RCMS Risk Assessment & Internal Controls 3 β Questions and Answers
Question 1: Segregation of duties is LEAST effective when which condition exists?
- Multiple employees share access to the same system (Correct answer)
- One person handles both transaction authorization and recording
- Supervisors review reconciliations monthly
- IT staff can modify application code without change control
Correct answer: Multiple employees share access to the same system
Shared system access alone does not eliminate segregation of duties; the critical failure is when one person controls conflicting functions such as authorization and recording.
Question 2: A financial institution uses stress testing to model the impact of a sudden 300 basis point interest rate spike. This activity primarily supports which risk management objective?
- Control environment assessment
- Scenario-based risk quantification (Correct answer)
- Compliance calendar planning
- Detective control enhancement
Correct answer: Scenario-based risk quantification
Stress testing applies hypothetical adverse scenarios to quantify potential losses, which is a form of scenario-based risk quantification.
Question 3: Which internal control principle requires that audit trails and transaction records be preserved and accessible for review?
- Authorization
- Documentation and record retention (Correct answer)
- Physical safeguards
- Independent verification
Correct answer: Documentation and record retention
Documentation and record retention ensures that all transactions are recorded and evidence is available for subsequent review or audit.
Question 4: A compliance team rates a vendor relationship as high-risk due to geographic location in a high-corruption jurisdiction. This rating is an output of which process?
- Third-party due diligence screening (Correct answer)
- Key risk indicator monitoring
- Business impact analysis
- Control gap assessment
Correct answer: Third-party due diligence screening
Third-party due diligence screening evaluates external parties based on factors including jurisdiction, ownership, and corruption indices to assign risk ratings.
Question 5: Which statement BEST describes a Key Risk Indicator (KRI)?
- A financial metric tracking quarterly revenue performance
- A forward-looking metric that signals increasing risk exposure before a loss occurs (Correct answer)
- A historical audit finding from the prior year assessment
- A regulatory penalty issued after a compliance failure
Correct answer: A forward-looking metric that signals increasing risk exposure before a loss occurs
KRIs are leading indicators designed to provide early warning of rising risk levels, allowing management to act before incidents occur.
Question 6: An organization discovers that a preventive control failed to stop a policy violation but an exception report flagged the transaction. Which control type caught the issue?
- Preventive control
- Detective control (Correct answer)
- Corrective control
- Directive control
Correct answer: Detective control
Detective controls, such as exception reports and reconciliations, identify issues that have already occurred after the preventive layer has failed.
Question 7: Control risk in the context of an internal audit engagement refers to:
- The risk that auditors will not detect a material misstatement
- The risk that internal controls will fail to prevent or detect a material error (Correct answer)
- The probability that a risk event will occur in the absence of any controls
- The likelihood that management will override existing controls
Correct answer: The risk that internal controls will fail to prevent or detect a material error
Control risk is the risk that an entity's internal controls will not prevent or detect a material misstatement on a timely basis.
Segregation of duties is LEAST effective when which condition exists?