CFS Internal Controls & Auditing 3 — Questions and Answers
Question 1: Which type of audit opinion is issued when financial statements are free of material misstatement but the auditor has a scope limitation?
- Adverse opinion
- Disclaimer of opinion
- Qualified opinion (Correct answer)
- Unmodified opinion
Correct answer: Qualified opinion
A qualified opinion is issued when the financial statements are fairly presented except for a specific matter, including certain scope limitations.
Question 2: The three-lines-of-defense model assigns which responsibility to internal audit?
- First line: day-to-day risk ownership
- Second line: risk oversight functions
- Third line: independent assurance (Correct answer)
- Fourth line: external regulatory review
Correct answer: Third line: independent assurance
Internal audit is the third line of defense, providing independent assurance over the effectiveness of governance, risk management, and internal controls.
Question 3: When performing a walkthrough, an auditor is primarily trying to:
- Confirm that controls are described accurately in documentation (Correct answer)
- Test a large sample of transactions for errors
- Assess the competence of accounting staff
- Verify year-end account balances
Correct answer: Confirm that controls are described accurately in documentation
A walkthrough traces a transaction from initiation through recording to verify that the process works as documented, confirming the accuracy of control descriptions.
Question 4: A key risk indicator (KRI) for accounts payable fraud would most likely be:
- Increasing number of new vendors with P.O. box addresses only (Correct answer)
- Rising inventory turnover ratios
- Growing number of customer returns
- Declining days sales outstanding
Correct answer: Increasing number of new vendors with P.O. box addresses only
Vendors with only P.O. box addresses and no physical location are a red flag for fictitious vendor schemes in accounts payable.
Question 5: Management override of internal controls is considered particularly dangerous because:
- It is always illegal under Sarbanes-Oxley
- Controls cannot detect or prevent actions by those who designed them (Correct answer)
- It only occurs in small companies without audit committees
- External auditors are required to report it immediately to the SEC
Correct answer: Controls cannot detect or prevent actions by those who designed them
Controls are typically designed by management, so management has the authority and knowledge to circumvent them, making management override a significant inherent limitation.
Question 6: Which sampling method gives every transaction in a population an equal chance of being selected?
- Haphazard sampling
- Judgmental sampling
- Stratified random sampling
- Simple random sampling (Correct answer)
Correct answer: Simple random sampling
Simple random sampling ensures each item in the population has an equal and independent probability of selection, eliminating bias.
Question 7: Under SOX Section 404, management is required to:
- Hire an external forensic accountant annually
- Assess and report on the effectiveness of internal controls over financial reporting (Correct answer)
- Rotate external auditors every five years
- Submit quarterly fraud risk assessments to the SEC
Correct answer: Assess and report on the effectiveness of internal controls over financial reporting
SOX Section 404 requires management to evaluate and report on the effectiveness of internal controls over financial reporting, with the external auditor attesting to that assessment.
Which type of audit opinion is issued when financial statements are free of material misstatement but the auditor has a scope limitation?