CFS Internal Controls & Auditing 2 — Questions and Answers
Question 1: Which COSO component addresses the organization's risk appetite and tolerance levels?
- Control Activities
- Risk Assessment (Correct answer)
- Information & Communication
- Monitoring Activities
Correct answer: Risk Assessment
Risk Assessment is the COSO component where management identifies and analyzes risks, including setting acceptable risk appetite and tolerance thresholds.
Question 2: A company requires that journal entries above $10,000 be approved by the CFO. This control is best classified as:
- Preventive control (Correct answer)
- Detective control
- Corrective control
- Compensating control
Correct answer: Preventive control
Requiring CFO approval before posting large journal entries is a preventive control because it stops unauthorized entries from being recorded.
Question 3: During an audit, an auditor discovers that the same employee both approves purchase orders and reconciles vendor statements. This represents a failure of:
- Physical safeguards
- Segregation of duties (Correct answer)
- Independent verification
- Documentation controls
Correct answer: Segregation of duties
Allowing one employee to both authorize transactions and perform the reconciliation eliminates the segregation of duties needed to prevent and detect fraud.
Question 4: An auditor uses computer-assisted audit techniques (CAATs) primarily to:
- Replace the need for analytical procedures
- Test large volumes of transactions efficiently (Correct answer)
- Eliminate the need for internal control evaluation
- Satisfy documentation requirements automatically
Correct answer: Test large volumes of transactions efficiently
CAATs allow auditors to analyze entire populations of transactions quickly, detecting anomalies that sampling might miss.
Question 5: Which of the following best describes a 'tone at the top' weakness that increases fraud risk?
- Inadequate IT general controls
- Senior management overriding established approval limits (Correct answer)
- Missing audit trails in the accounting system
- Excessive segregation of duties
Correct answer: Senior management overriding established approval limits
When senior management routinely overrides controls, it signals that controls are not respected, eroding the ethical culture and increasing fraud risk.
Question 6: An organization's internal audit function reports directly to the CEO rather than the audit committee. The primary concern with this structure is:
- Increased audit costs
- Impaired auditor independence (Correct answer)
- Reduced audit scope
- Excessive audit documentation
Correct answer: Impaired auditor independence
Reporting to the CEO rather than the audit committee compromises independence because management could pressure auditors to suppress unfavorable findings.
Question 7: A ghost employee scheme is most effectively prevented by which control?
- Requiring supervisory approval of all payroll checks
- Periodic physical verification of employees matched to payroll records (Correct answer)
- Mandatory direct deposit for all employees
- Monthly bank reconciliations performed by payroll staff
Correct answer: Periodic physical verification of employees matched to payroll records
Physically verifying that individuals on the payroll actually exist and work at the company directly prevents ghost employee fraud.
Which COSO component addresses the organization's risk appetite and tolerance levels?