Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

IIA IIA-CIA-Part1 Internal Audit Fundamentals Exam Practice Test

Internal Audit Fundamentals Questions and Answers

Question 1

Which of the following describes the primary objective when implementing a risk management framework?

Options:

A.

To achieve planned profitability for business expansion.

B.

To enhance an organization ' s confidence in achieving strategy.

C.

To strengthen corporate governance standards.

D.

To eliminate business risks and uncertainties.

Question 2

An organization has limited resources to spend on corporate social responsibility initiatives. Which is the most suitable approach to determine how these resources should be used?

Options:

A.

Support a mix of environmental economic and social initiatives to ensure a balanced approach is taken

B.

Survey employees and external stakeholders to see which causes are best suited to the organization.

C.

Select corporate social responsibility initiatives that support the overall strategic goals of the organization

D.

Conduct a financial analysis to determine where the most impact can be made with the budget available

Question 3

Which of the following actions should the organization ' s governing body perform to provide the most effective governance over the organization ' s culture?

Options:

A.

Coordinate control activities.

B.

Provide direction.

C.

Design key controls.

D.

Deliver assurance.

Question 4

Which of the following statements is true regarding the role of the internal audit activity in the organization ' s risk management process?

Options:

A.

The internal audit activity should not be responsible for developing the organization ' s risk management framework, even with appropriate safeguards.

B.

The internal audit activity is typically responsible for alerting operational management to emerging risks and changes in regulatory scenarios

C.

The internal audit activity may coach management on risk response scenarios if safeguards have been implemented.

D.

The internal audit activity should avoid giving assurance regarding the accuracy of risk evaluations if safeguards have not been implemented.

Question 5

An organization allows the same individuals to physical access inventory and purchase new assets when supplies are depleted. Which of the following would best help the organization manage the risk of fraud?

Options:

A.

Accounting personnel should regularly perform reconciliation between invoices and purchase orders

B.

Accounting personnel should conduct a periodic inventory count and reconcile inventory movements

C.

internal auditors should review Vie frequency and volume of purchased assets to detect trends in the inventory levels

D.

Management should established a policy requiring new inventory asset purchases to be made on serialized order forms with copies retained

Question 6

Internal controls belong to which risk response category?

Options:

A.

Reduction.

B.

Avoidance.

C.

Sharing.

D.

Acceptance.

Question 7

While auditing an organization ' s credit approval process, an internal auditor learns that the organization has made a large loan to another auditor ' s relative. Which course of action should the auditor take?

Options:

A.

Proceed with the audit engagement, but do not include the relative ' s information.

B.

Have the chief audit executive and management determine whether the auditor should continue with the audit engagement.

C.

Disclose in the engagement final communication that the relative is a customer.

D.

Immediately withdraw from the audit engagement.

Question 8

Which of the following scenarios best illustrates due professional care?

Options:

A.

An internal auditor who previously worked in the payroll department within the last year was intentionally excluded by the chief audit executive from the audit team assigned to a payroll audit

B.

While performing a payroll audit an auditor became skeptical about significant payments made to a manager. The auditor sought to determine whether these payments were reasonable through discussion with a manager in a different department in the organization

C.

The head of the payroll department being audited is a business partner of the engagement supervisor During the audit the engagement supervisor sought to maintain his objectivity by not participating in fieldwork

D.

An auditor assigned to a payroll audit was unable to reperform some complex payroll computations for a small number of employees The sum of these payments was below the materiality thresholds provided so the auditor did not perform further tests

Question 9

Which of the following is the best example of a computer forensic audit activity?

Options:

A.

An internal auditor compared vendor addresses to employee home addresses.

B.

An internal auditor used analytical software to trace all disbursements processed on weekends.

C.

An internal auditor tried to circumvent the logical access controls of the purchasing system.

D.

An internal auditor recovered emails of an employee who was suspected of fraudulent activities

Question 10

Which of the following is most likely to impair the organizational independence of the internal audit activity?

Options:

A.

The chief audit executive (CAE) reports administratively to the chief financial officer.

B.

The CAE oversees the effectiveness of the organization’s risk management function.

C.

The CAE reports functionally to the CEO.

D.

The CAE managed the finance department for the past five years.

Question 11

Which of the following is an appropriate roe fa the internal audit activity?

Options:

A.

Ensuring the organization ' s key risks are managed through appropriate controls.

B.

Assisting the organization in maintaining effective controls.

C.

implementing new controls to promote continuous improvement

D.

Validating control assessments performed by the external auditor.

Question 12

Which of the following would be the most appropriate first step for the board to take when developing an effective system of governance?

Options:

A.

Determine the organization’s overall risk appetite.

B.

Establish a governance committee.

C.

Delegate authority to members of senior management.

D.

Identify key stakeholders and their expectations

Question 13

In its five years of existence, an internal audit activity conducted a single internal assessment of its quality assurance and improvement program (QAIP). The results of that assessment showed that the internal audit activity did not conform with the Standards. Prior to this, an external assessment of the internal audit activity ' s QAIP was conducted, which reported that the internal audit activity was in conformance with the Standards. Considering the two assessments, what would be the internal audit activity ' s current state of conformance with the Standards?

Options:

A.

Conformance with the Standards.

B.

Nonconformance with the Standards

C.

Unable to determine conformance with the Standards.

D.

Partial conformance with the Standards

Question 14

According to IIA guidance, which of the following statements regarding ethics is true?

Options:

A.

Business ethics may vary within an organization with both domestic and foreign operations.

B.

Business ethics are universal in nature and organizations across the world are expected to comply with similar standards.

C.

A business ethics policy for an organization is established solely to direct the behavior and expectations of employees.

D.

Business ethics of an organization must remain independent from those of suppliers, customers, and business partners.

Question 15

Which of the following best describes the internal audit activity’s responsibility within a risk and control framework?

Options:

A.

The internal audit activity constitutes the first line of defense in effective risk management.

B.

The internal audit activity provides direction regarding internal controls implementation.

C.

The internal audit activity verifies that management has met its responsibility for implementing effective controls.

D.

The internal audit activity implements the internal control framework and advises management regarding best practices.

Question 16

Which of the following describes a primary responsibility for the internal audit activity in helping management maintain effective controls?

Options:

A.

Promoting continuous evaluation

B.

Promoting continuous monitoring

C.

Promoting continuous improvement

D.

Promoting continuous reporting

Question 17

A risk assessment showed that the cost of addressing a particular risk in the organization ' s human resources department is greater than the perceived benefit. Which risk response approach should the organization take in this scenario?

Options:

A.

Reduce the risk.

B.

Transfer the risk.

C.

Accept the risk.

D.

Share the risk.

Question 18

According to IIA guidance, which of the following statements is true of assurance services provided by the internal audit activity?

Options:

A.

Internal auditors cannot assess an operation for which they were responsible within the previous year.

B.

Management of the area under review must agree with the engagement objectives, scope, and techniques.

C.

The engagement results will vary in form and content depending upon the needs and wishes of the engagement client.

D.

The only parties involved in the engagement are the internal auditor and management of the area under review.

Question 19

In a retail organization, sales teams compete with each other to achieve and exceed sales targets. Each quarter, the members of the top sales team receive a bonus. In this environment, management should closely monitor for the emergence of which of the following potential risks?

Options:

A.

Risks related to employee turnover.

B.

Risks related to data manipulation.

C.

Risks related to employee competency.

D.

Risks related to not achieving sales targets.

Question 20

Management assessed the organization’s risk of expanding operations into a new, but volatile, region and began looking for a compatible local partner to manage sales and distribution. Which of the following best describes this risk management technique?

Options:

A.

Avoidance.

B.

Acceptance.

C.

Reduction.

D.

Sharing

Question 21

According to IIA guidance which of the following statements regarding ethics is true?

Options:

A.

Business ethics may vary within an organization with both domestic and foreign operations

B.

Business ethics are universal n nature and organizations across the world are expected to comply with smear standards

C.

A business ethics policy for an organization s established solely to direct me behavior and expectations of employees

D.

Business ethics of an organization must remain independent torn those of supplier’s customers and business partners

Question 22

Which of the following would best serve to deter unethical behavior and encourage internal auditors to be objective in their work?

Options:

A.

A requirement that internal auditors undergo objectivity training periodically

B.

Periodic communications reminding internal auditors of Standards requirements

C.

A review of the final audit report by the audit committee

D.

Ongoing monitoring and periodic internal quality assessments

Question 23

Operational management in the IT department has developed key performance indicator reports, which are reviewed in detail during monthly staff meetings. This activity is designed to prevent which of the following conditions?

Options:

A.

Knowledge/skills gap,

B.

Monitoring gap.

C.

Accountability/reward failure,

D.

Communication failure.

Question 24

Which of the following is most likely to result in the impairment of independence for the internal audit activity?

Options:

A.

The chief audit executive (CAE) has a dual reporting relationship within the organization.

B.

The CAE performs an audit of a functional area that is also under the CAE ' s oversight.

C.

The CAE has unrestricted access to information throughout the organization and to the board.

D.

The board is involved in decisions to hire or remove the CAE and in drafting and approving an internal audit charter.

Question 25

During a procurement process audit the internal audit activity undertakes a fraud risk assessment and considers a range of possible fraud scenarios within the process. Which of the following scenarios constitutes a pressure to commit fraud?

Options:

A.

An employee believes his poor compensation package justifies engaging in unethical behavior.

B.

The head of the department is the only signatory to purchase orders issued to third party contractors.

C.

Some employees strongly believe monetary gifts from vendors is a means of saving for life after employment.

D.

One of the employees was found to have an obsession with expensive jewelry

Question 26

Which principle of the HA Code of Ethics focuses on continuing education and professional development?

Options:

A.

Due professional care

B.

Professionalism

C.

Proficiency

D.

Competency

Question 27

Which of the following must be in existence as a precondition to developing an effective system of internal controls?

Options:

A.

A monitoring process,

B.

A risk assessment process.

C.

A strategic objective-setting process.

D.

An information and communication process.

Question 28

According to IIA guidance, which of the following actions by a new chief audit executive would be most appropriate to gain an understanding of the current level of knowledge, skills, and competencies required by an internal audit activity to fulfill its responsibilities?

Options:

A.

Identify gaps in the activity’s proficiency, based on criteria defined by a widely accepted competency framework.

B.

Have a quality assessment review performed by an expert external entity.

C.

Identify a mature internal audit activity to serve as a benchmark for measuring the internal audit activity’s competence.

D.

Assess whether members of the internal audit activity understand and apply the 11As mandatory guidance.

Question 29

An internal auditor assessed that the risk of steel theft at a plant is high. In response, the plant ' s management introduced a number of controls, including fences around the facility, a metal detector at the entrance, and monthly steel inventory counts. If the controls operate as intended, which of the following outcomes would the internal auditor hope to see?

Options:

A.

The inherent risk will be mitigated to a level lower than the residual risk.

B.

The inherent risk will be reduced to an acceptable level.

C.

The residual risk will be reduced to an acceptable level.

D.

The residual risk will be eliminated

Question 30

When the chief audit executive Is responsible for risk management in an organization, which of the following parties is responsible for overseeing the internal audit activity ' s assurance over risk management?

Options:

A.

The chief audit executive.

B.

A member of the compliance function.

C.

A party outside of the internal audit activity.

D.

A member of the risk management function.

Question 31

The internal audit activity completed its analysis of sample transactions to determine occurrences of double billings According to If A guidance, which of the following best demonstrates that internal auditors exercised due professional care during the review?

Options:

A.

Internal auditors found no instances of double billing and concluded there were no significant risks in this area.

B.

Internal auditors documented the scope and methodology of the data testing.

C.

Internal auditors discussed with management how data is safeguarded.

D.

Internal auditors received formal performance feedback from the engagement supervisor.

Question 32

The internal audit activity was denied access to expenditure and budget reports because they were considered to be confidential. This situation would result in which of the following limitations of the internal audit activity?

Options:

A.

Independence

B.

Integrity

C.

objectivity

D.

Authority

Question 33

According to NA guidance, which of the following provides the best evidence of conformance with the Standards with respect to the proficiency required of the internal audit activity?

Options:

A.

Discussions with the chief audit executive.

B.

A listing of employee profiles and certifications.

C.

Inquiry of external auditors.

D.

Validation by human resources.

Question 34

According to IIA guidance, which of the following activities is appropriate for an internal auditor to perform with regard to the organization ' s corporate social responsibility (CSR) program?

1. Determine whether the organization has adequate controls to achieve its CSR objectives.

2. Facilitate a management self-assessment of CSR controls and results.

3. Consult on the project design and implementation for the CSR program.

4. Exclude CSR-related external risks that are beyond the control of the organization.

Options:

A.

1 and 2 only.

B.

1, 2 and 3 only.

C.

2, 3, and 4 only.

D.

3 and 4 only.

Question 35

An automobile manufacturer will become one of the first in the industry to adopt a new inventory management software. Despite the system being new to the market, senior management believes that the benefits are great enough to offset the potential risks. Which of the following aspects of risk management does senior management’s decision best illustrate?

Options:

A.

Residual risk.

B.

Inherent risk.

C.

Risk tolerance.

D.

Risk appetite.

Question 36

According to IIA guidance, which policy, established by the chief audit executive, would most likely ensure internal audits are conducted with due professional care?

Options:

A.

The initial review of workpapers should be conducted after the final engagement report is issued.

B.

Independent internal assessments of the internal audit activity should be performed by entry-level staff as part of on-the-job training.

C.

Internal audit staff should be informed regularly of changes to policies and procedures.

D.

Training documents should be destroyed at the end of the year to create space for the next year ' s training documents.

Question 37

An organization established 20 years ago has had its internal audit activity in place for the last three years. Which of the following would allow the internal audit activity to accurately state that it is in conformance with the Standards ' ?

Options:

A.

Documented assessment was performed by the audit committee and confirmed conformance.

B.

Internal and external assessments are performed annually, and nonconformance results are reported to the board.

C.

The independent and objective judgement of the chief audit executive confirmed conformance with the Standards.

D.

Documented internal assessments are performed periodically and confirm conformance.

Question 38

Senior management is eager to assess the organization ' s risks with regard to electricity sales processes, but the senior management team does not know where to start. How can the internal audit activity assist?

Options:

A.

Outsource the identification of best practices for risk management to an external third party.

B.

Perform an audit engagement to identify risk management practices deployed in electricity sales processes.

C.

Recommend reporting the lack of risk management to government authorities and request guidance.

D.

Facilitate a self-assessment workshop with the employees responsible for process execution.

Question 39

According to IIA guidance, which of the following statements is true regarding consulting engagements performed by the internal audit activity?

Options:

A.

Consulting engagements typically involve four or five parties: the internal audit activity, engagement client, senior management, board, and sometimes the external auditor.

B.

The scope of a consulting engagement is determined by either the engagement supervisor or chief audit executive, and it is finalized prior to beginning fieldwork.

C.

According to the Standards, internal auditors are permitted to carry out certain management functions during a consulting engagement.

D.

A preliminary risk assessment may not be needed for consulting engagements, because the expectations and objectives of the engagement are determined by the engagement client.

Question 40

An internal auditor assessed the controls within his organization ' s payroll process and suspects that erroneous payments may have been made to a fraudulent bank account. What is the best course of action for the auditor to take?

Options:

A.

Speak to the payroll manager so he may investigate the auditor ' s observations.

B.

Continue to investigate the payments to confirm the accuracy of the observations, and determine whether further fraudulent payments have been made.

C.

Stop the audit and report the findings to senior management immediately.

D.

Escalate the concern to the engagement supervisor.

Question 41

Which of the following documents most directly describes the guidelines for and importance of the objectivity of internal auditors?

Options:

A.

Internal audit quality assessments.

B.

Internal audit charter.

C.

Internal audit plan.

D.

Internal audit reporting.

Question 42

The collaborating style for conflict resolution, where the parties promote assertiveness and work together to develop a mutually beneficial solution, is best used in which of the following situations?

Options:

A.

Parties are confident of the solution and are ready to defend it.

B.

There is a high level of trust among the parties.

C.

Resolution is time sensitive and a quick decision is necessary.

D.

The issue is more important to one patty than the others.

Question 43

With regard to organizational governance assurance, which of the following is an appropriate role for the internal audit activity ' ?

Options:

A.

Assess compliance with the organization ' s code of conduct

B.

Oversee the governance and risk management processes

C.

Initiate new organizational control processes

D.

Provide advice on organizational governance activities

Question 44

Management would like to self-assess the overall effectiveness of the controls in place for its 200-person manufacturing department. Which of the following client-facilitated approaches is likely to be the most efficient way to accomplish this objective?

Options:

A.

Workshops.

B.

Surveys.

C.

Interviews.

D.

Observation.

Question 45

Which of the following parties would be responsible for ongoing monitoring of the organization ' s corporate social responsibility activities to reduce its carbon footprint?

Options:

A.

Chief audit executive

B.

Facility operation manager

C.

Public relations manager

D.

Regulatory agency

Question 46

Which of the following actions would be most effective to help an internal auditor determine how successful the organization has been in communicating the existence of its ethics hotline?

Options:

A.

Reviewing the number of anonymous hotline allegations against employee complaints.

B.

Surveying employees to determine whether they are aware of the hotline.

C.

Benchmarking the average time to investigate hotline complaints.

D.

Tracking the number of hotline allegations per total number of employees.

Question 47

The accounting department asked the chief audit executive (CAE) to perform a review of suspicious transactions. The CAE was an accounting manager for the organization six months ago.

How should she respond to the request?

Options:

A.

Decline, if it is a consulting engagement, because she recently worked in the organization ' s accounting department.

B.

Accept, if it is an assurance engagement, as she has been out of the department long enough to not impair objectivity.

C.

Inform the accounting department that the engagement can take place in the future, once she has been removed from accounting for a longer period of time.

D.

Accept, if it is a consulting engagement with agreed-upon scope and services to be provided by the internal audit activity.

Question 48

Which of the following is a responsibility of the internal audit activity as it relates to risk and risk management?

Options:

A.

Evaluating and suggesting improvements to the risk management process.

B.

Establishing the organization ' s risk appetite.

C.

Determining whether the risk attitude is aligned with shareholder interests.

D.

Ensuring an adequate risk management system is in place.

Question 49

Which of the following is a primary responsibility of senior management with respect to ethical violations?

Options:

A.

Senior management provides oversight for the organization ' s ethical climate.

B.

Senior management promotes an ethical culture in the organization.

C.

Senior management assesses the effectiveness of the organization’s ethical programs.

D.

Senior management reviews major ethical policies in the organization for compliance

Question 50

Which of the following would show appropriate disclosure of nonconformance with the Standards?

Options:

A.

The chief audit executive (CAE) documented in the personnel file a critical conflict of interest involving an internal auditor on an upcoming contracting engagement.

B.

The CAE discussed with the board an issue regarding the internal audit activity performing an IT engagement without proper skills and knowledge.

C.

The CAE met with the peer review team to discuss an internal auditor ' s failure to meet the annual requirements for continuing professional education.

D.

The CAE revealed to operational managers that he failed to appropriately consider risks while he was developing the audit plan.

Question 51

Which of the following controls would best mitigate the risk of fraud in the bidding process?

Options:

A.

Have a bidding committee open the tender bids.

B.

Restrict the time to submit tender bids.

C.

Keep minutes of pre-bid meetings.

D.

Allow the higher tenders to rebid.

Question 52

An engagement supervisor noted that an internal auditor ' s personal relationship with a process owner resulted in the auditor providing a favorable and partial assessment during an audit within that process owner ' s area. According to MA guidance, which of the following should be used to manage this impairment?

Options:

A.

An internal audit charter.

B.

An employee disciplinary policy.

C.

A functional audit committee.

D.

A functional reporting placement.

Question 53

Which of the following circumstances would most likely be considered a potential red flag for fraud by the internal audit activity?

Options:

A.

The monthly payroll reports are not vetted to ensure terminated employees have been removed from the payroll system.

B.

The volume of nonroutine journal entries has steadily increased over time.

C.

The database of approved suppliers has not been reviewed in the last year.

D.

The recent employee survey indicates that some employees remain unaware of the organization’s whistleblower hotline.

Question 54

Which of the following would be an important aspect of an internal auditor ' s role in fraud management?

Options:

A.

Utilizing analytical techniques to actively discover instances of potential fraud

B.

Conducting fraud based audits to ensure that fraud will be detected during engagements

C.

Implementing fraud prevention controls to minimize and mitigate the risk of fraud

D.

Reporting instances of fraud discovered during engagements to regulatory bodies

Question 55

According to IIA guidance, the internal audit activity must be free from interference in which of the following areas in order to maintain organizational independence?

Options:

A.

Monitoring resources.

B.

Compensating the chief audit executive.

C.

Determining scope.

D.

Allocating internal costs.

Question 56

According to the IIA Code of Ethics, which of the following best describes the conduct of an internal auditor who demonstrates the principle of competency?

Options:

A.

The auditor is prudent in the use and protection of information acquired in the course of his work.

B.

The auditor does not accept anything that may impair or be presumed to impair his professional judgment.

C.

The auditor does not perform services in a particular area when he lacks skills in that area.

D.

The auditor performs work with honesty, diligence, and responsibility.

Question 57

Which of the following risk management techniques best describes the strategy of obtaining insurance to protect against losses due to bad weather conditions?

Options:

A.

Risk avoidance

B.

Risk reduction

C.

Risk acceptance

D.

Risk sharing

Question 58

The chief audit executive (CAE) has decided to outsource an audit of the organization ' s cloud governance in the annual audit plan. Why would the CAE outsource this audit?

Options:

A.

Lack of internal audit staff proficiency.

B.

Lack of audit planning.

C.

Lack of internal assessments.

D.

Lack of due professional care.

Question 59

Which of the following best demonstrates internal auditors performing their work with proficiency?

Options:

A.

Internal auditors meet with operational management at each phase of the audit process.

B.

Internal auditors adhere to The IIA’s Code of Ethics.

C.

Internal auditors work collaboratively with their engagement team.

D.

Internal auditors complete a program of continuing professional development.

Question 60

Which of the following is the best reason why the engagement supervisor should take care in explaining to local management the criteria that will be used to measure the effectiveness of the control environment?

Options:

A.

The assessment will cover soft controls and company values.

B.

The assessment will focus on the policy for a particular process.

C.

The assessment will lack a defined scope

D.

The assessment will probably uncover fraud risks.

Question 61

An internal auditor is finalizing an audit report on the effectiveness of the organization ' s overall system of internal control. Several audit tests were performed, and the only issue identified was that the CEO frequently asks employees to make exceptions or bypass the organization ' s standard written policies and procedures. Which of the following conclusions is most appropriate for the auditor to report?

Options:

A.

The auditor should indicate that the system of internal control is not effective.

B.

The auditor should indicate that the system of internal control is generally effective, except for the minor issue identified.

C.

The auditor should indicate that the system of internal control is effective.

D.

The auditor cannot express a conclusive opinion in the audit report.

Question 62

Which of the following best demonstrates that the internal audit activity is using due professional care?

Options:

A.

The internal audit activity reports directly to the board on the engagements it performs.

B.

Internal auditors undertake the necessary training to complete their audit work.

C.

The completion of engagements is based on the assumption that fraudulent activities may exist.

D.

Internal auditors consider the use of technology-based audit and other data analysts techniques

Question 63

Which of the following statements about internal audit consulting engagements is true?

Options:

A.

The primary purpose of a consulting engagement is to assess evidence and provide conclusions.

B.

The internal audit activity determines the nature and scope of work for the specific consulting engagement

C.

Internal auditors may provide consulting services relating to operations for which they had previous responsibilities.

D.

It is not appropriate to communicate control issues identified during consulting engagements to the board

Question 64

According to MA guidance, which of the following gives the internal audit activity the authority to request supporting documentation for the invoices of a third-party service provider?

Options:

A.

The internal audit policy manual.

B.

The internal audit charter.

C.

The board of directors.

D.

The quality assurance and improvement program.

Question 65

A chief audit executive (CAE) is considering hiring a candidate who most recently worked for a large public accounting firm What would be the CAE’s most likely concern regarding this candidate*?

Options:

A.

Low-level audit expertise

B.

Narrow industry experience

C.

MPotential conflict of interest

D.

Weak interpersonal skills

Question 66

Which of the following actions should the internal audit activity take during an audit engagement when examining the effectiveness of risk management processes?

Options:

A.

Evaluate how the organization manages fraud risk.

B.

Establish procedures for improving risk management processes.

C.

Ensure risk responses are aligned with industry standards.

D.

Verify that organizational objectives are aligned with each department’s objectives.

Question 67

The internal audit activity audited an organization ' s risk management function multiple times, and the recommendations that were made remain unaddressed by the head of risk management. Which of the following would be the next step for the internal audit activity?

Options:

A.

The internal audit activity should add value by implementing the recommendations on management ' s behalf.

B.

The chief audit executive (CAE) must discuss this matter with senior management and the board

C.

The CAE should determine which recommendations to implement based on the severity of the associated risks.

D.

The internal audit activity, led by the CAE. should assume responsibility for risk management function.

Question 68

An internal auditor is providing consulting services on an area he was responsible for three years ago. Part of the consulting scope covers a review of a performance measuring system that the auditor helped to develop. What is the best course of action for the auditor to take concerning the consulting service?

Options:

A.

Accept the consulting services only after receiving approval to do so from the board.

B.

Accept the consulting services. The objectivity won ' t be impaired if it has been more than a year since he last worked in the area under review.

C.

Refrain from providing the consulting service because he was responsible for that area and his objectivity will be impaired,

D.

Disclose the potential impairment to the customer before accepting the consulting engagement

Question 69

Which of the following best describes the board’s role in establishing effective organizational governance?

Options:

A.

The board is involved in approving operational policy

B.

The board monitors key processes and procedures

C.

The board has oversight responsibility for organizational resources

D.

The board approves management ' s detailed plans and objectives

Question 70

Which of the following items related to the quality assurance and improvement program should the chief audit executive report to the board?

Options:

A.

Ongoing monitoring results

B.

Periodic management assessment results

C.

Annual risk assessment results

D.

Internal auditors ' training evaluation results

Question 71

According to IIA guidance, which of the following best demonstrates that the chief audit executive is properly reporting the results of the quality assurance and improvement program to senior management and the board?

Options:

A.

Providing a written conformance statement to both senior management and the board.

B.

Giving copies of both external and internal assessments to the board.

C.

Keeping files of reports of ongoing external assessment monitoring.

D.

Retaining copies of board meeting minutes showing that discussions of assessments took place.

Question 72

Which of the following would be included in quality assurance and improvement program (QAIP) reporting?

Options:

A.

Descriptions of standardized work practices.

B.

Outcomes of internal audit key performance indicators.

C.

Conformance of individual engagements with the Standards,

D.

Annual summaries of consulting and audit engagements.

Question 73

Which of the following factors is most important for internal auditors to consider when prioritizing fraud risks?

Options:

A.

The organization’s code of conduct.

B.

The organization’s competition.

C.

The organization’s code of ethics.

D.

The organization’s culture

Question 74

Which of the following best describes the internal audit activity ' s contribution to the implementation of the risk management framework?

Options:

A.

Internal audit identifies key risk areas during assurance reviews and provides audit findings.

B.

Internal audit assists with the prioritization of identified risks.

C.

Internal audit participates in setting the risk appetite.

D.

Internal audit takes part in the design of risk mitigation measures.

Question 75

Senior management asks the chief audit executive to review the organization ' s compliance with recently introduced legislation on international transfer pricing. The review requires an internal auditor who thoroughly understands the legislation and pricing methods. The internal audit activity does not have an auditor with those skills. Which of the following is the most appropriate course of action?

Options:

A.

Outsource the engagement to an external audit firm that has appropriate skills.

B.

Recruit a lawyer with knowledge of the legislation to the audit team and ask the new auditor to perform the engagement.

C.

Decline to perform the engagement, as the internal audit activity does not have the appropriate skill set.

D.

Carry out the engagement using existing internal audit staff to help them gain the appropriate experience.

Question 76

Which of the following is the primary benefit of establishing a formal training program for the internal audit activity?

Options:

A.

It is useful to reinforce the independence of the internal audit activity.

B.

It is useful to guide internal auditors as they perform specific engagements.

C.

It is useful to maintain the skills and competencies of internal audit staff.

D.

It is useful to measure the effectiveness and maturity of the internal audit activity.

Question 77

At the beginning of an IT development project, key risks were identified and assessed, and risk owners were appointed. Six months later, the IT development team reported that the project is significantly over budget, it will not be completed on time, and key personnel had left the organization. Which of the following risk management practices should be improved for future projects?

Options:

A.

Risk response

B.

Risk assessment

C.

Risk monitoring

D.

Risk avoidance

Question 78

According to The IIA’s Code of Ethics, which of the following scenarios offers the best example of violating the principle of integrity?

Options:

A.

An internal audit manager collaborates with senior management to provide misleading information to government authorities.

B.

An internal audit manager provides sample audit reports and workpapers to a friend without obtaining prior approval

C.

An internal audit manager carries out a technical audit request without seeking expert opinion, despite a lack of the requisite skills.

D.

An internal audit manager assigned to audit a sales process failed to reveal that the process owner is a relative

Question 79

Which of the following strategies would be the most effective to share an organization ' s risk of losses through foreign currency transactions related to the accounts payable process?

Options:

A.

Using a hedging strategy.

B.

Implementing controls to follow up on deviations.

C.

Purchasing liability insurance.

D.

Purchasing foreign currency reserves.

Question 80

During an assurance engagement, an internal auditor identified that a developer of the organization ' s enterprise resource planning (ERP) system had intentionally modified the production code to commit a fraudulent transaction. Which control activity should be implemented to prevent such issues in the future?

Options:

A.

Segregate duties between code development and migrating changes into production.

B.

Conduct fraud training for the IT team responsible for the ERP system.

C.

Penalize the developer who committed the fraud by terminating employment.

D.

Restrict developers ' access to the ERP system ' s test environment.

Question 81

Which of the following is a detective control strategy against fraud?

Options:

A.

Requiring employees to attend ethics training.

B.

Performing background checks on employees.

C.

Implementing a control self-assessment.

D.

Performing a surprise audit

Question 82

Which of the following most accurately describes corporate social responsibility at an organization?

Options:

A.

An organizational locus on improving the overall environment, even it is to the detriment of the local community.

B.

A philosophy driven by employees that flows up to senior management and the board of directors.

C.

An overall commitment of the organization to improve the quality of life for not only the employees but the community at large.

D.

A policy of ensuring that the organization is socially responsible, even if it leads to unprofitability due to increased costs.

Question 83

In order for an internal auditor to assess the opportunity for fraud to occur in an organization, which of the following does the auditor first need to understand?

Options:

A.

Fraud prevention.

B.

Fraud detection.

C.

Corporate culture.

D.

Forensic analysis techniques.

Question 84

Which of the following is an area that an organization would most likely include as part of its corporate social responsibility reporting?

Options:

A.

The profitability impact of its products in developing markets.

B.

The amount of political donations to local government races.

C.

The number of complaints related to traffic from its new factory.

D.

The compensation packages awarded to senior management.

Question 85

Which of the following would provide the best support for internal auditors to meet their continuing professional development requirements?

Options:

A.

Access to online internal audit and business skills courses.

B.

