CORES Internal Audit & Three Lines of Defense 2 — Questions and Answers
Question 1: A risk-based internal audit approach prioritizes audit resources based on:
- Alphabetical order of business units
- The relative risk exposure and significance of auditable entities (Correct answer)
- Management's personal preferences for audit coverage
- The age of the previous audit engagement
Correct answer: The relative risk exposure and significance of auditable entities
Risk-based auditing allocates audit effort proportionally to the risk profile of each auditable entity, ensuring the highest-risk areas receive the most scrutiny.
Question 2: The 'audit universe' in internal audit planning refers to:
- The external regulatory bodies that govern the organization
- A comprehensive inventory of all auditable entities, processes, and systems (Correct answer)
- The scope of a single audit engagement
- The pool of certified internal auditors available for assignment
Correct answer: A comprehensive inventory of all auditable entities, processes, and systems
The audit universe is a complete catalog of all auditable areas across the organization, which the audit function uses to develop its risk-based multi-year audit plan.
Question 3: During an operational risk audit, an auditor identifies a control that exists in policy but is consistently not followed in practice. This situation BEST exemplifies:
- Design deficiency
- Operating effectiveness deficiency (Correct answer)
- Inherent risk escalation
- Residual risk acceptance
Correct answer: Operating effectiveness deficiency
An operating effectiveness deficiency means a control is properly designed but fails to function as intended during the period under review.
Question 4: When rating audit findings, a 'high' or 'critical' severity classification typically indicates:
- A minor process improvement opportunity with limited financial impact
- A significant control gap exposing the organization to material risk or regulatory breach (Correct answer)
- A finding that management has already remediated
- A theoretical risk with no current evidence of occurrence
Correct answer: A significant control gap exposing the organization to material risk or regulatory breach
High/critical findings represent material control failures that could result in significant financial loss, regulatory sanction, or reputational damage requiring urgent remediation.
Question 5: Which practice BEST supports the integrity of the audit follow-up process for operational risk findings?
- Accepting management's assertion that a finding is remediated without validation
- Independently testing and validating that remediation actions have been effectively implemented (Correct answer)
- Closing all findings at the end of each fiscal year regardless of status
- Allowing the first line to self-certify remediation with no second or third line review
Correct answer: Independently testing and validating that remediation actions have been effectively implemented
Effective follow-up requires internal audit to independently verify that management's corrective actions have been implemented and are operating effectively, not merely relying on management assertions.
Question 6: What is the PRIMARY reporting responsibility of the Chief Audit Executive (CAE) in most governance frameworks?
- Reporting exclusively to the Chief Risk Officer
- Reporting functionally to the Audit Committee of the Board and administratively to senior management (Correct answer)
- Reporting to the Chief Financial Officer for budget purposes and risk purposes
- Reporting only to the Chief Executive Officer
Correct answer: Reporting functionally to the Audit Committee of the Board and administratively to senior management
The CAE has dual reporting lines: functional reporting to the audit committee (ensuring independence) and administrative reporting to senior management (operational matters like budget).
Question 7: Which International Standards for the Professional Practice of Internal Auditing (ISPPIA) attribute standard addresses the organizational independence of internal audit?
- Standard 2010 – Planning
- Standard 1110 – Organizational Independence (Correct answer)
- Standard 2300 – Performing the Engagement
- Standard 2600 – Communicating the Acceptance of Risk
Correct answer: Standard 1110 – Organizational Independence
Standard 1110 requires the CAE to confirm to the board at least annually that the internal audit function is free from conditions that threaten independence.
A risk-based internal audit approach prioritizes audit resources based on: