Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Internal Audit Fundamentals Question and Answers

Internal Audit Fundamentals

Last Update Jul 26, 2026
Total Questions : 735

We are offering FREE IIA-CIA-Part1 IIA exam questions. All you do is to just go and sign up. Give your details, prepare IIA-CIA-Part1 free exam questions and then go for complete pool of Internal Audit Fundamentals test questions that will help you more.

IIA-CIA-Part1 pdf

IIA-CIA-Part1 PDF

$36.75  $104.99
IIA-CIA-Part1 Engine

IIA-CIA-Part1 Testing Engine

$43.75  $124.99
IIA-CIA-Part1 PDF + Engine

IIA-CIA-Part1 PDF + Testing Engine

$57.75  $164.99
Questions 1

In its five years of existence, an internal audit activity conducted a single internal assessment of its quality assurance and improvement program (QAIP). The results of that assessment showed that the internal audit activity did not conform with the Standards. Prior to this, an external assessment of the internal audit activity ' s QAIP was conducted, which reported that the internal audit activity was in conformance with the Standards. Considering the two assessments, what would be the internal audit activity ' s current state of conformance with the Standards?

Options:

A.  

Conformance with the Standards.

B.  

Nonconformance with the Standards

C.  

Unable to determine conformance with the Standards.

D.  

Partial conformance with the Standards

Discussion 0
Questions 2

Which of the following scenarios is a characterize of an organization with a highly effective ethical culture?

Options:

A.  

An organization implements and communicates to staff a formal and comprehensive code of conduct, which is clear and understandable.

B.  

An organization waives reference and background checks when hiring for certain sensitive positions in order to not violate potential employees ' rights to privacy.

C.  

An organization punishes senior management more harshly for ethics violations than it would for lower-level staff to send a message throughout the organization.

D.  

An organization conducts surveys of employees, suppliers, and customers once every five years to determine the slate of the ethical climate in the organization.

Discussion 0
Questions 3

An internal audit activity is using the auditing-by-element approach to audit the organization ' s controls around corporate social responsibility. Which of the following would be an element for the internal audit activity to consider?

Options:

A.  

Working conditions.

B.  

Employees ' families.

C.  

Marketplace competition.

D.  

Shareholders and investors

Discussion 0
Questions 4

Which of the following situations would cause the greatest concern regarding impairment of internal audit objectivity?

Options:

A.  

The eternal auditor reviewed the audit clients proposed procedures and standards of control and offered suggested improvements at the client’s request.

B.  

The internal auditor performed nonaudit work for the audit client which was communicated to senior management and the board before the engagement was performed and restated in the audit report

C.  

internal auditors accepted limited access to the audit client ' s systems and records m accordance with the scope of the engagement

D.  

The internal auditor used his in-depth knowledge of systems development to assist the audit client m designing a new operational system with robust controls.

Discussion 0
Questions 5

Which of the following would be considered an indicator that an organization ' s ethics program is not yet well developed?

Options:

A.  

Disciplinary actions for ethics compliance violations are reviewed by the internal audit activity for consistency.

B.  

Communication of ethics compliance expectations is the responsibility of employees ' direct managers.

C.  

The organization ' s code of ethics and related compliance policy are reviewed annually for potential updates.

D.  

The board of directors reviews ethics oversight metrics for violations and compliance.

Discussion 0
Questions 6

Which of the following scenarios provides the most concerning red flag or indicator of possible fraud?

Options:

A.  

An employee receives a bonus for perfect attendance

B.  

During the past 18 months three chief financial officers have left the organization after having been promoted to the position

C.  

The organization does not perform any due diligence research on third party service providers

D.  

Three competitors are highly profitable but a fourth equal in size is approaching bankruptcy limits

Discussion 0
Questions 7

An experienced internal auditor is planning an assurance engagement of the organization ' s sales activities. During process walkthroughs and interviews, many sales representatives expressed concerns about management ' s escalating demands to meet the organization ' s sales goals. According to the MA guidance, which of the following is the best application of due professional care in planning the engagement?

Options:

A.  

Disregard the complaints because the information isn ' t reliable and isn ' t sufficient to support engagement conclusions and results.

B.  

Consider the significance of the risks related to the complaints and develop appropriate assurance procedures in work programs.

C.  

Disregard the complaints because using them would violate the confidentiality principle.

D.  

Discuss management ' s needs and expectations related to including the complaints in the audit scope.

Discussion 0
Questions 8

Which of the following is a control that is used mainly to check the integrity of data entered into a business application, whether the data is entered directly by staff, remotely by a business partner, or through a web-enabled application?

Options:

A.  

General IT control.

B.  

Processing control.

C.  

Input control

D.  

Integrity control

Discussion 0
Questions 9

The chief audit executive (CAE) annually develops a budget and resource plan and submits it to the board for approval. This action best fulfills which of the following responsibilities of the CAE?

Options:

A.  

The responsibility to maintain organizational independence.

B.  

The responsibility to perform engagements with due professional care.

C.  

The responsibility to communicate corrective action plans to the board.

D.  

The responsibility to define the purpose of the internal audit activity.

Discussion 0
Questions 10

When an organization purchases a derivative contract in the stock market to limit the potential loss in the value of a security, the organization is applying which of the following risk management techniques?

Options:

A.  

Avoiding the risk altogether.

B.  

Transferring the risk.

C.  

Introducing a control feature.

D.  

Accepting the risk.

Discussion 0
Questions 11

In which of the following audits would the internal auditors most likely contribute to the assessment of organizational governance?

Options:

A.  

An assessment of compliance of individual data protection procedures with data protection regulations

B.  

An assessment of profit and loss generated by financial assets and instruments in the past quarter

C.  

An assessment of the effectiveness of back-up procedures and execution of business recovery plans

D.  

An assessment of performance management practices and establishment of key performance indicators

Discussion 0
Questions 12

According to MA guidance, which of the following gives the internal audit activity the authority to request supporting documentation for the invoices of a third-party service provider?

Options:

A.  

The internal audit policy manual.

B.  

The internal audit charter.

C.  

The board of directors.

D.  

The quality assurance and improvement program.

Discussion 0
Questions 13

Which of the following policies promotes internal audit objectivity?

Options:

A.  

The chief audit executive (CAE) reports functionally to the CEO

B.  

The CAE s compensation is approved by the chief financial officer

C.  

The CAF ' s appointment is determined by the CEO

D.  

The CAE reports administratively to the chief operating officer

Discussion 0
Questions 14

Evidence discovered during the course of an engagement suggests that multiple incidents of fraud have occurred. There do not appear to be sufficient controls in place to prevent reoccurrence. Which of the following is the internal auditor ' s most appropriate next step?

Options:

A.  

Immediately notify management of the area under review and the other internal auditors involved in the engagement.

B.  

Discuss the situation with the engagement supervisor to determine whether fraud investigation experts are required to investigate the matter properly.

C.  

Fully document in the workpapers the evidence that has been discovered and recommend appropriate controls to address the fraud.

D.  

Provide the evidence that was discovered to local law enforcement for possible prosecution of the suspected fraud.

Discussion 0
Questions 15

A large commercial bank was fined by regulators for fraudulent practices when employees, over a period of time, opened thousands of new accounts for existing clients without the clients ' consent. It was later found that employees were given unrealistic new account targets and were aggressively monitored by management on a daily basis.

Which of the following controls would have most likely reduced the likelihood of the fraudulent practice from occurring?

Options:

A.  

An evaluation of the current performance and compensation program.

B.  

The performance of background investigations on all existing employees.

C.  

The availability of fraud training to all employees.

D.  

The availability of an employee whistleblower hotline

Discussion 0
Questions 16

Which of the following is the best reason why the engagement supervisor should take care in explaining to local management the criteria that will be used to measure the effectiveness of the control environment?

Options:

A.  

The assessment will cover soft controls and company values.

B.  

The assessment will focus on the policy for a particular process.

C.  

The assessment will lack a defined scope

D.  

The assessment will probably uncover fraud risks.

Discussion 0
Questions 17

An internal audit of warehouse inventory revealed no material deficiencies. However, management later discovered fraud, which occurred during the period that was audited, and determined that a major control deficiency allowed the fraud to occur. Given management ' s discovery, which of the following statements is valid?

Options:

A.  

The internal auditors violated the standard for due professional care because they did not detect the fraud, even though it occurred during the period that was reviewed.

B.  

The internal auditors should have had sufficient knowledge of fraud to identify red flags indicating possible fraud.

C.  

The internal auditors could not have detected the fraud due to collusion among employees in the inventory unit.

D.  

The internal auditors are not responsible for considering fraud risk, which is a management responsibility.

Discussion 0
Questions 18

Which of the following best demonstrates internal auditors performing their work with proficiency?

Options:

A.  

Internal auditors meet with operational management at each phase of the audit process.

B.  

Internal auditors adhere to The IIA’s Code of Ethics.

C.  

Internal auditors work collaboratively with their engagement team.

D.  

Internal auditors complete a program of continuing professional development.

Discussion 0
Questions 19

Which of the following is (he most effective way any organization can ensure proper governance over its internal controls?

Options:

A.  

By adopting the best practices of similar organizations in the industry.

B.  

By adjusting their internal control framework as business practices evolve.

C.  

By introducing the universally accepted COSO internal control framework.

D.  

By encouraging the internal audit activity to provide training on internal controls.

Discussion 0
Questions 20

Which of the following is most likely to be considered a control weakness?

Options:

A.  

Vendor invoice payment requests are accompanied by a purchase order and receiving report.

B.  

Purchase orders are typed by the purchasing department using prenumbered forms.

C.  

Buyers promptly update the official vendor listing as new supplier sources become known.

D.  

Department managers initiate purchase requests that must be approved by the plant superintendent.

Discussion 0
Questions 21

Which of the following is the best example of a risk appetite statement concerning an investment portfolio?

Options:

A.  

We will request CEO approval for investments greater than S20 million and board approval for investments greater than $50 million.

B.  

We will hedge 95 percent of our U S. currency exposure and 100 percent of our European currency exposure.

C.  

We have a moderate tolerance for investment earnings volatility with a target value at risk of S50 million.

D.  

We will report to the risk committee all credit losses greater than S10 million and all market value losses greater than S20 million.

Discussion 0
Questions 22

An internal auditor performed a consulting engagement last year which included assisting with management ' s design of controls over the procurement function. How should the chief audit executive plan an assurance engagement on the adequacy of the internal control system in the procurement function in the current year?

Options:

A.  

Assign the engagement to another internal auditor on staff

B.  

Outsource the engagement to ensure independence

C.  

Harness the auditor ' s knowledge of the procurement function by assigning the engagement to the same internal auditor

D.  

Postpone the engagement to the following year to ensure enough time has passed since the controls were designed

Discussion 0
Questions 23

An external assessment of an organization ' s internal audit activity was last completed four years ago Which of the following options would be acceptable this year if the internal audit activity is to fulfill the requirements of the Standards?

Options:

A.  

The internal audit activity conducts a self-assessment that is validated by a qualified and experienced internal auditor and then schedules a qualified, independent external assessor

B.  

The board nominates an independent individual from senior management in the organization to conduct an assessment of the internal audit activity

C.  

An external auditor conducts an audit of the organization which includes information about the internal audit activity

D.  

The chief audit executive schedules a self-assessment and the board approves the results

Discussion 0
Questions 24

According to IIA guidance which of the following statements regarding ethics is true?

Options:

A.  

Business ethics may vary within an organization with both domestic and foreign operations

B.  

Business ethics are universal n nature and organizations across the world are expected to comply with smear standards

C.  

A business ethics policy for an organization s established solely to direct me behavior and expectations of employees

D.  

Business ethics of an organization must remain independent torn those of supplier’s customers and business partners

Discussion 0
Questions 25

Which of the following should the internal audit activity establish to ensure auditors develop the appropriate skills for conducting audits?

Options:

A.  

An audit charter that includes the internal audit activity mission and vision

B.  

A policy encouraging audit staff to earn certifications

C.  

A quality assurance and improvement program to address audit risk areas

D.  

An internal audit plan that links engagements to strategic objectives

Discussion 0
Questions 26

Which of the following statements is the most appropriate for a chief audit executive to include in the internal audit policy manual in order to promote objectivity?

Options:

A.  

Internal auditors may conduct a financial effectiveness engagement in a business unit at any point after being transferred from that area.

B.  

Internal auditors may conclude that a business unit ' s current control environment is adequate and effective if the review of the prior year ' s workpapers and audit report supports that conclusion.

C.  

Internal auditors may conduct an engagement in a business unit at any point after providing a training workshop in that area.

D.  

Internal auditors should limit the scope of an engagement if they become aware of a potential impairment of their objectivity in order to reduce the potential impact of the impairment on the engagement results.

Discussion 0
Questions 27

An internal auditor at a multinational organization is reviewing the effectiveness of the organization ' s risk management framework. In this scenario, which of the following statements is true?

Options:

A.  

The auditor should consider local cultures and customs in various regions when assessing control effectiveness.

B.  

Regardless of their location, employees at all levels share responsibility for designing effective controls to mitigate risks.

C.  

To achieve an effective internal control environment, the organization ' s risk management plan must be documented and communicated to all levels throughout each region.

D.  

Setting clear objectives is a precondition to effectively identifying, assessing, and responding to the organization ' s risks.

Discussion 0
Questions 28

An organization is testing a new IT system for digital data storage and security. The internal audit activity has been asked to evaluate the system in a consulting engagement. Although several internal auditors on staff are qualified to perform basic assessments of IT systems, none are familiar with the new system. Which of the following is a legitimate response to the prospective client?

1. Decline the engagement.

2. Proceed with the engagement, performing only those parts of the engagement that the internal auditors are qualified to perform.

3. Accept the engagement and develop the additional competencies in-house prior to the engagement ' s starting date.

4. Make arrangements to obtain assistance from a competent IT auditing expert.

Options:

A.  

1 and 4 only.

B.  

2 and 3 only.

C.  

1. 2, and 3 only.

D.  

1, 3, and 4 only.

Discussion 0
Questions 29

Which of the following would be the most effective in helping to detect fraud?

Options:

A.  

Code of conduct.

B.  

Exit interviews.

C.  

Fraud awareness training

D.  

Employee promotion policy.

Discussion 0
Questions 30

A new internal audit activity is considering the adoption of a risk and control framework. Which of the following is the most appropriate consideration during this process?

Options:

A.  

The framework should not be developed by the internal audit activity

B.  

The framework should apply to individual projects rather than the organization as a whole

C.  

The framework should always be tailored to the organization

D.  

The framework should require fewer resources to implement

Discussion 0
Questions 31

The internal audit activity was denied access to expenditure and budget reports because they were considered to be confidential. This situation would result in which of the following limitations of the internal audit activity?

Options:

A.  

Independence

B.  

Integrity

C.  

objectivity

D.  

Authority

Discussion 0
Questions 32

Which of the following are some of the requirements of the quality assurance and improvement program (QAIP)?

Options:

A.  

The OAIP should be conducted at least once every three years, and must be performed by an external assessor.

B.  

The OAIP should be conducted on an ongoing basis, and can be completed as a self-assessment,

C.  

he QAIP should include both internal assessments performed by staff and external assessments performed by independent, objective individuals

D.  

The OAIP should be performed with scoping limitations established by the board.

Discussion 0
Questions 33

Which of the following is a true statement regarding whistleblowing?

Options:

A.  

Whistleblowing is one of several possible ethical structures an organization can undertake to encourage ethical behavior.

B.  

Whistleblowing programs help employees deal with ethical questions and instill ethical values into everyday behavior

C.  

Whistleblowers are current or former employees who are disgruntled and looking to retaliate.

D.  

Whistleblowers should inform the organization about actual criminal circumstances, not assumed allegations

Discussion 0
Questions 34

A chief audit executive (CAE) was asked by senior management to establish and manage a risk management function. A new chief risk officer was hired a year later to assume these responsibilities. As this function was included in the current annual audit plan, the CAE engaged an external resource for a risk management engagement. Which of the following potential threats to objectivity was the CAE likely addressing?

Options:

A.  

Self-review threat.

B.  

Advocacy threat.

C.  

Familiarity threat.

D.  

Personal relationship threat.

Discussion 0
Questions 35

Which of the following resources would be most effective for an organization that would like to improve how it informs stakeholders of its social responsibility performance?

Options:

A.  

ISO 26000.

B.  

Global Reporting Initiative.

C.  

Open Compliance and Ethics Group.

D.  

COSO’s enterprise risk management framework

Discussion 0
Questions 36

An internal audit team received the following feedback from operational management via a post-engagement survey " Management agrees with all audit findings However, the audit team did not consider our input on the best way to resolve the issues”

This feedback is an indication that the internal audit activity may need to improve which of the following interpersonal skills?

Options:

A.  

Leadership

B.  

Conflict management

C.  

Communication

D.  

Influence

Discussion 0
Questions 37

According to IIA guidance which of the following correctly describes the standard risk treatments outlined in the process element approach of the framework for risk management?

Options:

A.  

Risk avoidance risk sharing application of controls, risk application.

B.  

Risk avoidance risk identification application of controls risk acceptance.

C.  

Risk identification risk assessment risk avoidance risk monitoring

D.  

Risk identification risk assessment application of controls risk acceptance

Discussion 0
Questions 38

When the chief audit executive Is responsible for risk management in an organization, which of the following parties is responsible for overseeing the internal audit activity ' s assurance over risk management?

Options:

A.  

The chief audit executive.

B.  

A member of the compliance function.

C.  

A party outside of the internal audit activity.

D.  

A member of the risk management function.

Discussion 0
Questions 39

Which of the following scenarios would cause a chief audit executive (CAE) to immediately discontinue using any statements that would indicate conformance with the Standards in an audit report?

Options:

A.  

The internal audit activity used a risk-based approach to create the internal audit plan.

B.  

The engagement supervisor considered requests from senior management regarding engagements to include in the internal audit plan.

C.  

The CAE only accepted engagements that the internal audit activity collectively had the knowledge to perform.

D.  

The area under review restricted the internal audit activity ' s ability to access records, impacting the audit results.

Discussion 0
Questions 40

Which of the following strategies would be the most effective to share an organization ' s risk of losses through foreign currency transactions related to the accounts payable process?

Options:

A.  

Using a hedging strategy.

B.  

Implementing controls to follow up on deviations.

C.  

Purchasing liability insurance.

D.  

Purchasing foreign currency reserves.

Discussion 0
Questions 41

According to NA guidance, which of the following describes the primary reason to implement environmental and social safeguards within an organization?

Options:

A.  

To enable Triple Bottom Line reporting capability.

B.  

To facilitate the conduct of risk assessment.

C.  

To achieve and maintain sustainable development.

D.  

To fulfill regulatory and compliance requirements.

Discussion 0
Questions 42

Which of the following would most likely be classified as a consulting engagement?

Options:

A.  

Examining the internal control effectiveness of the marketing department

B.  

Assessing the adequacy of the IT system ' s business process design

C.  

Facilitating a self assessment of the organizations business risk and control identification

D.  

Reviewing the application controls in the human resources system

Discussion 0
Questions 43

According to IIA guidance, which of the following best describes the chief audit executive s responsibility for confirming to the board the organizational independence of the internal audit activity ' ?

Options:

A.  

The CAE must do this at least annually

B.  

The CAE must do this at least once every five years

C.  

The CAE must do this upon completion of each external quality assessment

D.  

The CAE should do this periodically in conjunction with a review of the internal audit charter

Discussion 0
Questions 44

To achieve conformance with the Standards, the chief audit executive must include which of the following activities in the quality assurance and improvement program (QAIP)?

Options:

A.  

Require board oversight of the QAIP.

B.  

Assess Standards conformance for each individual engagement.

C.  

Conduct a self assessment at least once every five years.

D.  

Report the results of the QAIP to senior management

Discussion 0
Questions 45

During an audit of the purchasing department, an internal auditor identifies significant issues that could affect the organization ' s financial reporting. Management disagrees with the audit results. Which of the following responses best demonstrates the internal auditor has the necessary competencies related to professional Judgment and conflict management?

Options:

A.  

The auditor maintains his convictions and continues to proceed with the review process despite management ' s concerns related to the results.

B.  

The auditor bypasses management, discusses the results with the board, and seeks the board ' s input on how best to address the recommendations.

C.  

The auditor consults with other members of the audit team, and together they develop alternative recommendations that management may be more likely to accept.

D.  

The auditor meets with management to discuss the results and obtain a better understanding of the specific concerns.

Discussion 0
Questions 46

Which of the following statements is true regarding reporting results of the quality assurance and improvement program to senior management and the board?

Options:

A.  

Internal assessments must be reported to the board at least every five years

B.  

If supported by assessment results, reporting provides assurance that internal auditors demonstrate conformance with the Code of Ethics

C.  

Following the reporting the board must give the internal audit activity five years to correct any deviations

D.  

A report, including the results of both internal and external assessments must be provided to the board annually

Discussion 0
Questions 47

An organization is considering purchasing a new banking software system and has asked the internal audit activity to evaluate the system. An internal auditor assigned to perform the engagement worked at the software company two years ago and is familiar with the system ' s design strengths and weaknesses. Which of the following is true regarding impairment to the auditor ' s objectivity?

Options:

A.  

This situation does not necessitate any action related to the auditor ' s objectivity.

B.  

The auditor should decline to perform the audit because personal conflicts of interest are likely.

C.  

The auditor must disclose to the chief audit executive that this situation may impair her objectivity.

D.  

The auditor can provide only consulting services, not assurance.

Discussion 0
Questions 48

Which of the following best demonstrates conformance with the Standards regarding the internal audit activity ' s purpose authority, and responsibility?

Options:

A.  

Discussion and formal presentation of the internal audit charter to the board of directors

B.  

Certification by external auditors on the purpose, authority and responsibility of the internal audit activity

C.  

Approval of senior management that the internal audit activity is functioning as originally designed

D.  

Self-assessment of the internal audit activity completed by the chief audit executive

Discussion 0
Questions 49

An organization allows the same individual to physically access inventory and purchase new assets when supplies are depleted. Which of the following would best help the organization manage the risk of fraud?

Options:

A.  

Accounting personnel should regularly perform a reconciliation between invoices and purchase orders.

B.  

Accounting personnel should conduct a periodic inventory count and reconcile all inventory movements.

C.  

Internal auditors should review the frequency and volume of purchased assets to detect trends in the inventory levels.

D.  

Management should establish a policy requiring new inventory asset purchases to be made on serialized order forms with copies retained.

Discussion 0
Questions 50

Which of the following activities best demonstrates an internal auditor’s commitment to developing professional competencies?

Options:

A.  

Requesting to be part of all engagements on the annual audit plan.

B.  

Attending a series of locally offered training courses.

C.  

Completing a skills assessment and development plan for targeted training needs,

D.  

Attending a webinar on how to use data analytics

Discussion 0
Questions 51

According to IIA guidance, which of the following statements is true regarding the internal audit activity’s responsibilities in providing consulting services?

Options:

A.  

The chief audit executive is responsible for deciding the priority of consulting services in the internal audit plan

B.  

The scope of consulting services is determined primarily by the internal auditor with input from management of the area under review

C.  

The board defines the internal audit activity’s responsibilities over consulting activities

D.  

Adding value to an organization requires the internal audit activity to initiate a consulting engagement

Discussion 0
Questions 52

Senior management asks the chief audit executive to review the organization ' s compliance with recently introduced legislation on international transfer pricing. The review requires an internal auditor who thoroughly understands the legislation and pricing methods. The internal audit activity does not have an auditor with those skills. Which of the following is the most appropriate course of action?

Options:

A.  

Outsource the engagement to an external audit firm that has appropriate skills.

B.  

Recruit a lawyer with knowledge of the legislation to the audit team and ask the new auditor to perform the engagement.

C.  

Decline to perform the engagement, as the internal audit activity does not have the appropriate skill set.

D.  

Carry out the engagement using existing internal audit staff to help them gain the appropriate experience.

Discussion 0
Questions 53

Which of the following would be considered a violation of The HAfs mandatory guidance on independence?

Options:

A.  

The chief audit executive (CAE) reports functionally to the board and administratively to the chief financial officer.

B.  

The board seeks senior management ' s recommendation before approving the annual salary adjustment of the CAE.

C.  

The CAE confirms to the board, at least once every five years, the organizational independence of the internal audit activity,

D.  

The CAE updates the internal audit charter and presents it to the board for approval periodically, not on a specific timeline

Discussion 0
Questions 54

For a new board chair who has not previously served on the organization ' s board, which of the following steps should first be undertaken to ensure effective leadership to the board?

Options:

A.  

Chair should learn the current organizational culture of the company.

B.  

Chair should learn the current risk management system of the company.

C.  

Chair should determine the appropriateness of the current strategic risks.

D.  

Chair should gain an understanding of the needs of key stakeholders.

Discussion 0
Questions 55

Which of the following practices is generally most effective to protect internal audit objectivity?

Options:

A.  

Ensuring regular documentation of auditor skills and experience in the workpapers.

B.  

Basing performance evaluations heavily on customer satisfaction surveys.

C.  

Prohibiting auditors from accepting gifts from audit clients or potential clients.

D.  

Ensuring that auditors have a balance of both operational and internal audit responsibilities.

Discussion 0
Questions 56

Which of the following approaches will internal audit utilize when developing a set of performance standards to measure an organization’s risk management process against?

Options:

A.  

Key principles approach

B.  

Process elements approach

C.  

Holistic approach

D.  

Maturity model approach

Discussion 0
Questions 57

Which of the following fraud prevention measures is most likely to trigger undesired adverse behavior if improperly designed?

Options:

A.  

Disclosure of outside business activities

B.  

Ethics training programs

C.  

Compensation programs

D.  

Exit interviews

Discussion 0
Questions 58

The results of an assessment of the adequacy of controls would be considered incomplete or misleading unless the internal auditor considers which of the following?

Options:

A.  

Number of mitigating controls.

B.  

Effectiveness of the control environment

C.  

Use of computer-assisted auditing techniques.

D.  

IT security controls

Discussion 0
Questions 59

An existing Internal audit charter is currently under review for revision. Who is responsible for assuring that all required components are included?

Options:

A.  

The audit committee.

B.  

The head of legal and compliance.

C.  

The chief audit executive.

D.  

Senior management.

Discussion 0
Questions 60

Which of the following best describes the risk created when a manager bypasses organizational policies and procedures in order to meet an organization’s objective?

Options:

A.  

Accountability/reward risk.

B.  

Monitoring failure risk.

C.  

Communication failure risk.

D.  

Knowledge/skills risk

Discussion 0
Questions 61

To comply with the proficiency standard which of the following would the chief audit executive likely consider as the primary hiring criterion when choosing a new internal auditor?

Options:

A.  

The length and consistency of the auditor ' s work experience

B.  

The auditor ' s demonstrated problem-solving skills

C.  

The auditor ' s skills compared to those already possessed by other audit staff

D.  

The auditor ' s ability to be self motivated and a good team player

Discussion 0
Questions 62

Which of the following is an example of a risk avoidance strategy?

Options:

A.  

Hedging against exchange rate variations.

B.  

Limiting access to an organization’s data center.

C.  

Selling a nonstrategic business unit.

D.  

Outsourcing a high-risk activity

Discussion 0
Questions 63

An internal auditor wants to compare her organization’s governance processes to those of a well-known governance model. Which of the following approaches would the auditor take for this purpose?

Options:

A.  

Perform a gap analysis to assess me differences between the approaches

B.  

Assess the governance processes using computerized modeling techniques

C.  

identify any differences between the processes using a variance analysis

D.  

Benchmark the governance processes using a capability maturity modal

Discussion 0
Questions 64

A business unit manager was impressed by the competence of the internal auditor who was conducting an assurance engagement in his area and the manager made the auditor an attractive job offer to begin after the audit was completed The auditor later told her auditor in charge that she was considering the offer. Which of the following IIA Code of Ethics principles was most likely violated?

Options:

A.  

Integrity

B.  

Confidentiality

C.  

Objectivity

D.  

No violation was committed

Discussion 0
Questions 65

Which of the following statements best represents the due professional care that is required of internal auditors?

Options:

A.  

Internal auditors should perform assurance procedures to ensure that all significant risks are identified.

B.  

Internal auditors should not perform consulting engagements for operations for which they had previous responsibilities.

C.  

Internal auditors should consider the cost of assurance in relation to the potential benefits.

D.  

Internal auditors should devise internal audit programs to confirm that the results are accurate.

Discussion 0
Questions 66

As a result of a high-profile processing error, respective business unit managers are implementing new controls. The internal audit team was asked for their advice regarding the controls. The objective of this consulting engagement would be determined by which of the following?

Options:

A.  

The organization ' s board of directors.

B.  

The chief audit executive.

C.  

The business unit manager and the engagement supervisor.

D.  

The compliance manager and the business unit manager.

Discussion 0
Questions 67

According to IIA guidance, which of the following is an appropriate role for the internal audit activity?

Options:

A.  

Coaching management in responding to risks.

B.  

Implementing risk responses on management ' s behalf.

C.  

Imposing risk management processes.

D.  

Setting the risk appetite.

Discussion 0
Questions 68

Which of the following should be part of the internal audit activity ' s duties?

Options:

A.  

Actively reporting to the governing body.

B.  

Providing risk management frameworks.

C.  

Assisting management in developing processes and controls to manage risks and issues.

D.  

Identifying and mitigating significant risks to the organization.

Discussion 0
Questions 69

Which of the following is the most appropriate way to ensure that a newly formed internal audit activity remains free from undue influence by management?

Options:

A.  

Appoint the chief audit executive as a member of the board.

B.  

Adopt written policies and procedures for the internal audit activity, approved by the board.

C.  

Ensure the chief audit executive reports administratively to the audit committee.

D.  

Establish the internal audit activity’s position within the organization in an audit charter.

Discussion 0
Questions 70

An internal auditor creates a professional development plan to obtain more experience in the organization ' s environmental, social, and corporate governance initiatives. Which of the following would the auditor include in the plan to support these objectives?

Options:

A.  

A plan to study for and obtain a certification in nonprofit management.

B.  

A deadline within the individual development plan to meet the overall engagement objectives.

C.  

A plan to perform a variety of engagements to develop general skills that could be used to assess environmental, social, and governance initiatives.

D.  

A request to attend the organization ' s committee meeting that is focused on strategic community awareness.

Discussion 0
Questions 71

Which of the following is a way to demonstrate an individual internal auditor ' s competency through continuing professional development?

Options:

A.  

Create different training budgets for each of the internal auditors

B.  

Define average training hours per auditor as a team performance measure

C.  

Analyze internal audit client survey feedback following audits

D.  

Review training records for all internal auditors

Discussion 0
Questions 72

According to NA guidance which of the following should be documented in the internal audit chatter?

Options:

A.  

The risk assessment process applied by the internal audit activity

B.  

The organization ' s internal control framework used by the internal audit activity

C.  

The nature of consulting services provided by the internal audit activity

D.  

The performance evaluation process used by the internal audit activity

Discussion 0
Questions 73

Which of the following would be the most effective fraud prevention control?

Options:

A.  

Email alert sent to management for checks issued over $100,000.

B.  

Installation of a video surveillance system in a warehouse prone to inventory loss.

C.  

New hire training to explain fraud and employee misconduct.

D.  

Daily report that identifies unsuccessful system log-in attempts

Discussion 0
Questions 74

It is important for the chief audit executive to consider the level of competence of the internal audit staff because their competence influences which of the following?

Options:

A.  

The cost-benefit relationship of planned audits.

B.  

Proficiency needed to carry out engagements.

C.  

Achievement of the objectives of internal control.

D.  

Quantity of the audits performed.

Discussion 0
Questions 75

An organization ' s board has approved an expansion plan into a new market. The board acknowledged that if the expansion is not successful, the organization would encounter large monetary losses consisting of legal fees, research and development costs, rent expenses, and labor fees. Which of the following has the board approved?

Options:

A.  

The risk response.

B.  

The risk tolerance.

C.  

The residual risk.

D.  

The inherent risk.

Discussion 0
Questions 76

An IT contractor applied for an internal audit position at a bank. The contractor worked for the bank ' s IT security manager two years ago. If the audit manager interviewed the contractor and wants to extend a job offer, which of the following actions should the chief audit executive pursue?

Options:

A.  

Allow the audit manager to hire the contractor and state that the individual is free to perform IT audits, including security.

B.  

Not allow the audit manager to hire the contractor, as it would be a conflict of interest

C.  

Allow the audit manager to hire the contractor, but state that the individual is not allowed to work on IT security audits for one year.

D.  

Not allow the audit manager to hire the contractor and ask the individual to apply again in one year.

Discussion 0
Questions 77

Which of the following tools would be most useful to an internal auditor performing an assessment of the effectiveness of the organization ' s risk responses?

Options:

A.  

Heat map.

B.  

Risk and control matrix.

C.  

Risk register.

D.  

Process map.

Discussion 0
Questions 78

After the draft engagement report is issued, the manager of the area that was reviewed is informally interviewed by the engagement supervisor regarding the audit experience. Which of the following is most likely the purpose for this interview?

Options:

A.  

Such an interview is performed when there is a need to dismiss an internal auditor

B.  

Feedback from the manager will contribute to the audit team ' s professional development

C.  

The manager ' s opinion will be used to form the final audit assessment and report rating.

D.  

The manager will provide insights into the audited industry ' s trends

Discussion 0
Questions 79

An internal audit team was assigned to review the organization’s information security protocol After fieldwork was completed an internal auditor identified an error in the review of security access The error could affect the overall results of the engagement Which of the following is the most appropriate course of action for the internal auditor?

Options:

A.  

Proceed with addressing the error and report any corrections to the engagement supervisor during the scheduled exit meeting

B.  

Issue the audit report to senior management on schedule but include a disclaimer about the error

C.  

Proceed with the scheduled closing of the engagement without consideration of the identified error

D.  

Inform the engagement supervisor of the error and allow the supervisor to determine the appropriate action to take

Discussion 0
Questions 80

Which of the following best demonstrates the board of directors ' governance over internal control?

Options:

A.  

The board bears direct responsibility for developing and implementing the internal control system.

B.  

The majority of board members are experienced and qualified members of the organization ' s executive management team.

C.  

The board may be assisted by an audit committee, chaired by the chief audit executive.

D.  

The board is responsible for succession planning for the CEO and other key members of the executive management team.

Discussion 0
Questions 81

According to IIA guidance, which of the following is required of an internal audit activity?

Options:

A.  

The internal audit activity should refrain from conducting an assurance engagement for which it lacks the necessary competencies or skills

B.  

The chief audit executive must decline a consulting engagement or obtain competent advice and assistance if internal auditors lack the necessary competencies or skills

C.  

The audit committee should ensure that the internal audit activity continuously improves its knowledge and skills in order to fulfill its responsibilities

D.  

In today ' s business climate which is dominated by technology and big data, it is imperative that each staff internal auditor has detailed knowledge about IT risks and technology-based audit techniques

Discussion 0
Questions 82

Which of the following statements represents the most appropriate correlation between an organization ' s risk maturity and the internal audit activity’s consulting role in risk management processes?

Options:

A.  

When an organization has a high level of risk maturity the internal audit activity is less likely to provide consulting services related to risk management

B.  

When an organization has a low level of risk maturity, the internal audit activity is less likely to provide consulting services related to risk management

C.  

When an organization has a high level of risk maturity the internal audit activity is more likely to provide consulting services related to risk management

D.  

There is typically no correlation between an organization’s risk maturity and the extent to which the internal audit activity’s consulting role in risk management processes

Discussion 0
Questions 83

According to IIA guidance, which of the following statements is true regarding reporting the results of the quality assurance and improvement program?

Options:

A.  

Results of internal assessments need to be reported to the board at least once every five years.

B.  

The external assessor must present the findings from the external assessment to senior management and the board upon completion.

C.  

Deficiencies within the internal audit activity must be reported to the board as soon as they are noted.

D.  

Results of ongoing monitoring of the internal audit activity ' s performance must be reported to senior management and the board at least annually

Discussion 0
Questions 84

Which of the following would be considered a primary control to reduce the risk associated with setting up duplicate vendors?

Options:

A.  

Receipt of a signed and approved vendor setup form.

B.  

Segregation of duties between setting up vendors and making vendor payments.

C.  

System validation and edit checks on vendor identification number

D.  

A vendor setup policy and procedure.

Discussion 0
Questions 85

Which of the following is an example of corruption?

Options:

A.  

Recognizing revenue up front rather than over a contract’s life to inflate revenue for the current period

B.  

Requesting reimbursement for overstated travel and entertainment expense amount

C.  

Misstating realized foreign currency transaction gains or losses

D.  

Demanding payment from a vendor for decisions made in the vendor’s favor

Discussion 0
Questions 86

A whistle blower notified internal audit of a conflict of interest between an organization ' s employee and a major supplier. Which of the following steps should be undertaken first?

Options:

A.  

Interview the employee identified by the whistleblower.

B.  

Attain an understanding of the employee ' s role, responsibilities, and relationship with the supplier.

C.  

Notify senior management, the board, and the external auditor about the alleged fraud

D.  

Review all the orders issued to the supplier to investigate potential fraud.

Discussion 0
Questions 87

Which of the following statements is true regarding the independent peer review process undertaken to fulfill the requirement for an external quality assessment?

Options:

A.  

Two individuals in the same internal audit activity may perform an independent peer review as long as they do not report to the same audit manager

B.  

Individuals from a separate but related organization such as an affiliate may perform peer reviews

C.  

Individuals working in separate internal audit activities may be considered independent as long as do not report to the same chief audit executive

D.  

Peer reviews are generally less cost-effective than hiring an external quality assessor

Discussion 0
Questions 88

Once an organization ' s risks are identified, what would be the next step to ensure resources are properly allocated to manage those risks?

Options:

A.  

Risk responses must be selected.

B.  

Risks must be assessed.

C.  

The risk universe must be established.

D.  

Risk responses must be aligned.

Discussion 0
Questions 89

An internal auditor is performing testing to gather evidence regarding an organization’s inventory account balance and is mindful of the possibility that the sample used might support the conclusion that the recorded account balance is not materially misstated when, in fact, it is. The auditor ' s concern best describes which of the following risks?

Options:

A.  

incorrect rejection risk

B.  

Incorrect acceptance risk.

C.  

Tolerable misstatement risk.

D.  

Anticipated misstatement risk

Discussion 0
Questions 90

Which of the following principles of The IIA ' s Code of Ethics implies that internal auditors should refrain from performing assurance services when there is an impairment to audit independence that has not been declared?

Options:

A.  

Confidentiality.

B.  

Objectivity.

C.  

Integrity.

D.  

Competency.

Discussion 0
Questions 91

Which of the following scenarios demonstrates nonconformance with the Standards?

Options:

A.  

An internal auditor failed to expand the engagement and include managements preferences when determining the scope of an upcoming assurance engagement.

B.  

An internal audit activity lacks the skills need to perform a high-risk security engagement included on the annual audit plan.

C.  

A chief audit executive fated to perform a risk assessment prior to preparing the audit plan

D.  

An internal audit activity has existed for two years and has not undergone external quality assessment

Discussion 0
Questions 92

An accounts payable clerk has recently transferred into the internal audit activity and has been assigned to an engagement related to accounts payable processes for which he was previously responsible. Which of the following is the best action for the new internal auditor to take?

Options:

A.  

If it is an assurance engagement, accept the assignment because direct knowledge of the existing accounts payable processes wifi provide depth and add more value.,

B.  

If it is a consulting engagement, decline the assignment and ask to be reassigned, because in a consulting engagement the auditor must not assess operations for areas in which they were previously responsible.

C.  

If it is a consulting engagement, accept the assignment because direct knowledge of the existing accounts payable processes will provide depth and add more value.

D.  

If it is an assurance engagement, accept the assignment because the chief audit executive had knowledge of the internal auditor ' s previous role when this engagement was assigned.

Discussion 0
Questions 93

Which of the following should be implemented to promote independence of the internal audit activity?

Options:

A.  

Internal auditors do not review an area where they previously worked

B.  

The internal audit charter is reviewed and updated annually

C.  

The chief audit executive reports functionally to the board

D.  

Management does not influence the consulting services provided by the internal audit activity

Discussion 0
Questions 94

An internal auditor is providing consulting services on an area he was responsible for three years ago. Part of the consulting scope covers a review of a performance measuring system that the auditor helped to develop. What is the best course of action for the auditor to take concerning the consulting service?

Options:

A.  

Accept the consulting services only after receiving approval to do so from the board.

B.  

Accept the consulting services. The objectivity won ' t be impaired if it has been more than a year since he last worked in the area under review.

C.  

Refrain from providing the consulting service because he was responsible for that area and his objectivity will be impaired,

D.  

Disclose the potential impairment to the customer before accepting the consulting engagement

Discussion 0
Questions 95

A chief audit executive (CAE) recruited a few new internal auditors to reduce the resource gaps identified in this year ' s internal audit plan. One of the new recruits has several years of experience with the organization. Ten months ago. she served as a senior supervisor in the finance department. However, for the past 10 months, she has been helping the organization with implementing a new IT system. What approach should the CAE take for the upcoming financial statement controls audit?

Options:

A.  

Assign the new auditor to assist with conducting the fieldwork. but ensure that her work is reviewed by the CAE.

B.  

Assign the new auditor to assist with developing the audit program, but ensure that the audit program is executed by other audit staff.

C.  

Ensure that the new auditor ' s previous manager, and other close former coworkers, are excused during the audit.

D.  

Ensure that the new auditor is responsible only for the supervisory review, but not the execution of the audit field work.

Discussion 0
Questions 96

Which of the following statements best describes a functional difference between external auditors and internal auditors?

Options:

A.  

Internal auditors evaluate past achievements to understand whether controls are operating effectively, and external auditors focus on the accuracy of financial reporting.

B.  

Internal auditors provide assurance about the sufficiency of controls to manage risks. Including risks of failure to achieve future goals, and external auditors evaluate the accuracy and understandability of financial reporting.

C.  

internal auditors are always employed by the organization, rather than outsourced, and external auditors are never employed by the organization but contracted independently.

D.  

Internal auditors are most directly concerned with the detection of fraud, while external auditors are most directly concerned with the prevention of fraud.

Discussion 0
Questions 97

Which of the following statements best describes internal auditors ' role in fraud detection?

Options:

A.  

Internal auditors ' roles are similar to those performed by loss prevention managers or fraud investigators.

B.  

Internal auditors ' demonstration of adequate professional skepticism during an audit engagement is of paramount importance.

C.  

Internal auditors should consider fraud risks in every assignment and demonstrate due care by detecting fraud instances.

D.  

Internal auditors should possess a fraud-related body of knowledge, enabling them to carry out preventative and detective measures.

Discussion 0
Questions 98

Which of the following statements is true regarding occupational fraud?

Options:

A.  

An employee who diverts the organization ' s purchases for personal use is demonstrating asset misappropriation

B.  

An employee who intentionally omits negative information in the financial statement disclosures is demonstrating an example of corruption

C.  

An employee who made an error in estimating losses may have committed fraud even if the error was not intentional

D.  

An employee who creates a denial of service in the organization’s computer systems is committing asset misappropriation

Discussion 0
Questions 99

What is the primary reason a chief audit executive should dedicate time and resources to support continuing professional development of internal audit staff?

Options:

A.  

To ensure that internal audit staff maintains high overall job satisfaction.

B.  

To ensure that internal audit staff acquired continuing professional education credits timely.

C.  

To ensure that top risks are mitigated to an acceptance level.

D.  

To ensure that internal audit staff have the competency to address high-priority risks.

Discussion 0
Questions 100

Which of the following is a primary responsibility of senior management with respect to ethical violations?

Options:

A.  

Senior management provides oversight for the organization ' s ethical climate.

B.  

Senior management promotes an ethical culture in the organization.

C.  

Senior management assesses the effectiveness of the organization’s ethical programs.

D.  

Senior management reviews major ethical policies in the organization for compliance

Discussion 0
Questions 101

Which of the following best describes the internal audit activity’s responsibility within a risk and control framework?

Options:

A.  

The internal audit activity constitutes the first line of defense in effective risk management.

B.  

The internal audit activity provides direction regarding internal controls implementation.

C.  

The internal audit activity verifies that management has met its responsibility for implementing effective controls.

D.  

The internal audit activity implements the internal control framework and advises management regarding best practices.

Discussion 0
Questions 102

An organization allows the same individuals to physical access inventory and purchase new assets when supplies are depleted. Which of the following would best help the organization manage the risk of fraud?

Options:

A.  

Accounting personnel should regularly perform reconciliation between invoices and purchase orders

B.  

Accounting personnel should conduct a periodic inventory count and reconcile inventory movements

C.  

internal auditors should review Vie frequency and volume of purchased assets to detect trends in the inventory levels

D.  

Management should established a policy requiring new inventory asset purchases to be made on serialized order forms with copies retained

Discussion 0
Questions 103

What should be the first step for a newly hired chief audit executive to build and maintain the proficiency of the internal audit activity ' ?

Options:

A.  

Incorporate the basic criteria of internal audit competency into job descriptions

B.  

Complete a periodic skills assessment of the internal audit activity

C.  

Develop a competency or skill assessment tool.

D.  

Perform benchmarking with competitors to learn what other firms are doing related to this topic

Discussion 0
Questions 104

According to the Standards, in today ' s technology and business environments, how much computer and information systems-related knowledge and skills must an internal auditor have to be effective in fulfilling his job responsibilities?

Options:

A.  

Auditors must have an IT specialty in at least one of their organization ' s key information technology systems.

B.  

Auditors must be proficient in data analysis and computer assisted audit techniques for their organization.

C.  

Auditors must understand their organization ' s integrated test facilities and generalized audit software.

D.  

Auditors must understand their organization ' s IT governance, risk, and control processes.

Discussion 0
Questions 105

After being assigned to an audit of the accounts payable process, an internal auditor privately notifies the chief audit executive that she is a finalist for an open manager position within the accounts payable department. Which of the following is the IIA Code of Ethics principle that the auditor upheld?

Options:

A.  

Independence.

B.  

Confidentiality.

C.  

Objectivity.

D.  

Competency

Discussion 0
Questions 106

According to IIA guidance, which of the following would be included in an internal audit charter to help establish the authority of the internal audit activity?

Options:

A.  

Outline expectations for communicating the results of all aspects of the internal audit activity.

B.  

Declare the internal audit activity’s accountability for safeguarding assets and confidentiality.

C.  

Document the chief audit executive’s (CAE ' s) reporting line

D.  

Document agreement between the CAE and the individual to whom the CAE reports

Discussion 0
Questions 107

An internal auditor believes that a weakness exists in the control environment relating to the delegation of authority and responsibility within the management structure. Which of the following actions should the internal auditor first consider in this matter?

Options:

A.  

Recommend a control change and obtain management support.

B.  

Evaluate the potential Impact on related controls.

C.  

Address the risk with senior management and the board.

D.  

Develop and communicate the scope and evaluation criteria to be used by management.

Discussion 0
Questions 108

In a retail organization, sales teams compete with each other to achieve and exceed sales targets. Each quarter, the members of the top sales team receive a bonus. In this environment, management should closely monitor for the emergence of which of the following potential risks?

Options:

A.  

Risks related to employee turnover.

B.  

Risks related to data manipulation.

C.  

Risks related to employee competency.

D.  

Risks related to not achieving sales targets.

Discussion 0
Questions 109

Which of the following indicates that internal audit independence may be compromised?