Records of self-assessment reports completed by the internal audit staff.

C.

Cosourcing arrangements with external providers on specific engagements.

D.

Performance reviews comparing internal auditors ' achievements against specified goals.

Question 86

Who is responsible for setting the risk appetite?

Options:

A.

External auditors.

B.

Chief risk officer.

C.

Operations management.

D.

Board of directors.

Question 87

A financial services organization ' s board is assessing increased regulations and its effect on current industry lending practices. Which of the following committees would help the board identify and assess the effects of the increased regulations?

Options:

A.

Quality committee.

B.

Audit committee.

C.

Risk committee.

D.

Governance committee.

Question 88

An internal auditor has completed an assurance engagement Which of the following is most likely true regarding the engagement?

Options:

A.

During audit planning, the auditor provided the client with the scope of the engagement for their agreement

B.

The results of the engagement were included in a written report that was issued to the client who requested the engagement

C.

During audit planning, the auditor determined that the engagement scope would include a review of the security and privacy of payroll records

D.

The client requested the review of a new payroll system in order to improve the security of the system

Question 89

Which of the following activities aligns with The IIA ' s Core Principles for the Professional Practice of Internal Auditing?

Options:

A.

The chief audit executive reports to senior management for compensation decisions and communications of audit results to the board

B.

Final reports from consulting engagements show the summary of findings, and the internal auditor’s advice is clearly distinct and separate from management ' s decisions

C.

Internal auditors rotate through operations and management positions then perform audit engagements on these areas to ensure timely application of their knowledge

D.

Due to limited resources, internal auditors prioritize assurance on internal controls and risk management and exclude evaluating governance processes, which are deemed outside of their core responsibilities

Question 90

Guidelines need to be set for various levels of suspected fraud within an organization and when it would be reported to the audit committee. Which of the following would be

reported at the next meeting?

Options:

A.

Minor theft of less than $10,000, not involving senior management.

B.

Theft using collusion for more than $10,000. but not involving senior management.

C.

Denial of access to requested employees during an audit.

D.

Discussion of replacement of the chief audit executive.

Question 91

According to IIA guidance, which of the following is an appropriate role for the internal audit activity?

Options:

A.

Coaching management in responding to risks.

B.

Implementing risk responses on management ' s behalf.

C.

Imposing risk management processes.

D.

Setting the risk appetite.

Question 92

In which of the following situations has the internal auditor violated the IIA ' s Code of Ethics?

Options:

A.

An employee confided in an internal auditor and told him about fradulent activities. Although the employee asked for confidentially, the auditor disclosed her identity later during police questioning.

B.

While auditing payroll controls, an auditor was granted temporary access to salary data. The auditor referred to the acquired information while negotiating her work conditions three months later.

C.

Management considers an auditor to be highly competent and asked the audit to participate in an upcoming acquisition project. The auditor declined the request, calming a lack of knowledge.

D.

An internal auditor failed to acquire the continuing education credits needed for the year and requested that. The IIA change his certification status to inactive until the completed the required education activities.

Question 93

Which of the following would be the most effective in helping to detect fraud?

Options:

A.

Code of conduct.

B.

Exit interviews.

C.

Fraud awareness training

D.

Employee promotion policy.

Question 94

Who is held responsible for oversight of the organization ' s risk management framework?

Options:

A.

Operational management.

B.

Board of directors.

C.

Internal auditors.

D.

Head of risk management.

Question 95

An organization ' s board has approved an expansion plan into a new market. The board acknowledged that if the expansion is not successful, the organization would encounter large monetary losses consisting of legal fees, research and development costs, rent expenses, and labor fees. Which of the following has the board approved?

Options:

A.

The risk response.

B.

The risk tolerance.

C.

The residual risk.

D.

The inherent risk.

Question 96

As part of a fraud investigation by regulators, a court order was issued to a bank. The court order requested the chief audit executive (CAE) to provide access to a number of audit reports and workpapers, some of which included customers ' confidential information such as transaction activity and other personal details. What is the appropriate response by the CAE?

Options:

A.

Reject the court order, citing a potential breach of customers ' confidentiality agreement

B.

Consult with legal counsel to determine what information to provide.

C.

Respond promptly and provide all that was requested by the court order.

D.

Seek permission from customers prior to sharing their information.

Question 97

Which of the following should be considered in developing a risk and control model for use in an engagement?

Options:

A.

The risk and control model should be globally accepted by the profession.

B.

The risk and control model should be strictly adhered to in performing the engagement.

C.

The risk and control model should be tailored to the organization that will be the subject of the engagement.

D.

The risk and control model should be developed individually by the auditor for use on individual audit projects within the planned engagement.

Question 98

Which of the following would best preserve the organizational independence of the internal audit activity?

Options:

A.

The internal audit charter is approved by the chief audit executive (CAE).

B.

The CAE reports functionally to the CEO.

C.

The CAE ' s internal audit plan is endorsed by the board.

D.

The chief financial officer determines the appointment of the CAE.

Question 99

During an audit engagement, a junior staff internal auditor begins to suspect a fraud may have occurred involving a friend of the engagement supervisor. He reports his concerns to the engagement supervisor, who disagrees with his suspicions and directs him to continue with the engagement as planned. Given the circumstance, what is the most appropriate action for the junior auditor to take?

Options:

A.

Document in the workpapers and expand testing.

B.

Continue with the engagement as planned, per the more senior auditor.

C.

Report the suspected fraud to law enforcement officials and seek financial restitution.

D.

Escalate the concern to the chief audit executive.

Question 100

Which of the following describes a responsibility of operating management in an organization ' s corporate social responsibility (CSR) efforts?

Options:

A.

Responsible for implementing CSR principles and overseeing of CSR performance.

B.

Responsible for performing periodic internal self-verifications of reported CSR results.

C.

Responsible for performing analysis and comparison of CSR reports and performance.

D.

Responsible for ongoing CSR reporting and accomplishing of performance targets.

Question 101

Which of the following is the primary engagement responsibility of an entry-level internal auditor?

Options:

A.

Leadership.

B.

Documentation.

C.

Analysis.

D.

Reporting.

Question 102

Which type of engagement requires that the client agrees with the techniques used by the internal audit activity?

Options:

A.

A performance audit.

B.

A sensitive fraud investigation.

C.

A compliance audit

D.

A consulting service.

Question 103

Which of the following statements would typically be included in the responsibility section of the internal audit charter?

Options:

A.

The internal audit activity will have free and unrestricted access to the chief executive officer, audit committee, and chairman of the board of directors.

B.

The internal audit activity shall develop a flexible audit plan, based on a risk assessment conducted at least annually and taking into consideration the risks or control concerns identified by management, and shall submit the plan to the board for approval.

C.

The chief audit executive shall obtain the necessary assistance of personnel in areas where audits are performed, as well as specialized services within or outside of the organization.

D.

The internal audit activity will not implement controls, develop procedures, install systems, prepare records, or engage in activities that may impair internal auditors’ judgments.

Question 104

During a payroll audit, the internal auditor discovered that several individuals who have the same position classification as he are earning a significantly higher salary. The auditor noted the names and amounts of each, and he planned to prepare a request to the chief audit executive for a salary increase based on this information. Which of the following IIA Code of Ethics principles was violated in this scenario?

Options:

A.

Competency.

B.

Objectivity,

C.

Integrity.

D.

Confidentiality

Question 105

Which of the following disclosures must the chief audit executive (CAE) include when communicating the results of the quality assurance and improvement program to senior management and the board?

Options:

A.

Authority and responsibility of the internal audit activity

B.

Hours and sources of continuing professional education

C.

Scope and frequency of both the internal and external assessments

D.

independence and objectivity impairments of the CAE

Question 106

According to IIA guidance, which of the following actions best demonstrates that due professional care has been considered by the internal audit activity when conducting a review of an organization ' s assets?

Options:

A.

Determining whether any opportunity exists for senior executives to misappropriate property or funds

B.

Planning and executing fieldwork In a complete and timely manner to identify all significant risks

C.

Verifying whether the board of directors has implemented effective internal controls

D.

Having senior management determine whether the degree of work planned is sufficient to meet engagement objectives

Question 107

A chief audit executive ensures that the internal audit activity provides annual training to management on internal controls. Where is the nature of these services defined?

Options:

A.

The annual audit plan.

B.

The audit report.

C.

The annual risk assessment.

D.

The audit charter.

Question 108

According to IIA guidance, which of the following is an appropriate role for the internal audit activity?

Options:

A.

Coaching management in responding to risks.

B.

Implementing risk responses on management’s behalf.

C.

Imposing risk management processes.

D.

Setting the risk appetite.

Question 109

Which of the following situations would best indicate to the chief audit executive that one of the audit team members is struggling with application of due professional care?

Options:

A.

The engagement supervisor requests that an auditor carry out improvements to workpapers to address numerous problems: evidence is missing, references are incorrect, and conclusions are superfluous

B.

Audit work was completed m accordance with the established goals; however, a material misstatement was later uncovered in the audited area by another assurance provider.

C.

According to the audit report, several control failures occurred due to irresponsible behavior of local management, who was consequently deprived of bonuses and wrote a negative feedback to the auditor

D.

The delivery of audit results was several weeks late because the internal auditor had to spend additional time trying to understand the nature of certain transactions with derivation.

Question 110

Which of the following is an example of an entity-level control pertaining to the finance area of an organization ' ?

Options:

A.

Key account reconciliation such as bank reconciliation

B.

Segregation of duties between posting and reviewing journal entnes

C.

A signing authority matrix for spending approvals

D.

The establishment of a finance and audit committee

Question 111

In which of the following audits would the internal auditors most likely contribute to the assessment of organizational governance?

Options:

A.

An assessment of compliance of individual data protection procedures with data protection regulations

B.

An assessment of profit and loss generated by financial assets and instruments in the past quarter

C.

An assessment of the effectiveness of back-up procedures and execution of business recovery plans

D.

An assessment of performance management practices and establishment of key performance indicators

Question 112

Which of the following is true with regard to an organization ' s risk management practices?

Options:

A.

Risks represent a single point estimate

B.

Each organization faces the same types of risk.

C.

Risks may relate to failing to achieve positive outcomes.

D.

Mitigated risks are no longer considered to be inherent.

Question 113

Which of the following techniques should an internal auditor use in order to conduct an effective interview?

Options:

A.

Use technical language to establish credibility with the employee being interviewed

B.

Avoid straightforward questions to make the person being interviewed think before answering

C.

Prepare the next question while the interviewee is responding to demonstrate preparedness

D.

