CSCP Internal Controls & Auditing 2 — Questions and Answers
Question 1: Which control framework specifically addresses internal controls over financial reporting for publicly traded companies?
- COBIT 5
- COSO 2013 Framework (Correct answer)
- ISO 27001
- ITIL v4
Correct answer: COSO 2013 Framework
The COSO 2013 Internal Control – Integrated Framework is the primary standard used for evaluating internal controls over financial reporting under SOX Section 404.
Question 2: A 'detective control' in a securities firm is best exemplified by which of the following?
- Dual approval required before trade execution
- Automated pre-trade position limit checks
- Monthly reconciliation of broker statements to internal records (Correct answer)
- Segregation of duties between front and back office
Correct answer: Monthly reconciliation of broker statements to internal records
Monthly reconciliation is a detective control because it identifies errors or irregularities after transactions have already occurred.
Question 3: Under SOX Section 404(b), which party is required to attest to the effectiveness of a public company's internal control over financial reporting?
- The company's Chief Compliance Officer
- The company's external auditor (Correct answer)
- The company's internal audit department
- The company's audit committee
Correct answer: The company's external auditor
SOX Section 404(b) requires the registered public accounting firm (external auditor) to attest to and report on management's assessment of internal controls.
Question 4: What is the primary purpose of a 'walkthrough' in an internal audit of a securities firm?
- To physically inspect trading floor operations
- To trace a transaction from initiation through completion to verify controls operate as described (Correct answer)
- To interview all employees about their awareness of compliance policies
- To test a statistical sample of transactions for errors
Correct answer: To trace a transaction from initiation through completion to verify controls operate as described
A walkthrough traces a single transaction end-to-end to confirm that documented controls exist and function as described in process narratives.
Question 5: A broker-dealer's internal audit function discovers that a trader has been executing trades just below the reporting threshold to avoid detection. This activity is known as:
- Front-running
- Structuring (Correct answer)
- Spoofing
- Churning
Correct answer: Structuring
Structuring involves breaking transactions into smaller amounts specifically to evade reporting thresholds, which is illegal under the Bank Secrecy Act.
Question 6: Which of the following best describes the 'three lines of defense' model used in securities firm risk management?
- Regulators, external auditors, and board of directors
- Business lines, compliance/risk functions, and internal audit (Correct answer)
- Front office, middle office, and back office
- CEO, CFO, and General Counsel
Correct answer: Business lines, compliance/risk functions, and internal audit
The three lines of defense model designates business lines as the first line (own/manage risk), compliance/risk as the second line (oversee), and internal audit as the third line (independent assurance).
Question 7: When an internal auditor issues an 'adverse' opinion on internal controls, it means:
- Minor deficiencies were found that require management attention
- Significant deficiencies exist but no material weaknesses were identified
- A material weakness exists and internal controls are not effective (Correct answer)
- The auditor was unable to form an opinion due to scope limitations
Correct answer: A material weakness exists and internal controls are not effective
An adverse opinion on internal controls means the auditor has concluded that internal control over financial reporting is not effective due to the presence of a material weakness.
Which control framework specifically addresses internal controls over financial reporting for publicly traded companies?