AICPA Risk Management & Internal Control 1 — Questions and Answers
Question 1: What is the primary purpose of internal controls?
- To increase profits
- To eliminate all risks
- To ensure employee satisfaction
- To safeguard assets and ensure reliability (Correct answer)
Correct answer: To safeguard assets and ensure reliability
The primary purpose of internal controls is to safeguard an organization's assets, ensure the accuracy and reliability of its financial reporting, and promote operational efficiency and adherence to policies and laws. By establishing checks and balances, internal controls help prevent fraud, errors, and mismanagement. This contributes to the overall integrity and stability of the organization.
Question 2: Which framework is widely used to assess internal control systems?
- SOX
- COBIT
- COSO (Correct answer)
- GAAP
Correct answer: COSO
COSO (Committee of Sponsoring Organizations of the Treadway Commission) provides a widely recognized framework for designing, implementing, and assessing internal control systems. Its framework, 'Internal Control – Integrated Framework,' is a benchmark for organizations worldwide to establish effective internal controls. This helps ensure financial reporting integrity and operational effectiveness.
Question 3: Which of the following is an example of a preventive control?
- Audit logs
- Reconciliation
- Segregation of duties (Correct answer)
- Review of financial reports
Correct answer: Segregation of duties
Segregation of duties is a fundamental preventive control designed to reduce the risk of error and fraud by ensuring that no single individual has control over all aspects of a financial transaction. By dividing responsibilities among different people, it makes it harder for one person to commit and conceal irregularities. This control aims to stop undesirable events from occurring in the first place.
Question 4: What is risk appetite?
- The level of risk to be avoided at all costs
- The total possible loss from risk
- The willingness to accept risk to meet goals (Correct answer)
- The outcome of risk tolerance testing
Correct answer: The willingness to accept risk to meet goals
Risk appetite refers to the amount and type of risk an organization is willing to accept or take in pursuit of its objectives. It defines the boundaries within which the organization operates when making decisions involving risk. Understanding risk appetite is crucial for effective risk management, as it guides strategic choices and resource allocation.
Question 5: Which control activity involves verifying data accuracy after a process is completed?
- Preventive control
- Corrective control
- Detective control (Correct answer)
- Redundant control
Correct answer: Detective control
Detective controls are designed to identify errors, irregularities, or unauthorized activities *after* they have occurred. They do not prevent issues but rather alert management to problems so corrective action can be taken. Examples include reconciliations, reviews of financial reports, and audit logs, which verify data accuracy post-process.
Question 6: Which term refers to reducing the impact of a risk to an acceptable level?
- Risk elimination
- Risk transfer
- Risk retention
- Risk mitigation (Correct answer)
Correct answer: Risk mitigation
Risk mitigation involves implementing strategies and actions to reduce the likelihood or impact of a potential risk to an acceptable level. This can include various measures like implementing controls, diversifying investments, or improving processes. The goal is to lessen the severity of a risk, not necessarily eliminate it entirely, making it manageable for the organization.
Question 7: Which law mandates internal control assessments for public companies in the U.S.?
- GLBA
- HIPAA
- SOX (Correct answer)
- FERPA
Correct answer: SOX
The Sarbanes-Oxley Act (SOX) of 2002 is a federal law that mandates internal control assessments for public companies in the U.S. Specifically, Sections 302 and 404 require management and external auditors to report on the adequacy and effectiveness of the company's internal controls over financial reporting. This law was enacted to restore investor confidence after major accounting scandals.
Question 8: Who is ultimately responsible for an organization's risk management?
- Internal auditor
- IT department
- Board of Directors (Correct answer)
- External consultant
Correct answer: Board of Directors
The Board of Directors holds the ultimate responsibility for an organization's risk management. While management implements risk management processes, the board is responsible for overseeing these efforts, setting the risk appetite, and ensuring that the organization's risk exposure aligns with its strategic objectives. This oversight role is crucial for protecting shareholder interests and ensuring long-term sustainability.
Question 9: Which component of the COSO framework focuses on oversight and culture?
- Control Activities
- Monitoring
- Control Environment (Correct answer)
- Risk Assessment
Correct answer: Control Environment
The Control Environment component of the COSO framework sets the tone of an organization, influencing the control consciousness of its people. It encompasses the ethical values, integrity, competence, and philosophy of management, as well as the oversight responsibilities of the board of directors. A strong control environment is foundational for effective internal control across all other components.
What is the primary purpose of internal controls?