← All Certified Public Accountant Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real Certified Public Accountant practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. During an audit, an auditor determines that inherent risk and control risk are both high. The auditor should:

    Answer: Set detection risk at a low level by expanding substantive testing

    When inherent and control risk are high, auditors must set detection risk low, which requires more extensive substantive audit procedures.

  2. Which of the following is an example of a key risk indicator (KRI)?

    Answer: Number of failed system login attempts per day

    Failed login attempts is a KRI because it signals potential cybersecurity threats before they materialize into actual incidents.

  3. A company outsources its payroll processing to a third-party vendor. Which risk does the company primarily take on?

    Answer: Vendor/third-party risk

    Outsourcing critical functions like payroll creates vendor or third-party risk, where the company depends on an external party's performance and controls.

  4. The risk that a counterparty will fail to fulfill its contractual obligations is called:

    Answer: Credit risk

    Credit risk is the possibility that a counterparty will default on its obligations, resulting in financial loss to the other party.

  5. Which internal control activity is most effective at preventing fraudulent journal entries from being recorded?

    Answer: Segregation of duties between journal entry preparation and approval

    Segregation of duties ensures that the person who prepares a journal entry cannot also approve it, reducing the risk of unauthorized or fraudulent entries.

  6. An auditor's assessment of control risk at maximum means the auditor believes:

    Answer: Internal controls cannot be relied upon to prevent or detect misstatements

    Setting control risk at maximum means the auditor will not rely on internal controls and must rely entirely on substantive procedures to detect misstatements.

  7. Enterprise risk management (ERM) differs from traditional risk management primarily because ERM:

    Answer: Integrates risk management across the entire organization with strategic alignment

    ERM provides a holistic, enterprise-wide view of risk that is integrated with strategic planning, unlike traditional approaches that manage risks in isolation.