GRC Internal Controls & Audit Processes 5 — Questions and Answers
Question 1: What does 'inherent risk' represent in the audit risk model?
- Risk remaining after controls are applied
- The risk that controls will fail to detect a misstatement
- The susceptibility of an assertion to material misstatement before considering controls (Correct answer)
- The risk that the auditor issues an incorrect opinion
Correct answer: The susceptibility of an assertion to material misstatement before considering controls
Inherent risk is the natural susceptibility of an account or assertion to misstatement, independent of any internal controls.
Question 2: Which type of audit focuses on whether organizational activities conform to established policies and regulations?
- Operational audit
- Financial audit
- Compliance audit (Correct answer)
- IT audit
Correct answer: Compliance audit
A compliance audit evaluates whether the organization adheres to applicable laws, regulations, and internal policies.
Question 3: IT General Controls (ITGCs) primarily address:
- Business process controls within individual applications
- Pervasive controls over the IT environment that affect multiple systems (Correct answer)
- End-user training and awareness
- Physical security of employee workstations
Correct answer: Pervasive controls over the IT environment that affect multiple systems
ITGCs are foundational controls over the IT environment—such as change management, access controls, and operations—that support application-level controls.
Question 4: Management's response to an audit finding typically includes:
- A legal challenge to the auditor's conclusions
- Agreement or disagreement with the finding and a corrective action plan with a target date (Correct answer)
- Payment of a penalty to the internal audit department
- Reclassification of the finding as immaterial
Correct answer: Agreement or disagreement with the finding and a corrective action plan with a target date
Management responses address whether they concur with the finding and outline planned remediation steps and timelines.
Question 5: Which principle ensures that internal auditors are free from conditions that threaten their ability to carry out responsibilities objectively?
- Confidentiality
- Competency
- Independence and objectivity (Correct answer)
- Due professional care
Correct answer: Independence and objectivity
Independence and objectivity are foundational to the IIA Standards, ensuring auditors can report findings without bias or conflict of interest.
Question 6: A 'control gap' is BEST described as:
- A time delay between when a control operates and when it is tested
- A situation where a required control does not exist or is not operating effectively (Correct answer)
- The difference between planned and actual audit hours
- A missing signature on an audit work paper
Correct answer: A situation where a required control does not exist or is not operating effectively
A control gap exists when an identified risk has no corresponding control or the existing control is insufficient to mitigate that risk.
Question 7: Under the COSO ERM framework, 'risk appetite' is defined as:
- The maximum loss the organization can absorb before becoming insolvent
- The amount of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The total inventory of identified risks in the risk register
- The percentage of risks that have been mitigated
Correct answer: The amount of risk an organization is willing to accept in pursuit of its objectives
Risk appetite reflects the board-approved level of risk the organization is willing to take on while pursuing strategic goals.
What does 'inherent risk' represent in the audit risk model?