FAC Internal Controls & Risk Assessment 2 — Questions and Answers
Question 1: Which COSO component focuses on a company's processes for identifying, assessing, and responding to risk?
- Control Activities
- Risk Assessment (Correct answer)
- Information & Communication
- Monitoring Activities
Correct answer: Risk Assessment
Risk Assessment is the COSO component dedicated to identifying and analyzing relevant risks that may prevent achievement of objectives.
Question 2: A control that prevents an error from occurring in the first place is classified as:
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Preventive controls are designed to stop errors or fraud before they occur, unlike detective controls that identify them after the fact.
Question 3: Inherent risk is best defined as:
- Risk remaining after management applies controls
- Risk before considering any mitigating controls (Correct answer)
- Risk arising from control failures
- Risk transferred to third parties
Correct answer: Risk before considering any mitigating controls
Inherent risk is the level of risk present in the absence of any internal controls or mitigating factors.
Question 4: Which document maps specific risks to the controls designed to address them?
- Audit trail
- Risk control matrix (Correct answer)
- Flowchart
- Control environment assessment
Correct answer: Risk control matrix
A risk control matrix links identified risks to the specific controls implemented to mitigate each risk.
Question 5: The 'tone at the top' concept in internal controls refers to:
- Setting numerical risk thresholds
- Management's attitude and commitment to ethical behavior and controls (Correct answer)
- Frequency of internal audits
- Hierarchical approval levels
Correct answer: Management's attitude and commitment to ethical behavior and controls
Tone at the top describes how senior leadership's values and actions shape the organization's overall control environment.
Question 6: Which risk response strategy involves accepting a risk without taking additional action?
- Risk avoidance
- Risk transfer
- Risk reduction
- Risk acceptance (Correct answer)
Correct answer: Risk acceptance
Risk acceptance means management decides to tolerate the risk, typically when the cost of mitigation exceeds the potential impact.
Question 7: A surprise cash count performed by an internal auditor is an example of which type of control?
- Preventive control
- Corrective control
- Detective control (Correct answer)
- Directive control
Correct answer: Detective control
A surprise cash count is a detective control because it identifies discrepancies or misappropriations after they have occurred.
Which COSO component focuses on a company's processes for identifying, assessing, and responding to risk?