CIG Governance & Internal Controls 4 — Questions and Answers
Question 1: Which element of the COSO framework specifically involves identifying and analyzing risks that may prevent an organization from achieving its objectives?
- Control Environment
- Control Activities
- Risk Assessment (Correct answer)
- Monitoring Activities
Correct answer: Risk Assessment
Risk Assessment is the COSO component that requires management to identify and analyze risks that could impede achievement of organizational objectives.
Question 2: A federal IG determines that an agency's financial management system lacks adequate audit trails for transactions. This MOST directly affects which internal control objective?
- Strategic alignment
- Operational efficiency
- Compliance with regulations
- Reliability of financial reporting (Correct answer)
Correct answer: Reliability of financial reporting
Audit trails are essential for tracing transactions and verifying accuracy, directly supporting the reliability of financial reporting.
Question 3: In governance frameworks, 'three lines of defense' refers to which arrangement?
- IG, external auditor, and Congress
- Operational management, risk/compliance functions, and internal audit (Correct answer)
- Agency head, CFO, and Inspector General
- Policy, procedures, and training
Correct answer: Operational management, risk/compliance functions, and internal audit
The three lines of defense model positions operational management as first line, risk and compliance functions as second, and internal audit as the third independent line.
Question 4: An agency implements continuous monitoring of its financial transactions using automated data analytics. This BEST represents which type of control activity?
- Preventive control
- Detective control (Correct answer)
- Directive control
- Physical safeguard
Correct answer: Detective control
Continuous monitoring detects anomalies and errors after transactions occur, classifying it as a detective control activity.
Question 5: According to GAO Government Auditing Standards, when auditors identify internal control deficiencies during a performance audit, they are required to:
- Immediately report findings directly to Congress
- Report significant deficiencies found during the audit (Correct answer)
- Suspend the audit pending management corrective action
- Refer all deficiencies to the Department of Justice
Correct answer: Report significant deficiencies found during the audit
GAGAS requires auditors to report significant deficiencies in internal control identified during a performance audit in their audit report.
Question 6: Which governance structure feature BEST ensures that an IG's findings reach appropriate oversight authorities even if agency management disagrees?
- The IG's appointment by the agency head
- Dual reporting to the agency head and to Congress (Correct answer)
- The IG's authority to issue subpoenas
- Mandatory rotation of IG staff every five years
Correct answer: Dual reporting to the agency head and to Congress
Dual reporting requirements ensure IG findings reach Congress even when agency leadership disagrees or attempts to suppress findings, preserving independent oversight.
Question 7: A control that requires managers to review and approve budget variances exceeding 10% is BEST classified as:
- A physical control
- A performance review control (Correct answer)
- An IT general control
- A reconciliation control
Correct answer: A performance review control
Reviewing budget variances against thresholds is a performance review control that compares actual results to budgeted expectations to identify anomalies.
Which element of the COSO framework specifically involves identifying and analyzing risks that may prevent an organization from achieving its objectives?