CRMA Internal Audit's Assurance Role 2 — Questions and Answers
Question 1: In the three-lines-of-defense model, internal audit occupies the third line primarily because it:
- Manages day-to-day operational risks directly
- Provides independent assurance to senior management and the board (Correct answer)
- Sets risk policy and risk appetite for the organization
- Coordinates risk oversight with external regulators
Correct answer: Provides independent assurance to senior management and the board
The third line (internal audit) provides independent, objective assurance over the effectiveness of risk management and controls operated by the first and second lines.
Question 2: When management requests that internal audit facilitate an ERM risk workshop, the MOST appropriate response is to:
- Decline entirely because any facilitation compromises objectivity
- Facilitate freely since it falls within normal assurance activities
- Accept only if no assurance will later be provided on the resulting framework (Correct answer)
- Accept and disclose the impairment of independence in the assurance report
Correct answer: Accept only if no assurance will later be provided on the resulting framework
IIA guidance allows internal audit to facilitate risk workshops as a consulting service, but doing so impairs objectivity for subsequent assurance work on that same area.
Question 3: Which activity would MOST compromise internal audit's independence when providing ERM assurance?
- Reviewing risk registers prepared by the risk management function
- Setting the organization's risk tolerance thresholds on behalf of management (Correct answer)
- Assessing the adequacy of management's risk identification process
- Recommending improvements to the ERM framework after the audit
Correct answer: Setting the organization's risk tolerance thresholds on behalf of management
Setting risk tolerance is a management responsibility; assuming that role removes internal audit's ability to independently assess those decisions.
Question 4: According to IIA standards, what most clearly distinguishes an assurance engagement from a consulting engagement?
- Assurance engagements are always initiated by the chief audit executive
- Consulting engagements require a written charter from the board
- Assurance engagements involve an independent assessment for a third-party stakeholder (Correct answer)
- Consulting engagements are limited to risk management topics only
Correct answer: Assurance engagements involve an independent assessment for a third-party stakeholder
Assurance engagements provide an objective assessment where the nature and scope are determined by internal audit for use by intended stakeholders, while consulting scope is defined by the client.
Question 5: Internal audit is reviewing risk management effectiveness. Management claims all key risks are within appetite. The BEST audit approach is to:
- Accept management's assertion and document it as audit evidence
- Independently verify that risk exposure measurements align with stated appetite thresholds (Correct answer)
- Escalate to the board without further testing since management may be biased
- Limit scope to controls testing and exclude risk appetite assessment
Correct answer: Independently verify that risk exposure measurements align with stated appetite thresholds
Effective assurance requires independent corroboration of management's risk assessments against documented appetite thresholds rather than reliance on assertion alone.
Question 6: A significant gap in ERM coverage is identified by internal audit. Who should receive this finding FIRST?
- External auditors so they can include it in their report
- Regulatory bodies because it represents a compliance breach
- Management, so they have an opportunity to remediate before board communication (Correct answer)
- The board audit committee directly, bypassing management
Correct answer: Management, so they have an opportunity to remediate before board communication
Standard practice requires informing management first so they can respond; internal audit escalates to the board if management does not act adequately.
Question 7: The scope of internal audit's assurance on risk management is BEST defined as:
- All operational processes regardless of risk level
- Only financial controls and compliance activities
- The adequacy and effectiveness of the organization's risk management processes (Correct answer)
- External threats identified by the risk management function
Correct answer: The adequacy and effectiveness of the organization's risk management processes
Internal audit's assurance role covers evaluating whether risk management processes are adequate and operating effectively to manage risks within the organization's risk appetite.
In the three-lines-of-defense model, internal audit occupies the third line primarily because it: