Certified Public Accountant Risk Assessment & Management 3 — Questions and Answers
Question 1: During an audit, an auditor determines that inherent risk and control risk are both high. The auditor should:
- Increase detection risk to compensate
- Set detection risk at a low level by expanding substantive testing (Correct answer)
- Reduce the scope of the audit
- Issue an adverse opinion without further testing
Correct answer: Set detection risk at a low level by expanding substantive testing
When inherent and control risk are high, auditors must set detection risk low, which requires more extensive substantive audit procedures.
Question 2: Which of the following is an example of a key risk indicator (KRI)?
- Net income for the quarter
- Number of failed system login attempts per day (Correct answer)
- Total assets on the balance sheet
- Gross margin percentage
Correct answer: Number of failed system login attempts per day
Failed login attempts is a KRI because it signals potential cybersecurity threats before they materialize into actual incidents.
Question 3: A company outsources its payroll processing to a third-party vendor. Which risk does the company primarily take on?
- Liquidity risk
- Vendor/third-party risk (Correct answer)
- Market risk
- Systematic risk
Correct answer: Vendor/third-party risk
Outsourcing critical functions like payroll creates vendor or third-party risk, where the company depends on an external party's performance and controls.
Question 4: The risk that a counterparty will fail to fulfill its contractual obligations is called:
- Market risk
- Credit risk (Correct answer)
- Operational risk
- Liquidity risk
Correct answer: Credit risk
Credit risk is the possibility that a counterparty will default on its obligations, resulting in financial loss to the other party.
Question 5: Which internal control activity is most effective at preventing fraudulent journal entries from being recorded?
- Mandatory vacation policies
- Segregation of duties between journal entry preparation and approval (Correct answer)
- Physical safeguarding of assets
- Monthly bank reconciliations
Correct answer: Segregation of duties between journal entry preparation and approval
Segregation of duties ensures that the person who prepares a journal entry cannot also approve it, reducing the risk of unauthorized or fraudulent entries.
Question 6: An auditor's assessment of control risk at maximum means the auditor believes:
- Internal controls are highly effective and reliable
- Internal controls cannot be relied upon to prevent or detect misstatements (Correct answer)
- No substantive testing is required
- The entity has no material weaknesses
Correct answer: Internal controls cannot be relied upon to prevent or detect misstatements
Setting control risk at maximum means the auditor will not rely on internal controls and must rely entirely on substantive procedures to detect misstatements.
Question 7: Enterprise risk management (ERM) differs from traditional risk management primarily because ERM:
- Focuses exclusively on financial risks
- Takes a siloed, department-by-department approach
- Integrates risk management across the entire organization with strategic alignment (Correct answer)
- Is only applicable to publicly traded companies
Correct answer: Integrates risk management across the entire organization with strategic alignment
ERM provides a holistic, enterprise-wide view of risk that is integrated with strategic planning, unlike traditional approaches that manage risks in isolation.
During an audit, an auditor determines that inherent risk and control risk are both high.
The auditor should: