CFC Internal Controls & Compliance 5 — Questions and Answers
Question 1: A controller is evaluating whether a compensating control adequately offsets a control deficiency. Which criterion is MOST important in this evaluation?
- The compensating control must be performed by a senior employee
- The compensating control must achieve the same control objective as the missing or deficient control (Correct answer)
- The compensating control must be automated rather than manual
- The compensating control must have been in place for at least 12 months
Correct answer: The compensating control must achieve the same control objective as the missing or deficient control
A compensating control must address the same risk and achieve the same control objective as the deficient control to be considered an effective substitute.
Question 2: Under GDPR compliance requirements for U.S. companies doing business with EU customers, which role is responsible for overseeing data protection activities and serving as the point of contact with supervisory authorities?
- Chief Compliance Officer
- Chief Information Security Officer
- Data Protection Officer (Correct answer)
- Chief Privacy Officer
Correct answer: Data Protection Officer
GDPR requires certain organizations to appoint a Data Protection Officer (DPO) who oversees data protection strategy, ensures compliance, and acts as liaison with supervisory authorities.
Question 3: A company's internal controls require that all journal entries above $50,000 have supporting documentation and a second reviewer's approval. An employee posts a $49,999 entry without documentation to avoid review. This is an example of:
- A control environment weakness
- Control circumvention through threshold manipulation (Correct answer)
- An IT application control failure
- A reconciliation control failure
Correct answer: Control circumvention through threshold manipulation
Structuring transactions just below control thresholds to avoid triggering required reviews is a form of control circumvention that exploits rigid threshold-based controls.
Question 4: Which COSO principle states that an organization should identify and analyze risks to the achievement of its objectives as a basis for determining how risks should be managed?
- Principle 6 — Specifies Suitable Objectives
- Principle 7 — Identifies and Analyzes Risk (Correct answer)
- Principle 8 — Assesses Fraud Risk
- Principle 9 — Identifies and Analyzes Significant Change
Correct answer: Principle 7 — Identifies and Analyzes Risk
COSO Principle 7 under the Risk Assessment component requires organizations to identify and analyze risks relevant to achieving objectives to determine how they should be managed.
Question 5: An organization's compliance program includes a helpline that allows employees to report violations anonymously. Under SOX, which provision requires public companies to establish such procedures?
- SOX Section 301 (Correct answer)
- SOX Section 302
- SOX Section 401
- SOX Section 906
Correct answer: SOX Section 301
SOX Section 301 requires audit committees of public companies to establish procedures for confidential, anonymous submission of employee concerns regarding accounting or auditing matters.
Question 6: A financial controller at a public company certifies quarterly financial statements under SOX. Which statement best describes their personal liability?
- Liability is limited to the company's internal counsel
- Knowingly certifying false statements can result in criminal penalties up to $5 million and 20 years imprisonment (Correct answer)
- Personal liability is capped at the controller's annual salary
- Liability only arises if the external auditor also certified the statements
Correct answer: Knowingly certifying false statements can result in criminal penalties up to $5 million and 20 years imprisonment
SOX Section 906 imposes criminal penalties on officers who knowingly certify materially false financial reports, including fines up to $5 million and imprisonment up to 20 years.
Question 7: Which of the following best describes the purpose of a 'control self-assessment' (CSA) program?
- An external auditor's independent evaluation of controls
- A process where business units evaluate and report on the effectiveness of their own controls (Correct answer)
- The SEC's annual review of a company's compliance program
- A risk management tool used exclusively by internal audit
Correct answer: A process where business units evaluate and report on the effectiveness of their own controls
Control self-assessment (CSA) is a methodology where management and process owners assess the effectiveness of controls within their own areas of responsibility.
A controller is evaluating whether a compensating control adequately offsets a control deficiency.
Which criterion is MOST important in this evaluation?