Options:

A.  

The internal auditor maintains a close personal relationship with operational management.

B.  

Material observations were intentionally left out of the audit report.

C.  

Internal auditors assigned to the audit engagement did not have the knowledge, skills, and competencies needed to perform their responsibilities.

D.  

An internal auditor failed to apply professional skepticism while performing audit tests in an area overseen by an experienced, reputable manager

Discussion 0
Questions 110

Which documents would help a forensic auditor identify instances of collusion between an employee and vendor to defraud the organization?

Options:

A.  

Email correspondence.

B.  

Payment request forms.

C.  

Vendor invoices.

D.  

Bank statements.

Discussion 0
Questions 111

Which of the following best describes organizational governance processes?

Options:

A.  

Processes employed by internal and external assurance providers to authorize, direct, and provide oversight to management to better enable the meeting of organizational objectives

B.  

Processes employed by the board of directors to authorize and provide guidance and oversight to management to promote the achievement of organizational objectives.

C.  

Processes employed by the board of directors and senior management to mitigate risks to acceptable levels.

D.  

Processes employed by risk owners to mitigate risks to acceptable levels within the organization ' s risk appetite

Discussion 0
Questions 112

During a review of employee benefits, a staff internal auditor observed an ambiguity in the incentive compensation policy. If reported, it could negatively impact the internal auditor ' s compensation. Which of the following would encourage the internal auditor to be objective in his work?

Options:

A.  

Periodic reinforcement of the internal audit activity ' s code of ethics disclosure practices.

B.  

External assessments of the internal audit activity every five years.

C.  

Audit committee review of every engagement report at the conclusion of the audit.

D.  

Internal audit charter approved by the board.

Discussion 0
Questions 113

Which of the following statements about internal audit consulting engagements is true?

Options:

A.  

The primary purpose of a consulting engagement is to assess evidence and provide conclusions.

B.  

The internal audit activity determines the nature and scope of work for the specific consulting engagement

C.  

Internal auditors may provide consulting services relating to operations for which they had previous responsibilities.

D.  

It is not appropriate to communicate control issues identified during consulting engagements to the board

Discussion 0
Questions 114

How should the internal audit activity promote continuous improvement of organizational controls?

Options:

A.  

By assessing implementation of controls m individual processes during audit engagements

B.  

By identifying the most significant business processes and designing effective controls for those processes

C.  

By implementing an internationally accepted internal control framework across the organization

D.  

By facilitating control self-assessment sessions for managers responsible for business processes

Discussion 0
Questions 115

According to IIA guidance, which of the following most appropriately justifies the CEO’s decision that the internal audit activity shall be responsible for risk management and investigation at a multinational organization?

Options:

A.  

The recommendation of the parent office external auditors.

B.  

The provisions of the internal audit charter

C.  

The authority of the CEO.

D.  

The level of proficiency of the chief audit executive

Discussion 0
Questions 116

Which of the following is true for consulting engagements ' ?

Options:

A.  

The internal audit activity must ensure management actions have been effectively implemented or risk accepted

B.  

A work program for the engagement is not required but may be developed

C.  

The nature of consulting services does not have to be in the internal audit charter

D.  

Risks identified from the engagement must be considered when evaluating the organization ' s risk management processes

Discussion 0
Questions 117

In which of the following scenarios would the internal auditor’s objectivity be best protected?

Options:

A.  

A former human resources manager conducts an effectiveness review of the appointment and termination process six months after transferring to the internal audit activity.

B.  

An accounts payable clerk assists the internal auditors during an effectiveness review of the physical access controls to the server room.

C.  

An internal auditor writes the system manual for a newly acquired payroll software application prior to conducting an effectiveness review of the system.

D.  

An internal auditor conducts an effectiveness review of an organization ' s business continuity plan in which his son is a minority stockholder.

Discussion 0
Questions 118

An external assessment was performed as part of the organization ' s quality assurance and improvement program. Which of the following conclusions confirms that the internal audit activity is in conformance with the Standards ' ?

Options:

A.  

The chief audit executive is well qualified and has responsibilities over operational areas that the internal audit activity assesses.

B.  

Periodic self-assessments are assigned to entry-level internal audit staff to support their continuing professional development.

C.  

All audit workpapers are reviewed and signed by the engagement supervisor before the audit report is issued.

D.  

Employees who rotate into the internal audit activity from other areas of the organization are assigned to audit areas where they previously worked, to take advantage of their operational expertise and experience.

Discussion 0
Questions 119

An internal auditor was completely honest with operational management when delivering unfavorable audit results. Which of the following best describes the IIA Code of Ethics principle that the auditor demonstrated?

Options:

A.  

Integrity

B.  

Objectivity

C.  

Competency

D.  

Transparency

Discussion 0
Questions 120

Which of the following should an internal auditor take into consideration when making a judgement regarding whether management selected appropriate risk responses?

Options:

A.  

Significant risks

B.  

Risk capacity

C.  

Risk appetite

D.  

Risk tolerance

Discussion 0
Questions 121

Which of the following would show appropriate disclosure of nonconformance with the Standards?

Options:

A.  

The chief audit executive (CAE) documented in the personnel file a critical conflict of interest involving an internal auditor on an upcoming contracting engagement.

B.  

The CAE discussed with the board an issue regarding the internal audit activity performing an IT engagement without proper skills and knowledge.

C.  

The CAE met with the peer review team to discuss an internal auditor ' s failure to meet the annual requirements for continuing professional education.

D.  

The CAE revealed to operational managers that he failed to appropriately consider risks while he was developing the audit plan.

Discussion 0
Questions 122

Which of the following would be considered a monitoring activity in organization wide risk management?

Options:

A.  

Validate the results of management ' s self-assessment.

B.  

Perform reviews of personnel.

C.  

Maintain rigorous and comprehensive documentation.

D.  

Obtain authorizations and signatures.

Discussion 0
Questions 123

Which of the following statements demonstrates that internal auditors are in conformance with the standard of due professional care?

Options:

A.  

Internal auditors have shown they have the freedom to carry out their responsibilities.

B.  

Internal auditors have demonstrated the skills needed to carry out the audit engagement.

C.  

Internal auditors have strictly followed a formal audit process in conducting their work.

D.  

Internal auditors have demonstrated an unbiased mental attitude.

Discussion 0
Questions 124

An internal auditor observed that sales staff are able to modify or cancel an order in the system prior to shipping* She wonders whether they can also modify orders after shipping. Which of the following types of controls should she examine?

Options:

A.  

Batch controls.

B.  

Application controls.

C.  

General IT controls.

D.  

Logical access controls

Discussion 0
Questions 125

A newly hired chief audit executive is reviewing available documentation to provide evidence of conformance with the standard for continuing professional development. Which of the following documents is the most reliable source for this purpose?

Options:

A.  

The organization ' s training policy.

B.  

A list of auditors who requested to attend the next audit conference.

C.  

Self-assessments against an internally developed audit benchmark

D.  

In house training manual

Discussion 0
Questions 126

According to The IIA ' s Competency Framework, which competency is considered the mandatory minimum for internal auditors to possess when performing internal audit engagements?

Options:

A.  

To recognize red flags that indicate fraud.

B.  

To recommend controls to prevent fraud.

C.  

To apply forensic auditing techniques to detect fraud.

D.  

To evaluate the potential for fraud.

Discussion 0
Questions 127

An organization ' s operations management is aware of existing internal control deficiencies but they lack the competency to execute internal control measures. Which of the following actions if taken by the internal audit activity is appropriate to assist operating management in achieving continuous improvement on internal controls?

Options:

A.  

Foster the importance of the control environment

B.  

Provide training on controls and on self-monitoring processes

C.  

Recommend installing an enterprisewide risk management system.

D.  

Conduct more assurance assignments on high risk areas

Discussion 0
Questions 128

Which of the following requests, if accepted by the internal audit activity, would impair its independence?

Options:

A.  

A request to develop workshops on corporate governance for management.

B.  

A request to act as liaison with external auditors.

C.  

A request to determine appropriate risk management responses for management.

D.  

A request to provide counseling services on ethical matters.

Discussion 0
Questions 129

An internal audit team analyzed the organization ' s value-at-risk model during an assurance engagement and suggested several useful improvements. Management was impressed by the internal audit team’s work and requested additional actions. Which of the following requested actions would impact internal audit independence most severely if fulfilled?

Options:

A.  

Assess the effectiveness of the model at least semi-annually.

B.  

Modify model inputs and suggest courses of action based on outcomes.

C.  

Employ acquired experience to test other models used by the company.

D.  

Validate whether model outputs serve the purpose stated by the model.

Discussion 0
Questions 130

Which of the following is considered to be a threat to the internal auditor ' s objectivity?

Options:

A.  

The auditor drafted the operational procedures of the area that she is currently auditing.

B.  

The auditor received a bonus that was approved by the board of directors.

C.  

The assigned auditor recommended operational procedures for the organization.

D.  

The assigned auditor rotated out of the same business activity three years ago

Discussion 0
Questions 131

A chief audit executive ensures that the internal audit activity provides annual training to management on internal controls. Where is the nature of these services defined?

Options:

A.  

The annual audit plan.

B.  

The audit report.

C.  

The annual risk assessment.

D.  

The audit charter.

Discussion 0
Questions 132

During an audit of company expenses, the internal auditor performed a test using data analytics and identified a violation of the company ' s expenses policy. The auditor who discovered the issue considered it a potential fraudulent transaction and informed the chief financial officer (CFO). The CFO dismissed the concern because he did not understand the data analytics test that was performed and the transaction was of a low value. Given this situation, which skills or competencies should this internal auditor seek to improve?

Options:

A.  

Skills in evaluating the risk of fraud.

B.  

Knowledge of key IT risks and controls

C.  

Soft skills such as communication and negotiation.

D.  

Knowledge and understanding of the company ' s expenses policy

Discussion 0
Questions 133

Which of the following types of policies best helps promote objectivity in the interna! audit activity ' s work?

Options:

A.  

Policies that are distributed to all members of the internal audit activity and require a signed acknowledgment,

B.  

Policies that match internal auditors ' performance with feedback from management of the area under review.

C.  

Policies that keep internal auditors in areas where they have vast audit expertise.

D.  

Policies that provide examples of inappropriate business relationships.

Discussion 0
Questions 134

A chief audit executive (CAE) is considering hiring a candidate who most recently worked for a large public accounting firm What would be the CAE’s most likely concern regarding this candidate*?

Options:

A.  

Low-level audit expertise

B.  

Narrow industry experience

C.  

MPotential conflict of interest

D.  

Weak interpersonal skills

Discussion 0
Questions 135

An internal audit activity maintains a quality assurance and improvement program that includes annual self-assessments. The internal audit activity includes in each engagement report a clause that the engagement is conducted in conformance with the International! Standards for the Professional Practice of Internal Auditing (Standards). Which of the following justifies inclusion of this clause in the reports?

Options:

A.  

Internal audit activity policies and engagement records provide relevant, sufficient, and competent evidence that the statement is correct.

B.  

The audit committee has reviewed the annual self-assessment results and approved the use of the clause.

C.  

The self-assessment results were validated by a qualified external review team three years prior.

D.  

The internal audit charter, approved by the audit committee, requires conformance with the Standards

Discussion 0
Questions 136

Which of the following accurately describes the concept of inherent risk?

Options:

A.  

Risk factors that exist when controls are in place and operating effectively

B.  

Internal risk factors assuming no controls are in place

C.  

Risk factors that cannot be mitigated because they are innate to a process

D.  

Combination of internal and external risk factors in their pure state assuming no controls are in place

Discussion 0
Questions 137

Which of the following describes the primary objective when implementing a risk management framework?

Options:

A.  

To achieve planned profitability for business expansion.

B.  

To enhance an organization ' s confidence in achieving strategy.

C.  

To strengthen corporate governance standards.

D.  

To eliminate business risks and uncertainties.

Discussion 0
Questions 138

Which of the following best demonstrates that an internal auditor is applying due professional care when planning an assurance engagement?