Appear confident but not arrogant during the interview to show professionalism

Question 114

Which of the following statements is true regarding the internal audit activity ' s quality assurance and improvement program (QAIP)?

Options:

A.

The QAIP scope includes assurance work performed by the internal audit activity but not consulting work.

B.

The QAIP verifies conformance with the Definition of Internal Auditing, Code of Ethics, and Standards.

C.

QAIP reports are for internal use primarily and typically are not shared with members outside of the internal audit activity.

D.

QAIPs make a distinction between fully outsourced internal audit activities and in-house internal audit teams, as a different set of criteria is applied for each.

Question 115

An internal auditor observed that sales staff are able to modify or cancel an order in the system prior to shipping* She wonders whether they can also modify orders after shipping. Which of the following types of controls should she examine?

Options:

A.

Batch controls.

B.

Application controls.

C.

General IT controls.

D.

Logical access controls

Question 116

Which of the following fundamental principles of The IIA ' s Code of Ethics is best described as performing work honestly diligently and responsibly?

Options:

A.

Integrity

B.

Proficiency

C.

Due Professional Care

D.

Competency

Question 117

An organization sells products through distributors. The organization ' s chief audit executive insists that the organization ' s code of conduct be applicable to their distributors as well. Which of the following risks would this mitigate?

Options:

A.

Business continuity

B.

Market manipulation

C.

intellectual property leakage

D.

Reputational damage

Question 118

Which of the following describes the internal audit activity ' s most appropriate role in an organization ' s risk management process?

Options:

A.

Reporting to the board on management ' s assessment of current risks

B.

Establishing a risk management policy and framework for the organization

C.

Assigning responsibility for identifying and managing significant risks

D.

Developing key controls to mitigate risks across the organization

Question 119

To encourage internal audit objectivity, which of the following is an appropriate policy the chief audit executive should establish?

Options:

A.

Internal auditors should report their audit findings directly to the audit committee.

B.

To receive an outstanding performance rating, internal auditors are required to generate audit findings.

C.

Prior to hiring a new internal auditor, the chief audit executive must determine whether the auditor owns stock in the organization.

D.

Internal auditors are permitted to audit an entity managed by a close friend or relative, as long as they notify the chief audit executive.

Question 120

The internal audit activity is performing an assessment of an organization ' s ethics program, and the engagement scope specifies a focus on the training program ' s design. According to IIA guidance, which of the following questions would be the most relevant?

1. Does the training include situations that require an ethical decision?

2. What percentage of employees have taken the training?

3. What are the results of the employee assessment of the organization ' s ethical climate?

4. Does the instructor provide feedback on the thought process to reach an ethical resolution?

Options:

A.

1 and 2.

B.

1 and 4.

C.

2 and 3.

D.

3 and 4.

Question 121

A new internal audit activity is considering the adoption of a risk and control framework. Which of the following is the most appropriate consideration during this process?

Options:

A.

The framework should not be developed by the internal audit activity

B.

The framework should apply to individual projects rather than the organization as a whole

C.

The framework should always be tailored to the organization

D.

The framework should require fewer resources to implement

Question 122

According to IIA guidance, which of the following actions by the chief audit executive (CAE) best demonstrates the organizational independence of the internal audit activity?

Options:

A.

The CAE seeks senior management approval of the internal audit charter

B.

The CAE obtains senior management ' s approval to hire staff

C.

The CAE reports significant issues to the organization ' s CEO

D.

The CAE provides the board with an annual budget for approval

Question 123

An internal auditor believes that a weakness exists in the control environment relating to the delegation of authority and responsibility within the management structure. Which of the following actions should the internal auditor first consider in this matter?

Options:

A.

Recommend a control change and obtain management support.

B.

Evaluate the potential Impact on related controls.

C.

Address the risk with senior management and the board.

D.

Develop and communicate the scope and evaluation criteria to be used by management.

Question 124

Which of the following statements relating to risk management is true?

Options:

A.

The high-level risk assessment performed during engagement planning is a detailed step-by-step analytical process

B.

External auditors must be engaged to evaluate the potential for fraud and how the organization manages fraud risk

C.

A lack of controls is acceptable if the risk is reduced to an acceptable level in some other way

D.

Internal auditors are responsible for managing the risks of the organization

Question 125

An internal auditor believes that a weakness exists in the control environment relating to the delegation of authority and responsibility within the management structure. Which of the following actions should the internal auditor first consider in this matter?

Options:

A.

Recommend a control change and obtain management support

B.

Evaluate the potential impact on related controls

C.

Address the risk with senior management and the board

D.

Develop and communicate the scope and evaluation criteria to be used by management

Question 126

Which of the following activities is most likely to require a fraud specialist to supplement the knowledge and skills of the internal audit activity?

Options:

A.

Planning an engagement of the area in which fraud is suspected.

B.

Employing audit tests to detect fraud.

C.

Interrogating a suspected fraudster

D.

Completing a process review to improve controls to prevent fraud

Question 127

An external assessment was performed as part of the organization ' s quality assurance and improvement program. Which of the following conclusions confirms that the internal audit activity is in conformance with the Standards ' ?

Options:

A.

The chief audit executive is well qualified and has responsibilities over operational areas that the internal audit activity assesses.

B.

Periodic self-assessments are assigned to entry-level internal audit staff to support their continuing professional development.

C.

All audit workpapers are reviewed and signed by the engagement supervisor before the audit report is issued.

D.

Employees who rotate into the internal audit activity from other areas of the organization are assigned to audit areas where they previously worked, to take advantage of their operational expertise and experience.

Question 128

Which of the following is a greater consideration for internal auditors when they are performing a consulting engagement than when they are performing an assurance engagement ' ?

Options:

A.

The relative complexity of the engagement

B.

The cost of the engagement relative to its benefits

C.

The extent of work needed to achieve the engagement ' s objective

D.

The needs and expectations of the engagement client

Question 129

An internal auditor is assessing the effectiveness of the organization ' s risk management practices. She checks to see whether risk management is an integral part of decision making and whether risk management is transparent, responsive to change, and addresses uncertainty. According to IIA guidance on risk management frameworks, which of the following approaches is the auditor most likely using?

Options:

A.

Maturity model approach.

B.

Process element approach.

C.

Key principles approach.

D.

Key performance indicators approach.

Question 130

Which of the following drivers of fraud is directly controllable by an organization?

Options:

A.

Pressure

B.

Rationalization

C.

Opportunity

D.

Incentive

Question 131

Anew internal auditor suspects fraud is taking place. Which action should the new auditor take?

Options:

A.

Collect relevant audit evidence and begin working with management of the area to investigate the fraud.

B.

Inform the chief audit executive and meet with the suspect to determine whether the person committed fraud.

C.

Document supporting information and recommend an investigation to the appropriate audit management.

D.

Evaluate existing controls and implement new procedures to mitigate the opportunity for fraud.

Question 132

According to IIA guidance, which of the following statements is true regarding risk management in an organization?

Options:

A.

The risk management function has the sole responsibility for identifying and managing risks in all departments

B.

Risk management is a core responsibility of the internal audit activity

C.

The internal audit activity should consider the organization’s maturity, structure, and the competitive environment to establish the organization’s risk appetite

D.

The internal audit activity may use a risk management or control framework to assist in risk identification

Question 133

Which of the following is the most appropriate way to ensure that a newly formed internal audit activity remains free from undue influence by management?

Options:

A.

Appoint the chief audit executive as a member of the board.

B.

Adopt written policies and procedures for the internal audit activity, approved by the board.

C.

Ensure the chief audit executive reports administratively to the audit committee.

D.

Establish the internal audit activity’s position within the organization in an audit charter.

Question 134

An internal auditor failed to identify transactions between the parent organization and a subsidiary. What is the most likely reason for the failure?

Options:

A.

The auditor misunderstood the audit objectives.

B.

The auditor lacked professional skepticism.

C.

The auditor ' s fieldwork was not properly supervised.

D.

The auditor lacked an understanding of the organization.

Question 135

Which of the following is a legitimate requirement for an internal audit activity’s quality assurance and improvement program (QAIP)?

Options:

A.

Quality assessments should be performed by individuals with sufficient knowledge of the internal audit practices

B.

External quality assessments should be conducted every seven years

C.

All quality assessments should be either conducted or validated by an independent assessment team

D.

The results of the QAIP should be communicated to shareholders annually

Question 136

The internal audit activity is undergoing a self-assessment as part of its quality assurance and improvement program. Which of the following observations must be addressed in order for the internal audit activity to achieve conformance with the Standards?

Options:

A.

The internal audit charter does not identify which audit services are outsourced.

B.

The internal audit charter has not been reviewed by the legal department.

C.

The internal audit charter has not been approved by the board within the past year.

D.

The internal audit charter does not describe the authority of the internal audit activity.

Question 137

Which of the following is an indicator that the organization s risk management process is effective?

Options:

A.

The organization s risk appetite mission, and objectives are dearly outlined.

B.

The organization s risk management practices are assessed as mature.

C.

The organization has adopted risk management frameworks and global models.

D.

The organization s significant risks are identified and adequately assessed

Question 138

After the draft engagement report is issued, the manager of the area that was reviewed is informally interviewed by the engagement supervisor regarding the audit experience. Which of the following is most likely the purpose for this interview?

Options:

A.

Such an interview is performed when there is a need to dismiss an internal auditor

B.

Feedback from the manager will contribute to the audit team ' s professional development

C.

The manager ' s opinion will be used to form the final audit assessment and report rating.

D.

The manager will provide insights into the audited industry ' s trends

Question 139

Which of the following is an example of a detective control?

Options:

A.

Automatic shut-off valve.

B.

Auto-correct software functionality.

C.

Confirmation with suppliers and vendors.

D.

Safety instructions.

Question 140

The internal audit activity is asked to review the effectiveness of controls around the disposal of chemical waste. However, the internal auditors on staff lack the necessary skills to conduct this review. Which of the following would be the most appropriate approach?

Options:

A.

An internal auditor who recently attended a three-day workshop on chemical waste disposal, and therefore has the most knowledge on the topic, should lead the engagement.

B.

A team of available internal auditors should be assembled and should consult with an external nonaudit expert on chemical waste disposal to plan and conduct the engagement.

C.

A team of the most knowledgeable auditors could be assembled and use the engagement work program from the previous year to gather additional insight regarding recommended audit procedures.

D.

A nonaudit employee from the chemical disposal area may share his expertise with the audit team, provided the internal audit manager conducts a detailed review of all engagement work performed.

Question 141

An internal auditor has suspicions that some fictitious vendors have been created in the organization ' s computer system. Which of the following would be the best technique to detect this fraud?

