Certified Management Accountant Internal Controls 4 — Questions and Answers
Question 1: Which risk response strategy involves transferring the financial consequences of a risk to a third party?
- Risk avoidance
- Risk reduction
- Risk sharing (Correct answer)
- Risk acceptance
Correct answer: Risk sharing
Risk sharing (or transfer) moves the financial impact of a risk to another party, such as through insurance or outsourcing.
Question 2: Under the COSO Enterprise Risk Management (ERM) framework, 'risk appetite' is defined as:
- The maximum loss a company can absorb before insolvency
- The amount of risk an entity is willing to accept in pursuit of value (Correct answer)
- The probability that a control will fail
- The residual risk after controls are applied
Correct answer: The amount of risk an entity is willing to accept in pursuit of value
Risk appetite is the broad-based amount of risk an organization is willing to pursue or retain while pursuing its strategy.
Question 3: Password complexity requirements, automatic logoffs, and encryption are all examples of:
- Application controls
- Physical access controls
- Logical access controls (Correct answer)
- Detective controls
Correct answer: Logical access controls
Logical access controls restrict access to systems and data through software-based mechanisms like passwords and encryption.
Question 4: A company processes payroll in-house. Which control best prevents a fictitious employee from being added to payroll?
- Reconciling payroll expense to the general ledger monthly
- Requiring HR and payroll to be separate departments that both authorize new hires (Correct answer)
- Distributing checks in person by someone independent of payroll preparation
- Reviewing the payroll register after each pay period
Correct answer: Requiring HR and payroll to be separate departments that both authorize new hires
Separating HR (authorization of employees) from payroll (processing of payments) prevents a single person from creating and paying fictitious employees.
Question 5: When assessing internal controls, 'residual risk' refers to:
- Risk that remains after management has implemented controls (Correct answer)
- The initial risk before any controls are considered
- Risk transferred to a third party
- The total of all identified risks in a process
Correct answer: Risk that remains after management has implemented controls
Residual risk is the remaining exposure after management applies controls to the inherent risk of a process or activity.
Question 6: Which of the following is the primary objective of a whistleblower hotline as an internal control?
- Replacing the internal audit function
- Providing an anonymous channel for reporting suspected fraud or misconduct (Correct answer)
- Satisfying external audit requirements for SOX compliance
- Detecting errors in financial statement preparation
Correct answer: Providing an anonymous channel for reporting suspected fraud or misconduct
Whistleblower hotlines give employees a confidential way to report suspected violations without fear of retaliation, supporting the monitoring environment.
Question 7: The internal audit function contributes to internal control primarily by:
- Designing and implementing controls for management
- Providing independent assurance that controls are functioning effectively (Correct answer)
- Taking responsibility for preventing all financial fraud
- Replacing external auditors for SOX compliance purposes
Correct answer: Providing independent assurance that controls are functioning effectively
Internal audit provides independent, objective assurance to management and the board that controls are adequate and operating effectively.
Which risk response strategy involves transferring the financial consequences of a risk to a third party?