Options:

A.  

Assessing the risk of noncompliance with laws and regulations

B.  

Following the policies as prescribed by the internal audit manual.

C.  

Advising management of the area under review on how to mitigate internal control risks.

D.  

Conducting the engagement on the presupposition that fraud exists.

Discussion 0
Questions 139

According to IIA guidance, which of the following actions best demonstrates that due professional care has been considered by the internal audit activity when conducting a review of an organization ' s assets?

Options:

A.  

Determining whether any opportunity exists for senior executives to misappropriate property or funds

B.  

Planning and executing fieldwork In a complete and timely manner to identify all significant risks

C.  

Verifying whether the board of directors has implemented effective internal controls

D.  

Having senior management determine whether the degree of work planned is sufficient to meet engagement objectives

Discussion 0
Questions 140

Which of the following is part of a fraud detection program?

Options:

A.  

Whistleblower hotline.

B.  

Authority limits.

C.  

Background investigations

D.  

Evaluation of compensation programs.

Discussion 0
Questions 141

Which of the following is a preventive control the organization could implement to mitigate fraudulent activity in the accounts payable department?

Options:

A.  

Delivering fraud awareness training to employees in the department.

B.  

Segregating duties between employees in the department.

C.  

Requesting the internal audit activity perform an independent evaluation of fraud risk in the department.

D.  

Requiring accounts payable employees to sign a code of conduct awareness confirmation.

Discussion 0
Questions 142

Which of the following best describes a consulting engagement rather than an assurance engagement?

Options:

A.  

Bank internal auditors review an activity checklist to determine that the loan officer followed proper procedures.

B.  

The chief financial officer asks for the internal auditor ' s opinion regarding whether the new accounting pronouncements were properly and comprehensively adopted.

C.  

An internal auditor is assigned to assess whether a proposed new initiative to convert a customer service system would be cost-effective.

D.  

Senior management asks the internal audit activity to review compliance with customer data security regulations.

Discussion 0
Questions 143

According to IIA guidance, which of the following activities would typically be examined when using the maturity model approach for assessing an organization ' s risk management program?

Options:

A.  

Monitor and review.

B.  

Performance measurement.

C.  

Setting the context.

D.  

Communication.

Discussion 0
Questions 144

The organization ' s chief audit executive (CAE) is planning an immediate assurance engagement following several product recalls. However, the internal audit staff does not have the required Knowledge and experience to adequately assess all the relevant processes and procedures. According to 11A guidance, which of the following actions should the CAE take under these circumstances?

Options:

A.  

Use the current available resources to conduct the review and exclude those procedures that can ' t currently be performed.

B.  

Implement an accelerated training plan to provide the audit staff with the necessary skills and knowledge to conduct the engagement.

C.  

Encourage management to accept the assessed risk until the internal audit activity is able to adequately review the area.

D.  

Obtain assistance for the audit team from other internal assurance providers who possess the requisite expertise in the area.

Discussion 0
Questions 145

According to IIA guidance, which of the following would the internal audit activity examine in order to evaluate the organization ' s governance process for strategic and operational decisions ' ?

Options:

A.  

The risk assessment process including interviews with senior management.

B.  

The organization’s mission and value statements, code of conduct, and whistleblowing policy

C.  

Board meeting minutes the board policy manual, and past audit reports

D.  

Staff compensation objective setting and the performance evaluation policy and process

Discussion 0
Questions 146

An organization’s senior management team is awarding substantial bonuses if employees meet financial targets. Which of the following motivators to potentially commit fraud would become most likely in this scenario?

Options:

A.  

Opportunity

B.  

Pressure

C.  

Rationalization

D.  

Justification

Discussion 0
Questions 147

Which of the following written documents typically offers the best evidence that internal auditors exercise due professional care in conformance with the Standards?

Options:

A.  

Internal audit charter.

B.  

Workpaper.

C.  

Audit report.

D.  

Code of ethics.

Discussion 0
Questions 148

The organization ' s internal audit charter was last updated six years ago. To update the charter, which of the following actions is most appropriate for the chief audit executive to take?

Options:

A.  

Wait for the next external assessment and address all of the missing information in the charter based on the recommendations from the external assessment team.

B.  

Perform a review of IIA guidance to become acquainted with the latest mandatory elements prior to updating the charter

C.  

Use an internal audit charter template from another organization that operates within the same industry.

D.  

Identify an individual within the internal audit activity who has in-depth knowledge of mandatory IIA guidance elements to address any gaps or areas of the current version of the charter that could be improved.

Discussion 0
Questions 149

A technology company recently hired an entry-level internal auditor. To achieve conformance with the Standards, which of the following must the newly hired internal auditor possess?

Options:

A.  

An understanding of fraud and fraud risk.

B.  

IT audit expertise.

C.  

Industry-specific knowledge

D.  

At least one audit-related certification

Discussion 0
Questions 150

According to IIA guidance, which of the following statements is true regarding the internal audit activity ' s quality assurance and improvement program (QAIP)?

Options:

A.  

Internal assessments rely solely on the review of completed audit engagements for demonstrated performance

B.  

The chief audit executive is responsible for assessing the suitability and competence of an external assessor.

C.  

QAIP results must first be discussed with the board and approval obtained for distribution to senior management

D.  

At the board ' s discretion, the frequency of external assessments can exceed the five-year guideline

Discussion 0
Questions 151

Which of the following statements is true regarding the importance of risk management?

Options:

A.  

Risk management ensures the ability to eliminate potential hazards to the organization.

B.  

Risk management includes consideration of potential opportunities for the organization.

C.  

Risk management aids with the establishment of appropriate key performance indicators.

D.  

Risk management increases employees ' commitment and belief in strategic goals.

Discussion 0
Questions 152

Which of the following is true regarding internal audit role ' s in The IIA ' s Three Lines Model?

Options:

A.  

As internal control is part of risk management, the internal audit role in risk management implies reduced emphasis on internal control.

B.  

Internal audit can blur the distinction between the second and the third lines as long as value is added.

C.  

Internal audit cannot rely on other assurance providers when opining on the effectiveness of risk management.

D.  

Internal audit should be aligned with first- and second-line functions through effective communication, cooperation, and collaboration.

Discussion 0
Questions 153

An organization established 20 years ago has had its internal audit activity in place for the last three years. Which of the following would allow the internal audit activity to accurately state that it is in conformance with the Standards ' ?

Options:

A.  

Documented assessment was performed by the audit committee and confirmed conformance.

B.  

Internal and external assessments are performed annually, and nonconformance results are reported to the board.

C.  

The independent and objective judgement of the chief audit executive confirmed conformance with the Standards.

D.  

Documented internal assessments are performed periodically and confirm conformance.

Discussion 0
Questions 154

Which of the following best describes a consulting engagement rather an assurance engagement?

Options:

A.  

Bank internal auditors review an activity checklist to determine that the loan officer followed proper procedures.

B.  

The chief financial officer asks for the internal auditor ' s opinion regarding whether the new accounting pronouncements were properly and comprehensively adopted

C.  

An internal auditor is assigned to assess whether a proposed new initiative to convert a customer service system would be cost effective.

D.  

Senior management asks the internal audit activity to review compliance with customer data security regulations

Discussion 0
Questions 155

Which of the following documents would promote objectivity within an organization ' s internal audit activity?

Options:

A.  

Internal audit charter.

B.  

Internal audit manual.

C.  

Audit committee charter

D.  

Human resources employee handbook.

Discussion 0
Questions 156

An internal auditor believes that the internal audit activity ' s independence is impaired. Which of the following actions should the internal auditor take first?

Options:

A.  

Report the impairment to senior management

B.  

Discuss the impairment with the audit manager

C.  

Ascertain the best approach to disclose the impairment.

D.  

Decide on the extent of impact of the impairment

Discussion 0
Questions 157

Which of the following describes the internal audit activity ' s most appropriate role in an organization ' s risk management process?

Options:

A.  

Reporting to the board on management ' s assessment of current risks

B.  

Establishing a risk management policy and framework for the organization

C.  

Assigning responsibility for identifying and managing significant risks

D.  

Developing key controls to mitigate risks across the organization

Discussion 0
Questions 158

Recently an organization’s internal audit activity discovered ghost employees who receive payments Senior management decides to strengthen the internal control measures to address this Which of the following is considered an effective control to mitigate payments to ghost employees?

Options:

A.  

Staff transfers are reviewed by the recruiting manager and approved by the head of human resources

B.  

New staff requisition forms are authorized by operational management and acknowledged by the head of human resources

C.  

Staff salary payments and accounting records are approved by the head of accounting and acknowledged by the head of human resources

D.  

The staff salary payment list is reviewed by the head of payroll and endorsed by the head of human resources

Discussion 0
Questions 159

An investment advisory firm purchased professional liability insurance to offer protection from lawsuits brought by customers claiming they received poor or erroneous advice. Which of the following best describes this risk management technique?

Options:

A.  

Mitigation.

B.  

Acceptance

C.  

Transfer.

D.  

Avoidance

Discussion 0
Questions 160

Which of the following should play a leading role in overseeing the ethical atmosphere of an organization?

Options:

A.  

Internal audit activity

B.  

Operating management

C.  

Senior management

D.  

Board of directors

Discussion 0
Questions 161

Which requirement should the chief audit executive consider when communicating results of the quality assurance and improvement program to the board of a large

organization?

Options:

A.  

The internal assessment results should be discussed once every five years,

B.  

The rating conclusions and the impact from results of the external assessment should be explained,

C.  

The results of the external assessment should be discussed every seven years,

D.  

The qualifications and independence of the internal assessment team should be discussed

Discussion 0
Questions 162

The chief audit executive (CAE) is drafting the annual internal audit plan and seeks input from senior management and the external auditor prior to submitting it for approval to the board. According to MA guidance, which of the following statements is true regarding this scenario?

Options:

A.  

The CAE ' s actions are likely to impair the Independence of the internal audit activity.

B.  

The CAE acted appropriately, and the independence of the internal audit activity was not impaired.

C.  

The CAE should have developed the audit plan without outside influence to maintain objectivity.

D.  

The CAE acted appropriately, as he has authority to determine who reviews and approves the audit plan.

Discussion 0
Questions 163

Which of the following documents are internal auditors most likely to be asked to sign as a demonstration of due professional care?

A description of their job responsibilities,

Options:

A.  

A non-disclosure agreement.

B.  

An annual declaration of commitment to

C.  

The IIA s Code of Ethics.

D.  

The internal audit charter.

Discussion 0
Questions 164

Which of the following situations undermines the independence of the internal audit activity?

Options:

A.  

The internal audit activity is responsible for the company ' s risk management function, and its head manager reports to the chief audit executive.

B.  

A senior member of the internal audit activity once worked in the corporate finance department.

C.  

The organization’s CEO reviews the internal audit activity’s annual budget per the organization’s policies and procedures.

D.  

The internal audit activity often uses management ' s risk profile to build its own risk profile for annual planning.

Discussion 0
Questions 165

During a review of the procurement function, an internal auditor identified an existing control for adding new vendors into the vendor contract system. Which of the following would best help the auditor determine the adequacy of the control ' s design?

Options:

A.  

Flowchart of the vendor addition process.

B.  

Independent confirmations sent to vendors.

C.  

Analysis of the control ' s costs and benefits.

D.  

Interview with management of the procurement function.

Discussion 0
Questions 166

During the planning stage of an assurance engagement, a payroll clerk informed the internal auditor that he is often asked to add new employees to the payroll without any formal new-hire documentation from human resources. The auditor is concerned that this increases the risk for fraud. To complete engagement planning, which of the following is the most appropriate next step for the auditor to take?

Options:

A.  

Increase the sample size to be tested, ensuring a thorough review of the payroll records.

B.  

Advise the chief audit executive of the clerk ' s assertion, despite the lack of supporting evidence.

C.  

Ask the clerk to provide a list of any suspicious new employee names on the payroll.

D.  

Investigate the matter further to understand precisely how many payroll records were affected.

Discussion 0
Questions 167

Which of the following would be the best choice for a continuing professional development requirement for a newly created internal audit activity?

Options:

A.  

Require all internal auditors to create a training plan based on a competency self-assessment.

B.  

Require internal auditors to complete all of their training through webinars, to increase efficiency and avoid traveling

C.  

Require all internal auditors to become a member of The Institute of Internal Auditors.

D.  

Require internal auditors to create a training plan based on their areas of interest

Discussion 0
Questions 168

Which of the following statements is true regarding intangible assets?

Options:

A.  

The amortization period of an intangible asset cannot exceed 20 years.

B.  

The cost intangible assets with indefinite lives should be amortized.

C.  

Intangible assets are categorized as having either a limited life or an indefinite life.

D.  

Companies should record intangible assets at fair market value

Discussion 0
Questions 169

Which of the following statements is true regarding an organization ' s code of ethics?

Options:

A.  

It should be written with primary consideration given to using a rule-based approach.

B.  

It should be of two variations: one applicable internally and one applicable for third parties.

C.  

Its operational effectiveness cannot be tested using traditional audit and rating systems such as maturity models.

D.  

It should require an annual attestation of compliance with the code of conduct by all employees.

Discussion 0
Questions 170

Management decided to post the organization ' s newly established code of conduct on its website. This decision is primarily intended to mitigate which of the following risks?

Options:

A.  

Accountability risk.

B.  

Communication risk.

C.  

Knowledge risk.

D.  

Cultural risk.

Discussion 0
Questions 171

As part of a fraud investigation by regulators, a court order was issued to a bank. The court order requested the chief audit executive (CAE) to provide access to a number of audit reports and workpapers, some of which included customers ' confidential information such as transaction activity and other personal details. What is the appropriate response by the CAE?

Options:

A.  

Reject the court order, citing a potential breach of customers ' confidentiality agreement

B.  

Consult with legal counsel to determine what information to provide.

C.  

Respond promptly and provide all that was requested by the court order.

D.  

Seek permission from customers prior to sharing their information.

Discussion 0
Questions 172

What would be the proper sequence of steps for an internal auditor to take in order to draw a conclusion on internal control effectiveness and adequacy after ascertaining the key controls?

Options:

A.  

Evaluate the adequacy of the controls and then test the controls for effectiveness.

B.  

Test the controls for effectiveness and then evaluate the adequacy of the controls.

C.  

Identify risks and then evaluate the controls for effectiveness.

D.  

Evaluate the controls for effectiveness and then assess the risks in the area.

Discussion 0
Questions 173

The principle that " no action should be taken that may harm in some way the least fortunate people " is an expression of which of the following more general ethical principles?

Options:

A.  

Utilitarian benefits.

B.  

Personal virtues.

C.  

Religious injunctions.

D.  

Distributive justice.

Discussion 0
Questions 174

Which of the following would provide the best support for internal auditors to meet their continuing professional development requirements?

Options:

A.  

Access to online internal audit and business skills courses.

B.  

Records of self-assessment reports completed by the internal audit staff.

C.  

Cosourcing arrangements with external providers on specific engagements.

D.  

Performance reviews comparing internal auditors ' achievements against specified goals.

Discussion 0
Questions 175

An engagement supervisor noted that an internal auditor ' s personal relationship with a process owner resulted in the auditor providing a favorable and partial assessment during an audit within that process owner ' s area. According to MA guidance, which of the following should be used to manage this impairment?

Options:

A.  

An internal audit charter.

B.  

An employee disciplinary policy.

C.  

A functional audit committee.

D.  

A functional reporting placement.

Discussion 0
Questions 176

During an assurance engagement, an internal auditor identified that a developer of the organization ' s enterprise resource planning (ERP) system had intentionally modified the production code to commit a fraudulent transaction. Which control activity should be implemented to prevent such issues in the future?

Options:

A.  

Segregate duties between code development and migrating changes into production.

B.  

Conduct fraud training for the IT team responsible for the ERP system.

C.  

Penalize the developer who committed the fraud by terminating employment.

D.  

Restrict developers ' access to the ERP system ' s test environment.

Discussion 0
Questions 177

According to IIA guidance, which of the following statements is true regarding the internal audit activity ' s quality assurance and improvement program (QAIP)?

Options:

A.  

Internal assessments rely solely on the review of completed audit engagements for demonstrated performance.

B.  

The chief audit executive is responsible for assessing the suitability and competence of an external assessor.

C.  

QAIP results must first be discussed with the board and approval obtained for distribution to senior management.

D.  

At the board ' s discretion, the frequency of external assessments can exceed the five-year guideline.

Discussion 0
Questions 178

During an assurance engagement, an internal auditor uses benchmarking research to support preparation of a report to stakeholders that contains significant findings about control deficiencies. Which of the following skills did the auditor demonstrate?

Options:

A.  

Internal audit management.

B.  

Conflict negotiation.

C.  

Critical thinking.

D.  

Persuasion and collaboration.

Discussion 0
Questions 179

Which of the following strategies for professional development best demonstrates an internal auditor’s competency ' ?

Options:

A.  

Completed education credits

B.  

Membership in professional organizations

C.  

Subscriptions to sources of relevant professional information

D.  

Professional development and training plans

Discussion 0
Questions 180

Which of the following is a primary benefit of implementing a governance, risk management, and compliance framework within an organization?

Options:

A.  

Fewer internal audits.

B.  

More effective interviews.

C.  

Automated risk management strategy tools.

D.  

Reduced assurance costs.

Discussion 0
Questions 181

Which of the following is true regarding the stakeholder theory of corporate social responsibility?

Options:

A.  

An organization has a fiduciary duty to put shareholders ' needs first

B.  

Customers ' needs are the primary responsibility of the organization

C.  

Competitors are considered stakeholders of the organization

D.  

Employees are the organization ' s best assets and primary responsibility

Discussion 0
Questions 182

How do assurance services and consulting services differ?

Options:

A.  

There is less variety of consulting services that an internal audit activity might provide compared to assurance services

B.  

Assurance services are limited to financial events or actions, and consulting services are not limited in this way

C.  

Consulting services do not have to be included in the internal audit charter

D.  

Other employees in an organization can provide consulting services but only an internal audit activity can provide assurance services

Discussion 0
Questions 183

According to IIA guidance, which of the following is an appropriate role for the internal audit activity?

Options:

A.  

Coaching management in responding to risks.

B.  

Implementing risk responses on management’s behalf.

C.  

Imposing risk management processes.

D.  

Setting the risk appetite.

Discussion 0
Questions 184

During a payroll audit, the internal auditor discovered that several individuals who have the same position classification as he are earning a significantly higher salary. The auditor noted the names and amounts of each, and he planned to prepare a request to the chief audit executive for a salary increase based on this information. Which of the following IIA Code of Ethics principles was violated in this scenario?

Options:

A.  

Competency.

B.  

Objectivity,

C.  

Integrity.

D.  

Confidentiality

Discussion 0
Questions 185

Which of the following corporate social responsibility strategies is associated with responding to outside pressure by assuming additional responsibility?

Options:

A.  

Accommodation.

B.  

Reaction.

C.  

Defense.

D.  

Proaction.

Discussion 0
Questions 186

During a quality assessment of the internal audit activity an auditor is assessing whether the independence of the internal audit activity is at risk of being compromised. According to IIA guidance, which of the following would provide the best source of evidence for such an assessment?

Options:

A.  

An organizational chart showing the reporting line of the chief audit executive to the CEO

B.  

The internal audit charter as endorsed by the organization’s governing body

C.  

A review of the audit opinions issued from a sample of recent audit engagements

D.  

An assessment of the scope of the audit work performed by the internal au < M activity

Discussion 0
Questions 187

Which of the following actions by the internal audit activity requires disclosure to the board of nonconformance with the Standards?

Options:

A.  

The internal audit activity did not complete an external assessment within the last seven years

B.  

The internal audit activity performed an engagement with limited scope due to lack of knowledge

C.  

The internal audit activity failed to consider risk when conducting a review of a department

D.  

An internal auditor was assigned to an engagement m an area where she previously worked more than 10 years ago

Discussion 0
Questions 188

Which of the following best describes a purpose for the internal audit charter?

Options:

A.  

The internal audit charter authorizes the internal audit activity ' s reporting structure and clearly defines the roles of each internal auditor.

B.  

The internal audit charter defines the roles and responsibilities of the chief audit executive, board of directors, and senior management.

C.  

The internal audit charter authorizes access to records, personnel, and physical properties relevant to the performance of audit engagements.

D.  

The internal audit charter defines the criteria by which the internal audit activity ' s performance will be evaluated

Discussion 0
Questions 189

Which of the following is an example of a detective control?

Options:

A.  

Automatic shut-off valve.

B.  

Auto-correct software functionality.

C.  

Confirmation with suppliers and vendors.

D.  

Safety instructions.

Discussion 0
Questions 190

A whistleblower reveals to the chief audit executive (CAE) detailed allegations of potential fraud at the senior management level. Although the CAE has some experience in the area, she chooses to retain an external fraud expert to conduct the investigation. When asked by the director of finance to defend the expenditure, which of the following statements represents the CAE ' s best response?

Options:

A.  

The CAE refers to the Standards and explains that to protect her independence, she needs to remain isolated from the investigation.

B.  

The CAE refers to the Standards and explains that the internal audit activity must obtain competent assistance if needed.

C.  

The CAE refers to the Standards and explains that to protect her objectivity, she needs to remain isolated from the investigation.

D.  

The CAE describes the specifics of the allegation to underscore the importance of the situation and the need for expert investigation

Discussion 0
Questions 191

What is the primary reason for establishing a continuing professional development program within an organization ' s internal audit activity?

Options:

A.  

To ensure all internal audit responsibilities can be met

B.  

To ensure all audit staff members are capable of performing a quality self-assessment.

C.  

To ensure that each auditor maintains responsibility for his own professional development.

D.  

To attract the best and most talented candidates in the profession

Discussion 0
Questions 192

Which of the following survey questions would be most effective to identify ethics violations within the organization?

Options:

A.  

Are the performance targets in your department realistic and attainable?

B.  

Do your coworkers have the knowledge, skills, and training needed to perform their job duties?

C.  

Does your supervisor comply with laws and regulations affecting the organization?

D.  

Do you have sufficient resources, tools, and time to accomplish your work objectives?

Discussion 0
Questions 193

Which of the following actions best demonstrates an internal auditor exercising due professional care?

Options:

A.  

Testing an entire population, even when a sample would suffice

B.  

Using technology and data analysis techniques for efficiency

C.  

Enhancing knowledge, skills, and other competencies through professional development

D.  

Establishing audit objectives, performing audit tests, and implementing missing controls

Discussion 0
Questions 194

Which of the following demonstrates that the internal audit activity exercises due professional care?

Options:

A.  

Supervisors provide feedback to internal auditors after workpapers are reviewed

B.  

A self-assessment is conducted through the quality assurance and improvement program every five years

C.  

Internal auditors are required to give absolute assurance of regulatory compliance

D.  

The chief audit executive reports functionally to the board

Discussion 0
Questions 195

Which of the following statements relating to risk management is true?

Options:

A.  

The high-level risk assessment performed during engagement planning is a detailed step-by-step analytical process

B.  

External auditors must be engaged to evaluate the potential for fraud and how the organization manages fraud risk

C.  

A lack of controls is acceptable if the risk is reduced to an acceptable level in some other way

D.  

Internal auditors are responsible for managing the risks of the organization

Discussion 0
Questions 196

An internal auditor is assessing the effectiveness of the organization ' s risk management practices She checks to see whether risk management is an intégrai part of decision making and whether risk management is transparent, responsive to change and addresses uncertainty. According to HA guidance on risk management frameworks, which of the following approaches is the auditor most likely using?

Options:

A.  

Maturity model approach

B.  

Process element approach

C.  

Key principles approach

D.  

Key performance indicators approach.

Discussion 0
Questions 197

Which of the following scenarios demonstrates an impairment to internal audit independence?

Options:

A.  

The internal auditor s denied access to partner information from management of me area under review

B.  

