CGFO Internal Controls 2 — Questions and Answers
Question 1: Which internal control principle requires that no single employee can both authorize a transaction and record it in the accounting system?
- Dual authorization
- Segregation of duties (Correct answer)
- Management override
- Compensating controls
Correct answer: Segregation of duties
Segregation of duties prevents any one employee from controlling all phases of a transaction, reducing fraud and error risk.
Question 2: In a government entity, a 'compensating control' is best described as:
- A control that duplicates another control
- A control that mitigates risk when a primary control cannot be implemented (Correct answer)
- A detective control applied after errors occur
- A manual override procedure authorized by management
Correct answer: A control that mitigates risk when a primary control cannot be implemented
Compensating controls offset the risk when an ideal primary control (such as segregation of duties) is not feasible.
Question 3: The Government Finance Officers Association (GFOA) recommends that internal auditors report functionally to the:
- Chief Financial Officer
- Finance Director
- Governing board or audit committee (Correct answer)
- City Manager
Correct answer: Governing board or audit committee
Reporting to the governing board or audit committee preserves auditor independence from management.
Question 4: Which COSO component addresses an organization's values, ethical standards, and commitment to competence?
- Risk Assessment
- Control Activities
- Control Environment (Correct answer)
- Monitoring Activities
Correct answer: Control Environment
The Control Environment sets the tone at the top and encompasses integrity, ethical values, and management's philosophy.
Question 5: A government's accounts payable clerk creates a vendor, then approves invoices from that vendor. This situation illustrates a failure in:
- Physical safeguards
- Segregation of duties (Correct answer)
- Management review
- Authorization limits
Correct answer: Segregation of duties
The same employee performing vendor setup and invoice approval violates segregation of duties and creates fraud risk.
Question 6: Under the Green Book (GAO Standards for Internal Control), which of the following is NOT one of the five components of internal control?
- Control Environment
- Risk Assessment
- Control Activities
- External Reporting (Correct answer)
Correct answer: External Reporting
The five Green Book components are Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring.
Question 7: A government finance officer discovers that a subordinate has been making unauthorized journal entries. Which control type would have best prevented this?
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Directive control
Correct answer: Preventive control
Preventive controls, such as access restrictions and pre-approval requirements, stop unauthorized actions before they occur.
Which internal control principle requires that no single employee can both authorize a transaction and record it in the accounting system?