CRMA Coordinating Assurance Efforts 3 — Questions and Answers
Question 1: Under the IIA's Three Lines Model (2020), which entity bears primary responsibility for managing risks day-to-day?
- The internal audit function (third line)
- The board and governing body
- Management and operational staff (first line) (Correct answer)
- The external auditor
Correct answer: Management and operational staff (first line)
The first line — operational management and staff — owns and manages risks as part of their day-to-day activities.
Question 2: Which statement BEST defines 'combined assurance' as used in the CRMA context?
- A single internal audit engagement that covers all enterprise risks simultaneously
- An integrated approach where multiple assurance providers coordinate to optimize total risk coverage (Correct answer)
- The merger of internal and external audit departments into one team
- A requirement for management to self-assess every risk before internal audit reviews it
Correct answer: An integrated approach where multiple assurance providers coordinate to optimize total risk coverage
Combined assurance integrates efforts across all lines of defense so that coverage is comprehensive, efficient, and free of major gaps.
Question 3: Under IIA Standard 2050, internal audit may rely on the work of other internal and external providers if the CAE determines that the work is adequate for internal audit purposes. What does 'adequate' primarily require?
- The other provider used the same workpaper format as internal audit
- The other provider has appropriate professional certification only
- The work was performed with due professional care by a competent and objective provider (Correct answer)
- The findings were previously reviewed by the CFO
Correct answer: The work was performed with due professional care by a competent and objective provider
Adequacy under Standard 2050 requires the provider to demonstrate competence, objectivity, and professional care in performing their work.
Question 4: When internal audit relies on the work of the risk management function to reduce its own testing scope, what must be documented in the workpapers?
- The salary and experience level of each risk staff member
- The basis for the reliance decision, the scope relied upon, and any limitations identified (Correct answer)
- Approval from the CFO to transfer audit responsibility
- Evidence that external auditors have also reviewed the same work
Correct answer: The basis for the reliance decision, the scope relied upon, and any limitations identified
Proper documentation of reliance includes the rationale, scope of reliance, and any caveats so the decision is transparent and auditable.
Question 5: Which of the following BEST describes 'integrated assurance' as distinguished from 'combined assurance'?
- Integrated assurance involves only first-line management activities; combined assurance includes all three lines
- Integrated assurance is a deeper form where assurance activities are jointly planned and reported across providers from the outset (Correct answer)
- Integrated assurance is an IIA-deprecated term replaced by the Three Lines Model
- Integrated assurance refers exclusively to the coordination between external audit and regulators
Correct answer: Integrated assurance is a deeper form where assurance activities are jointly planned and reported across providers from the outset
Integrated assurance goes beyond coordination to joint planning and unified reporting, while combined assurance may simply align separately planned activities.
Question 6: The IIA's Three Lines Model (2020) replaced which earlier framework?
- COSO Internal Control — Integrated Framework (1992)
- The Three Lines of Defense model (Correct answer)
- The King IV Report on Corporate Governance
- ISO 31000 Risk Management Guidelines
Correct answer: The Three Lines of Defense model
The 2020 Three Lines Model updated and replaced the 'Three Lines of Defense' model to better reflect collaboration rather than defensive positioning.
Question 7: A CAE learns that the compliance function's controls testing covered all high-risk financial processes last quarter. To avoid duplication, internal audit plans to rely on those results. What is the FIRST step internal audit should take?
- Immediately remove financial processes from the annual audit plan
- Assess the competence, objectivity, and rigor of the compliance team's methodology and results (Correct answer)
- Notify the external auditors that internal audit is reducing its scope
- Request that compliance transfer all findings to the external audit firm
Correct answer: Assess the competence, objectivity, and rigor of the compliance team's methodology and results
Before relying on any third party's work, internal audit must first evaluate whether the provider's quality and objectivity meet the standard required for reliance.
Under the IIA's Three Lines Model (2020), which entity bears primary responsibility for managing risks day-to-day?