The internal auditor tarts to disclose a potential conflict of interest relationship with management of the area under review

C.  

The internal auditor concludes that controls operate effectively, although he did not gather supporting evidence

D.  

The internal auditor was assigned to an assurance review of an area for which he previously had responsibilities

Discussion 0
Questions 198

Which of the following engagements would be considered an appropriate consulting service?

Options:

A.  

The internal audit activity of a commercial bank routinely performs branch audits for compliance with regulations.

B.  

The internal audit activity participates in a cosourcing arrangement with an IT audit firm to test information systems security.

C.  

The internal audit activity facilitates biannual training of the risk management team in risk identification methodologies.

D.  

The internal audit activity partners with external auditors annually to complete fieldwork required as a part of the external audit exercise.

Discussion 0
Questions 199

An internal audit activity uses a rotational program to recruit high-performing staff members from other parts of the organization One of these individuals is nearing the end of her four-year internal audit rotation The chief audit executive assigned her to an assurance engagement in the business area she will be going into when she leaves the internal audit activity Which of the following statements is

true regarding this scenario?

Options:

A.  

Accepting the assignment is a violation of internal audit independence

B.  

Accepting the assignment will improve competencies and develop relationships that will be needed in her next assignment

C.  

Accepting the assignment creates the appearance of an impairment to her professional judgment and detectivity

D.  

Accepting the assignment on the assurance engagement would be a breach of due professional care

Discussion 0
Questions 200

Management of an area under review is aggressive, upset, and questioning the knowledge and experience of the organization ' s internal auditors, as the audit results highlight critical findings. The relationship between the internal audit activity and management has continued to degenerate. as previous audit reports also showed a large number of issues. What would be the best strategy for working through the current audit results while also attempting to repair the relationship with management?

Options:

A.  

Take an accommodating approach and change the overall rating of the audit report.

B.  

Take a compromising approach by modifying the tone of the report, while maintaining the critical findings.

C.  

Take an assertive approach and be persistent in attempting to convince the director.

D.  

Take an assisting approach and offer to assist with the implementation of action plans.

Discussion 0
Questions 201

Which of the following scenarios best illustrates due professional care?

Options:

A.  

An internal auditor who previously worked in the payroll department within the last year was intentionally excluded by the chief audit executive from the audit team assigned to a payroll audit

B.  

While performing a payroll audit an auditor became skeptical about significant payments made to a manager. The auditor sought to determine whether these payments were reasonable through discussion with a manager in a different department in the organization

C.  

The head of the payroll department being audited is a business partner of the engagement supervisor During the audit the engagement supervisor sought to maintain his objectivity by not participating in fieldwork

D.  

An auditor assigned to a payroll audit was unable to reperform some complex payroll computations for a small number of employees The sum of these payments was below the materiality thresholds provided so the auditor did not perform further tests

Discussion 0
Questions 202

Which of the following best demonstrates the application of due professional care?

Options:

A.  

An engagement supervisor requests that the employment of a process owner be terminated due to a significant control failure.

B.  

An audit lead establishes internal audit manuals to guide the internal audit activity on now to undertake audit engagements.

C.  

An audit manager provides a guarantee to senior management that internal controls relating to an audited process operate effectively.

D.  

An organization ' s internal audit activity operates under a direct reporting structure to tie audit committee of the board

Discussion 0
Questions 203

According to IIA guidance, which of the following best demonstrates how the chief audit executive may ensure that due professional care is applied?

Options:

A.  

Establish policies and procedures concerning the engagement process

B.  

Develop a strategy for recruiting assigning, and training staff

C.  

Outsource complex engagements to an external service provider

D.  

Base the auditor evaluation process on the number of observations

Discussion 0
Questions 204

Which of the following situations is most likely to heighten an internal auditor ' s professional skepticism regarding potential fraud?

Options:

A.  

A procurement manager does not have the expected academic credentials for his position.

B.  

A salesperson frequently complains about the organization ' s policy on sales commissions.

C.  

The accounts payable supervisor has requested advances against her monthly salary on several occasions.

D.  

A financial accountant is absent from work frequently due to regular medical procedures.

Discussion 0
Questions 205

An organization has limited resources to spend on corporate social responsibility initiatives. Which is the most suitable approach to determine how these resources should be used?

Options:

A.  

Support a mix of environmental economic and social initiatives to ensure a balanced approach is taken

B.  

Survey employees and external stakeholders to see which causes are best suited to the organization.

C.  

Select corporate social responsibility initiatives that support the overall strategic goals of the organization

D.  

Conduct a financial analysis to determine where the most impact can be made with the budget available

Discussion 0
Questions 206

In the context of an internal control framework, organizational structure and assignment of authority and responsibility is related to which of the following?

Options:

A.  

Control activities.

B.  

Information and communication.

C.  

Risk assessment.

D.  

Control environment.

Discussion 0
Questions 207

With regard to the internal audit activity ' s quality assurance and improvement program, which of the following topics would the chief audit executive include on the quarterly board meeting agenda?

Options:

A.  

The scope and frequency of both internal and external quality assessments.

B.  

The list of audit engagements that will be assessed during the year.

C.  

The number and qualifications of internal audit staff members assigned to perform internal assessments during the year.

D.  

The compensation structure of the qualified assessment team.

Discussion 0
Questions 208

Which of the following most accurately describes corporate social responsibility at an organization?

Options:

A.  

An organizational locus on improving the overall environment, even it is to the detriment of the local community.

B.  

A philosophy driven by employees that flows up to senior management and the board of directors.

C.  

An overall commitment of the organization to improve the quality of life for not only the employees but the community at large.

D.  

A policy of ensuring that the organization is socially responsible, even if it leads to unprofitability due to increased costs.

Discussion 0
Questions 209

Which of the following is a greater consideration for internal auditors when they are performing a consulting engagement than when they are performing an assurance engagement ' ?

Options:

A.  

The relative complexity of the engagement

B.  

The cost of the engagement relative to its benefits

C.  

The extent of work needed to achieve the engagement ' s objective

D.  

The needs and expectations of the engagement client

Discussion 0
Questions 210

A chief audit executive (CAE) has just joined an organization with an existing internal audit activity. Based on her review of the current organizational structure, the CAE determines that the internal audit activity lacks adequate independence. Which of the following actions is the CAE ' s best step to take next to move the internal audit activity toward organizational independence?

Options:

A.  

Ensure the limitations are disclosed through communication with the board and senior management, so that the internal audit activity can continue operating under the same organizational structure.

B.  

Request that the board restructure the reporting line of the internal audit activity to ensure the CAE has unrestricted access to the board.

C.  

Rotate internal audit assignments among members of the internal audit activity to minimize the effects of the current structure.

D.  

Train internal auditors about organizational independence and have them sign an acknowledgment of understanding.

Discussion 0
Questions 211

According to IIA guidance, which of the following activities are considered a core internal audit role with regard to enterprise risk management?

Reviewing the management of key risks.

Evaluating the reporting of key risks.

Evaluating risk management processes.

Consolidating the reporting of risks.

Options:

A.  

1 and 4.

B.  

2 and 4.

C.  

2, 3, and 4.

D.  

1, 2, and 3.

Discussion 0
Questions 212

According to the Standards, which of the following demonstrates the proficiency of an internal auditor?

Options:

A.  

Each internal auditor must hold one or more certifications in the area of fraud and seek out continuing professional development related to fraud detection and fraud investigation.

B.  

Each internal auditor must have sufficient knowledge of IT risks and controls, and be able to evaluate the risk of fraud and the manner in which it is managed by the organization.

C.  

Each internal auditor on the engagement team must possess the same level of knowledge, skills, and other competencies as other auditors on the engagement team.

D.  

Each internal auditor must be paired, by the chief audit executive, with an individual who possesses the knowledge, skills, or other competencies required to complete the audit.

Discussion 0
Questions 213

An audit client who was unsatisfied with the audit report rating called the chief audit executive (CAE) and complained that the internal auditor who performed the audit was biased because his spouse, who worked in the area under review, was on a list of employees to be terminated. Which of the following measures would be most appropriate to prevent this situation from arising?

Options:

A.  

Initiating an internal investigation to clarify whether a biased judgment took place.

B.  

Requiring the internal auditors to disclose any potential conflicts of interest.

C.  

Requiring that the audit client disclose any potential conflicts of interest with the auditor.

D.  

Requiring human resources manager to submit all future job applicants ' data in order to identify relatives of auditors.

Discussion 0
Questions 214

According to IIA guidance, which of the following activities would typically be examined when using the maturity model approach for assessing an organization ' s risk management program?

Options:

A.  

Monitor and review

B.  

Performance measurement.

C.  

Setting the context.

D.  

Communication.

Discussion 0
Questions 215

Which of the following is most likely to result in the impairment of independence for the internal audit activity?

Options:

A.  

The chief audit executive (CAE) has a dual reporting relationship within the organization.

B.  

The CAE performs an audit of a functional area that is also under the CAE ' s oversight.

C.  

The CAE has unrestricted access to information throughout the organization and to the board.

D.  

The board is involved in decisions to hire or remove the CAE and in drafting and approving an internal audit charter.

Discussion 0
Questions 216

Which of the following scenarios best demonstrates the application of internal audit proficiency?

Options:

A.  

Management requests that the internal audit activity review and provide feedback on its strategic plans for a merger, but the chief audit executive (CAE) declines the engagement due to the team ' s lack of experience with mergers.

B.  

A CAE reassigns auditors from other audits to perform testing on all of the fixed asset additions for a period, including amounts below the materiality level stated by external auditors.

C.  

Due to the routine and recurring nature of bank branch audits, an audit manager often excludes detailed planning at the beginning of the audit and immediately performs fieldwork.

D.  

During fieldwork, an auditor observed a lack of segregation of duties over cash management. The auditor reported this observation to his supervisor, who decided that the area should be examined in a subsequent audit.

Discussion 0
Questions 217

Guidelines need to be set for various levels of suspected fraud within an organization and when it would be reported to the audit committee. Which of the following would be

reported at the next meeting?

Options:

A.  

Minor theft of less than $10,000, not involving senior management.

B.  

Theft using collusion for more than $10,000. but not involving senior management.

C.  

Denial of access to requested employees during an audit.

D.  

Discussion of replacement of the chief audit executive.

Discussion 0
Questions 218

A chief audit executive (CAE) has no direct access to the board. According to IIA guidance, which of the following is the most appropriate way for the CAE to react?

Options:

A.  

Ensure all subsequent audit reports include a disclaimer as to the lack of access to the board,

B.  

Focus on operational audit work and disregard lack of direct access to the members of the board.

C.  

Initiate changes to the internal audit charter to report to senior management for the time being,

D.  

Engage in written communications with the board and present relevant issues in writing

Discussion 0
Questions 219

The chief audit executive (CAE) has hired a new internal auditor who was immediately assigned to a procurement function audit. Because the new auditor ' s name is similar to that of the procurement manager, some staff members think the two are related, although they are not. Which of the following actions is most appropriate for the CAE to take?

Options:

A.  

Take no action, as there is no impairment to independence.

B.  

Remove the new internal auditor from the engagement team.

C.  

Discuss the matter with the appropriate personnel to alleviate concerns.

D.  

Closely supervise the new auditor and carefully review his work.

Discussion 0
Questions 220

At a conference, an interna! auditor presented a new computer-assisted audit technique developed by his organization. The presentation included sample data derived from performing audit engagements for the organization. Travel costs were paid by the conference organizers, and the trip was approved by the chief audit executive (CAE).

However, neither management nor the CAE was aware that the internal auditor would be making a presentation based on work completed for the organization. According to IIA guidance, which of the following statements is most relevant regarding the actions of the auditor?

Options:

A.  

The auditor did not violate the standard of objectivity because the presentation had no impact on the organization.

B.  

The auditor violated the principle of confidentiality by disclosing information about the organization without approval.

C.  

The auditor should have obtained permission before using the material, but did not violate the IIA Code of Ethics or Standards,

D.  

The auditor breached the conflict of interest standard by accepting payment for travel costs

Discussion 0