CFP Auditing Principles & Procedures 3 — Questions and Answers
Question 1: In auditing a cryptocurrency exchange, which procedure is most appropriate for verifying the existence of digital assets held in custody?
- Confirming balances directly with the exchange's banking partners
- Independently verifying wallet addresses on the public blockchain and reconciling to the ledger (Correct answer)
- Inspecting the physical servers that store private keys
- Reviewing insurance certificates for the crypto holdings
Correct answer: Independently verifying wallet addresses on the public blockchain and reconciling to the ledger
Public blockchain verification allows auditors to independently confirm that assets at specific wallet addresses exist without relying solely on management representations.
Question 2: Which standard framework is most commonly referenced when evaluating IT general controls in a US fintech audit?
- ISO 27001
- COBIT (Control Objectives for Information and Related Technologies) (Correct answer)
- PCI DSS
- NIST Cybersecurity Framework
Correct answer: COBIT (Control Objectives for Information and Related Technologies)
COBIT is the most widely adopted framework for IT governance and control objectives referenced in financial audits within the US.
Question 3: A fintech auditor discovers that a key payment processing control failed for 15 days before being remediated. What is the auditor's most appropriate next step?
- Accept management's remediation and issue an unmodified opinion
- Assess whether transactions processed during the failure period require additional substantive testing (Correct answer)
- Immediately report the failure to the SEC
- Expand the sample size for unrelated controls
Correct answer: Assess whether transactions processed during the failure period require additional substantive testing
A control failure creates a gap that may have allowed undetected errors or fraud; auditors must perform additional substantive testing covering the period the control was inoperative.
Question 4: Under SOX Section 404, management of a public fintech company must:
- Have all internal controls independently verified by a third-party firm annually
- Assess and report on the effectiveness of internal control over financial reporting (Correct answer)
- Obtain PCAOB certification for all IT systems used in financial reporting
- Submit a quarterly control self-assessment to the FDIC
Correct answer: Assess and report on the effectiveness of internal control over financial reporting
SOX Section 404(a) requires management to assess and report on the design and operating effectiveness of ICFR as of the fiscal year-end.
Question 5: Which sampling method is most appropriate when an auditor wants every transaction in a fintech dataset to have an equal probability of selection?
- Judgmental sampling
- Systematic (interval) sampling
- Simple random sampling (Correct answer)
- Stratified sampling
Correct answer: Simple random sampling
Simple random sampling gives each item in the population an equal and independent chance of being selected, meeting the criterion of equal probability.
Question 6: Which of the following best describes 'audit trail completeness' in the context of fintech systems?
- All financial statements are signed by senior management
- Every significant system event is recorded in an immutable, time-stamped log (Correct answer)
- Customer data is backed up to a secondary location each night
- API response times are monitored and logged for performance purposes
Correct answer: Every significant system event is recorded in an immutable, time-stamped log
A complete audit trail requires that every material action within the system is captured in a tamper-evident, chronological record to support reconstruction and investigation.
Question 7: When auditing a buy-now-pay-later (BNPL) fintech, which revenue recognition risk is most significant?
- Overstatement of customer acquisition costs
- Premature recognition of interest and fee income before collection is probable (Correct answer)
- Undervaluation of physical assets
- Misclassification of equity instruments
Correct answer: Premature recognition of interest and fee income before collection is probable
BNPL companies face pressure to accelerate recognition of interest and fees; auditors must assess whether income is recognized only when collectability is probable under ASC 310.
In auditing a cryptocurrency exchange, which procedure is most appropriate for verifying the existence of digital assets held in custody?