Internal Control Evaluation Flashcards
7 cards from real CFA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Internal Control Evaluation flashcards as text
Which control technique is specifically designed to detect unauthorized changes to a computer program after it is deployed to production?
Answer: Change management logs and version control comparison
Change management logs and version control allow auditors to compare current code against approved baselines, detecting unauthorized modifications.
A fraud examiner assesses the risk that management override of controls could occur. This risk is considered unique because:
Answer: Management has the authority and access to circumvent controls they themselves designed
Management override is uniquely dangerous because those with authority to design controls also have the ability to bypass them, making standard controls ineffective against it.
In reviewing an accounts receivable process, which red flag suggests that receivables may be overstated to conceal a cash misappropriation scheme?
Answer: Increasing days sales outstanding (DSO) with a growing number of disputed accounts
Rising DSO and disputed accounts may indicate that cash collected from customers is being pocketed while fictitious or inflated receivables are recorded to cover the theft.
Which COSO Internal Control component directly addresses the process of identifying and analyzing risks to achieving objectives?
Answer: Risk Assessment
Risk Assessment is the COSO component where organizations identify, analyze, and respond to risks relevant to achieving their objectives.
An employee is able to create new employee records in the HR system AND approve payroll runs. This control gap most directly enables which fraud scheme?
Answer: Ghost employee fraud
The ability to add fictitious employees and then approve payroll disbursements enables ghost employee fraud, where paychecks are issued to non-existent workers.
Which of the following is the PRIMARY purpose of a whistleblower hotline as an internal control?
Answer: To provide a confidential channel for reporting suspected fraud or misconduct
A whistleblower hotline's primary purpose is to give employees a confidential, often anonymous, means to report suspected fraud or policy violations.
The concept of 'reasonable assurance' in internal control means that:
Answer: Controls are designed to reduce risk to an acceptably low level, not eliminate it entirely
Reasonable assurance acknowledges that no control system is perfect; controls aim to reduce risk to an acceptable level because absolute assurance is not achievable or cost-effective.