Certified Management Accountant Internal Controls 5 — Questions and Answers
Question 1: Which document formally defines the authority, responsibility, and organizational independence of the internal audit function?
- The audit committee charter
- The internal audit charter (Correct answer)
- The engagement letter
- The audit plan
Correct answer: The internal audit charter
The internal audit charter establishes the purpose, authority, and responsibility of the internal audit activity as approved by the board.
Question 2: A company allows its warehouse manager to also maintain the inventory records. Which fraud is this control weakness most likely to enable?
- Fictitious vendor fraud
- Inventory theft and concealment (Correct answer)
- Payroll diversion
- Financial statement overstatement
Correct answer: Inventory theft and concealment
When one person controls both physical custody and the records, they can steal inventory and alter records to conceal the theft.
Question 3: According to COSO, 'information and communication' as a component of internal control primarily ensures that:
- Financial statements are filed on time with regulators
- Relevant information is identified, captured, and communicated to enable control responsibilities (Correct answer)
- The IT department maintains system documentation
- Management reviews financial results quarterly
Correct answer: Relevant information is identified, captured, and communicated to enable control responsibilities
The information and communication component ensures that people get the right information at the right time to fulfill their control responsibilities.
Question 4: An independent bank reconciliation performed by someone with no cash handling duties is an example of a:
- Preventive control over cash disbursements
- Detective control with segregation of duties (Correct answer)
- Corrective control for prior period errors
- Directive control over cash receipts
Correct answer: Detective control with segregation of duties
Bank reconciliation detects discrepancies and errors, and performing it independently from cash handlers incorporates segregation of duties.
Question 5: The Committee of Sponsoring Organizations (COSO) was formed primarily in response to which event?
- The Enron and WorldCom accounting scandals
- The savings and loan crisis of the 1980s and the Treadway Commission report (Correct answer)
- The passage of Sarbanes-Oxley in 2002
- The global financial crisis of 2008
Correct answer: The savings and loan crisis of the 1980s and the Treadway Commission report
COSO was formed in 1985 to sponsor the Treadway Commission, which studied fraudulent financial reporting following the S&L crisis.
Question 6: Management's assessment of internal control over financial reporting under SOX Section 404 must be based on a recognized control framework such as:
- GAAP
- COSO Internal Control — Integrated Framework (Correct answer)
- ISO 9001
- PCAOB Auditing Standard No. 5
Correct answer: COSO Internal Control — Integrated Framework
SOX Section 404 requires management to use a suitable recognized framework, and the COSO framework is the most widely accepted standard in the US.
Question 7: Which concept describes the process of evaluating whether internal controls are present and functioning over time through both ongoing monitoring and separate evaluations?
- Control activities
- Risk assessment
- Monitoring (Correct answer)
- Control environment
Correct answer: Monitoring
Monitoring, the fifth COSO component, involves ongoing and periodic evaluations to determine whether controls are designed and operating effectively.
Which document formally defines the authority, responsibility, and organizational independence of the internal audit function?