CFP Auditing Principles & Procedures 2 — Questions and Answers
Question 1: Which audit procedure is most effective for detecting unauthorized access to a fintech platform's core banking APIs?
- Reconciliation of ledger balances
- Review of API gateway access logs and OAuth token issuance records (Correct answer)
- Physical inspection of server hardware
- Confirmation of customer account balances
Correct answer: Review of API gateway access logs and OAuth token issuance records
API gateway logs and OAuth token records provide a direct trail of who accessed which endpoints and when, making them the primary evidence for detecting unauthorized access.
Question 2: In a fintech audit, 'control risk' is best described as:
- The risk that auditors will not detect a misstatement
- The risk that internal controls will fail to prevent or detect material misstatements (Correct answer)
- The inherent vulnerability of financial technology to cyber threats
- The probability that sampling will produce an unrepresentative result
Correct answer: The risk that internal controls will fail to prevent or detect material misstatements
Control risk is the probability that a client's internal controls will not prevent or detect a material misstatement, regardless of auditor procedures.
Question 3: A fintech auditor is assessing the adequacy of a company's disaster recovery plan. Which procedure provides the most reliable evidence?
- Reviewing the written DR policy document
- Interviewing the IT manager about recovery objectives
- Observing a live DR drill and comparing results to RTO/RPO targets (Correct answer)
- Inspecting certificates of completion from past DR training sessions
Correct answer: Observing a live DR drill and comparing results to RTO/RPO targets
Observing a live drill and comparing outcomes against established RTO/RPO targets provides direct, independent evidence of whether controls operate as designed.
Question 4: Which of the following is an example of a substantive analytical procedure in a fintech audit?
- Testing the segregation of duties in transaction approval workflows
- Comparing month-over-month payment transaction volumes to identify anomalies (Correct answer)
- Interviewing compliance officers about AML policy updates
- Reviewing board minutes for approval of new product launches
Correct answer: Comparing month-over-month payment transaction volumes to identify anomalies
Substantive analytical procedures involve comparing financial or operational data to expected patterns to identify material misstatements or anomalies.
Question 5: Under PCAOB standards, when is it appropriate for an auditor to use the work of an internal audit function?
- Never — external auditors must independently perform all procedures
- When the internal audit function has sufficient competence and objectivity, and the work is relevant (Correct answer)
- Only when the SEC grants a specific exemption
- Whenever the client requests cost savings on the engagement
Correct answer: When the internal audit function has sufficient competence and objectivity, and the work is relevant
PCAOB AS 2605 permits external auditors to use internal audit work when they evaluate and conclude that the internal auditors have sufficient competence and objectivity.
Question 6: A robo-advisory platform generates automated investment recommendations. From an audit perspective, which risk deserves the highest attention?
- The physical security of the data center housing the algorithm
- Algorithm bias or errors causing systematically unsuitable recommendations to clients (Correct answer)
- The brand reputation of the cloud provider used
- Variability in UI design across different devices
Correct answer: Algorithm bias or errors causing systematically unsuitable recommendations to clients
Algorithmic errors or bias can cause widespread harm at scale, creating material misstatement risk in disclosures and regulatory compliance failures across the entire client base.
Question 7: Which type of audit opinion would be issued if a fintech company's financial statements contain a material misstatement that is pervasive?
- Unmodified (clean) opinion
- Qualified opinion
- Adverse opinion (Correct answer)
- Disclaimer of opinion
Correct answer: Adverse opinion
An adverse opinion is issued when misstatements are both material and pervasive, meaning the financial statements as a whole do not present fairly.
Which audit procedure is most effective for detecting unauthorized access to a fintech platform's core banking APIs?