Options:

A.

Review for duplicate invoice numbers, duplicate dates, and duplicate amounts

B.

Run checks to find matches between vendor and employee addresses

C.

Check for recurring requests for refunds where invoices are paid twice

D.

Review for unexplained increases in inventory

Question 142

An internal auditor was completely honest with operational management when delivering unfavorable audit results. Which of the following best describes the IIA Code of Ethics principle that the auditor demonstrated?

Options:

A.

Integrity

B.

Objectivity

C.

Competency

D.

Transparency

Question 143

Which of the following is an example of the chief audit executive (CAE) demonstrating due professional care?

Options:

A.

The CAE relies on CAEs in other organizations to understand how due professional care should be executed in her internal audit activity

B.

The CAE meets with the board of directors on a quarterly basis to provide a status update.

C.

The CAE assesses the audit staff ' s knowledge and skills annually to determine whether additional resources are needed to fulfill the internal audit plan.

D.

The CAE provides absolute assurance to line management during each eternal audit engagement

Question 144

Which of the following organizations is adopting an acceptance technique in terms of its risk response?

Options:

A.

An organization that takes no action in managing the possible exposure to an earthquake.

B.

An organization that opts out of investing in a new region due to volatility in foreign exchange rates.

C.

An organization that takes out insurance policies to protect its property and equipment.

D.

An organization that deploys policies and procedures to guide business activities and practices

Question 145

According to IIA guidance, which of the following actions is a chief audit executive required to take with regard to reporting the results of the quality assurance and improvement program?

Options:

A.

Report external assessments upon completion of such assessments

B.

Report external assessments at least annually

C.

Report ongoing monitoring quarterly

D.

Report post-engagement reviews at least once every five years

Question 146

According to IIA guidance, which of the following is a required aspect of an internal audit charter?

Options:

A.

Management approval

B.

Independent review

C.

Reporting relationships

D.

Quarterly assessment

Question 147

In which of the following situations would the organizational independence of an internal audit activity be impaired?

Options:

A.

The chief audit executive reports administratively to the CEO.

B.

Scope limitations are imposed on internal audits.

C.

The internal audit activity provides assurance services for an activity for which the engagement supervisor had responsibility within the previous year.

D.

The compensation committee of the board approves the remuneration of the chief audit executive.

Question 148

The internal audit activity is responsible for conducting fraud investigations. A potential fraud instance was identified during an audit engagement. The chief audit executive appoints a lead investigator. Which of the following would most likely be the next step?

Options:

A.

Ask internal auditors to gather all relevant information and evidence.

B.

Identify and interview witnesses first and potential suspects later.

C.

Conduct a fraud risk assessment to identify the most vulnerable areas.

D.

Determine the competencies needed and assess whether team members have a conflict of Interest.

Question 149

Regarding the chief audit executive (CAE). which ot the following is considered an impairment to the independence of the internal audit activity?

Options:

A.

The CAE reports administratively to the CEO.

B.

The CAE is asked to submit the liquidation of her travel allowances to human resources for approval.

C.

The CAE ' s supervisor is responsible for the risk management function.

D.

The CAE is asked to review new procedures before implementation.

Question 150

Which of the following statements is true regarding consulting engagements?

Options:

A.

Internal auditors cannot provide consulting services related to operations for which they had previous responsibilities.

B.

The nature of consulting services to be performed by internal auditors must be defined in the internal audit charter

C.

If internal auditors have potential impairments to objectivity related to the proposed consulting engagement, the engagement must be declined.

D.

If internal auditors lack the knowledge, skills, or other competencies needed to perform the consulting engagement, the engagement can proceed with proper disclosures.

Question 151

Which of the following scenarios best illustrates the concept of due professional care?

Options:

A.

After establishing engagement objectives and reviewing a process, the internal auditor assured process owners that all significant risk events were identified and tested using a systematic, disciplined approach.

B.

After conducting an audit based upon a predefined scope and objective, the internal auditor guaranteed management that the system of internal controls in an audited area operates effectively.

C.

As head of the internal audit activity, the chief audit executive reported functionally to the organization ' s board and administratively to senior management.

D.

As head of the internal audit activity, the chief audit executive ensures that engagement supervisors conduct post-engagement staff meetings.

Question 152

In addition to her internal audit activity responsibilities, the chief audit executive has been asked to oversee the organization ' s insurance function. Which of the following responses is most appropriate?

Options:

A.

Welcome the additional responsibility, as it represents an opportunity to gain more information for future audits.

B.

Revise the internal audit charter to include oversight of the insurance function, ensuring that all of her responsibilities are properly documented.

C.

Report the request to the board and recommend alternate processes to obtain assurance related to insurance activities.

D.

Promptly remove the organization ' s insurance function from the audit universe.

Question 153

According to ISO 31000, which of the following statements is correct?

Options:

A.

The board is responsible for setting the organizational attitude through tone at the top,

B.

The internal audit activity will provide assurance over operating effectiveness but not over the design of risk management activities,

C.

The internal audit activity can give objective assurance on any part of the risk management framework for which it is responsible.

D.

The framework is designed to be effective for organizations no matter how small.

Question 154

A multinational organization has asked the internal audit activity to assist in setting up the organization’s risk management system. The chief audit executive (CAE) agrees to take on the engagement as a consultant. Which of the following tasks is appropriate for the CAE to undertake?

Options:

A.

Coordinate and facilitate risk workshops for management to attend.

B.

Establish the degree of risk appetite for management to accept.

C.

Set risk indicators and mitigation plans for management to implement

D.

Determine the number of significant risks for management to report to the board.

Question 155

According to IIA guidance, which of the following statements is true regarding reporting the results of the quality assurance and improvement program?

Options:

A.

Results of internal assessments need to be reported to the board at least once every five years.

B.

The external assessor must present the findings from the external assessment to senior management and the board upon completion.

C.

Deficiencies within the internal audit activity must be reported to the board as soon as they are noted.

D.

Results of ongoing monitoring of the internal audit activity ' s performance must be reported to senior management and the board at least annually

Question 156

Which of the following would best describe a control implemented to detect cash register disbursement fraud in a large retail store?

Options:

A.

Separate the duties of processing and authorizing refunds on merchandise

B.

Post signs in the register area prompting customers to ask for and examine their sales receipts

C.

Periodically count the cash in the register and compare it to the expected amount

D.

Use cash registers with internal tapes that are tamper proof and that require a manager to process voids or refunds

Question 157

Senior management has decided to adopt the key principles approach of the ISO 31000 risk management framework. According to IIA guidance, which of the following principles is most appropriate when implementing the risk management process in a dynamic agency?

Options:

A.

Everyone in the agency has a primary responsibility for identifying and managing risks as part of the risk management process.

B.

The risk management process, while evaluating risk, should develop a mechanism to rank the relative importance of each risk.

C.

The risk management process should be regularly reviewed and respond to changes in the environment, to remain relevant.

D.

The risk management process should use a formal technique to consider the consequence and likelihood of each risk.

Question 158

A chief audit executive (CAE) has just joined an organization with an existing internal audit activity. Based on her review of the current organizational structure, the CAE determines that the internal audit activity lacks adequate independence. Which of the following actions is the CAE ' s best step to take next to move the internal audit activity toward organizational independence?

Options:

A.

Ensure the limitations are disclosed through communication with the board and senior management, so that the internal audit activity can continue operating under the same organizational structure.

B.

Request that the board restructure the reporting line of the internal audit activity to ensure the CAE has unrestricted access to the board.

C.

Rotate internal audit assignments among members of the internal audit activity to minimize the effects of the current structure.

D.

Train internal auditors about organizational independence and have them sign an acknowledgment of understanding.

Question 159

An internal auditor is performing testing to gather evidence regarding an organization’s inventory account balance and is mindful of the possibility that the sample used might support the conclusion that the recorded account balance is not materially misstated when, in fact, it is. The auditor ' s concern best describes which of the following risks?

Options:

A.

incorrect rejection risk

B.

Incorrect acceptance risk.

C.

Tolerable misstatement risk.

D.

Anticipated misstatement risk

Question 160

Which of the following statements best represents the due professional care that is required of internal auditors?

Options:

A.

Internal auditors should perform assurance procedures to ensure that all significant risks are identified.

B.

Internal auditors should not perform consulting engagements for operations for which they had previous responsibilities.

C.

Internal auditors should consider the cost of assurance in relation to the potential benefits.

D.

Internal auditors should devise internal audit programs to confirm that the results are accurate.

Question 161

A chief audit executive (CAE) identifies that the internal audit activity lacks a necessary skill to perform a management request for a consulting engagement. According to IIA guidance, which of the following is the most appropriate action the CAE should take regarding the request?

Options:

A.

Assign the engagement to a more senior internal auditor.

B.

Decline the engagement request.

C.

Allow the internal auditors to acquire the needed skills while performing the engagement.

D.

Supervise the assigned internal auditors throughout the engagement.

Question 162

According to IIA guidance, which of the following training methods is considered most effective in assisting new entry-level internal auditors in achieving competence with internal audit practices in the workplace?

Options:

A.

Pursuance of an internal audit certification.

B.

Enrollment in internal audit practice webinars.

C.

Attendance of internal audit workshops.

D.

Involvement in a variety of audit assignments.

Question 163

When would on-the-job training be more effective?

Options:

A.

When participants already have a certain degree of experience and knowledge.

B.

When it makes up the largest part of the training budget.

C.

When it includes ongoing feedback and coaching from experienced team members.

D.

When it is standardized for the whole entire staff.

Question 164

Which of the following statements is correct regarding disclosure of conformance or Standards?

Options:

A.

An internal audit activity that has been in existence fewer than five years cannot Indicate that it is operating in conformance with the Standards because it has not yet undergone an external assessment.

B.

Once an external assessment validates conformance with the Standards, the internal audit activity may continue to use the statement until the next external assessment.

C.

If it has been more than five years since the last external assessment was conducted, the Internal audit activity must cease indicating that it operates in conformance with the Standards.

D.

The chief audit executive must disclose every instance of noncompliance with the Code of Ethics or the Standards.

Question 165

An internal auditor in a newly established internal audit activity identifies many control weaknesses and raises a number of high-priority recommendations in her first few audit engagements. The internal auditor is concerned that there seems to be a poor understanding by management of risk and control. Which of the following is the most likely reason for this?

Options:

A.

Poor performance by individual operational managers in the areas audited.

B.

Unrealistic expectations by the internal audit activity on the quality of risk management and control.

C.

A lack of an effective organizational framework for risk management and control.

D.

A failure by the internal audit activity to identify and manage the organization ' s risks.

