Certified Internal Auditor Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Under the Sarbanes-Oxley Act, which section requires management to assess and report on the effectiveness of internal controls over financial reporting?
- Section 302
- Section 404 (Correct answer)
- Section 409
- Section 802
Correct answer: Section 404
Section 404 of SOX requires management to assess internal control over financial reporting and requires the external auditor to attest to that assessment.
Question 2: The COSO Internal Control–Integrated Framework identifies how many components of internal control?
- Three
- Four
- Five (Correct answer)
- Seven
Correct answer: Five
COSO's framework includes five components: Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring Activities.
Question 3: Which regulatory body enforces compliance with the Bank Secrecy Act (BSA) requirements for financial institutions in the US?
- SEC
- PCAOB
- FinCEN (Correct answer)
- FASB
Correct answer: FinCEN
The Financial Crimes Enforcement Network (FinCEN) is the primary bureau administering and enforcing BSA compliance requirements.
Question 4: An internal auditor discovers that a company's compliance program lacks a formal process for employees to report violations anonymously. Which framework element is most deficient?
- Risk Assessment
- Control Activities
- Whistleblower Mechanisms (Correct answer)
- Tone at the Top
Correct answer: Whistleblower Mechanisms
An anonymous reporting mechanism (whistleblower hotline) is a fundamental element of an effective compliance program under DOJ/OIG guidance.
Question 5: Under GDPR, what is the maximum timeframe within which a data breach must be reported to the supervisory authority?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 6: The Foreign Corrupt Practices Act (FCPA) prohibits US companies from bribing which category of individuals?
- Foreign private sector employees
- Foreign government officials (Correct answer)
- Foreign competitors
- Foreign media representatives
Correct answer: Foreign government officials
The FCPA's anti-bribery provisions prohibit payments to foreign government officials to obtain or retain business.
Question 7: Which framework provides guidance specifically for enterprise risk management and is considered an extension of the COSO Internal Control framework?
- ISO 31000
- COSO ERM (Correct answer)
- Basel III
- COBIT
Correct answer: COSO ERM
COSO ERM (Enterprise Risk Management–Integrating with Strategy and Performance, 2017) extends COSO's internal control framework to address risk at an enterprise level.
Under the Sarbanes-Oxley Act, which section requires management to assess and report on the effectiveness of internal controls over financial reporting?