Certified Management Accountant Internal Controls 2 — Questions and Answers
Question 1: Which type of control is designed to detect errors or fraud after they have already occurred?
- Preventive control
- Detective control (Correct answer)
- Corrective control
- Directive control
Correct answer: Detective control
Detective controls identify errors or irregularities that have already occurred, such as reconciliations and audits.
Question 2: The Foreign Corrupt Practices Act (FCPA) requires US public companies to maintain books and records that:
- Are audited annually by the PCAOB
- Accurately and fairly reflect transactions and dispositions of assets (Correct answer)
- Are stored in the US for at least 10 years
- Are reviewed quarterly by the audit committee
Correct answer: Accurately and fairly reflect transactions and dispositions of assets
The FCPA's accounting provisions require companies to keep accurate books and records and maintain adequate internal controls.
Question 3: A company discovers that a single employee has been both approving purchase orders and signing checks to vendors. This is a failure of:
- Physical safeguards
- Segregation of duties (Correct answer)
- Documentation procedures
- Independent verification
Correct answer: Segregation of duties
Segregation of duties requires that no single person controls authorization, recording, and custody of an asset across a transaction.
Question 4: Under the COSO framework, which component involves policies and procedures that help ensure management directives are executed?
- Control environment
- Risk assessment
- Control activities (Correct answer)
- Monitoring
Correct answer: Control activities
Control activities are the policies and procedures that ensure management's risk responses are carried out.
Question 5: An inherent limitation of internal controls is that they can be overridden by:
- External auditors
- Management (Correct answer)
- The audit committee
- Regulatory agencies
Correct answer: Management
Management override is a key inherent limitation because management has the authority to bypass established controls.
Question 6: Which control technique involves reviewing system access logs to identify unauthorized data access attempts?
- Application control
- General IT control
- Monitoring control (Correct answer)
- Physical access control
Correct answer: Monitoring control
Reviewing access logs is a monitoring control that detects potential unauthorized activities after the fact.
Question 7: A 'compensating control' is best described as:
- A control that prevents employee compensation fraud
- An alternative control that mitigates risk when a primary control is absent (Correct answer)
- A control that compensates for prior period errors
- A detective control used after a material weakness is found
Correct answer: An alternative control that mitigates risk when a primary control is absent
Compensating controls are alternative measures implemented when a standard control cannot be applied, providing equivalent risk mitigation.
Which type of control is designed to detect errors or fraud after they have already occurred?