GRC Internal Controls and Auditing 5 — Questions and Answers
Question 1: What is the PRIMARY objective of an internal audit function according to the IIA Standards?
- Ensure compliance with all laws and regulations
- Add value and improve the organization's operations through assurance and consulting (Correct answer)
- Detect and investigate all instances of fraud
- Prepare financial statements for external reporting
Correct answer: Add value and improve the organization's operations through assurance and consulting
The IIA defines internal audit's mission as enhancing and protecting organizational value through risk-based assurance, advice, and insight.
Question 2: When an auditor evaluates whether controls would have prevented or detected a known fraud scheme, this is an example of:
- Compliance testing
- Fraud risk assessment (Correct answer)
- Retrospective control analysis
- Control gap analysis
Correct answer: Fraud risk assessment
Fraud risk assessment involves identifying fraud schemes and evaluating whether existing controls adequately prevent or detect them.
Question 3: Which concept requires that no single individual should be able to initiate, authorize, record, AND reconcile a transaction?
- Dual authorization
- Segregation of duties (Correct answer)
- Mandatory review
- Access control policy
Correct answer: Segregation of duties
Segregation of duties ensures that incompatible functions are divided across multiple people to reduce risk of error or fraud.
Question 4: A 'control deficiency' exists when:
- A control prevents all unauthorized transactions
- A control is missing or not operating effectively enough to prevent or detect misstatements (Correct answer)
- Management disagrees with auditor findings
- A control is overly complex and redundant
Correct answer: A control is missing or not operating effectively enough to prevent or detect misstatements
A control deficiency occurs when the design or operation of a control does not allow management to prevent or detect misstatements on a timely basis.
Question 5: What is the purpose of an audit committee in relation to internal controls?
- Conduct day-to-day internal audit activities
- Provide independent oversight of financial reporting and internal audit function (Correct answer)
- Approve all internal control policies
- Replace the need for external auditors
Correct answer: Provide independent oversight of financial reporting and internal audit function
The audit committee, composed of independent directors, oversees financial reporting integrity and serves as a liaison with internal and external auditors.
Question 6: Which audit testing approach starts from the financial statement balance and traces back to supporting source documents?
- Tracing (vouching forward)
- Vouching (tracing backward) (Correct answer)
- Analytical procedures
- Cut-off testing
Correct answer: Vouching (tracing backward)
Vouching tests for existence/occurrence by starting from recorded amounts and tracing back to source documents to verify they are real.
Question 7: In the context of internal auditing, what does 'independence' mean?
- The auditor has no formal reporting structure
- The internal audit function is free from conditions that threaten objectivity (Correct answer)
- Auditors are not employees of the company
- The audit is conducted without management's knowledge
Correct answer: The internal audit function is free from conditions that threaten objectivity
Independence means the internal audit function operates without interference or bias, typically reporting to the audit committee rather than operational management.
What is the PRIMARY objective of an internal audit function according to the IIA Standards?