CGRC Audit Management 5 — Questions and Answers
Question 1: Which phase of the audit lifecycle involves confirming the audit's scope, objectives, and approach with management before fieldwork begins?
- Audit completion
- Preliminary survey / planning meeting (Correct answer)
- Audit reporting
- Follow-up review
Correct answer: Preliminary survey / planning meeting
The planning meeting (sometimes called an entrance conference) aligns auditor and management expectations before substantive testing starts.
Question 2: A walk-through procedure is performed primarily to:
- Test large transaction samples statistically
- Confirm that a process operates as described and that controls are in place (Correct answer)
- Evaluate compliance with regulatory requirements
- Determine the final audit opinion
Correct answer: Confirm that a process operates as described and that controls are in place
Walk-throughs trace one or a few transactions end-to-end to verify that the documented process and controls actually function as described.
Question 3: Under COSO Internal Control framework, the component that focuses on monitoring whether controls are operating effectively over time is:
- Control environment
- Risk assessment
- Control activities
- Monitoring activities (Correct answer)
Correct answer: Monitoring activities
Monitoring activities involve ongoing evaluations and separate evaluations to ascertain whether the components of internal control are present and functioning.
Question 4: Which type of control test provides the strongest evidence that a control is operating effectively?
- Inquiry of management
- Observation of the control being performed once
- Reperformance of the control by the auditor (Correct answer)
- Inspection of the policy document describing the control
Correct answer: Reperformance of the control by the auditor
Reperformance—where the auditor independently executes the control—provides the highest level of assurance about control effectiveness.
Question 5: An auditor is assessing IT general controls (ITGCs). Which area is NOT typically covered by ITGCs?
- Access management and user provisioning
- Change management for applications and infrastructure
- Application-level input validation rules for a specific business process (Correct answer)
- Computer operations and job scheduling
Correct answer: Application-level input validation rules for a specific business process
Application input validation is an application control specific to one system; ITGCs are pervasive controls that support the overall IT environment.
Question 6: Which standard-setting body issues the International Standards for the Professional Practice of Internal Auditing?
- ISACA
- AICPA
- The Institute of Internal Auditors (IIA) (Correct answer)
- PCAOB
Correct answer: The Institute of Internal Auditors (IIA)
The IIA publishes the International Standards for the Professional Practice of Internal Auditing, which govern internal audit globally.
Question 7: When an audit engagement is classified as 'consulting' rather than 'assurance,' a key difference is that:
- Consulting engagements always result in a formal written report
- Consulting engagements are initiated by management and do not express an opinion on controls (Correct answer)
- Consulting engagements require external auditor co-signature
- Consulting engagements must follow the same scope restrictions as assurance work
Correct answer: Consulting engagements are initiated by management and do not express an opinion on controls
Consulting engagements are advisory in nature, typically requested by management, and do not provide formal assurance or an opinion on control effectiveness.
Which phase of the audit lifecycle involves confirming the audit's scope, objectives, and approach with management before fieldwork begins?