Internal Controls and Auditing Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Internal Controls and Auditing flashcards as text
Which element of the COSO Internal Control Framework addresses the organization's commitment to integrity and ethical values?
Answer: Control Environment
The Control Environment is the foundation of COSO and encompasses the tone at the top, ethical values, and organizational culture.
What is 'residual risk' in the context of internal controls?
Answer: Risk remaining after controls have been applied
Residual risk is the level of risk that remains after management has implemented controls to reduce inherent risk.
An internal auditor is reviewing access logs and finds that a privileged user accessed sensitive files outside of business hours. This is an example of what type of testing?
Answer: Computer-assisted audit technique (CAAT)
CAATs use automated tools to analyze electronic data, such as log files, to identify anomalies and test controls.
Which of the following BEST describes a 'material weakness' in internal controls?
Answer: A control deficiency where there is a reasonable possibility of material financial misstatement
A material weakness is the most severe level of deficiency, indicating a significant risk that financial statements could be materially misstated.
Job rotation as an internal control is PRIMARILY designed to:
Answer: Detect and deter fraud by reducing opportunity for concealment
Rotating employees through different roles limits the time any individual has to commit and conceal fraud.
What does 'inherent risk' represent in audit and risk assessment?
Answer: Risk that exists before any controls are implemented
Inherent risk is the susceptibility of an assertion to material misstatement assuming no related controls exist.
Which of the following is an example of an IT General Control (ITGC)?
Answer: Logical access controls restricting who can modify financial data
ITGCs include logical access, change management, and data center operations that support the reliability of application-level controls.