CFA Internal Control Evaluation 3 — Questions and Answers
Question 1: Which control technique is specifically designed to detect unauthorized changes to a computer program after it is deployed to production?
- Data encryption at rest
- Change management logs and version control comparison (Correct answer)
- Two-factor authentication for system access
- Periodic password resets for all IT users
Correct answer: Change management logs and version control comparison
Change management logs and version control allow auditors to compare current code against approved baselines, detecting unauthorized modifications.
Question 2: A fraud examiner assesses the risk that management override of controls could occur. This risk is considered unique because:
- Management lacks knowledge of how internal controls work
- Management has the authority and access to circumvent controls they themselves designed (Correct answer)
- External auditors are responsible for preventing management override
- Lower-level employees typically have more system access than managers
Correct answer: Management has the authority and access to circumvent controls they themselves designed
Management override is uniquely dangerous because those with authority to design controls also have the ability to bypass them, making standard controls ineffective against it.
Question 3: In reviewing an accounts receivable process, which red flag suggests that receivables may be overstated to conceal a cash misappropriation scheme?
- Increasing days sales outstanding (DSO) with a growing number of disputed accounts (Correct answer)
- A consistent write-off rate maintained over several years
- Customers consistently paying within their credit terms
- A declining trend in total receivables as the business grows
Correct answer: Increasing days sales outstanding (DSO) with a growing number of disputed accounts
Rising DSO and disputed accounts may indicate that cash collected from customers is being pocketed while fictitious or inflated receivables are recorded to cover the theft.
Question 4: Which COSO Internal Control component directly addresses the process of identifying and analyzing risks to achieving objectives?
- Control Environment
- Control Activities
- Risk Assessment (Correct answer)
- Monitoring Activities
Correct answer: Risk Assessment
Risk Assessment is the COSO component where organizations identify, analyze, and respond to risks relevant to achieving their objectives.
Question 5: An employee is able to create new employee records in the HR system AND approve payroll runs. This control gap most directly enables which fraud scheme?
- Ghost employee fraud (Correct answer)
- Skimming cash receipts
- Inflating expense reimbursements
- Bid-rigging in procurement
Correct answer: Ghost employee fraud
The ability to add fictitious employees and then approve payroll disbursements enables ghost employee fraud, where paychecks are issued to non-existent workers.
Question 6: Which of the following is the PRIMARY purpose of a whistleblower hotline as an internal control?
- To replace the need for internal auditors
- To provide a confidential channel for reporting suspected fraud or misconduct (Correct answer)
- To collect employee grievances about working conditions
- To satisfy regulatory filing requirements for public companies
Correct answer: To provide a confidential channel for reporting suspected fraud or misconduct
A whistleblower hotline's primary purpose is to give employees a confidential, often anonymous, means to report suspected fraud or policy violations.
Question 7: The concept of 'reasonable assurance' in internal control means that:
- Internal controls guarantee the complete prevention and detection of all fraud
- Controls are designed to reduce risk to an acceptably low level, not eliminate it entirely (Correct answer)
- Only material risks need to be controlled, and immaterial ones are ignored
- Management is personally liable for any fraud that occurs despite controls
Correct answer: Controls are designed to reduce risk to an acceptably low level, not eliminate it entirely
Reasonable assurance acknowledges that no control system is perfect; controls aim to reduce risk to an acceptable level because absolute assurance is not achievable or cost-effective.
Which control technique is specifically designed to detect unauthorized changes to a computer program after it is deployed to production?