← All CFA Flashcard Decks

Internal Control Evaluation Flashcards

7 cards from real CFA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Internal Control Evaluation flashcards as text
  1. A company requires that two senior officers co-sign wire transfers exceeding $100,000. This is an example of which type of control activity?

    Answer: Authorization control requiring dual approval

    Dual authorization controls require approval by more than one authorized individual before a high-risk transaction can be executed.

  2. Which scenario best illustrates the concept of 'control override' in the context of fraud?

    Answer: A CFO instructs the accounting team to record a transaction outside the normal journal entry approval workflow

    Control override occurs when someone in authority deliberately bypasses established control procedures, as when a CFO circumvents the normal approval workflow.

  3. Which element of the fraud triangle is most directly addressed by strong internal controls?

    Answer: Opportunity

    Internal controls primarily reduce opportunity by limiting access, requiring authorization, and creating detection mechanisms that make fraud more difficult to commit.

  4. During an internal control review, an auditor finds that user access rights are never removed when employees change roles or leave the company. This is best described as:

    Answer: An access control deficiency creating excessive privilege accumulation

    Failure to remove or update access rights leads to privilege accumulation, where users retain permissions beyond what their current role requires, increasing fraud risk.

  5. Which type of audit procedure is MOST effective for evaluating the design adequacy of an internal control?

    Answer: Walkthrough of the process from initiation to recording

    A walkthrough traces a transaction through the entire process, allowing the auditor to observe and assess whether the control is appropriately designed to address the relevant risk.

  6. A purchasing manager approves invoices from a company in which her spouse is a silent partner. Which internal control would most likely detect this?

    Answer: Mandatory conflict of interest disclosure and review process

    A conflict of interest disclosure policy requires employees to reveal related-party relationships, which would surface the undisclosed connection to the vendor.

  7. Under SOX Section 404, management is required to:

    Answer: Assess and report on the effectiveness of internal control over financial reporting

    SOX Section 404 requires management to assess internal control over financial reporting (ICFR) effectiveness and for the external auditor to attest to that assessment.