Question 166

Which of the following actions taken during an audit engagement is the best demonstration of an internal auditor ' s due professional care?

Options:

A.

Ensure that all financial information related to the engagement is included in the audit plan and examined for irregularities.

B.

Document all audit tests completely.

C.

Consider the possibility of noncompliance or irregularities at all times during an engagement.

D.

Notify the audit committee of any noncompliance or irregularity discovered during an engagement

Question 167

Which of the following is an advantage of using nongovernmental organization (NGO) members on an assurance team when auditing corporate social responsibility?

Options:

A.

Typically less time is needed to train the NGO members on the audit process.

B.

NGO members are often more unbiased and objective

C.

A report with a positive statement from an NGO member is deemed to be more credible. As opposed to auditors.

D.

NGO members are licensed to audit corporate social responsibility.

Question 168

Which of the following should play a leading role in overseeing the ethical atmosphere of an organization?

Options:

A.

Internal audit activity

B.

Operating management

C.

Senior management

D.

Board of directors

Question 169

Which of the following controls would most likely prevent fraud related to the overpayment of vendors?

Options:

A.

Require supervisory review of all invoices and cash disbursements exceeding a stated threshold.

B.

Require the matching of a purchase order, receiving report, and invoice before payment.

C.

Require all checks to be signed by more than one person.

D.

Require all invoices to be paid within 30 days by check only.

Question 170

The chief audit executive (CAE) of a large organization has been asked by the board to assume responsibility for risk management and compliance operations, both of which are distinct departments within the organization and are subject to periodic audits by the internal audit activity In regards to future audits of these functions which of the following approaches would be most appropriate?

Options:

A.

Audits of risk management and compliance functions should be overseen by a competent external assurance provider

B.

Audits of risk management and compliance functions should be overseen by a senior audit manager within the internal audit activity other than the CAE

C.

Audits of risk management and compliance functions should be conducted by internal auditors under the supervision of management from both functions

D.

Audits of risk management and compliance functions should be earned out by a team of the most experienced auditors overseen by the CAE

Question 171

A global organization established a new internal audit activity and the recently hired chief audit executive needs to develop an internal audit manual for internal auditors Among the following policies in the manual, which would facilitate internal auditors in upholding their objectivity?

Options:

A.

Internal auditors shall attend professional workshops to refresh internal audit norms and concepts

B.

Internal auditors ' performance is synchronized with satisfaction ratings given by audit clients

C.

Internal auditors take prior audit results into account when conducting current audit engagements

D.

Internal auditors observe the audit client’s expectations when scoping audit engagements

Question 172

Which data analytics competency is critical for new internal auditors to possess in order to plan and perform internal audit engagements in conformance with the Standards?

Options:

A.

Describe data analytics and the application of data analytics methods in internal auditing.

B.

Apply data analytics methods in internal auditing.

C.

Evaluate the use of data analytics in an internal audit.

D.

Understand the definition of data analytics only.

Question 173

Which of the following characteristics is typical of the internal audit activity?

Options:

A.

Serves third parties that need reliable financial information from audit engagements

B.

Responds to the needs and desires of senior management and the board, but remains independent of areas under review

C.

Ensures the organization complies with laws and regulations in the area under review

D.

Is completely independent of senior management, the board and the area under review

Question 174

When beginning an engagement to assess the effectiveness of the organization ' s newly revamped risk management processes, which of the following should internal auditors review first?

Options:

A.

Key risk disclosures in the annual report.

B.

Existing risk assessment and identification processes.

C.

Organizational strategy and business plans.

D.

Risk mitigation plans and risk responses.

Question 175

An internal auditor is reviewing the results of an employee survey at a mining company. Which of the following would alert the auditor to a potential ethics issue?

Options:

A.

Women account for 20% of the total number of employees in the company.

B.

Thirty percent of employees feel confident in raising concerns without a fear of retaliation.

C.

Most employees believe that transparent and fair decision-making forms the basis of business ethics.

D.

Employees with longer work experience believe that they deserve more privileges than new hires.

Question 176

The manager of the payroll department requested a review of the payroll process, but only wants the engagement to include processes related to approval of time worked. What type of activity is this?

Options:

A.

Financial assurance engagement.

B.

Operational consulting engagement.

C.

Compliance assurance engagement.

D.

Risk management consulting engagement.

Question 177

Which of the following statements is true regarding a key difference between assurance and consulting services provided by the internal audit activity?

Options:

A.

When conducting a consulting engagement, the nature and scope of the engagement are determined by the internal audit activity.

B.

Three parties are participants in assurance services, while consulting engagements generally involve two parties.

C.

An assurance engagement has two participants, while consulting engagements generally involve three parties.

D.

When conducting an assurance engagement, the engagement objectives, scope, and techniques are agreed with the area under review.

Question 178

Which of the following practices is generally most effective to protect internal audit objectivity?

Options:

A.

Ensuring regular documentation of auditor skills and experience in the workpapers.

B.

Basing performance evaluations heavily on customer satisfaction surveys.

C.

Prohibiting auditors from accepting gifts from audit clients or potential clients.

D.

Ensuring that auditors have a balance of both operational and internal audit responsibilities.

Question 179

Which of the following offers the best evidence that the internal audit activity has achieved organizational independence?

Options:

A.

An independent third party has assessed the organization ' s system of internal controls to be adequate and effective,

B.

The chief audit executive reports both functionally and administratively to the CEO.

C.

The internal audit charter is drafted properly and approved by the appropriate parties.

D.

The mission statement and strategy of the internal audit activity demonstrates alignment to organizational objectives.

Question 180

Which of the following actions would an internal auditor perform primarily during a consulting engagement of a debt collections process?

Options:

A.

Reviewing journal entries for accuracy and completeness.

B.

Comparing the policies and procedures to regulatory collections guidance.

C.

Advising management on streamlining the recording of accounts receivable.

D.

Performing a walk-through of the debt collections process to determine whether proper segregation of duties exists

Question 181

Which of the following controls would be most useful to prevent an employee from using the organization ' s funds for inappropriate expenditures and falsifying financial records to conceal the fraud?

Options:

A.

Segregating duties in the payroll processes.

B.

Confirming receipt of goods or services.

C.

Performing background checks on newly hired employees.

D.

Requiring management approval for expenses.

Question 182

Which of the following actions by the internal audit activity requires disclosure to the board of nonconformance with the Standards?

Options:

A.

The internal audit activity did not complete an external assessment within the last seven years

B.

The internal audit activity performed an engagement with limited scope due to lack of knowledge

C.

The internal audit activity failed to consider risk when conducting a review of a department

D.

An internal auditor was assigned to an engagement m an area where she previously worked more than 10 years ago

Question 183

The internal audit activity was asked to conduct an investigation for potential fraud in the treasury department and subsequently contracted with a forensic accountant to join the team for the engagement. Which of the following parties has the primary responsibility for resolving any fraud incidents found as a result of this investigation?

Options:

A.

Chief audit executive.

B.

Senior management.

C.

The forensic accountant.

D.

The legal department.

Question 184

Which of the following represents an example of an ethical issue that the organization should address ' ?

Options:

A.

An employee discovered that there is no personal protective equipment at a temporary construction site

B.

An employee saw that a group of other employees were smoking in close proximity to petrol distribution tanks

C.

A supervisor insists that an employee complete time sheets regularly

D.

An employee received concert tickets from a vendor and asked whether she could keep them

Question 185

Which of the following would be most helpful to measure whether an internal audit activity successfully provides risk-based assurance?

Options:

A.

Percentage of highly significant risks covered by internal audit plan.

B.

Percentage of previously unknown risks identified per engagement.

C.

Percentage of internal audit staff skilled in alignment with the organization ' s structure and key risks.

D.

Percentage of observations made in assurance engagements compared to advisory engagements.

Question 186

Which of the following best demonstrates that an internal auditor is applying due professional care when planning an assurance engagement?

Options:

A.

Assessing the risk of noncompliance with laws and regulations

B.

Following the policies as prescribed by the internal audit manual.

C.

Advising management of the area under review on how to mitigate internal control risks.

D.

Conducting the engagement on the presupposition that fraud exists.

Question 187

According to MA guidance, which of the following is an appropriate role for the internal audit activity?

Options:

A.

Coaching management in responding to risks.

B.

Implementing risk responses on management ' s behalf.

C.

Imposing risk management processes.

D.

Setting the risk appetite.

Question 188

Which of the following is part of a fraud detection program?

Options:

A.

Whistleblower hotline.

B.

Authority limits.

C.

Background investigations

D.

Evaluation of compensation programs.

Question 189

Which statement is accurate regarding reporting on the quality assurance and improvement program (OAIP) to conform with the International Standards for the Professional Practice of Internal Auditing?

Options:

A.

The chief audit executive (CAE) should report all stages of the OAlP ' s development and key milestones.

B.

The CAE should report only corrective action plans that meet external assessor or stakeholder requirements.

C.

The CAE should establish the form and content of program communication so that it is in alignment with the internal audit activity charter.

D.

The CAE should disclose program details only after both internal and external assessments have been completed.

Question 190

According to IIA guidance, which of the following activities are considered a core internal audit role with regard to enterprise risk management?

Reviewing the management of key risks.

Evaluating the reporting of key risks.

Evaluating risk management processes.

Consolidating the reporting of risks.

Options:

A.

1 and 4.

B.

2 and 4.

C.

2, 3, and 4.

D.

1, 2, and 3.

Question 191

An existing Internal audit charter is currently under review for revision. Who is responsible for assuring that all required components are included?

Options:

A.

The audit committee.

B.

The head of legal and compliance.

C.

The chief audit executive.

D.

Senior management.

Question 192

A newly appointed chief audit executive (CAE) is tasked with creating a new internal audit activity within the organization. Which of the following would the CAE need to include in the new internal audit charter?

Options:

A.

The requirement to provide an annual cost analysis that justifies having an internal audit activity

B.

The specific engagements that the internal audit activity will perform for the organization

C.

The board s oversight role and responsibilities pertaining to the internal audit activity

D.

The relevant regulations that will guide the internal audit activity ' s regulatory compliance assessments

Question 193

Which of the following is the best way for an internal auditor to demonstrate due professional care?

Options:

A.

Conduct an audit to the same extent that another prudent auditor would under similar circumstances

B.

Seek feedback from the engagement supervisor during the engagement

C.

Execute internal audit work in such a manner as to provide absolute assurance of compliance

D.

Request and receive client feedback surveys during the engagement

Question 194

An internal auditor believes that the internal audit activity ' s independence is impaired. Which of the following actions should the internal auditor take first?

