CRMA Coordinating Assurance Efforts 2 — Questions and Answers
Question 1: What is the primary purpose of an assurance map in a coordinated assurance framework?
- To visually display which assurance providers cover which risks and identify gaps or overlaps (Correct answer)
- To rank individual auditors by their level of professional certification
- To document the budget allocated to each line of defense activity
- To replace the internal audit's annual risk assessment process
Correct answer: To visually display which assurance providers cover which risks and identify gaps or overlaps
An assurance map displays risk coverage across all providers, revealing gaps where risks are unassured and overlaps where effort is duplicated.
Question 2: When internal audit chooses to rely on work performed by another assurance provider, what is the CAE's primary obligation?
- Obtain approval from the external auditors before accepting any reliance
- Evaluate the competence, objectivity, and quality of the other provider's work (Correct answer)
- Reduce the internal audit budget proportionally to the work relied upon
- Disclose the reliance only if the audit committee specifically requests it
Correct answer: Evaluate the competence, objectivity, and quality of the other provider's work
IIA standards require internal audit to assess the competence, objectivity, and due professional care of any provider whose work it relies upon.
Question 3: Which document most formally defines the scope, responsibilities, and interaction protocols among all assurance providers in an organization?
- The annual internal audit plan
- A combined assurance charter or memorandum of understanding (Correct answer)
- The organization's code of ethics
- The external auditor's engagement letter
Correct answer: A combined assurance charter or memorandum of understanding
A combined assurance charter or MOU formally establishes how each provider coordinates, reducing confusion and duplication.
Question 4: Coverage duplication occurs when multiple assurance providers independently test the same control without coordination. What is the MOST significant risk of this situation?
- Excessive assurance coverage that improves risk detection accuracy
- Wasted resources and increased burden on control owners without proportional risk reduction (Correct answer)
- Inflated assurance budgets that benefit shareholders
- External auditors losing access to internal audit workpapers
Correct answer: Wasted resources and increased burden on control owners without proportional risk reduction
Duplicated coverage wastes limited assurance resources and strains control owners through repeated testing of the same area.
Question 5: When coordinating with external auditors, internal audit should primarily focus on which of the following?
- Replicating external audit procedures to confirm their accuracy
- Sharing risk assessments, audit plans, and relevant workpapers to minimize duplication and coverage gaps (Correct answer)
- Restricting access to internal workpapers to protect independence
- Replacing substantive external audit testing with management self-assessments
Correct answer: Sharing risk assessments, audit plans, and relevant workpapers to minimize duplication and coverage gaps
Effective coordination with external auditors centers on information sharing to align coverage, avoid redundancy, and optimize total assurance effort.
Question 6: An assurance map reveals that a high-inherent-risk area has no current assurance coverage from any provider. What should the CAE recommend?
- Accept the gap because management has already evaluated that risk
- Immediately escalate the gap to the board and recommend assurance coverage be assigned (Correct answer)
- Request that the external auditors add the area to their scope without further analysis
- Remove the risk from the risk register to avoid board concern
Correct answer: Immediately escalate the gap to the board and recommend assurance coverage be assigned
A high-risk area with no assurance coverage is a critical gap that must be reported to the board with a recommendation to assign appropriate coverage.
Question 7: Internal audit identifies that the compliance function is independently testing the same IT general controls as internal audit. What is the BEST immediate response?
- Continue both programs independently to benefit from double verification
- Meet with the compliance function to coordinate scope, leverage each other's results, and eliminate redundancy (Correct answer)
- Notify the audit committee that compliance is encroaching on internal audit territory
- Discontinue internal audit testing and rely entirely on compliance results without evaluation
Correct answer: Meet with the compliance function to coordinate scope, leverage each other's results, and eliminate redundancy
Coordinating directly with the compliance function to align scopes is the most efficient response and reflects best-practice combined assurance principles.
What is the primary purpose of an assurance map in a coordinated assurance framework?