CIA Auditing Principles & Procedures 3 — Questions and Answers
Question 1: Which internal control is most effective at preventing unauthorized changes to policyholder premium rates?
- Requiring dual authorization for rate changes in the policy system (Correct answer)
- Performing annual loss reserve reviews
- Reconciling bank statements monthly
- Rotating claims adjusters across regions
Correct answer: Requiring dual authorization for rate changes in the policy system
Dual authorization (segregation of duties) ensures no single employee can unilaterally alter premium rates.
Question 2: Audit risk is defined as the risk that:
- The insured files a fraudulent claim
- The auditor issues an incorrect opinion on materially misstated financial statements (Correct answer)
- An insurer fails to collect premiums on time
- The reinsurer defaults on treaty obligations
Correct answer: The auditor issues an incorrect opinion on materially misstated financial statements
Audit risk is the probability that the auditor expresses an inappropriate opinion when the financial statements contain material misstatement.
Question 3: In the context of insurance fraud detection during an audit, 'red flags' most commonly include:
- Claims filed within 30 days of policy inception with unusually high values (Correct answer)
- Consistent loss ratios over multiple years
- Claims supported by third-party police reports
- Premium payments made ahead of schedule
Correct answer: Claims filed within 30 days of policy inception with unusually high values
Claims filed shortly after policy issuance for large amounts are classic indicators of potential fraud that warrant further investigation.
Question 4: Control risk in an insurance audit is the risk that:
- A misstatement will not be detected by the auditor's procedures
- Internal controls fail to prevent or detect a material misstatement (Correct answer)
- The auditor lacks sufficient competence to evaluate reserves
- Reinsurance treaties are not properly disclosed
Correct answer: Internal controls fail to prevent or detect a material misstatement
Control risk measures the likelihood that the client's internal controls will fail to catch a material error or fraud.
Question 5: When assessing inherent risk in an insurance company audit, which factor would MOST increase inherent risk?
- Simple, standardized product lines with low claim frequency
- Complex long-tail liability lines requiring subjective reserve estimates (Correct answer)
- A large, experienced actuarial staff
- Automated premium billing systems with minimal manual intervention
Correct answer: Complex long-tail liability lines requiring subjective reserve estimates
Long-tail liability lines involve highly subjective reserve estimates that are susceptible to significant management bias, increasing inherent risk.
Question 6: The Sarbanes-Oxley Act requirements most directly affect insurance company audits by:
- Setting minimum reserve standards for property-casualty insurers
- Requiring management assessment and auditor attestation of internal controls over financial reporting (Correct answer)
- Mandating actuarial certification of loss reserves
- Establishing premium rate approval processes
Correct answer: Requiring management assessment and auditor attestation of internal controls over financial reporting
SOX Section 404 requires management to assess internal controls and the auditor to attest to that assessment for public companies.
Question 7: Which sampling technique ensures every item in the population has an equal chance of selection?
- Judgmental sampling
- Haphazard sampling
- Random sampling (Correct answer)
- Block sampling
Correct answer: Random sampling
Random (probability) sampling gives each population item an equal and known probability of selection, supporting statistical inference.
Which internal control is most effective at preventing unauthorized changes to policyholder premium rates?