Options:

A.

Report the impairment to senior management

B.

Discuss the impairment with the audit manager

C.

Ascertain the best approach to disclose the impairment.

D.

Decide on the extent of impact of the impairment

Question 195

Considering the concepts of organization wide risk management and the system of internal controls, the internal audit activity as a whole can be considered which of the following types of control?

Options:

A.

Transaction-level control.

B.

Management-oversight control.

C.

Governance control.

D.

Process-level control.

Question 196

Which of the following is an indicator that an organization ' s risk management processes are effective?

Options:

A.

Departmental objectives are managed by department heads and are independent of the organization ' s mission.

B.

Organization wide mechanisms exist to enable the identification and assessment of all significant risks.

C.

Department heads have the autonomy to determine risk responses that fall outside of the organizations risk appetite

D.

Relevant risk information is captured and communicated primarily between management and the board

Question 197

Which of the following statements is true regarding the internal audit activity ' s quality assurance and improvement program (QAIP)?

Options:

A.

Internal assessments must be performed by the chief audit executive.

B.

An internal assessment must be performed at least once every five years.

C.

It Is permissible to share the results of the QAIP with the organization ' s external auditors.

D.

Results of ongoing monitoring must be validated annually by an independent external assessor.

Question 198

An internal audit of warehouse inventory revealed no material deficiencies. However, management later discovered fraud, which occurred during the period that was audited, and determined that a major control deficiency allowed the fraud to occur. Given management ' s discovery, which of the following statements is valid?

Options:

A.

The internal auditors violated the standard for due professional care because they did not detect the fraud, even though it occurred during the period that was reviewed.

B.

The internal auditors should have had sufficient knowledge of fraud to identify red flags indicating possible fraud.

C.

The internal auditors could not have detected the fraud due to collusion among employees in the inventory unit.

D.

The internal auditors are not responsible for considering fraud risk, which is a management responsibility.

Question 199

Which of the following is most accurate concerning corporate social responsibility?

Options:

A.

A moral agent in an organization makes decisions that are based on the rules and regulations of the organization as they apply to human resources decisions

B.

The utilitarian approaching deciding on ethical dilemmas is concerned with choosing the simplest solution that will apply to the most people

C.

Ethics are not defined by laws but they are not a matter of free choice ethics are based on standards of conduct derived from shared principles and values

D.

The individualism approach to ethical decision making is focused on implementing a customized long-term outcome that is most beneficial for the entire organization

Question 200

Which of the following is the best example of a risk appetite statement concerning an investment portfolio?

Options:

A.

We will request CEO approval for investments greater than S20 million and board approval for investments greater than $50 million.

B.

We will hedge 95 percent of our U S. currency exposure and 100 percent of our European currency exposure.

C.

We have a moderate tolerance for investment earnings volatility with a target value at risk of S50 million.

D.

We will report to the risk committee all credit losses greater than S10 million and all market value losses greater than S20 million.

Question 201

Which of the following best describes a purpose for the internal audit charter?

Options:

A.

The internal audit charter authorizes the internal audit activity ' s reporting structure and clearly defines the roles of each internal auditor.

B.

The internal audit charter defines the roles and responsibilities of the chief audit executive, board of directors, and senior management.

C.

The internal audit charter authorizes access to records, personnel, and physical properties relevant to the performance of audit engagements.

D.

The internal audit charter defines the criteria by which the internal audit activity ' s performance will be evaluated

Question 202

In which scenario might it be considered problematic for the chief audit executive (CAE) to provide assurance services over the payroll function?

Options:

A.

The CAE previously undertook a consulting assignment in that area to improve processes,

B.

A couple of years ago, the CAE performed accounting functions for the payroll department.

C.

Prior to becoming the CAE, the CAE was the payroll manager.

D.

The assurance review was initiated following issues identified during a consulting assignment requested by management.

Question 203

Which of the following factors are commonly assessed to determine the magnitude of risk events?

Options:

A.

Tolerance and appetite

B.

Inherent and residual risk

C.

Cost and benefit

D.

Impact and likelihood

Question 204

Which of the following statements is true regarding reporting results of the quality assurance and improvement program to senior management and the board?

Options:

A.

Internal assessments must be reported to the board at least every five years

B.

If supported by assessment results, reporting provides assurance that internal auditors demonstrate conformance with the Code of Ethics

C.

Following the reporting the board must give the internal audit activity five years to correct any deviations

D.

A report, including the results of both internal and external assessments must be provided to the board annually

Question 205

The level of authority for the internal audit activity is granted by which of the following?

Options:

A.

The chief audit executive.

B.

The internal audit charter.

C.

The International Professional Practices Framework.

D.

The IIA ' s Code of Ethics.

Question 206

According to IIA guidance, which of the following is accurate regarding the chief audit executive ' s (CAE ' s) requirement to report the results of quality assessments?

1. The CAE must report the results of external assessments at least annually.

2. The CAE must report the results of ongoing monitoring at least annually.

3. The CAE must report the results of quality assessments to senior management.

4. The CAE must report the results of quality assessments to the board.

Options:

A.

1 and 3 only.

B.

2 and 4 only.

C.

1,2. and 3.

D.

2,3, and 4.

Question 207

An internal auditor has documented several instances in which management asked employees to ad against the policies and procedures. Which of the following is the most appropriate next step?

Options:

A.

Report the non-compliance cases to the board of directors.

B.

Recommend that management update its policies and procedures based on the circumstances.

C.

Investigate the rationale for management ' s actions.

D.

Recommend those employees to report the cases through the designed whistleblowing channel for the appropriate treatment.

Question 208

Which of the following actions should an organization take to detect an emerging risk of potential fraud?

Options:

A.

Adopt reward and recognition programs that promote good behaviors

B.

Undertake background checks for new employees as part of the hiring process

C.

Establish an anonymous platform for reporting suspected unethical behaviors

D.

Institute periodic educational training on expected ethical behaviors

Question 209

According to IIA guidance, which of the following best demonstrates due professional care?

Options:

A.

Staffing audit engagements with internal auditors who possess professional designations.

B.

Relying on prior audit work to save planning time and costs.

C.

Performing assurance procedures to guarantee all significant risks are identified.

D.

Assessing the cost of assurance in relation to the potential benefits.

Question 210

Which of the following best describes the differences between internal auditors and external auditors?

Options:

A.

External auditors are concerned about misstatements in the organization ' s financial statements, while internal auditors are concerned about fraudulent activities that could impact the organization’s financial statements

B.

External auditors are required to hold an accounting designation and are responsible for continuing their education, while internal auditors are required to hold an internal audit designation.

C.

External auditors focus on the accuracy and understandability of financial statements, while internal auditors help the organization accomplish its objectives by evaluating and improving the effectiveness of the control process.

D.

External auditors are not employees of the organization, while internal auditors are employees who have in-depth knowledge of the business, making their opinion more reliable to the board and senior management.

Question 211

According to IIA guidance, which of the following statements is true regarding the internal audit activity’s responsibilities in providing consulting services?

Options:

A.

The chief audit executive is responsible for deciding the priority of consulting services in the internal audit plan

B.

The scope of consulting services is determined primarily by the internal auditor with input from management of the area under review

C.

The board defines the internal audit activity’s responsibilities over consulting activities

D.

Adding value to an organization requires the internal audit activity to initiate a consulting engagement

Question 212

An internal auditor performed a consulting engagement last year which included assisting with management ' s design of controls over the procurement function. How should the chief audit executive plan an assurance engagement on the adequacy of the internal control system in the procurement function in the current year?

Options:

A.

Assign the engagement to another internal auditor on staff

B.

Outsource the engagement to ensure independence

C.

Harness the auditor ' s knowledge of the procurement function by assigning the engagement to the same internal auditor

D.

Postpone the engagement to the following year to ensure enough time has passed since the controls were designed

Question 213

A sales manager was recently bypassed for a promotion. He feels entitled to a higher salary and is angry that management does not recognize his contributions. To make up for this perceived injustice, he begins to record false expenses on his travel expense reports. This scenario best illustrates which of the following fraud risk factors?

Options:

A.

Incentive.

B.

Rationalization.

C.

Pressure.

D.

Opportunity.

Question 214

Which of the following organizations has reached the most mature level of corporate social responsibility?

Options:

A.

An organization that is able to provide goods and services society needs and thus maximizes profit to its owners.

B.

An organization that ensures compliance to legal frameworks of the countries in which it operates and sells its products.

C.

An organization that is willing to make contributions not mandated by law or economics and expects no payback.

D.

An organization that requires its decision makers to act with equity, fairness, and respect for the rights of individuals.

Question 215

According to HA guidance, which of the following is true regarding independence and objectivity for small internal audit activities?

Options:

A.

The chief audit executive (CAE) may consider including a disclaimer on independence in audit reports.

B.

The CAE may consider greater involvement of those with suitable knowledge of audit practice.

C.

Conformance with this Standard is not dependent upon the size of the internal audit activity.

D.

Due to the small size of the internal audit activity, having an external assessment once every seven years is acceptable.

Question 216

According to IIA guidance, which of the following statements is true regarding mentoring programs designed to assist internal auditors with their professional development?

Options:

A.

The mentor must have a higher position in the organization than the mentee

B.

An auditor s supervisor is best positioned to serve as the auditor ' s mentor

C.

Meetings between a mentor and a mentee should be formal and well documented

D.

Auditors at the same level may be assigned different mentors and some auditors may have no mentor

Question 217

Which of the following scenarios demonstrates an impairment to internal audit independence?

Options:

A.

The internal auditor s denied access to partner information from management of me area under review

B.

The internal auditor tarts to disclose a potential conflict of interest relationship with management of the area under review

C.

The internal auditor concludes that controls operate effectively, although he did not gather supporting evidence

D.

The internal auditor was assigned to an assurance review of an area for which he previously had responsibilities

Question 218

Which of the following procedures will best help an internal auditor assess operating effectiveness of fraud prevention and detection controls?

Options:

A.

Benchmarking best practices

B.

Testing,

C.

Mapping,

D.

Interviewing

Question 219

Which documents would help a forensic auditor identify instances of collusion between an employee and vendor to defraud the organization?

Options:

A.

Email correspondence.

B.

Payment request forms.

C.

Vendor invoices.

D.

Bank statements.

Question 220

During fieldwork, an internal auditor located a significant internal control issue. Without identifying the origins of the issue, the auditor concluded the engagement and included the issue in the final audit report. To enhance audit quality, which of the following skills should the internal auditor improve?

Options:

A.

Business acumen.

B.

Critical thinking.

C.

Communication.

D.

Audit report writing.