Risk Assessment & Management Flashcards
7 cards from real Certified Public Accountant practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
During an audit, an auditor determines that inherent risk and control risk are both high. The auditor should:
Answer: Set detection risk at a low level by expanding substantive testing
When inherent and control risk are high, auditors must set detection risk low, which requires more extensive substantive audit procedures.
Which of the following is an example of a key risk indicator (KRI)?
Answer: Number of failed system login attempts per day
Failed login attempts is a KRI because it signals potential cybersecurity threats before they materialize into actual incidents.
A company outsources its payroll processing to a third-party vendor. Which risk does the company primarily take on?
Answer: Vendor/third-party risk
Outsourcing critical functions like payroll creates vendor or third-party risk, where the company depends on an external party's performance and controls.
The risk that a counterparty will fail to fulfill its contractual obligations is called:
Answer: Credit risk
Credit risk is the possibility that a counterparty will default on its obligations, resulting in financial loss to the other party.
Which internal control activity is most effective at preventing fraudulent journal entries from being recorded?
Answer: Segregation of duties between journal entry preparation and approval
Segregation of duties ensures that the person who prepares a journal entry cannot also approve it, reducing the risk of unauthorized or fraudulent entries.
An auditor's assessment of control risk at maximum means the auditor believes:
Answer: Internal controls cannot be relied upon to prevent or detect misstatements
Setting control risk at maximum means the auditor will not rely on internal controls and must rely entirely on substantive procedures to detect misstatements.
Enterprise risk management (ERM) differs from traditional risk management primarily because ERM:
Answer: Integrates risk management across the entire organization with strategic alignment
ERM provides a holistic, enterprise-wide view of risk that is integrated with strategic planning, unlike traditional approaches that manage risks in isolation.