CGFO Internal Controls 5 — Questions and Answers
Question 1: A government finance officer is reviewing the results of a fraud risk assessment. Which factor would MOST increase the risk of asset misappropriation?
- High employee turnover in the accounts payable department (Correct answer)
- Implementation of an ERP financial system
- Adoption of a formal ethics policy
- Regular third-party audits
Correct answer: High employee turnover in the accounts payable department
High turnover in sensitive financial positions reduces institutional knowledge, weakens oversight, and creates opportunities for fraud.
Question 2: The three elements of the 'fraud triangle' that internal controls are designed to address include opportunity, rationalization, and:
- Motivation
- Pressure (Correct answer)
- Authorization
- Override
Correct answer: Pressure
The fraud triangle consists of pressure (incentive), opportunity, and rationalization; controls primarily address opportunity.
Question 3: Which statement about internal control limitations is most accurate?
- A well-designed internal control system eliminates all risk of fraud
- Internal controls can be overridden by management collusion (Correct answer)
- Internal controls are only effective when externally audited annually
- Automated controls have no limitations once implemented
Correct answer: Internal controls can be overridden by management collusion
Even well-designed controls cannot prevent fraud when management colludes to circumvent them, which is a fundamental limitation.
Question 4: A government's petty cash fund is subject to surprise counts by the supervisor. This control is best classified as:
- Preventive and automated
- Detective and manual (Correct answer)
- Corrective and systematic
- Directive and manual
Correct answer: Detective and manual
A surprise count identifies discrepancies after they have occurred (detective) and is performed by a person (manual).
Question 5: Under the Single Audit Act, a government that expends $750,000 or more in federal awards must:
- Obtain a compliance audit of all federal programs
- Undergo a single audit covering federal award expenditures (Correct answer)
- Submit quarterly internal control certifications to the federal agency
- Engage a Big Four accounting firm for audit services
Correct answer: Undergo a single audit covering federal award expenditures
The Single Audit Act threshold of $750,000 triggers a requirement for a single audit that covers both financial statements and federal compliance.
Question 6: When a government entity documents its internal controls, which tool is most commonly used to map control activities to specific risks?
- Organizational chart
- Risk and control matrix (Correct answer)
- Chart of accounts
- Budget variance report
Correct answer: Risk and control matrix
A risk and control matrix links identified risks to specific controls, ownership, and testing procedures.
Question 7: Which of the following represents a 'corrective control' in a government finance environment?
- Encrypting sensitive financial data at rest
- Requiring dual approval before wire transfers
- Recovering duplicate payments through a vendor refund process (Correct answer)
- Performing daily review of exception reports
Correct answer: Recovering duplicate payments through a vendor refund process
Corrective controls fix problems after they have been detected, such as recovering duplicate or erroneous payments.
A government finance officer is reviewing the results of a fraud risk assessment.
Which factor would MOST increase the risk of asset misappropriation?