GRC Internal Controls and Auditing 4 — Questions and Answers
Question 1: Which element of the COSO Internal Control Framework addresses the organization's commitment to integrity and ethical values?
- Risk Assessment
- Control Environment (Correct answer)
- Monitoring Activities
- Information and Communication
Correct answer: Control Environment
The Control Environment is the foundation of COSO and encompasses the tone at the top, ethical values, and organizational culture.
Question 2: What is 'residual risk' in the context of internal controls?
- Risk that has been fully eliminated by controls
- Risk remaining after controls have been applied (Correct answer)
- Risk identified during the audit but not yet remediated
- The risk of a control failure
Correct answer: Risk remaining after controls have been applied
Residual risk is the level of risk that remains after management has implemented controls to reduce inherent risk.
Question 3: An internal auditor is reviewing access logs and finds that a privileged user accessed sensitive files outside of business hours. This is an example of what type of testing?
- Substantive testing
- Compliance testing
- Computer-assisted audit technique (CAAT) (Correct answer)
- Physical observation
Correct answer: Computer-assisted audit technique (CAAT)
CAATs use automated tools to analyze electronic data, such as log files, to identify anomalies and test controls.
Question 4: Which of the following BEST describes a 'material weakness' in internal controls?
- A minor control gap with no financial impact
- A control deficiency where there is a reasonable possibility of material financial misstatement (Correct answer)
- Any failed control identified during an audit
- A weakness that only affects IT systems
Correct answer: A control deficiency where there is a reasonable possibility of material financial misstatement
A material weakness is the most severe level of deficiency, indicating a significant risk that financial statements could be materially misstated.
Question 5: Job rotation as an internal control is PRIMARILY designed to:
- Improve employee skills and morale
- Detect and deter fraud by reducing opportunity for concealment (Correct answer)
- Ensure business continuity
- Meet regulatory staffing requirements
Correct answer: Detect and deter fraud by reducing opportunity for concealment
Rotating employees through different roles limits the time any individual has to commit and conceal fraud.
Question 6: What does 'inherent risk' represent in audit and risk assessment?
- Risk after controls are applied
- Risk of a control failing to detect an error
- Risk that exists before any controls are implemented (Correct answer)
- Risk introduced by the auditor's methodology
Correct answer: Risk that exists before any controls are implemented
Inherent risk is the susceptibility of an assertion to material misstatement assuming no related controls exist.
Question 7: Which of the following is an example of an IT General Control (ITGC)?
- A three-way invoice match in accounts payable
- Logical access controls restricting who can modify financial data (Correct answer)
- Monthly bank reconciliation review
- Dual authorization for wire transfers
Correct answer: Logical access controls restricting who can modify financial data
ITGCs include logical access, change management, and data center operations that support the reliability of application-level controls.
Which element of the COSO Internal Control Framework addresses the organization's commitment to integrity and ethical values?