Certified Internal Auditor Case Studies & Practical Application 5 — Questions and Answers
Question 1: An auditor finds that a nonprofit organization's board approved a $500,000 grant to a charity where the executive director serves as a board member, with no conflict of interest disclosure on record. What is the primary issue?
- The grant amount exceeds typical nonprofit giving limits
- An undisclosed conflict of interest that may violate the organization's governance policies and state nonprofit law (Correct answer)
- The board approval process lacked sufficient documentation
- The charity may not be a qualified 501(c)(3) recipient
Correct answer: An undisclosed conflict of interest that may violate the organization's governance policies and state nonprofit law
Failure to disclose and manage a board member's conflict of interest in grant decisions violates fiduciary duty and may constitute self-dealing under nonprofit law.
Question 2: During an operational audit of a hospital's medication dispensing, the auditor finds that controlled substances dispensed exceed physician orders by 12% at one unit. What should the auditor prioritize?
- Recommending a new medication management software system
- Investigating whether the discrepancy indicates diversion of controlled substances by staff (Correct answer)
- Auditing the physician ordering process for accuracy
- Expanding the scope to review all medication types
Correct answer: Investigating whether the discrepancy indicates diversion of controlled substances by staff
A consistent excess of controlled substances dispensed over physician orders is a primary indicator of drug diversion, a serious patient safety and legal issue.
Question 3: An auditor reviewing a company's third-party risk management program finds that 40% of critical vendors have never been assessed for financial stability or operational resilience. What is the correct audit conclusion?
- Third-party risk management is not the internal audit function's responsibility
- A material gap in vendor risk oversight that exposes the organization to unmitigated concentration and operational risks (Correct answer)
- The program is acceptable because 60% of critical vendors have been assessed
- Vendor financial assessments should be performed by the finance department, not audit
Correct answer: A material gap in vendor risk oversight that exposes the organization to unmitigated concentration and operational risks
Unassessed critical vendors represent unmitigated risks to the organization's operations and financial condition that the TPRM program should be capturing.
Question 4: An auditor is presenting a draft audit report to management. Management disputes a finding, arguing that the auditor misunderstood the control. After reviewing management's evidence, the auditor concludes the finding is valid. What is the appropriate action?
- Remove the finding to maintain a collaborative relationship with management
- Retain the finding but accurately reflect management's response and disagreement in the report (Correct answer)
- Escalate immediately to the audit committee without further discussion
- Retest the control before issuing the report
Correct answer: Retain the finding but accurately reflect management's response and disagreement in the report
IIA standards require that audit reports reflect the auditor's objective conclusions while also including management's responses, including disagreements.
Question 5: A company implements a new ERP system and the internal audit team is asked to assess implementation controls. The auditor finds that parallel testing was skipped due to go-live timeline pressure. What risk does this create?
- The ERP vendor may void the support contract
- Data migration errors and system configuration issues may not be detected before the system goes live, compromising data integrity (Correct answer)
- Staff training costs will increase post-implementation
- The ERP system may not integrate with existing applications
Correct answer: Data migration errors and system configuration issues may not be detected before the system goes live, compromising data integrity
Skipping parallel testing removes the primary detective control for identifying data migration errors and misconfigured processes before they affect production operations.
Question 6: An auditor assessing a construction company finds that project managers are authorizing their own subcontractor invoices and approving final project completion. What is the segregation of duties concern?
- Project managers may lack accounting expertise to review invoices
- A single individual controlling both invoice approval and completion sign-off removes checks against inflated billings or fictitious charges (Correct answer)
- Subcontractor invoices should be approved by the CFO
- Project completion should be certified by a licensed inspector
Correct answer: A single individual controlling both invoice approval and completion sign-off removes checks against inflated billings or fictitious charges
Combining invoice approval with project completion authorization gives project managers unchecked ability to approve payments for incomplete or fictitious work.
Question 7: An internal auditor discovers during fieldwork that a control tested as effective last year is now completely absent — the responsible employee left and the process was never reassigned. What does this situation illustrate about control environments?
- Last year's audit conclusions were incorrect and should be restated
- Controls dependent on specific individuals without succession planning are fragile and susceptible to breakdown when personnel change (Correct answer)
- The current audit should be immediately halted and reported as a crisis
- The former employee should be held responsible for the control failure
Correct answer: Controls dependent on specific individuals without succession planning are fragile and susceptible to breakdown when personnel change
Person-dependent controls without documented procedures or succession planning are a systemic fragility — personnel changes routinely cause them to collapse.
An auditor finds that a nonprofit organization's board approved a $500,000 grant to a charity where the executive director serves as a board member, with no conflict of interest disclosure on record.
What is the primary issue?