Internal Controls & Auditing Flashcards
7 cards from real CFS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Internal Controls & Auditing flashcards as text
Which control best mitigates the risk of a system administrator granting themselves unauthorized access rights?
Answer: User access reviews conducted by business process owners
Having business process owners (not IT) periodically review and certify user access ensures that IT staff cannot grant themselves inappropriate permissions undetected.
An auditor identifies that reconciliations are completed but never reviewed by a supervisor. This is an example of a control:
Answer: That is designed effectively but operating ineffectively
The reconciliation process exists (good design) but lacks the supervisory review step to function as intended, creating an operating deficiency.
Which fraud scheme involves an employee submitting the same legitimate expense twice for reimbursement?
Answer: Multiple reimbursement scheme
A multiple reimbursement scheme occurs when an employee submits the same receipt or expense claim more than once to receive duplicate payment.
The primary purpose of an audit committee's oversight of the external auditor is to:
Answer: Safeguard auditor independence from management influence
The audit committee acts as an independent body overseeing the external auditor relationship to ensure auditors are not unduly influenced by the management they are auditing.
Data analytics applied to journal entry testing most commonly looks for which fraud indicator?
Answer: Journal entries posted on weekends or holidays by senior management
Journal entries posted outside normal business hours—especially by management—are a red flag for fraudulent manual adjustments used to manipulate financial results.
A control environment weakness exists when:
Answer: Management's actions are inconsistent with stated ethical standards
When management acts contrary to the ethical standards it espouses, it undermines the entire control environment by signaling that controls are not genuinely enforced.
Which activity is a component of continuous monitoring rather than periodic auditing?
Answer: Real-time alerts triggered by transactions exceeding approval thresholds
Real-time automated alerts that trigger immediately when control thresholds are exceeded are the hallmark of continuous monitoring versus periodic audit activities.