer: Decline to initial and explain that the auditor is an observer, not a participant, to maintain independence
Initialing documents makes the auditor a participant rather than an independent observer, impairing objectivity and creating an appearance of complicity.
Question 7: A financial services firm's auditor finds that traders are setting their own position limits and there is no independent risk management review. What is the most significant risk this control gap creates?
- Traders may not understand their own risk appetite
- Traders can take on excessive risk without organizational oversight, potentially leading to catastrophic losses similar to rogue trading events (Correct answer)
- The firm may not meet Basel III capital requirements
- Position data may be inaccurate in the general ledger
Correct answer: Traders can take on excessive risk without organizational oversight, potentially leading to catastrophic losses similar to rogue trading events
Self-set position limits without independent oversight remove a critical risk management control and create conditions for large unauthorized risk exposures.
An internal auditor learns through an anonymous tip that the CFO may be manipulating revenue recognition.
The CAE informs the board audit committee chair privately.
What is the most appropriate next step?