← All CFS Flashcard Decks

Internal Controls & Auditing Flashcards

7 cards from real CFS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Internal Controls & Auditing flashcards as text
  1. Which COSO component addresses the organization's risk appetite and tolerance levels?

    Answer: Risk Assessment

    Risk Assessment is the COSO component where management identifies and analyzes risks, including setting acceptable risk appetite and tolerance thresholds.

  2. A company requires that journal entries above $10,000 be approved by the CFO. This control is best classified as:

    Answer: Preventive control

    Requiring CFO approval before posting large journal entries is a preventive control because it stops unauthorized entries from being recorded.

  3. During an audit, an auditor discovers that the same employee both approves purchase orders and reconciles vendor statements. This represents a failure of:

    Answer: Segregation of duties

    Allowing one employee to both authorize transactions and perform the reconciliation eliminates the segregation of duties needed to prevent and detect fraud.

  4. An auditor uses computer-assisted audit techniques (CAATs) primarily to:

    Answer: Test large volumes of transactions efficiently

    CAATs allow auditors to analyze entire populations of transactions quickly, detecting anomalies that sampling might miss.

  5. Which of the following best describes a 'tone at the top' weakness that increases fraud risk?

    Answer: Senior management overriding established approval limits

    When senior management routinely overrides controls, it signals that controls are not respected, eroding the ethical culture and increasing fraud risk.

  6. An organization's internal audit function reports directly to the CEO rather than the audit committee. The primary concern with this structure is:

    Answer: Impaired auditor independence

    Reporting to the CEO rather than the audit committee compromises independence because management could pressure auditors to suppress unfavorable findings.

  7. A ghost employee scheme is most effectively prevented by which control?

    Answer: Periodic physical verification of employees matched to payroll records

    Physically verifying that individuals on the payroll actually exist and work at the company directly prevents ghost employee fraud.