CFC Internal Controls & Compliance 3 — Questions and Answers
Question 1: An organization's internal audit function discovers that IT access controls allow users to override journal entries without a secondary approval. This is an example of which type of control gap?
- Compensating control gap
- IT general control weakness
- Application control deficiency (Correct answer)
- Change management failure
Correct answer: Application control deficiency
Application controls are controls built directly into software applications, and the ability to override journal entries without approval is an application-level control deficiency.
Question 2: Under the FCPA (Foreign Corrupt Practices Act), what is required of issuers regarding their books and records?
- Records must be stored on U.S. servers only
- Books must accurately reflect transactions and assets in reasonable detail (Correct answer)
- All foreign payments must be pre-approved by the SEC
- Financial records must be audited quarterly
Correct answer: Books must accurately reflect transactions and assets in reasonable detail
The FCPA's books and records provision requires issuers to keep records that accurately and fairly reflect transactions and asset dispositions in reasonable detail.
Question 3: A financial controller implements a monthly bank reconciliation process. Which control objective does this primarily serve?
- Authorization
- Completeness and accuracy of cash balances (Correct answer)
- Safeguarding of physical assets
- Compliance with tax regulations
Correct answer: Completeness and accuracy of cash balances
Bank reconciliations are detective controls that verify the completeness and accuracy of recorded cash transactions by comparing book balances to bank statements.
Question 4: When a company relies on a third-party service organization to process payroll, management should obtain which report to understand the controls at that organization?
- An SAS 70 report
- A SOC 1 Type II report (Correct answer)
- A SOC 2 Type I report
- An ISAE 3402 report
Correct answer: A SOC 1 Type II report
A SOC 1 Type II report (formerly SAS 70) evaluates the design and operating effectiveness of controls at a service organization relevant to user entities' financial reporting.
Question 5: Which of the following control activities is MOST effective at preventing fraudulent disbursements?
- Monthly expense report reviews by department heads
- Dual signatures required for checks above a materiality threshold (Correct answer)
- Annual audits of the accounts payable ledger
- Quarterly reconciliation of vendor master files
Correct answer: Dual signatures required for checks above a materiality threshold
Requiring dual signatures for large disbursements is a preventive control that stops unauthorized payments before they are made.
Question 6: The Committee of Sponsoring Organizations (COSO) ERM framework expands on internal controls by incorporating which additional concept?
- Financial reporting accuracy
- Objective setting and risk appetite (Correct answer)
- Segregation of duties requirements
- External audit coordination
Correct answer: Objective setting and risk appetite
COSO ERM adds enterprise-wide risk management concepts including objective setting, risk appetite, and portfolio view of risk, which extend beyond the internal control framework.
Question 7: A significant deficiency in internal controls differs from a material weakness primarily in:
- The type of control that failed
- The magnitude of the potential misstatement (Correct answer)
- The department where the deficiency was found
- Whether it was identified by internal or external auditors
Correct answer: The magnitude of the potential misstatement
A significant deficiency is less severe than a material weakness — both represent control deficiencies, but a material weakness involves a higher likelihood and magnitude of potential misstatement.
An organization's internal audit function discovers that IT access controls allow users to override journal entries without a secondary approval.
This is an example of which type of control gap?