CRMA Planning Risk-Based Engagements 2 β Questions and Answers
Question 1: When building a risk-based engagement plan, which method BEST prioritizes auditable entities?
- Risk ranking by inherent risk and control effectiveness (Correct answer)
- Alphabetical ordering of business units
- Random sampling across all departments
- Selection based solely on management requests
Correct answer: Risk ranking by inherent risk and control effectiveness
Risk-based planning prioritizes entities by weighing inherent risk against the strength of existing controls.
Question 2: Which definition BEST describes inherent risk in the context of engagement planning?
- Risk remaining after controls are fully applied
- Risk that exists before any mitigating controls are considered (Correct answer)
- Risk identified only after an audit is completed
- Risk that has been formally accepted by the board
Correct answer: Risk that exists before any mitigating controls are considered
Inherent risk is the level of risk present in a process before any controls are applied or considered.
Question 3: A risk-based engagement plan should be formally updated when:
- A significant change in the organization's risk profile occurs (Correct answer)
- The internal audit department receives additional budget
- External auditors complete their annual financial audit
- Senior management schedules an all-hands training event
Correct answer: A significant change in the organization's risk profile occurs
Material changes to the risk environment require corresponding updates to the engagement plan to keep it relevant.
Question 4: On a risk heat map used during engagement planning, what do the two primary axes represent?
- Likelihood of occurrence and potential impact (Correct answer)
- Cost of audit and potential benefit
- Control strength and residual risk level
- Detection frequency and process complexity
Correct answer: Likelihood of occurrence and potential impact
Heat maps plot risks on a two-dimensional grid of likelihood and impact to visualize relative risk severity.
Question 5: When determining audit engagement frequency for a high-risk area, which factor is MOST critical?
- Number of full-time employees in the area
- Annual budget allocated to internal audit overall
- Historical audit findings indicating recurring control weaknesses (Correct answer)
- Operational manager's preferred audit schedule
Correct answer: Historical audit findings indicating recurring control weaknesses
Prior audit findings reveal patterns of control failure that directly inform how often a high-risk area requires audit attention.
Question 6: In risk-based engagement planning, 'residual risk' is best defined as:
- Risk that remains after management applies controls to mitigate inherent risk (Correct answer)
- The total organizational risk universe before any auditing occurs
- Risk that has been contractually transferred to a third-party vendor
- Risks surfaced exclusively through prior internal audit engagements
Correct answer: Risk that remains after management applies controls to mitigate inherent risk
Residual risk is what remains after controls are applied; internal audit assesses whether this level falls within the organization's risk appetite.
Question 7: The PRIMARY purpose of developing an audit universe is to:
- Document the results of all prior audit engagements
- Establish the annual budget for the internal audit function
- Assign specific auditors to departments in advance
- Identify and catalog all entities potentially subject to audit (Correct answer)
Correct answer: Identify and catalog all entities potentially subject to audit
The audit universe is a comprehensive inventory of auditable entities that forms the starting point for risk-based engagement selection.
When building a risk-based engagement plan, which method BEST prioritizes auditable entities?