CIG Governance & Internal Controls 3 — Questions and Answers
Question 1: Enterprise Risk Management (ERM) expands upon traditional internal control frameworks by additionally addressing:
- Financial statement accuracy only
- Strategic and reputational risks across the entire organization (Correct answer)
- Compliance with procurement regulations
- Information security vulnerabilities exclusively
Correct answer: Strategic and reputational risks across the entire organization
ERM takes a broader, entity-wide view that includes strategic and reputational risks, not just operational and financial controls addressed in traditional frameworks.
Question 2: An agency's audit committee that includes a majority of non-federal-employee members BEST supports which governance principle?
- Management accountability
- Independence of oversight (Correct answer)
- Risk stratification
- Control self-assessment
Correct answer: Independence of oversight
Having outside members on an audit committee strengthens independence, ensuring oversight is not compromised by internal management relationships.
Question 3: Under OMB Circular A-123, management's responsibility for internal control includes issuing an annual assurance statement that covers:
- Only financial management systems
- The effectiveness of internal controls over financial reporting and operations (Correct answer)
- Cybersecurity and IT systems exclusively
- Human capital planning and workforce development
Correct answer: The effectiveness of internal controls over financial reporting and operations
OMB Circular A-123 requires agency heads to provide an annual assurance statement on the effectiveness of internal controls over both financial reporting and operations.
Question 4: A 'compensating control' is BEST described as:
- A financial incentive for employees who follow control procedures
- An alternative control that mitigates risk when a primary control cannot be implemented (Correct answer)
- A retroactive correction to an accounting error
- A detective control that identifies fraud after the fact
Correct answer: An alternative control that mitigates risk when a primary control cannot be implemented
Compensating controls provide alternative risk mitigation when ideal controls (like separation of duties in small offices) are not feasible.
Question 5: Which scenario BEST illustrates the governance concept of 'tone at the top'?
- The CFO mandates monthly reconciliations for all accounts
- The agency head publicly acknowledges and corrects an internal control failure identified by the IG (Correct answer)
- The IG recommends new software to automate procurement approvals
- Human resources updates the ethics training curriculum annually
Correct answer: The agency head publicly acknowledges and corrects an internal control failure identified by the IG
A leader publicly owning and addressing a control failure demonstrates the transparency and accountability that define a strong ethical tone from the top.
Question 6: The Inspector General Act of 1978 established OIGs primarily to promote which two governance objectives?
- Cost reduction and workforce efficiency
- Economy, efficiency, and effectiveness; and prevention of fraud, waste, and abuse (Correct answer)
- Congressional oversight and legislative compliance
- Strategic planning and performance management
Correct answer: Economy, efficiency, and effectiveness; and prevention of fraud, waste, and abuse
The IG Act created independent offices to promote economy, efficiency, and effectiveness, while preventing and detecting fraud, waste, and abuse.
Question 7: When assessing internal controls, an Inspector General should give the HIGHEST priority to controls that address:
- Administrative procedures with low dollar impact
- Risks with high likelihood and high potential impact (Correct answer)
- Controls already documented in policy manuals
- Areas with no prior audit findings
Correct answer: Risks with high likelihood and high potential impact
A risk-based approach prioritizes controls over high-likelihood, high-impact risks to focus limited audit resources where they matter most.
Enterprise Risk Management (ERM) expands upon traditional internal control frameworks by additionally addressing: