CFC Internal Controls & Compliance 2 — Questions and Answers
Question 1: Under COSO's Internal Control framework, which component addresses an organization's culture and values that influence employee behavior?
- Risk Assessment
- Control Environment (Correct answer)
- Monitoring Activities
- Information & Communication
Correct answer: Control Environment
The Control Environment is the foundation of the COSO framework and encompasses the tone at the top, ethical values, and organizational culture.
Question 2: A company discovers that a single employee can both approve purchase orders and process vendor payments. This represents a failure in which control principle?
- Authorization controls
- Segregation of duties (Correct answer)
- Physical access controls
- Reconciliation controls
Correct answer: Segregation of duties
Segregation of duties requires that no single individual can both initiate and approve a transaction to prevent fraud and errors.
Question 3: Which SOX section specifically requires management to assess and report on the effectiveness of internal controls over financial reporting?
- Section 201
- Section 302
- Section 404 (Correct answer)
- Section 806
Correct answer: Section 404
SOX Section 404 mandates that management assess and report on the effectiveness of internal controls over financial reporting, with external auditor attestation for large accelerated filers.
Question 4: When evaluating the design effectiveness of an internal control, an auditor is primarily concerned with:
- Whether the control has been operating for at least one year
- Whether the control, if operating as designed, would prevent or detect material misstatements (Correct answer)
- Whether employees can describe the control procedures
- Whether the control is documented in the policy manual
Correct answer: Whether the control, if operating as designed, would prevent or detect material misstatements
Design effectiveness asks whether the control, if operating as intended, is capable of preventing or detecting material misstatements.
Question 5: A company implements a detective control that compares actual expenses to budgeted amounts and investigates significant variances. This is best described as:
- A preventive control
- A variance analysis control (Correct answer)
- A budget control
- A corrective control
Correct answer: A variance analysis control
Variance analysis is a detective control because it identifies discrepancies after they have occurred rather than preventing them.
Question 6: The PCAOB's auditing standards for internal controls require external auditors to evaluate which of the following when assessing a company's ICFR?
- Only entity-level controls
- Only transaction-level controls
- Both entity-level and transaction-level controls (Correct answer)
- Only IT general controls
Correct answer: Both entity-level and transaction-level controls
PCAOB standards require auditors to evaluate both entity-level controls and transaction-level controls as part of an integrated audit of ICFR.
Question 7: Which of the following best describes a 'material weakness' in internal controls over financial reporting?
- A deficiency where the probability of a material misstatement is remote
- A deficiency or combination of deficiencies where there is a reasonable possibility of a material misstatement not being prevented or detected (Correct answer)
- Any control deficiency identified by management
- A deficiency that resulted in an actual financial restatement
Correct answer: A deficiency or combination of deficiencies where there is a reasonable possibility of a material misstatement not being prevented or detected
A material weakness is defined as a deficiency where there is a reasonable possibility (more than remote) that a material misstatement will not be prevented or detected on a timely basis.
Under COSO's Internal Control framework, which component addresses an organization's culture and values that influence employee behavior?