FAC Internal Controls & Risk Assessment 3 — Questions and Answers
Question 1: Under the COSO framework, which component ensures that relevant information is captured and shared in a timely manner?
- Control Environment
- Monitoring Activities
- Information & Communication (Correct answer)
- Control Activities
Correct answer: Information & Communication
Information & Communication is the COSO component focused on capturing and sharing information needed to support internal control functions.
Question 2: Residual risk is:
- The original risk before any controls
- The risk transferred to an insurer
- The risk remaining after controls are applied (Correct answer)
- The risk identified during external audit
Correct answer: The risk remaining after controls are applied
Residual risk is the level of risk that remains after management has implemented controls to mitigate inherent risk.
Question 3: Which of the following best represents a compensating control?
- Requiring two approvals when a normal segregation of duties is not feasible (Correct answer)
- Encrypting all financial data
- Monthly bank reconciliations
- Automated transaction matching
Correct answer: Requiring two approvals when a normal segregation of duties is not feasible
Compensating controls substitute for primary controls that cannot be implemented, such as dual approvals when duties cannot be fully segregated.
Question 4: An organization's risk appetite is best described as:
- The maximum loss the company can absorb before insolvency
- The amount of risk management is willing to accept in pursuit of objectives (Correct answer)
- The total of all identified risks in a period
- The probability of a material misstatement
Correct answer: The amount of risk management is willing to accept in pursuit of objectives
Risk appetite defines how much risk an organization is willing to take on while pursuing its strategic goals.
Question 5: Which audit technique tests whether controls are operating effectively over a period of time?
- Walkthrough
- Test of controls (Correct answer)
- Substantive testing
- Analytical procedure
Correct answer: Test of controls
Tests of controls evaluate whether internal controls are designed and operating effectively throughout the audit period.
Question 6: A control deficiency that does NOT rise to the level of a significant deficiency is called:
- Material weakness
- Control gap
- Control deficiency (Correct answer)
- Reportable condition
Correct answer: Control deficiency
A control deficiency exists when a control's design or operation fails to allow timely detection of a misstatement but is not severe enough to be significant.
Question 7: Which framework is most commonly used for enterprise risk management (ERM) in the United States?
- ISO 31000
- COSO ERM Framework (Correct answer)
- Basel III
- SOX Section 302
Correct answer: COSO ERM Framework
The COSO ERM Framework (2017) is the predominant standard used by US organizations to design and evaluate enterprise risk management processes.
Under the COSO framework, which component ensures that relevant information is captured and shared in a timely manner?