CGFO Internal Controls 4 — Questions and Answers
Question 1: A government's internal audit function should be organizationally positioned to ensure:
- Maximum efficiency in financial reporting
- Independence from the activities it audits (Correct answer)
- Direct reporting to the chief financial officer only
- Alignment with departmental operational goals
Correct answer: Independence from the activities it audits
Independence is the cornerstone of internal audit credibility, requiring separation from the operations being reviewed.
Question 2: Which of the following scenarios represents a 'management override' of internal controls?
- An automated system blocks a duplicate payment
- A supervisor approves a journal entry outside the normal approval process (Correct answer)
- An employee requests segregation of duties training
- A vendor is removed from the approved vendor list
Correct answer: A supervisor approves a journal entry outside the normal approval process
Management override occurs when a manager circumvents established controls, which is a significant fraud risk factor.
Question 3: Under COSO's Enterprise Risk Management (ERM) framework, 'risk appetite' is best described as:
- The maximum amount of loss an entity can absorb before insolvency
- The amount of risk an entity is willing to accept in pursuit of its objectives (Correct answer)
- The level of risk detected during an internal audit
- The cost of implementing preventive controls
Correct answer: The amount of risk an entity is willing to accept in pursuit of its objectives
Risk appetite is the broad amount of risk an entity is willing to accept in pursuit of value and its mission.
Question 4: A government entity uses an automated system that prevents a purchase order from being issued without a corresponding budget appropriation. This is an example of:
- A manual preventive control
- An automated application control (Correct answer)
- A detective compensating control
- An IT general control
Correct answer: An automated application control
Automated application controls are embedded within software applications and enforce business rules without human intervention.
Question 5: The Sarbanes-Oxley Act's influence on government internal controls is most notable because it:
- Directly mandates government compliance with Section 404
- Raised awareness of control environment importance across all sectors (Correct answer)
- Eliminated the need for external auditors in government
- Required governments to adopt COSO as their framework
Correct answer: Raised awareness of control environment importance across all sectors
While SOX applies to public companies, it elevated internal control consciousness and best practices across public and private sectors.
Question 6: Which of the following best describes 'continuous monitoring' as an internal control activity?
- Performing annual audits of all financial statements
- Using technology to automatically review transactions in real time for exceptions (Correct answer)
- Requiring weekly supervisor sign-offs on all transactions
- Conducting quarterly risk assessments
Correct answer: Using technology to automatically review transactions in real time for exceptions
Continuous monitoring uses automated tools to analyze 100% of transactions in real time, flagging anomalies immediately.
Question 7: In the context of government grant management, which internal control is most critical to ensure allowable costs?
- Annual independent audit of financial statements
- Pre-expenditure review against grant terms and federal cost principles (Correct answer)
- Monthly reconciliation of the general ledger
- Dual signatures on all disbursement checks
Correct answer: Pre-expenditure review against grant terms and federal cost principles
Pre-expenditure review ensures costs are allowable, allocable, and reasonable under grant terms before funds are spent.
A government's internal audit function should be organizationally positioned to ensure: