CRMA Planning Risk-Based Engagements 3 β Questions and Answers
Question 1: When presenting the risk-based engagement plan to the audit committee, the CAE should primarily communicate:
- Detailed timelines for every individual audit procedure
- How audit resources are allocated based on identified risk priorities (Correct answer)
- Results of all previously completed audit engagements
- Approval requests for each specific audit test step
Correct answer: How audit resources are allocated based on identified risk priorities
The audit committee needs high-level assurance that resources are directed toward the highest-risk areas, not procedural detail.
Question 2: Which stakeholder group typically provides the most valuable input during the risk identification phase of engagement planning?
- IT department personnel and data analysts
- External auditors and regulatory examiners
- Human resources specialists and training coordinators
- Senior management and business process owners (Correct answer)
Correct answer: Senior management and business process owners
Process owners and senior management have the deepest operational knowledge of risks within their specific areas.
Question 3: Assigning audit staff based solely on availability rather than competency primarily risks:
- Inadequate coverage of complex or specialized risk areas (Correct answer)
- Over-auditing familiar, low-risk, low-complexity areas
- Excessive reliance on contracted external specialists
- Missing regulatory filing deadlines for audit reports
Correct answer: Inadequate coverage of complex or specialized risk areas
Competency mismatches leave specialized or high-complexity risks inadequately assessed, undermining engagement quality.
Question 4: When coordinating with external auditors during risk-based planning, internal auditors should PRIMARILY:
- Defer all high-risk areas entirely to the external audit team
- Share risk assessments to eliminate duplication and fill coverage gaps (Correct answer)
- Restrict access to internal audit plans to preserve independence
- Conduct all planned engagements independently without any coordination
Correct answer: Share risk assessments to eliminate duplication and fill coverage gaps
Coordination between internal and external auditors increases efficiency and ensures no significant risk area goes uncovered.
Question 5: A key limitation of relying solely on management's risk self-assessments during engagement planning is:
- Management self-assessments always overstate risk severity
- Management may understate risks to avoid scrutiny or negative attention (Correct answer)
- Self-assessments automatically eliminate the need for independent review
- Management lacks sufficient visibility into its own operational processes
Correct answer: Management may understate risks to avoid scrutiny or negative attention
Management may have incentives to minimize reported risks, requiring internal audit to apply independent professional skepticism.
Question 6: Resource constraints require the CAE to reduce planned engagements. The BEST approach is to:
- Cancel all engagements until additional budget is approved
- Reduce engagements proportionally and equally across all risk levels
- Defer lower-risk engagements while maintaining focus on the highest-risk areas (Correct answer)
- Outsource the entire audit plan to an external accounting firm
Correct answer: Defer lower-risk engagements while maintaining focus on the highest-risk areas
Risk-based prioritization ensures that when resources are constrained, audit effort remains concentrated on the highest-risk areas.
Question 7: If internal audit identifies a significant emerging risk outside the current approved plan scope during planning, the CAE should:
- Ignore the risk because it falls outside the formally approved plan
- Assign the emerging risk assessment to external auditors without escalation
- Communicate the risk to senior management and the audit committee for consideration (Correct answer)
- Independently expand the plan to include the risk without notifying governance
Correct answer: Communicate the risk to senior management and the audit committee for consideration
Significant emerging risks must be escalated to governance bodies so the organization can decide on an appropriate response.
When presenting the risk-based engagement plan to the audit committee, the CAE should primarily communicate: