CIG Risk Management & Compliance 4 — Questions and Answers
Question 1: Which element is NOT typically included in a risk register?
- Risk description and category
- Risk owner and mitigation plan
- Auditor's personal opinion on management integrity (Correct answer)
- Likelihood and impact ratings
Correct answer: Auditor's personal opinion on management integrity
A risk register documents factual risk data including descriptions, owners, ratings, and response plans—personal opinions about individuals are not appropriate entries.
Question 2: Which principle holds that internal audit's effectiveness depends on its independence from the activities it reviews?
- Dual reporting principle
- Organizational independence (Correct answer)
- Scope limitation doctrine
- Segregation of audit and compliance
Correct answer: Organizational independence
Organizational independence requires that internal audit report to a level that enables it to fulfill responsibilities without interference from management whose activities it audits.
Question 3: A grant recipient fails to maintain records for the required retention period. Under federal compliance standards, what type of finding is this?
- Material weakness
- Noncompliance with requirements (Correct answer)
- Significant deficiency
- Fraud indicator
Correct answer: Noncompliance with requirements
Failure to maintain required records constitutes noncompliance with federal award requirements, regardless of whether it caused a monetary loss.
Question 4: What is the purpose of a 'control self-assessment' (CSA) in a compliance program?
- To replace external audits with management review
- To engage process owners in evaluating the effectiveness of their own controls (Correct answer)
- To identify employees who are likely to commit fraud
- To automatically generate corrective action plans
Correct answer: To engage process owners in evaluating the effectiveness of their own controls
CSA is a technique where the people who own and operate processes assess their own controls, promoting ownership and often surfacing risks that external auditors miss.
Question 5: Under the Standards for Internal Audit (IIA Standards), due professional care requires internal auditors to consider which factor?
- The personal reputation of program managers
- The likelihood of significant errors, fraud, or noncompliance (Correct answer)
- The audit client's budget constraints
- Whether findings will be politically sensitive
Correct answer: The likelihood of significant errors, fraud, or noncompliance
Due professional care requires auditors to consider the probability of significant errors, irregularities, or noncompliance when planning and executing audit work.
Question 6: A program office implements a new internal control but never tests it after deployment. This is an example of a failure in which COSO component?
- Control Environment
- Information & Communication
- Monitoring Activities (Correct answer)
- Risk Assessment
Correct answer: Monitoring Activities
Monitoring Activities require ongoing evaluation of controls to confirm they are operating effectively; failing to test a deployed control is a monitoring deficiency.
Question 7: Which scenario BEST illustrates a segregation of duties control?
- Two supervisors must both sign a document before it is filed
- The employee who authorizes purchases cannot also process payments for those purchases (Correct answer)
- All transactions above $10,000 require senior management approval
- Auditors must disclose conflicts of interest before beginning an engagement
Correct answer: The employee who authorizes purchases cannot also process payments for those purchases
Segregation of duties prevents one person from controlling an entire transaction from authorization through execution, reducing the risk of undetected error or fraud.
Which element is NOT typically included in a risk register?