CGAP Auditing & Corporate Governance 4 — Questions and Answers
Question 1: A government CAE (Chief Audit Executive) receives instructions from management to exclude a high-risk area from the annual audit plan. The appropriate response is to:
- Comply immediately to maintain the relationship with management
- Document the exclusion and communicate the resulting risk gap to the governing body (Correct answer)
- Resign from the position to avoid the conflict
- Audit the area secretly without informing management
Correct answer: Document the exclusion and communicate the resulting risk gap to the governing body
The CAE must document scope limitations and communicate the risk implications to the governing body to maintain transparency and independence.
Question 2: Which element of corporate governance specifically addresses mechanisms that align management's interests with those of stakeholders?
- Executive compensation and incentive structures (Correct answer)
- Financial statement footnote disclosures
- Procurement threshold policies
- Travel and expense reimbursement policies
Correct answer: Executive compensation and incentive structures
Compensation and incentive structures are key governance tools designed to align management behavior with organizational and stakeholder interests.
Question 3: During a CGAP audit, an auditor identifies a transaction that is legal but appears to conflict with the entity's code of ethics. The auditor should:
- Ignore it since it is not illegal
- Document and report it as a governance concern to appropriate oversight (Correct answer)
- Immediately notify law enforcement
- Include it only in internal working papers with no further action
Correct answer: Document and report it as a governance concern to appropriate oversight
Ethical violations, even when not illegal, are governance concerns that should be documented and communicated to the appropriate level of oversight.
Question 4: The concept of 'materiality' in government auditing differs from private sector auditing primarily because:
- Government auditors never use quantitative thresholds
- Materiality may include qualitative factors such as sensitivity, visibility, or public interest (Correct answer)
- Government audit materiality is always set at 5% of total expenditures
- Only financial statement users define materiality in government audits
Correct answer: Materiality may include qualitative factors such as sensitivity, visibility, or public interest
In government auditing, materiality encompasses qualitative factors like political sensitivity and public interest, not just dollar thresholds.
Question 5: Which type of audit evidence is generally considered MOST reliable for a government auditor?
- Oral representations from management
- Photocopies of original documents provided by the auditee
- Evidence obtained directly by the auditor from independent external sources (Correct answer)
- Internal memos created by program staff
Correct answer: Evidence obtained directly by the auditor from independent external sources
Evidence obtained directly from independent external sources is most reliable because it is uninfluenced by the auditee and carries the highest assurance.
Question 6: A government entity's risk assessment process should update identified risks when:
- Only at the start of each fiscal year
- Only when a significant budget increase occurs
- Whenever significant changes in the environment, operations, or personnel occur (Correct answer)
- Only after an external audit is completed
Correct answer: Whenever significant changes in the environment, operations, or personnel occur
Risk assessments must be dynamic and updated whenever significant organizational or environmental changes occur that could affect the control environment.
Question 7: Which IIA Standard requires internal audit to evaluate the effectiveness of the organization's risk management processes?
- Standard 2010 — Planning
- Standard 2120 — Risk Management (Correct answer)
- Standard 2200 — Engagement Planning
- Standard 2410 — Criteria for Communicating
Correct answer: Standard 2120 — Risk Management
IIA Standard 2120 specifically requires internal audit to evaluate the effectiveness and contribution of risk management processes.
A government CAE (Chief Audit Executive) receives instructions from management to exclude a high-risk area from the annual audit plan.
The appropriate response is to: