Big Black Friday Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Practice of Internal Auditing Question and Answers

Practice of Internal Auditing

Last Update Nov 30, 2025
Total Questions : 747

We are offering FREE IIA-CIA-Part2 IIA exam questions. All you do is to just go and sign up. Give your details, prepare IIA-CIA-Part2 free exam questions and then go for complete pool of Practice of Internal Auditing test questions that will help you more.

IIA-CIA-Part2 pdf

IIA-CIA-Part2 PDF

$36.75  $104.99
IIA-CIA-Part2 Engine

IIA-CIA-Part2 Testing Engine

$43.75  $124.99
IIA-CIA-Part2 PDF + Engine

IIA-CIA-Part2 PDF + Testing Engine

$57.75  $164.99
Questions 1

Which of the following actions should the internal audit activity take during an audit engagement when examining the effectiveness of risk management processes?

Options:

A.  

Evaluate how the organization manages fraud risk.

B.  

Establish procedures for improving risk management processes.

C.  

Ensure risk responses are aligned with industry standards

D.  

Verify that organizational objectives are aligned with each departments objectives.

Discussion 0
Questions 2

Besides a chief audit executive's professional experience what determines the frequency and approach to assessing residual risk?

Options:

A.  

The frequency of executing the internal audit engagements

B.  

The frequency of changes in the organization environment

C.  

The expectations set by the board and senior management

D.  

The expectations set by operating management and senior management

Discussion 0
Questions 3

Which of the following statements concerning workpapers is the most accurate?

Options:

A.  

The organization and the format of workpapers is the same for all engagements

B.  

The extent of what is included in workpapers is a matter of professional judgment

C.  

Workpapers should be complete so that every conceivable question that can be raised should be answered

D.  

Copies of operational managements records should not be included, but referenced so that they can be located

Discussion 0
Questions 4

Which of the following best describes the risk contained in an initial public offering for a new stock?

Options:

A.  

Residual risk.

B.  

Net risk.

C.  

Inherent risk.

D.  

Underlying risk

Discussion 0
Questions 5

Which of the following information is most appropriate for the chief audit executive to share when coordinating audit plans with other internal and external assurance providers?

Options:

A.  

Objectives scope and timing at a high level to support coordination while adhering to confidentiality requirements

B.  

The area and timing of the audit engagement to ensure confidentially and avoid conflict of interest.

C.  

All plan information, including risk assessments, planned tests and past results to maximize the opportunity for coordination with internal and external providers.

D.  

No information should be shared with internal and external provider as it could introduce bias into the engagement results.

Discussion 0
Questions 6

Which type of assurance engagement is conducted to determine whether a process or area is performing as intended, accomplishing its objectives, and doing so in an efficient and economical way?

Options:

A.  

Compliance audit.

B.  

Operational audit.

C.  

Financial audit.

D.  

Provider audit.

Discussion 0
Questions 7

Which of the following should management action plans include at a minimum?

Options:

A.  

An implementer for the action plan

B.  

An owner of the action plan

C.  

The internal auditor's next review date of the action plan

D.  

Detailed procedures for the action plan

Discussion 0
Questions 8

An internal audit team leader is having difficulties completing the planning phase of an assurance engagement because the business unit lacks a system of internal controls. Which of the following is the most appropriate course of action for the internal audit team leader?

Options:

A.  

Defer the engagement until a system of internal control has been established

B.  

Change the scheduled engagement from assurance to consulting to help correct the shortcomings

C.  

Add a consulting component to the already scheduled assurance engagement

D.  

Seek the involvement of the external auditor to assist with improving the internal controls

Discussion 0
Questions 9

Which of the following items, included in the preliminary audit communication would be most useful for management to formulate action plans in response to audit recommendations?

Options:

A.  

A condition

B.  

An audit objectives

C.  

An audit scope

D.  

An observation rating

Discussion 0
Questions 10

An internal auditor observed that sales staff are able to modify or cancel an order in the system prior to shipping She wonders whether they can also modify orders after shipping. Which of the following types of controls should she examine?

Options:

A.  

Batch controls.

B.  

Application controls

C.  

General IT controls.

D.  

Logical access controls

Discussion 0
Questions 11

The internal audit activity is responsible for which of the following actions related to an organization’s internal controls9

Options:

A.  

Mitigating risks affecting achievement of organizational objectives.

B.  

Enabling opportunities affecting achievement of organizational objectives.

C.  

Analyzing and advising regarding costs versus benefits of control activities.

D.  

Attesting to fairness of financial statements

Discussion 0
Questions 12

Internal audit staff lacks the expertise to perform a fraud investigation engagement stemming from a whistleblowing incident. Which of the following is the most appropriate

option for the chief audit executive?

Options:

A.  

Appoint an independent fraud investigation specialist to work with the selected internal auditors.

B.  

Organize in-house fraud investigation training sessions for selected internal auditors.

C.  

Assign an experienced auditor to the engagement for a development opportunity.

D.  

Hire a new internal auditor who possesses fraud investigation experience.

Discussion 0
Questions 13

The objective of an upcoming engagement is to review the wind park projects and assess compliance with established project management principles. Which of the following is most likely to be the aim of the engagement work program?

Options:

A.  

Evaluate the application of project management guidance in the development of wind parks.

B.  

Identify key risks and mitigation plans pertaining to the management of wind parks.

C.  

Assess whether development of wind parks is compliant with relevant legal acts and international best practices.

D.  

Review the wind park development strategy and compare its goals with operational targets and metrics.

Discussion 0
Questions 14

An organization's healthcare insurance costs have been rising approximately 10 percent per year for several years. Which of the following analytical review procedures would best evaluate the reasonableness of the increase in healthcare costs?

Options:

A.  

Develop a comparison of the costs incurred with similar costs incurred by other organizations.

B.  

Obtain the government index of healthcare costs for the comparable period of time and compare the rate of increase with that of the cost per employee incurred by the organization.

C.  

Obtain a bid from another healthcare administrator to provide the same administrative services as the current healthcare administrator.

D.  

Review all claims and compare with appropriate procedures to ensure that overpayments have not occurred.

Discussion 0
Questions 15

Which of the following approaches to understanding business processes is conducted from a broad organizational perspective and has the greatest risk of overlooking processes that are ultimately critical?

Options:

A.  

Process narrative.

B.  

Process mapping.

C.  

Bottom-up.

D.  

Top-down.

Discussion 0
Questions 16

Which of the following is a true statement regarding whistleblowing?

Options:

A.  

Whistleblowing is one of several possible ethical structures an organization can undertake to encourage ethical behavior.

B.  

Whistleblowing programs help employees deal with ethical questions and instill ethical values into everyday behavior

C.  

Whistleblowers are current or former employees who are disgruntled and looking to retaliate.

D.  

Whistleblowers should inform the organization about actual criminal circumstances, not assumed allegations.

Discussion 0
Questions 17

Which of the following best illustrates the primary focus of a risk-based approach to control self-assessment?

Options:

A.  

To evaluate controls regarding the computer security of an oil refinery.

B.  

To examine the processes involved in exploring, developing, and operating a gold mine.

C.  

To assess the likelihood and impact of events associated with operating a finished goods warehouse.

D.  

To link a financial institution's business objectives to a work unit responsible for the associated risk.

Discussion 0
Questions 18

An internal auditor determines that certain information from the engagement results is not appropriate for disclosure to all report recipients because it is privileged. In this situation, which of the following actions would be most appropriate?

Options:

A.  

Disclose the information in a separate report.

B.  

Distribute the information in a confidential report to the board only

C.  

Distribute the reports through the use of blind copies.

D.  

Exclude the results from the report and verbally report the conditions to senior management and the board.

Discussion 0
Questions 19

An internal auditor discovered a control weakness that needs to be communicated to management. Which of the following is the best method for first communicating the weakness?

Options:

A.  

Draft report, to be reviewed by management just prior to final report issuance.

B.  

Preliminary observation document, discussed during the engagement.

C.  

Final report, after review by audit management.

D.  

Verbal communication during the engagement, followed by the final report issuance.

Discussion 0
Questions 20

According to IIA guidance, which of the following should be a primary objective for an internal auditor who is conducting an exit conference?

Options:

A.  

Improve relations with the engagement clients.

B.  

Present the final engagement communication.

C.  

Identify concerns for future audit engagements.

D.  

Ensure the accuracy of engagement conclusions.

Discussion 0
Questions 21

If there is a significant error or omission in the final audit report that was communicated to management, which of the following is the key action for the internal audit activity?

Options:

A.  

Communicate the corrected information to the manager of the audited department.

B.  

There should be a follow-up audit to address the error or omission.

C.  

The auditor should update the scope of the audit to include the omission.

D.  

The corrected communication should be redistributed to the original recipients.

Discussion 0
Questions 22

It is close to the fiscal year end for a government agency, and the chief audit executive (CAE) has the following items to submit to either the board or the chief executive officer (CEO) for approval. According to IIA guidance, which of the following items should be submitted only to the CEO?

Options:

A.  

The internal audit risk assessment and audit plan for the next fiscal year.

B.  

The internal audit budget and resource plan for the coming fiscal year.

C.  

A request for an increase of the CAE's salary for the next fiscal year.

D.  

The evaluation and compensation of the internal audit team.

Discussion 0
Questions 23

Which procedure should an internal auditor perform to determine the audit objective?

Options:

A.  

Meet with the board to discuss emerging issues and concerns

B.  

Conduct a risk assessment of the area under review

C.  

Establish the boundaries of the engagement

D.  

Outline what will be included in the review

Discussion 0
Questions 24

In which of the following situations would it be most appropriate for an internal audit function to issue an interim report or memo?

Options:

A.  

A scheduled audit observed that several agreed improvements from the previous audit were still being implemented.

B.  

A planned inventory count at the production plant revealed a material variance.

C.  

An employee shared concerns of suspected fraud but did not provide evidence.

D.  

An auditor responsible for the fieldwork has carried out only half of the planned audit procedures and has no observations so far.

Discussion 0
Questions 25

If the skills and competencies are not present within the internal audit activity to complete an ad-hoc assurance engagement, which of the following is an acceptable resolution?

Options:

A.  

Politely decline the engagement due to a lack of qualified staff available at the time.

B.  

Complete the engagement as requested, with the best of the current staff’s abilities.

C.  

Consider using employees from other departments in the organization on the audit team.

D.  

Change the scope of the testing to ensure that only available staff proficiencies are used

Discussion 0
Questions 26

Which of the following best describes the guideline for preparing audit engagement workpapers?

Options:

A.  

Workpapers should be understandable to the auditor in charge and the chief audit executive

B.  

Workpapers should be understandable to the audit client and the board.

C.  

Workpapers should be understandable to another internal auditor who was not involved in the engagement.

D.  

Workpapers should be understandable to external auditors and regulatory agencies

Discussion 0
Questions 27

A chief audit executive (CAE) determined that management chose to accept a high-level risk that may be unacceptable lo the organization. Which is the best course of action for the CAE to Follow?

Options:

A.  

Include using in a subsequent audit to determine if the risks are still present

B.  

Discuss the matter with senior management and it not reserved with the board

C.  

Require that management implement controls to mitigate lie risks

D.  

Report the risks to the process owners so that they can modify their process

Discussion 0
Questions 28

Which of the following statements best explains why an internal auditor should pay attention to retained earnings of an organization?

Options:

A.  

Retained earnings indicate the amount of potential dividends to be paid out to new investors.

B.  

Retained earnings represent the amount of excess cash available in the organization.

C.  

Retained earnings demonstrate that the organization was able to generate working capital from its own activities.

D.  

Retained earnings constitute the main criterion used by ratings agencies to assess an organization.

Discussion 0
Questions 29

Which of the following processes does the board manage to ensure adequate governance?

Options:

A.  

Establish and measure performance objectives for the internal audit activity

B.  

Select board members with necessary knowledge and skills.

C.  

Develop, approve, and execute the strategic plan of the organization

D.  

Develop strategies to mitigate the risks to achieving the organization's objectives

Discussion 0
Questions 30

Which of the following would help the internal audit activity assess compliance with the organization's standard operating procedures for bank deposits during a preliminary survey?

Options:

A.  

Issue an internal control questionnaire to select branch customers.

B.  

Issue an internal control questionnaire to the president of the organization.

C.  

Issue an internal control questionnaire to the director of bank operations.

D.  

Issue an internal control questionnaire to select branch managers.

Discussion 0
Questions 31

Which of the following documents are internal auditors most likely to be asked to sign as a demonstration of due professional care?

Options:

A.  

A description of their job responsibilities.

B.  

A non-disclosure agreement

C.  

An annual declaration of commitment to The HAs Code of Ethics.

D.  

The internal audit charter

Discussion 0
Questions 32

Which of the following actions should the chief audit executive take when senior management decides to accept risks by choosing to do business with a questionable vendor?

Options:

A.  

Persuade senior management to take appropriate action.

B.  

Cancel issuing the engagement report due to the assumed risks.

C.  

Accept senior management’s assumption of the risks.

D.  

Discuss the issue with the board for them to take appropriate action.

Discussion 0
Questions 33

An internal auditor is performing testing to gather evidence regarding an organization's inventory account balance and is mindful of the possibility that the sample used might support the conclusion that the recorded account balance is not materially misstated when, in fact, it is The auditor's concern best describes which of the following risks?

Options:

A.  

Incorrect rejection risk.

B.  

Incorrect acceptance risk.

C.  

Tolerable misstatement risk

D.  

Anticipated misstatement risk

Discussion 0
Questions 34

According to IIA guidance, which of the following factors should the auditor in charge consider when determining the resource requirements for an audit engagement?

Options:

A.  

The number, experience, and availability of audit staff as well as the nature, complexity, and time constraints of the engagement.

B.  

The appropriateness and sufficiency of resources and the ability to coordinate with external auditors.

C.  

The number, proficiency, experience, and availability of audit staff as well as the ability to coordinate with external auditors.

D.  

The appropriateness and sufficiency of resources as well as the nature, complexity, and time constraints of the engagement.

Discussion 0
Questions 35

A snow removal company is conducting a scenario planning exercise where participating employees consider the potential impacts of a significant reduction in annual snowfall for the coming winter. Which of the following best describes this type of risk?

Options:

A.  

Residual

B.  

Net

C.  

inherent.

D.  

Accepted.

Discussion 0
Questions 36

Which of the following is the advantage of using internal control questionnaires (ICQs) as part of a preliminary survey for an engagement?

Options:

A.  

ICQs provide testimonial evidence.

B.  

ICQs are efficient.

C.  

ICQs provide tangible evidence to be quantified.

D.  

ICQs put observations into perspective.

Discussion 0
Questions 37

An internal auditor believes that the internal audit activity's independence is impaired Which of the following actions should the internal auditor take first?

Options:

A.  

Report the impairment to senior management

B.  

Discuss the impairment with the audit manager.

C.  

Ascertain the best approach to disclose the impairment.

D.  

Decide on the extent of impact of the impairment

Discussion 0
Questions 38

According to IIA guidance, which of the following accurately describes the responsibilities of the chief audit executive with respect to the final audit report?

1. Coordinate post-engagement conferences to discuss the final audit report with management.

2. Include management's responses in the final audit report.

3. Review and approve the final audit report.

4. Determine who will receive the final audit report.

Options:

A.  

1 and 2

B.  

1 and 4

C.  

2 and 3

D.  

3 and 4

Discussion 0
Questions 39

Which of the following statements is true regarding managements use of judgement to design, implement, and conduct internal control?

Options:

A.  

The use of judgment enhances managements ability to make better decisions about internal control, but cannot guarantee perfect outcomes.

B.  

introducing judgment generally diminishes managements ability to make good decisions about internal control

C.  

It is inappropriate for management to exercise judgement in areas such as specifying and using suitable accounting principles.

D.  

It is inappropriate for management to exercise judgement in assessing whether components are present, functioning, and operating together

Discussion 0
Questions 40

Which of the following statements is true regarding internal control questionnaires?

Options:

A.  

Internal control questionnaires are useful m evaluating the effectiveness of standard operating procedures

B.  

internal control questionnaires provide reliable documents allowing internal auditors to cover many control procedures in little time

C.  

Internal control questionnaires can be used by internal auditors as an interview guide

D.  

Internal control questionnaires provide direct audit evidence which may need corroboration

Discussion 0
Questions 41

Which of the following statements is true regarding engagement planning?

Options:

A.  

The scope of the engagement should be planned according to the internal audit activity's budget and then aligned to the risk universe.

B.  

The audit engagement objectives should be based on operational managements view of risk objectives

C.  

The planning phase of the engagement should be completed and approved before the fieldwork of the engagement begins.

D.  

The main purpose of the engagement work program is to determine the nature and timing of procedures required to gather audit evidence

Discussion 0
Questions 42

During the planning phase of an assurance engagement, which of the following would an internal auditor use to assess and present the severity of the impact of identified risks?

Options:

A.  

Kanban board

B.  

Control self-assessment

C.  

Heat map

D.  

Risk register

Discussion 0
Questions 43

During audit engagement planning, an internal auditor is determining the best approach for leveraging computer-assisted audit techniques (CAATs). Which of the following approaches maximizes the use of CAATs and why?

Options:

A.  

Tracing, because it would enable the auditor to verify quickly that the record counts were properly included in the compilation.

B.  

Inspection, because it would enable the auditor to verify how management enters the data into the application for processing.

C.  

Testing data, because it would enable the auditor to ensure that the application processes the transaction as described by management.

D.  

Reperformance, because it enables the auditor to verify that the application performed the calculation correctly.

Discussion 0
Questions 44

Which of the following best describes why an internal audit activity would consider sending written preliminary observations to the audit client?

Options:

A.  

Written observations allow for more interpretation.

B.  

Written observations help the internal auditors express the significance.

C.  

Written and verbal observations are equally effective.

D.  

Written observations limit premature agreement.

Discussion 0
Questions 45

Which of the following is an advantage of nonstatistical sampling over statistical sampling?

Options:

A.  

Nonstatistical sampling provides more objective recommendations for management.

B.  

Nonstatistical sampling provides an opportunity to select the minimum sample size required to satisfy the objectives of the audit tests.

C.  

Nonstatistical sampling provides for the use of subjective judgment in determining the sample size.

D.  

Nonstatistical sampling permits the auditor to specify a level of reliability and the desired degree of precision.

Discussion 0
Questions 46

Which of the following is true regarding the communication of engagement results with stakeholders?

Options:

A.  

When the chief audit executive (CAE) concludes that management has accepted a level of risk that may be unacceptable to the organization, the CAE must discuss the matter with senior management. If the CAE determines that the matter has not been resolved, the CAE should seek the opinion from regulatory bodies.

B.  

The CAE should avoid issuing any interim reports, even for high-risk observations, prior to the issuance of the final written report to avoid leakage of sensitive information.

C.  

It is mandatory for the CAE to assess the potential risk to the organization, consult with senior management and legal counsel as appropriate, and control dissemination by restricting the use of the results prior to releasing them to parties outside of the organization if not otherwise mandated by legal, statutory, or regulatory requirements.

D.  

The board should always be given the final written internal audit reports at the conclusion of all internal audit engagements. Executive summaries should be avoided in all cases.

Discussion 0
Questions 47

The internal audit function is performing an assurance engagement on the organization’s environmental, social, and governance (ESG) program. The engagement objective is to determine whether the ESG program’s activities are meeting the program’s established goals. The internal audit function has completed a risk and control assessment of the ESG program's activities. What is the appropriate next step?

Options:

A.  

Conclude whether the ESG program's activities are meeting the established goals

B.  

Communicate the results of the assessment to senior management

C.  

Develop recommendations based on the results of the assessment

D.  

Perform testing on the activities selected based on the assessment

Discussion 0
Questions 48

Which of the following statements is true regarding internal auditors and other assurance providers?

Options:

A.  

Assurance providers who report to management and/or are part of management cannot provide control serf-assessments services

B.  

Internal auditors should always reperform and validate audit work completed by external assurance providers

C.  

Internal auditors may rely on the work of internal compliance teams to expand their coverage of the organization without increasing direct audit

D.  

hours Internal auditors can rely on the work of other assurance providers only rf the other assurance providers report directly to the board

Discussion 0
Questions 49

As part of an audit engagement, an internal auditor verifies whether raw material is regularly delivered to the organization's warehouse in a timely manner. What type of objective does this exemplify?

Options:

A.  

Operations

B.  

Compliance

C.  

Financial reporting

D.  

Strategic

Discussion 0
Questions 50

Which of the following is an appropriate activity when supervising engagements?

Options:

A.  

During engagement planning, the audit work program should be discussed between auditors and the engagement supervisor with the supervisor approving the work program.

B.  

During fieldwork, scope changes made to the work program are at the auditor's discretion and should be supported adequately in the workpapers.

C.  

Engagement supervision is most critical to the fieldwork and reporting phases of the audit, as this is where the majority of the work takes place.

D.  

A degree of high supervision to no supervision may be provided to an auditor depending on his level of competence and the complexity of the engagement.

Discussion 0
Questions 51

Which statement best describes the benefit of using workpapers from recent internal audit engagements of the area under review to plan new engagements?

Options:

A.  

Recent workpapers can help during the planning of a new engagement to understand any corrective actions taken by management to address previous engagement observations.

B.  

Tests described in recent workpapers can be copied into the new workpapers to save time from reperforming a risk assessment.

C.  

Recent workpapers serve as the best source for identification of the risks to be examined in the new engagement.

D.  

The new engagement scope can be derived from recent workpapers to ensure the reperformance of engagement procedures.

Discussion 0
Questions 52

According to IIA guidance, which of the following statements is true regarding engagement planning?

Options:

A.  

For both assurance and consulting engagements, planning typically occurs after the engagement objectives and scope have already been determined.

B.  

The expectations and objectives of an assurance engagement are usually determined by. or in conjunction with, the engagement client

C.  

Internal auditors may not need to complete a preliminary risk assessment for a consulting engagement as they would when planning an assurance engagement.

D.  

For both consulting and assurance engagements, internal auditors usually form the engagement objectives prior to completing the preliminary risk assessment

Discussion 0
Questions 53

As part of internal audit's assistance with an annual external audit, the internal auditors are required to do a preliminary analytical review of an bank account balances. This involves verifying the current year end balances as web as comparing the current year end balances with previous year end balances to highlight significant changes. Which of the following is the most reliable source for verification of the current year end bank balances?

Options:

A.  

Bank confirmations

B.  

Internal bonk statements

C.  

Bank reconciliations as of the end of the year

D.  

Bank account general ledger balancer as of the end of the year

Discussion 0
Questions 54

According to IIA guidance, which of the following are the most important objectives for helping to ensure the appropriate completion of an engagement?

1. Coordinate audit team members to ensure the efficient execution of all engagement procedures.

2. Confirm engagement workpapers properly support the observations, recommendations, and conclusions.

3. Provide structured learning opportunities for engagement auditors when possible.

4. Ensure engagement objectives are reviewed for satisfactory achievement and are documented properly.

Options:

A.  

1, 2, and 3

B.  

1, 2, and 4

C.  

1, 3, and 4

D.  

2, 3, and 4

Discussion 0
Questions 55

An internal auditor wants to determine if employees spend more than their approved daily stipend for meals. Which technique would be most appropriate to identify meal expenses that exceed the approved threshold?

Options:

A.  

Using compliance verification data analytics

B.  

Using regression analysis

C.  

Using software with a gap testing function

D.  

Drafting a flowchart of the meal expense reporting process

Discussion 0
Questions 56

A multinational organization has multiple divisions that sell their products internally to other divisions When selling internally, which of the following transfer prices would lead to the best decisions for the organization?

Options:

A.  

Full cost

B.  

Full cost plus a markup.

C.  

Market price of the product.

D.  

Variable cost plus a markup.

Discussion 0
Questions 57

Which of the following statements generally true regarding audit engagement planning?

Options:

A.  

The best source tor detailed process information is senior management

B.  

Audit objectives should be general and do not change.

C.  

Computer-assisted audit techniques are typically not useful during engagement planning

D.  

Internal auditors should prepare a dented audit program for testing controls

Discussion 0
Questions 58

An internal auditor completed a review of expenses related to the launch of a new project. The auditor sampled 45 transactions approved by a senior project manager and identified 30 with questionable vendor documentation. Which of the following is the most appropriate conclusion for the auditor to include in the audit report?

Options:

A.  

The organization incurred excessive cost overruns that resulted in significant financial and legal risk to the project.

B.  

The organization experienced a potential conflict of interest

C.  

The organization had weaknesses in its review process which allowed questionable transactions with some vendors

D.  

The organization allowed the project to launch without assurance that all transactions were regularly approved

Discussion 0
Questions 59

When is an organic organizational structure likely to be more successful than a mechanistic organizational structure?

Options:

A.  

When a manufacturing organization has stable demand for its products.

B.  

When an organization is subjected to strong political and social pressures

C.  

When a manufacturer has reliable resources and suppliers.

D.  

When an organization is infrequently affected by technological advances

Discussion 0
Questions 60

To compete in the global market, an organization is restructuring and consolidating many of its divisions. Prior to the consolidation, senior management requested assistance from tie internal audit activity. Which of the following consulting services would be most appropriate in this situation?

Options:

A.  

Assess controls for potential compliance issues that may affect me consolidation

B.  

Brief vendors on the potential risks that will occur without continued business

C.  

Advise division managers on how to streamline operations for better efficiency

D.  

Determine whether the organization’s controls are effective in meeting business objectives

Discussion 0
Questions 61

Which of the following audit steps would an internal auditor most likely be questioned on?

Options:

A.  

The auditor confirms the organization's ownership of physical equipment by verifying its presence on site visually.

B.  

The auditor vouches for a sample of check copies to support voucher packages to test the checks' validity.

C.  

The auditor vouches a sales invoice to a shipping document to conclude that the invoice has been issued.

D.  

The auditor recalculates the allowance for doubtful accounts based on management assertions.

Discussion 0
Questions 62

Which of the following behaviors could represent a significant ethical risk if exhibited by an organization's board?

1. Intervening during an audit involving ethical wrongdoing.

2. Discussing periodic reports of ethical breaches.

3. Authorizing an investigation of an unsafe product.

4. Negotiating a settlement of an employee claim for personal damages.

Options:

A.  

1 and 2

B.  

1 and 4

C.  

2 and 3

D.  

3 and 4

Discussion 0
Questions 63

Which of the following best exemplifies having effective risk management and internal control processes?

Options:

A.  

Relevant risk indicators and mitigation plans are in place

B.  

All risks are identified and assessed

C.  

Business profitability is likely to be achieved

D.  

Risk information is communicated to customers and suppliers

Discussion 0
Questions 64

For which of the following fraud engagement activities would it be most appropriate to involve a forensic auditor?

Options:

A.  

Independently evaluating conflicts of interests.

B.  

Assessing contracts for relevant terms and conditions.

C.  

Performing statistical analysis for data anomalies.

D.  

Preparing evidentiary documentation.

Discussion 0
Questions 65

Which of the following constitutes supervisory activity undertaken during the planning phase of an assurance engagement?

Options:

A.  

Ensuring the process owner with the engagement objectives

B.  

Reviewing engagement draft reports

C.  

Ensuring workpapers support audit findings

D.  

Approving audit work programs

Discussion 0
Questions 66

Which of the following would be the most effective fraud prevention control?

Options:

A.  

Email alert sent to management for checks issued over S100.000.

B.  

installation of a video surveillance system in a warehouse prone to inventory loss

C.  

New hire training to explain fraud and employee misconduct.

D.  

Daily report that Identifies unsuccessful system log-in attempts

Discussion 0
Questions 67

Which of the following should be included in a company's year-end inventory valuation?

Options:

A.  

Company goods that were sold during the year, free on board shipping point, that have been shipped but not yet received by the customer

B.  

Goods purchased by the company, free on board destination, that have not yet been received.

C.  

Goods on consignment, which the company is trying to sell for its customers.

D.  

Company goods for sale on consignment at a consignment shop

Discussion 0
Questions 68

Which of the following best describes the guideline for preparing audit engagement workpapers?

Options:

A.  

Workpapers should be understandable to the auditor in charge and the chief audit executive.

B.  

Workpapers should be understandable to the audit client and the board.

C.  

Workpapers should be understandable to another internal auditor who was not involved in the engagement.

D.  

Workpapers should be understandable to external auditors and regulatory agencies.

Discussion 0
Questions 69

A chief audit executive (CAE) following up on action plans from previously completed audits identifies that management has determined that certain action plans are no longer necessary If the CAE disagrees with managements decision, which of the following is the most appropriate next step for the CAE to take?

Options:

A.  

The CAE must discuss the matter with senior management

B.  

The CAE must discuss the matter with key shareholders.

C.  

The CAE must discuss the matter with legal counsel.

D.  

The CAE must discuss the matter with the board

Discussion 0
Questions 70

Some lime after the final audit report was issued, the engagement supervisor teamed that several internal control deficiencies were not remedied, despite management's previous agreement to remedy them According to IIA guidance, which of the following is the most appropriate response'5

Options:

A.  

The engagement supervisor must notify the chief audit executive (CAE) that the deficiencies have not been rectified

B.  

The engagement supervisor should rely on professional judgment as to whether the CAE should be informed, or the management action plan should be adjusted

C.  

The engagement supervisor should rely on his negotiation skills and issue an ultimatum to management to remedy the control deficiencies

D.  

Ensure that these deficiencies are captured in the documentation as high-priority areas to be reviewed during the next audit.

Discussion 0
Questions 71

Which of the following statements describes an engagement planning best practice?

Options:

A.  

It is best to determine planning activities on a case-by-case basis because they can vary widely from engagement to engagement.

B.  

If the engagement subject matter is not unique, it is not necessary to outline specific testing procedures during the planning phase.

C.  

The engagement plan includes the expected distribution of the audit results, which should be kept confidential until the audit report is final.

D.  

Engagement planning activities include setting engagement objectives that align with audit client's business objectives.

Discussion 0
Questions 72

An internal auditor completed a test of 30 randomly selected accounts. For five of the accounts selected, the auditor was unable to find supporting documentation in the normal place of storage. Which of the following next steps would be most appropriate for the internal auditor to take?

Options:

A.  

Conclude that the test failed because at least 17 percent of the sample items were not supported.

B.  

Select five new accounts to replace the ones that were missing supporting documentation.

C.  

Expand the sample size to 60 to determine whether the error rate remains the same.

D.  

Contact management to determine whether the supporting documentation can be located elsewhere.

Discussion 0
Questions 73

An internal audit activity has to confirm the validity of the activities reported by a grantee that received a charitable contribution from the organization. Which of the following methods would best help meet this objective?

Options:

A.  

Visiting the grantee to assess whether the execution of the project was in line with the defined grant scope.

B.  

Verifying that the grantee's final report is in line with what was depicted in the initial budget request.

C.  

Reconciling general ledger accounts used by management of the area under review for reflecting expenses on charitable contributions.

D.  

Interviewing employees of the corporate affairs department, which is responsible for charitable activities.

Discussion 0
Questions 74

Which of the following is a detective control for managing the risk of fraud?

Options:

A.  

Awareness of prior incidents of fraud.

B.  

Contractor non-disclosure agreements.

C.  

Verification of currency exchange rates.

D.  

Receipts for employee expenses.

Discussion 0
Questions 75

Which of the following analytical procedures should an internal auditor use to determine whether monthly expenses for the accounting department are reasonable?

Options:

A.  

Review year-over-year trending of total dollars spent in each period.

B.  

Review changes to the vendor master file for suspicious activity.

C.  

Review the percentage of on-time payments against prior periods.

D.  

Review total expenses for accounting against other department expenses in the organization.

Discussion 0
Questions 76

An internal auditor is asked to determine why the production line for a large manufacturing organization has been experiencing shutdowns due to unavailable parts The auditor learns that production data used for generating automatic purchases via electronic interchange is collected on personal computers connected by a local area network (LAN) Purchases are made from authorized vendors based on both the production plans for the next month and an authorized materials requirements plan (MRP) that identifies the parts needed per unit of production. The auditor suspects the shutdowns are occurring because purchasing requirements have not been updated for changes in production techniques. Which of the following audit procedures should be used to test the auditor's theory?

Options:

A.  

Compare purchase orders generated from test data Input into the LAN with purchase orders generated from production data for the most recent period.

B.  

Develop a report of excess inventory and compare the inventory with current production volume.

C.  

Compare the parts needed based on current production estimates and the MRP for the revised production techniques with the purchase orders generated from the system for the same period

D.  

Select a sample of production estimates and MRPs for several periods and trace them into the system to determine that input is accurate

Discussion 0
Questions 77

According to the International Professional Practices Framework, which of the following is an appropriate reason for issuing an interim report?

To keep management informed of audit progress when audit engagements extend over a long period of time.

To provide an alternative to a final report for limited-scope audit engagements.

To communicate a change in engagement scope for the activity under review.

Options:

A.  

1 and 2 only.

B.  

1 and 3 only.

C.  

2 and 3 only.

D.  

1, 2, and 3.

Discussion 0
Questions 78

In which of the following situations would an internal auditor consider the need to outsource competencies and skills9

Options:

A.  

During the inspection of a wind turbine. an internal auditor notices that some replaced parts took used According to purchase documents, the parts still have a long lifespan.

B.  

The auditor believes that the audit client's actions contradict the organization's code of conduct The audit client disagrees and says his actions are for the organization's benefit

C.  

An audit team member is allocated to conduct an assurance engagement m the sales unit. However, the same auditor performed an assurance engagement in that area just one year prior

D.  

During an inventory count, the auditor ascertained that some goods were missing. The audit client argues that the auditor does not understand how inventory should be counted

Discussion 0
Questions 79

According to IIA guidance, which of the following is most likely to become part of the engagement work program?

Options:

A.  

Information obtained from historic audits and memos.

B.  

Risk and control registers or matrices.

C.  

Resource deployment plans and sampling methodologies.

D.  

Prior findings and management responses.

Discussion 0
Questions 80

The audit engagement objective is to identify vendors who might be involved in money laundering processes or tax evasion schemes. How would the internal auditor use data analytics to fulfill this objective?

Options:

A.  

Run reports listing all payments made in countries other than vendor locations

B.  

Run reports listing all credit limit overrides

C.  

Run reports listing all instances of delayed revenue recognition

D.  

Run three-way match reports, matching invoices, purchase orders, and receiving reports

Discussion 0
Questions 81

Which of the following has the greatest effect on the efficiency of an audit?

Options:

A.  

The complexity of deficiency findings.

B.  

The adequacy of preliminary survey information.

C.  

The organization and content of workpapers.

D.  

The method and amount of supporting detail used for the audit report.

Discussion 0
Questions 82

The final engagement communication contains the following observation:

The internal auditor discovered that three of the 10 contracts reviewed failed to meet the organization's competitive bidding requirements Management explained that senior management deemed these purchases to be critical and awarded them as sole-source."

Which of the following components is missing in the documentation of the observation?

Options:

A.  

Criteria.

B.  

Effect

C.  

Condition

D.  

Cause

Discussion 0
Questions 83

The internal audit function is in the fieldwork stage of the annual staff performance appraisal assurance engagement. A new auditor is hired and added to the engagement team. The auditor reviews the engagement work program with another member of the team and suggests improvements to make the fieldwork easier to complete. What action should be taken next?

Options:

A.  

Refer the suggested changes to the engagement supervisor for approval.

B.  

Note the suggested changes to be included in next year’s engagement program.

C.  

Update the engagement work program with the suggested changes.

D.  

No action is required as the work program has been approved and is underway.

Discussion 0
Questions 84

According to the theory of constraints, which of the following is most influenced by various bottlenecks the organization encounters?

Options:

A.  

Manufacturing.

B.  

Profitability.

C.  

Overheads.

D.  

Quality.

Discussion 0
Questions 85

After concluding a preliminary assessment, the engagement supervisor prepared a draft work program According to HA guidance which of the following would be tested by this program?

Options:

A.  

The process objectives.

B.  

The process risks

C.  

The process controls

D.  

The process scope

Discussion 0
Questions 86

An internal auditor is analyzing sates records and is concerned whether a transaction is recorded in the coned period. The accounting manager explains that the external auditor approved the records and produces an email from the external audit team leader. How should tie internal auditor respond?

Options:

A.  

Ask the external auditor to review the same transaction again as an independent third party

B.  

Consult account accounting principles, standards, and relevant guidelines in regard to timing of the entry

C.  

Interview the chief financial officer and obtain her opinion on how the transactions should be recorded

D.  

Compare the recording of this transaction to now similar ones were executed last year

Discussion 0
Questions 87

An internal auditor is using attributes sampling to test internal controls. Under which of the following circumstances would the auditor increase the original sample size to estimate error occurrence at a given precision and confidence level?

Options:

A.  

The sample rate of occurrence plus the precision exceeds the acceptable error rate.

B.  

The sample rate of occurrence is less than the acceptable error rate.

C.  

The acceptable rate of occurrence less the precision exceeds the sample rate of occurrence.

D.  

The sample rate of occurrence plus the precision equals the acceptable error rate.

Discussion 0
Questions 88

A newly appointed chief audit executive (CAE) of a small organization is developing a resource management plan Which of the following approaches would be most beneficial to help the CAE obtain details of the Internal audit activity's collective knowledge skills, and other competencies?

Options:

A.  

Review or establish a documented skills assessment of the internal audit staff and gather information from post-audit surveys

B.  

Obtain from the human resources department the job descriptions and position requirements for all internal audit staff

C.  

Conduct an objective written test of the internal audit staff to assess their knowledge and skills related to core internal audit competencies

D.  

Request the internal audit staff to submit a document that summarizes their most recent performance appraisals and post audit reviews

Discussion 0
Questions 89

An internal auditor is using computer-assisted audit techniques to examine employee expenses across several divisions of the organization. Which of the following is true in this situation?

Options:

A.  

The data from various sources should remain segregated for easier analysis and discovery of anomalies.

B.  

Fraud detection techniques should be performed against full data populations.

C.  

A reactive approach is best suited for fraud detection due to the effectiveness of tips and whistleblowing programs.

D.  

Random sampling is an effective method of detecting fraudulent transactions.

Discussion 0
Questions 90

An organization experiencing staff shortages wants to contract a temporary employee to assist with work in the accounting office. Which of the following controls should be in place to ensure the temporary employee performs the assigned work before payment is issued?

Options:

A.  

A three-way match between the invoice, purchase requisition, and documentation of receipt of services

B.  

A member of management approves the purchase requisition before the temporary employee begins work

C.  

A scope of work for the temporary employee is included in the purchase requisition and signed by the organization

D.  

Payments to the vendor are analyzed monthly to ensure they do not exceed the amount approved on the purchase order

Discussion 0
Questions 91

An internal auditor collected several employee testimonials Which of the following is the best action for the internal auditor to take before drawing a conclusion?

Options:

A.  

Ensure the testimonials are well documented

B.  

Substantiate the testimonials with physical or documentary evidence

C.  

Corroborate testimonials with the results from other soft control techniques

D.  

Review the testimonials with the interviewed employees

Discussion 0
Questions 92

An audit observation noted that annual inventory counts of biofuel was not being performed appropriately Fuel yards were not visited and physical amounts of biofuel were not reconciled with accounting data Management of the division understood the issue and promised to resolve the problem When should the internal auditor schedule a follow-up review?

Options:

A.  

As soon as possible, no later than two months after the audit

B.  

When convenient for both parties

C.  

When management has indicated that the issue has been resolved

D.  

Before financial year end

Discussion 0
Questions 93

An internal auditor was assigned to review controls in the accounts payable function. Most of tie accounts payable processes are performed by a third-party service provider. The auditor included in the audit report a number of control deficiencies involving processes performed by the service provider. The service provider requested a copy of the report Which of Vie following would be the most appropriate response from the chief audit executive (CAE)?

Options:

A.  

The CAE would automatically sand a copy of the report to the service provider as many of the findings relate to Via area managed by the service provider

B.  

The CAE may distribute the report to tie service provider at no cost, after consulting with legal counsel and tie chief compliance officer

C.  

The CAE may provide a copy of the audit report to the service provider If an agreement & signed and the service provider agrees to reimburse the cost of the auditD, The CAE should benchmark with other organization in the industry by consorting with colleagues and distribute the report only I it is an acceptable practice m the industry

Discussion 0
Questions 94

An internal auditor is asked to determine why the production line for a large manufacturing organization has been experiencing shutdowns due to unavailable pacts The auditor learns that production data used for generating automatic purchases via electronic interchange is collected on personal computers connected by a local area network (LAN) Purchases are made from authorized vendors based on both the production plans for the next month and an authorized materials requirements plan (MRP) that identifies the parts needed per unit of production The auditor suspects the shutdowns are occurring because purchasing requirements have not been updated for changes in production techniques. Which of the following audit procedures should be used to test the auditor's theory?

Options:

A.  

Compare purchase orders generated from test data input into the LAN with purchase orders generated from production data for the most recent period

B.  

Develop a report of excess inventory and compare the inventory with current production volume

C.  

Compare the pans needed based on current production estimates and the MRP for the revised production techniques with the purchase orders generated from the system for the same period

D.  

Select a sample of production estimates and MRPs for several periods and trace them into the system to determine that input is accurate

Discussion 0
Questions 95

When taken by a chief audit executive, which of the following actions would be most likely to prevent division management from exaggerating sales reports

1.Announcing a series of internal audit engagements focusing on compliance with corporate sales-reporting policies.

2.Asking the president and the board to issue a statement of corporate policy stressing the importance of accurate management reporting and the negative consequences of intentional misreporting

3.Setting up a hotline for employees to report fraudulent behavior anonymously.

4.Assisting the controller in developing and monitoring a series of business process indicators, which are historically correlated with, but independent of. sales.

Options:

A.  

1 and 2 only.

B.  

2 and 3 only.

C.  

2 and 4 only.

D.  

3 and 4 only.

Discussion 0
Questions 96

An organization has a health and safety division that conducts audits to meet regulatory requirements. The chief health and safety officer reports directly to the CEO. Which of the following describes an appropriate role for the chief audit executive (CAE) with regard to the organization's health and safety program?

Options:

A.  

The CAE has no role to play, because the chief health and safety officer reports to a senior executive.

B.  

The CAE should coordinate with, and review the work of, the chief health and safety officer to gain an understanding of whether risks related to health and safety are managed properly.

C.  

The CAE should give periodic reports directly to the regulator regarding health and safety issues, as it is the appropriate regulatory oversight body.

D.  

The CAE should hire an independent external specialist to conduct an annual assessment and provide assurance over the effectiveness of the health and safety program and the reliability of its reports.

Discussion 0
Questions 97

Prior to performing testing an internal auditor has determined that a primary process control failed due to design weakness. Which of the following actions should the auditor perform next?

Options:

A.  

Determine whether there are any compensating controls in place to reduce the nsk to an acceptable level, and discuss this matter with management of the business area to determine which corrective action is needed

B.  

Test the control anyway to determine the likelihood that the control was not performed property, and discuss this matter with management of the business area to determine which corrective action is needed

C.  

Conclude that the process control environment is weak, issue a finding on this conclusion and report this finding to management of the business area

D.  

Confer with a second internal auditor to determine whether the control failure is legitimate issue a finding on this conclusion and report this finding to management of the business area

Discussion 0
Questions 98

Which of the followings statements describes a best practice regarding assurance engagement communication activities?

Options:

A.  

All assurance engagement observations should be communicated to the audit committee.

B.  

All assurance engagement observations should be included in the main section of the engagement communication.

C.  

During the "communicate" phase of an assurance engagement, it is best to define the methods and timing of engagement communications.

D.  

A detailed escalation process should be developed during the planning stage of an assurance engagement.

Discussion 0
Questions 99

What is the primary objective of an engagement supervisor's review of key activities performed during the engagement?

Options:

A.  

To ensure that the engagement is completed on time and within budget

B.  

To ensure that all work performed meets acceptable quality standards

C.  

To ensure that management has provided suitable responses to all observations

D.  

To ensure that management is satisfied with the progress of the engagement

Discussion 0
Questions 100

Which of the following would be most useful for an internal auditor to obtain during the preliminary survey of an engagement on internal controls over user access management?

Options:

A.  

The policy for granting, modifying, and deleting user access to ensure processing requirements are clearly articulated.

B.  

A sample of change request forms to verify whether the forms bear the required approval for the user access change.

C.  

User access reports that were reviewed by management to ensure that access rights are appropriate for employee roles.

D.  

A current listing of system users and an employee listing to determine whether system users are active employees of the organization.

Discussion 0
Questions 101

While reviewing the workpapers and draft report from an audit engagement, the chief audit executive (CAE) found that an Important compensating control had not been considered adequately by the audit team when it reported a major control weakness Therefore, the CAE returned the documentation to the auditor in charge for correction Based on this Information, which of the following sections of the workpapers most likely would require changes?

1.Effect of the control weakness.

2.Cause of the control weakness

3.Conclusion on the control weakness.

4.Recommendation for the control weakness.

Options:

A.  

1, 2, and 3.

B.  

1.2. and 4

C.  

1,3, and 4.

D.  

2, 3, and 4.

Discussion 0
Questions 102

What is the primary reason that audit supervision includes approval of the engagement report?

Options:

A.  

To ensure the objectives of the area under review are met.

B.  

To ensure senior management supports the report's conclusions.

C.  

To ensure report style and grammar are appropriate.

D.  

To ensure report findings are substantiated.

Discussion 0
Questions 103

According to an internal audit observation, the organization’s rules of record management require all contracts to be registered and stored in a specific electronic system. One subsidiary has thousands of client contracts on paper, which are kept in the office because there are not enough assistants to scan the contracts into the system. Which of the following component should be added to this observation?

Options:

A.  

Criteria

B.  

Cause

C.  

Effect

D.  

Condition

Discussion 0
Questions 104

Senior IT management requests the internal audit activity to perform an audit of a complex IT area. The chief audit executive (CAE) knows that the internal audit activity lacks the expertise to perform the engagement. Which of the following is the most appropriate action for the CAE to take?

Options:

A.  

Decline the audit engagement, because the Standards prohibit internal auditors from performing engagements where they lack the necessary competencies.

B.  

Accept the audit engagement and use the engagement as an opportunity to develop the audit team's IT expertise while performing the audit work.

C.  

Temporarily hire an experienced and knowledgeable IT analyst from the organization's IT department to lead the audit.

D.  

Outsource the audit engagement to a reputable IT audit consulting firm.

Discussion 0
Questions 105

Which of the following is one of the five basic tnanoal statement assertions when an internal auditor evaluates controls over financial reporting?

Options:

A.  

Reliability or appropriateness

B.  

Reasonableness

C.  

Existence or occurrence

D.  

Relevance

Discussion 0
Questions 106

A manufacturing organization specializes in the production of evaporated milk and breakfast cereals. The manufacturing processes create significant loss in the form of waste and byproducts. The provision for normal production loss is known to senior management, but little action is taken when abnormal production losses occur. The organization sells its production byproducts to fish farmers at a reduced price. The byproducts are a widely recognized and used product in the fish farming industry. The organization has a policy that also allows its employees to purchase the byproducts at a negligible price. Based on the above, which of the following risks should the internal audit function consider when planning an engagement of the production process?

Options:

A.  

The production team may be incentivized to increase production losses.

B.  

The production team may work overtime and be overworked.

C.  

Increased misappropriation of finished products.

D.  

Risk that the finished product quality may be impaired.

Discussion 0
Questions 107

According to the MA guidance, which of the following does the engagement work program test in a review of an organizational process?

Options:

A.  

Process objectives.

B.  

Process risks

C.  

Process controls.

D.  

Process scope

Discussion 0
Questions 108

An engagement team is being assembled to audit of one of the organization's vendors Which of the following statements best applies to this scenario?

Options:

A.  

The engagement team should include internal auditors who have expertise in investigating vendor fraud

B.  

The engagement team should be composed of certified accountants who are proficient In financial statement analysis and local accounting principles

C.  

To preserve independence and objectivity, an auditor who worked for the vendor two years prior may not participate on the engagement team

D.  

The engagement team may include an auditor who lacks knowledge of the industry in which the vendor operates

Discussion 0
Questions 109

The chief audit executive of an international organization is planning an audit of the treasury function located at the organization's headquarters. The current internal audit team at headquarters lacks expertise in the area of financial markets which is needed tor the engagement When of the following would be the most approbate solution considering the time constraint?

Options:

A.  

Outsource the engagement 10 tie organization's external auditor who has expertise in the area of financial markets

B.  

Hire additional internal auditors who have expertise in the area of financial markets.

C.  

Invite a guest auditor from one of the organization's affiliates who has expertise m the area of financial markets.

D.  

Limit the scope of the engagement to the knowledge and skills possessed by the internal audit team.

Discussion 0
Questions 110

Which of the following manual audit approaches describes testing the validity of a document by following it backward to a previously prepared record?

Options:

A.  

Tracing

B.  

Reperformance

C.  

Vouching

D.  

Walkthrough

Discussion 0
Questions 111

An internal auditor is conducting an initial risk assessment of an audit area and wants to assess management's compliance with privacy laws for safeguarding customer information stored on the organization's servers. Which course of action is appropriate for this phase of the engagement?

Options:

A.  

Solicit the services of a specialist information systems auditor

B.  

Obtain the most current approved copies of the organization's privacy policy

C.  

Consult with legal counsel about new privacy laws to establish appropriate criteria

D.  

Consider the detection risk of noncompliance with the laws

Discussion 0
Questions 112

Which of the following is most likely to be judged as a significant residual risk that would exceed the organization's acceptable risk level?

Options:

A.  

Any risk involving organizational expansion into a new geographical area with an unstable political environment.

B.  

Any risk involving investments into bitcoin and suspicious derivatives

C.  

Any risk that can cause material or financial loss

D.  

Any risk that could cause injuries or pollute the environment

Discussion 0
Questions 113

An internal auditor recommended that an organization implement computerized controls in its sales system in order to prevent sales representatives from executing contracts in excess of their delegated authority levels A follow-up review found that the sales system had not been modified, but a process had been implemented to obtain written approval by the vice president of sales for all contracts in excess of S1 million The chief audit executive (CAE) would be justified in reporting this situation to the organization's board under which of the tollowing circumstances'?

1. In the opinion of the CAE the level of residual risk assumed by senior management is too high

2. Testing of compliance with the new process finds that all new contracts in excess of $1 million have been approved by the vice president of sales

3. The cost of modifying the sales system to include a preventive control is less than S100.000

Options:

A.  

1 only

B.  

3 only

C.  

1 and 3 only

D.  

1, 2, and3

Discussion 0
Questions 114

When addressing the excessive overtime being paid lo employees in an organization's customer service call center, which of the following would be most relevant for the internal auditor to use?

1 Confirmation.

2. Trend analysis.

3 External benchmarking

4. Internal benchmarking

Options:

A.  

1.2 and 3

B.  

1.2. and 4.

C.  

1.3. and 4.

D.  

2. 3. and 4.

Discussion 0
Questions 115

Who is responsible for ensuring internal auditors continuing professional development*

Options:

A.  

Individual internal auditors

B.  

Chief audit executive.

C.  

The board

D.  

Engagement supervisors

Discussion 0
Questions 116

Which of the following activities demonstrates an example of the chief audit executive performing residual risk assessment?

Options:

A.  

Cost-benefit analysis of management not implementing a recommendation to address an observation.

B.  

Inquiry of corrective action to be completed within a certain period.

C.  

Reporting the status of every observation for every engagement in a detailed manner.

D.  

Soliciting management’s feedback after completion of the audit engagement.

Discussion 0
Questions 117

In preparing the engagement work program, which of the following is generally true with respect to secondary controls?

Options:

A.  

A separate engagement work program should be created for secondary controls

B.  

Secondary controls do not necessarily need to be tested for effectiveness

C.  

Any documented secondary controls are deemed essential to the adequacy of control design

D.  

Secondary controls should be held to the same requirements as key controls

Discussion 0
Questions 118

Where should internal auditor focus their attention when identify and assessing key risks during the planning stage of an assurance engagement?

Options:

A.  

Sampling risk.

B.  

Audit risk.

C.  

Residual risk.

D.  

Inherent risk

Discussion 0
Questions 119

Following an IT systems audit, management agreed to implement a specific control in one of the IT systems. After a period, the internal auditor followed up and learned that management had not implemented the agreed management action due to the decision to move to another IT system that has built-in controls, which may address this risks highlighted by the Internal audit Which of the following Is the most appropriate action to address the outstanding audit recommendation?

Options:

A.  

The auditor examines the system documentation of the new system to verify that the risk has been addressed in the new system, then reports to senior management the closure of the issue.

B.  

The auditor accepts managements explanation that the previously identified issue is adequately addressed by the new IT system, as management understands the concern and is most knowledgeable about the new system, and closes the outstanding issue.

C.  

The auditor advises management that replacing the IT system does not dismiss the prior obligation to implement the agreed action plan, and escalates the issue to senior management and the board.

D.  

The auditor requires management to provide details regarding the process for selecting the new IT system and whether other systems were evaluated, and closure of the issue would depend on the new information provided.

Discussion 0
Questions 120

An internal auditor for a regional bank suspects that the head of commercial lending has been granting loans without the required collateral Which of the following sampling techniques will be most effective for investigating the auditor's suspicion?

Options:

A.  

Variables sampling

B.  

Dollar-unit sampling

C.  

Judgmental sampling

D.  

Discovery sampling

Discussion 0
Questions 121

What information would be most useful to an internal auditor who is attempting to identify specific processes to include in the scope of an assurance engagement?

Options:

A.  

Recent organizationwide recognition awards given to employees within the area.

B.  

The timing of the most recent audit of the area.

C.  

Management's presentation to the board regarding recent area achievements.

D.  

Recent area performance indicators against productivity metrics.

Discussion 0
Questions 122

Management asks the chief audit executive (CAE) to allocate an internal auditor as a non-voting member of a steering committee. The committee will oversee the implementation of a significant and confidential acquisition. Which of the following should guide the CAE’s selection?

Options:

A.  

To select a candidate who can be trusted to gather sensitive information on the acquisition

B.  

To select a candidate capable of conveying internal audit strategy even without voting status

C.  

To self-assign as only the CAE has authority to express opinions and offer advice to committee members

D.  

To select a candidate who has prior experience in mergers or the completion of due diligence of entities

Discussion 0
Questions 123

Which of the following risk assessment approaches involves gathering data from work team representing different levels of an organisation?

Options:

A.  

Surveys

B.  

Management produced analysis 0

C.  

Facilitated team workshops

D.  

Weighted risk factors

Discussion 0
Questions 124

When a significant finding is noted early during a review of the accounts payable function, which next course of action is best for communicating the issue?

Options:

A.  

Intern accounting management via an interim memorandum update

B.  

Note the item in the workpapers for inclusion in the final audit report

C.  

Call a meeting and discuss me issue with the audit committee

D.  

Alert the CEO as soon as the issue is discovered

Discussion 0
Questions 125

An internal auditor is performing a review of an organization's vendor for any possible conflicts of interest. Which of the following would provide the greatest assistance to the auditor in meeting this objective?

Options:

A.  

Vendor contracts.

B.  

Employee master list.

C.  

Payment records.

D.  

Purchasing policy.

Discussion 0
Questions 126

A toy manufacturer receives certain components from an overseas supplier and uses them to assemble final products Recently quality reviews have identified numerous issues regarding the components' compliance with mandatory quality standards. Which type of engagement would be most appropriate to assess the root causes of the quality issues?

Options:

A.  

A risk assessment

B.  

An operational audit

C.  

A third-party audit

D.  

A fraud investigation

Discussion 0
Questions 127

Which of the following is most likely the subject of a periodic report from the chief audit executive to the board?

Options:

A.  

A complete, accurate, and comprehensive account of engagement observations and recommendations.

B.  

Oversight of the coordination between the internal audit activity and independent outside auditors

C.  

The internal audit activity's purpose, authority, responsibility, and performance relative to plan.

D.  

Management's assertions regarding the system of internal controls.

Discussion 0
Questions 128

The chief audit executive (CAE) should determine whether the internal audit activity has confirmed the status of all of management's corrective actions Doing so would help the CAE assess which of the following?

Options:

A.  

Disclosure risk.

B.  

Residual risk

C.  

Compliance risk

D.  

Inherent risk

Discussion 0
Questions 129

An organization's internal audit plan includes a recurring assurance review of the human resources (HR) department. Which of the following statements is true regarding preliminary communication between the auditor in charge (AIC) and the HR department?

1. The AIC should notify HR management when the draft audit plan is being developed, as a courtesy.

2. The AIC should notify HR management before the planning stage begins.

3. The AIC should schedule formal status meetings with HR management at the start of the engagement.

4. The AIC should finalize the scope of the engagement before communicating with HR management.

Options:

A.  

1 and 3

B.  

1 and 4

C.  

2 and 3

D.  

2 and 4

Discussion 0
Questions 130

Which of the following steps should an internal auditor complete when conducting a review of an electronic data interchange application provided by a third-party service?

1.Ensure encryption keys meet ISO standards.

2.Determine whether an independent review of the service provider's operation has been conducted.

3.Verify that the service provider's contracts include necessary clauses.

4.Verify that only public-switched data networks are used by the service provider

Options:

A.  

1 and 3.

B.  

1 and 4

C.  

2 and 3.

D.  

2 and 4.

Discussion 0
Questions 131

A customer has supplied personal information to a bank to facilitate opening an account. The bank is part of a larger group of companies with core businesses including general insurance, life insurance, and investment products. Considering that the customer has closed his only account with the bank and the statutory data retention period has elapsed, which of the following actions by the bank is most likely to align with appropriate data privacy principles?

Options:

A.  

The bank destroys all records containing a customer's personal information without informing the customer.

B.  

Based on an assessment of likely products of interest to the customer, the bank shares the customer’s personal information with other companies within the group and informs the customer.

C.  

The bank retains customer information to facilitate easier verification of personal information in the event that the customer returns to reopen his account. The customer is not informed.

D.  

The customer's personal information is used for market research by an external company and the customer is informed prior to publishing the results of the market research.

Discussion 0
Questions 132

The chief audit executive (CAE) of a small internal audit activity (IAA) plans to test conformance with the Standards through a quality assurance review. According to the Standards, which of the following are acceptable practice for this review?

1. Use an external service provider.

2. Conduct a self-assessment with independent validation.

3. Arrange for a review by qualified employees outside of the IAA.

4. Arrange for reciprocal peer review with another CAE.

Options:

A.  

1 and 2

B.  

2 and 4

C.  

1, 2, and 3

D.  

2, 3, and 4

Discussion 0
Questions 133

While planning for an accounts payable audit an internal auditor performs an entity level controls analysis. Which of the following statements is true regarding me approach used by the auditor?

Options:

A.  

It enables the auditor to identify the inherent risks to the effective operation of accounts payable process controls.

B.  

It enables the auditor to understand the framework of the activities and associated accounts payable subprocesses

C.  

it enables the auditor to understand the accounts payable process and its flow, including key steps and systems.

D.  

It enables the auditor to categorize the population of transactions within the accounts payable process

Discussion 0
Questions 134

An internal auditor reviewed bank reconciliations prepared by management of the area under review. The auditor noted that the bank statements attached did not have the

bank heading, logo, or address. Which of the following statements is true regarding this situation?

Options:

A.  

The evidence may not be reliable.

B.  

The evidence is not relevant.

C.  

The evidence may not be sufficient.

D.  

The information missing is not relevant to the audit.

Discussion 0
Questions 135

Which of the following is the best audit procedure to obtain evidence of an organization's legal ownership of a new property?

Options:

A.  

Review documents registered with the appropriate governmental authority.

B.  

Examine the board of directors' minutes and look for approvals to acquire property.

C.  

Confirm with senior management and legal counsel concerning property acquisition.

D.  

Confirm ownership with the title company that handles the escrow account.

Discussion 0
Questions 136

An auditor reviews tender results for the procurement of construction equipment. Based on her significant experience the auditor believes that the obtained bid prices are too high. Which of the following is required to develop a relevant conclusion?

Options:

A.  

Description of the procurement policy

B.  

Summary of the tendering process

C.  

Substantiated and comparative evidence

D.  

Impact analysis of unfavorable prices

Discussion 0
Questions 137

Which of the following structures would best suit a maintenance organization that needs to adapt quickly to rapidly changing technology?

Options:

A.  

Traditional

B.  

Decentralized

C.  

Centralized

D.  

Customer-centric

Discussion 0
Questions 138

Which of the following is most appropriate for internal auditors to do during the internal audit recommendations monitoring process?

Options:

A.  

Report the monitoring status to senior management when requested.

B.  

Assist management with implementing corrective actions.

C.  

Determine the frequency and approach to monitoring.

D.  

Include all types of observations in the monitoring process.

Discussion 0
Questions 139

During a review of the treasury function an internal auditor identified a risk that all bank accounts may net to include in the daily reconciliation process.

Which of the following responses would be most effective to mitigate this risk?

Options:

A.  

The treasury supervisor establishes a threshold for amounts on bank statements to be reconciled against data in the system

B.  

The treasury analyst performs a daily reconciliation of al bank statements obtained via email against data in the system

C.  

The treasury analyst reviews a daily report automatically generated by the treasury system, which shows bank statements that have not been uploaded into the accounting system.

D.  

The treasury supervisor seeks an annual confirmation from the bank regarding the bank statements processed within a year

Discussion 0
Questions 140

Which of the following parties is accountable for ensuring adequate support for conclusions and opinions readied by the internal audit activity while relying on external auditors' work?

Options:

A.  

Board of directors

B.  

External auditors

C.  

Chief audit executive

D.  

Senior management

Discussion 0
Questions 141

An internal auditor is conducting an assurance engagement. One engagement objective is to evaluate the project manager’s effectiveness at controlling project costs. Which of the following audit tests should be included in the engagement program?

Options:

A.  

Prepare a bank reconciliation statement for all the bank accounts of the organization

B.  

Track a sample of project payments from accounts payable to concluded agreements and authorization rights

C.  

Validate the accuracy of assumptions and inputs used for calculations in the project’s feasibility model

D.  

Investigate whether the budget of the project was approved timely as required by internal policies

Discussion 0
Questions 142

Which of the following is a primary reason for an internal auditor to use a risk and control questionnaire when auditing financial processes?

Options:

A.  

To gain an understanding of the control environment

B.  

To collect as much financial data as possible before engagement fieldwork begins.

C.  

To test the effectiveness of financial controls in an efficient and relatively inexpensive way

D.  

To facilitate the quantification of financial data obtained

Discussion 0
Questions 143

A large retail organization, which sells most of its products online, experiences a computer hacking incident. The chief IT officer immediately investigates the incident and concludes that the attempt was not successful. The chief audit executive (CAE) learns of the attack in a casual conversation with an IT auditor. Which of the following actions should the CAE take?

1. Meet with the chief IT officer to discuss the report and control improvements that will be implemented as a result of the security breach, if any.

2. Immediately inform the chair of the audit committee of the security breach, because thus far only the chief IT officer is aware of the incident.

3. Meet with the IT auditor to develop an appropriate audit program to review the organization's Internet-based sales process and key controls.

4. Include the incident in the next quarterly report to the audit committee.

Options:

A.  

1 and 2

B.  

1 and 3

C.  

2 and 4

D.  

3 and 4

Discussion 0
Questions 144

An internal audit activity is planning its first audit of IT shared services. Which of the following controls would typically be evaluated first?

Options:

A.  

Entity-level controls

B.  

Application controls

C.  

General controls.

D.  

Transaction controls

Discussion 0
Questions 145

Which of the following engagement techniques would be best to meet the objective of denting a personal conflict -of -interest situation affecting an organization’s procurement function?

Options:

A.  

Inquiry

B.  

Analytical review

C.  

Observation

D.  

Inspection of documents

Discussion 0
Questions 146

During the filework phase of an assurance engagement the internal auditor decides that she wants to adjust the audit work program. Which of the following is the most appropriate next step for the auditor to take9

Options:

A.  

Request additional information needed from management of the area under review.

B.  

Obtain approval from the engagement supervisor

C.  

Obtain the required resources, including IT. to complete the work

D.  

Discuss the change in scope with management of the area under review.

Discussion 0
Questions 147

Which of the following is most likely to be considered a control weakness?

Options:

A.  

Vendor invoice payment requests are accompanied by a purchase order and receiving report.

B.  

Purchase orders are typed by the purchasing department using prenumbered forms

C.  

Buyers promptly update the official vendor listing as new supplier sources become known.

D.  

Department managers initiate purchase requests that must be approved by the plant superintendent

Discussion 0
Questions 148

To effectively communicate the acceptance of risk in an organization a chief audit executive must first consider which of the following?

Options:

A.  

The organization's view on risk tolerance

B.  

The organization's principal risk events.

C.  

The organization's risk response strategies

D.  

The organization's major control activities

Discussion 0
Questions 149

Which of the following statements is true regarding an organization’s inventory valuation?

Options:

A.  

The valuation will be incorrect if the inventory includes goods in transit shipped free on board (FOB) destination to another organization.

B.  

The valuation will be correct if the inventory includes goods received on consignment from another organization.

C.  

The valuation will be incorrect if the inventory includes goods in transit shipped FOB shipping point from another organization.

D.  

The valuation will be correct if the inventory includes goods sent on consignment to another organization

Discussion 0
Questions 150

Which of the following is an example of a properly supervised engagement?

Options:

A.  

Auditors are asked to keep a daily record of their activity for review by the auditor in charge following the engagement.

B.  

The senior internal auditor requires each auditor to review and initial colleagues’ workpapers for completeness and format

C.  

A new internal auditor is accompanied by an experienced auditor during a highly sensitive fraud investigation.

D.  

The auditor in charge provides reasonable assurance that engagement objectives were met

Discussion 0
Questions 151

The only internal auditor, who was part of a larger team of individuals trained in the testing and reading of the organization’s quality control equipment, has resigned. With a scheduled audit of the quality department not yet completed for this year, what alternative approach should the internal audit function take in this scenario?

Options:

A.  

Explain the situation to senior management and remove the audit from the audit plan until next year

B.  

Conduct the audit of the quality department but adjust the audit program to remove the quality control testing

C.  

Engage one of the other trained employees to participate in the audit review of the quality department

D.  

Request that external auditors include this area as part of their review and provide independent assurance

Discussion 0
Questions 152

According to IIA guidance, which of the following statements is true regarding audit workpapers?

Options:

A.  

Review notes on audit workpapers must be retained to provide a record of questions raised by the reviewer.

B.  

Audit workpaper documentation policies are reviewed and approved by the audit committee.

C.  

Management of the department being audited should review the prepared workpapers for accuracy.

D.  

Audit workpaper preparation contributes to the professional development of the internal audit staff.

Discussion 0
Questions 153

An internal audit function described scenarios of fraud indicators and fraud-related key words. The objective is for this data to serve as an input into algorithms that will forecast potentially fraudulent behavior and prevent the execution of flagged transactions. Which of the following analytic methods is the internal audit function most likely developing?

Options:

A.  

Diagnostic analytics

B.  

Descriptive analytics

C.  

Prescriptive analytics

D.  

Predictive analytics

Discussion 0
Questions 154

Which of the following is an example of a properly supervised engagement?

Options:

A.  

Auditors are asked to keep a daily record of their activity for review by the auditor in charge following the engagement.

B.  

The senior internal auditor requires each auditor to review and initial colleagues' workpapers for completeness and format.

C.  

A new internal auditor is accompanied by an experienced auditor during a highly sensitive fraud investigation.

D.  

The auditor in charge provides reasonable assurance that engagement objectives were met.

Discussion 0
Questions 155

With regard to project management, which of the following statements about project crashing is true?

Options:

A.  

It leads to an increase in risk and often results in rework.

B.  

It is an optimization technique where activities are performed in parallel rather than sequentially

C.  

It involves a revaluation of project requirements and/or scope.

D.  

It is a compression technique in which resources are added to the project

Discussion 0
Questions 156

During the planning phase of an assurance engagement, the internal audit engagement team identifies and evaluates the inherent fraud risks within the procurement function. What should be the engagement team’s next step?

Options:

A.  

Identify and map existing controls to their relevant inherent fraud risks

B.  

Detect fraudulent activities in the activity under review for the audited period

C.  

Select the appetite level for each inherent fraud risk

D.  

Evaluate and respond to residual fraud risks that need to be mitigated

Discussion 0
Questions 157

Internal auditors map a process by documenting the steps in the process, which provides a framework for understanding. Which of the following is a reason to use narrative memoranda?

Options:

A.  

To create a detailed risk assessment.

B.  

To identify individuals who perform key roles.

C.  

To explain a simple process.

D.  

To document which outputs support other activities.

Discussion 0
Questions 158

An internal auditor is conducting a preliminary survey of the investments area, and sends an internal control questionnaire to the management of the function. (An extract of the survey is provided below).

1. Are there any restrictions for any company's investments?

2. Are there any written policies and procedures that document the flow of investment processing?

3. Are investment purchases recorded in the general ledger on the date traded?

4. Is the documentation easily accessible to an persons who need in to perform their job?

Which of the following is a drawback of testing methods like this?

Options:

A.  

They ore kitted as they do not allow the auditor to test many controls.

B.  

They do not highlight control gaps

C.  

They are not useful for identifying areas on which the auditor should locus.

D.  

They are limited as there is a risk that management may not answer fairly.

Discussion 0
Questions 159

An organization facing financial hardships is planning to reduce its internal audit function size without a reduction in workload. The organization plans to aid internal auditors by providing a generative artificial intelligence application that will process written responses from the activity under review to identify high-risk areas on which the remaining auditors will concentrate. Which of the following would be the most significant concern in this process?

Options:

A.  

Slight variations in answers can result in very different risk assessments

B.  

Generative artificial intelligence cannot make inferences out of free text responses

C.  

Replacing auditor judgment with machine judgment is contrary to the Global Internal Audit Standards

D.  

Poor acceptance of the new system by the activity under review will impact engagement outcomes

Discussion 0
Questions 160

Which of the following represents a ratio that measures short term debt-paying ability?

Options:

A.  

Debt-to-equity ratio.

B.  

Profit margin.

C.  

Current ratio.

D.  

Times interest earned.

Discussion 0
Questions 161

While auditing an organization's credit approval process, an internal auditor learns that the organization has made a large loan to another auditors relative. Which course of action should the auditor take?

Options:

A.  

Proceed with the audit engagement, but do not include the relative's information.

B.  

Have the chief audit executive and management determine whether the auditor should continue with the audit engagement.

C.  

Disclose in the engagement final communication that the relative Is a customer

D.  

Immediately withdraw from the audit engagement

Discussion 0
Questions 162

Which of the following would most likely be found in an organization that uses a decentralized organizational structure?

Options:

A.  

There is a higher reliance on organizational culture

B.  

There are clear expectations set for employees.

C.  

There are electronic monitoring techniques employed

D.  

There is a defined code for employee behavior

Discussion 0
Questions 163

Options:

A.  

The organization’s attitude to hierarchy.

B.  

The organization's whistleblowing strategy.

C.  

The organization’s ongoing risk monitoring process.

D.  

The organization’s risk management policy.

Discussion 0
Questions 164

A bakery chain has a statistical model that can be used to predict daily sales at individual stores based on a direct relationship to the cost of ingredients used and an inverse relationship to rainy days What conditions would an auditor look for as an Indicator of employee theft of food from a specific store?

Options:

A.  

On a rainy day. total sales are greater than expected when compared to the cost of ingredients used

B.  

On a sunny day. total sales are less than expected when compared to the cost of ingredients used.

C.  

Both total sales and cost of ingredients used are greater than expected.

D.  

Both total sales and cost of ingredients used are less than expected.

Discussion 0
Questions 165

According to IIA guidance, which of the following statements are true regarding the internal audit plan?

1. The audit plan is based on an assessment of risks to the organization.

2. The audit plan is designed to determine the effectiveness of the organization's risk management process.

3. The audit plan is developed by senior management of the organization.

4. The audit plan is aligned with the organization's goals.

Options:

A.  

1 and 2 only

B.  

3 and 4 only

C.  

1, 2, and 4

D.  

1, 3, and 4

Discussion 0
Questions 166

Which of the following resources would be most effective for an organization that would like to improve how it informs stakeholders of its social responsibility performance?

Options:

A.  

ISO 26000

B.  

Global Reporting Initiative.

C.  

Open Compliance and Ethics Group.

D.  

COSO’s enterprise risk management framework.

Discussion 0
Questions 167

According to the Standards, which of the following is leastimportant in determining the adequacy of an annual audit plan?

Options:

A.  

Sufficiency.

B.  

Appropriateness.

C.  

Effective deployment.

D.  

Cost effectiveness.

Discussion 0
Questions 168

Which of the following is a true statement regarding the use of flowcharts as an audit tool?

Options:

A.  

Flowcharts are typically not well suited to support information provided by a risk and control matrix.

B.  

Flowcharts are preferred to narratives, as they can provide much greater detail on the design and operation of a process.

C.  

Flowcharts are best applied to linear process flows but cannot address all risks related to the process.

D.  

Flowcharts describe process steps but cannot provide the level of detail needed to adequately assess the design of the process.

Discussion 0
Questions 169

Which of the following factors would the auditor in charge be least likely to consider when assigning tasks to audit team members for an engagement?

Options:

A.  

The amount of experience the auditors have conducting audits in the specific area of the organization.

B.  

The availability of the auditors in relation to the availability of key client staff.

C.  

Whether the budgeted hours are sufficient to complete the audit within the current scope.

D.  

Whether outside resources will be needed, and their availability.

Discussion 0
Questions 170

A chief audit executive (CAE) received a detailed internal report of senior management's internal control assessment. Which of the following subsequent actions by the CAE would provide the greatest assurance over management's assertions?

Options:

A.  

Assert whether the described and reported control processes and systems exist.

B.  

Assess whether senior management adequately supports and promotes the internal control culture described in the report.

C.  

Evaluate the completeness of the report and management's responses to identified deficiencies.

D.  

Determine whether management's operating style and the philosophy described in the report reflect the effective functioning of internal controls.

Discussion 0
Questions 171

An internal auditor is starting the fieldwork of an assurance engagement. The auditor will conduct a walkthrough of selected controls with control owners. What should be the primary objective of this walkthrough?

Options:

A.  

Collect the policies and procedures relevant to the audited area

B.  

Understand the financial results published for the period under review

C.  

Assess the design of the internal controls in place

D.  

Define the objectives of the assurance engagement

Discussion 0
Questions 172

Which of the following is the most important concept to be included in a consulting engagement agreement?

Options:

A.  

Define the duties and responsibilities needed from management to perform the engagement.

B.  

Disclose the fact that auditors who perform the work may not be subject matter experts in the topic of the review.

C.  

Clarify that matters discovered during the engagement may also be reported to senior management and the audit committee.

D.  

Disclose the fact that follow-up reviews may be conducted to ensure that recommendations are implemented adequately.

Discussion 0
Questions 173

In the years after the mid-service point of a depreciable asset, which of the following depreciation methods will result in the highest depreciation expense?

Options:

A.  

Sum of the years’ digits.

B.  

Declining balance.

C.  

Double-declining balance.

D.  

Straight line.

Discussion 0
Questions 174

An internal auditor accessed accounts payable records and extracted data related to fuel purchased tor the organization's vehicles As a first step, she sorted the data by vehicle and used spreadsheet functions to identify all instances of refueling on the same or sequential dates She then performed other tests Based on the auditor's actions which of the following is most likely the objective of this engagement1?

Options:

A.  

To identify whether fuel was purchased for work-related purposes

B.  

To estimate future fuel costs for the organization's fleet of vehicles

C.  

To determine trends in average fuel consumption by vehicle

D.  

To determine whether the organization is paying more than the industry average for fuel

Discussion 0
Questions 175

Which of the following situations is most critical for the chief audit executive to report to the board?

Options:

A.  

The chief audit executive disagreed with the business unit manager's initial decision to accept a particular risk Management ultimately agreed to address the risk only after discussing the issue with senior management.

B.  

The internal audit activity was restructured, which resulted in a significant change in responsibilities among audit managers and supervisors for some audits

C.  

A staff internal auditor had difficulties completing a portion of the audit because management of the area under review was unwilling to cooperate and provide information timely.

D.  

The resignation of an internal audit manager during the year caused the chief audit executive to defer a number of audit engagements to the following year.

Discussion 0
Questions 176

Due to emerging new technologies that greatly affect the organization, the chief audit executive (CAE) wants to conduct frequent IT audit and is particularly focused on improving the quality of these engagements. Which of the following is the most viable solution for the CAE to ensure that IT audit quality is immediately enhanced and maintained long-term?

Options:

A.  

Each year send a different member of the internal audit staff to an IT audit conference to learn about emerging technologies

B.  

Contract an external IT special to offer advice and consult on IT audits

C.  

Employ an independent external IT specialist to perform IT audits for the first year

D.  

Invite qualified staff from the IT department to serve as guest auditors and lead IT audits

Discussion 0
Questions 177

Which of the following is the most appropriate reason for a chief audit executive to conduct an external assessment more frequently than five years?

Options:

A.  

Significant changes in the organization's accounting policies or procedures would warrant timely analysis and feedback.

B.  

More frequent external assessments can serve as an equivalent substitute for internal assessments.

C.  

The parent organization's internal audit activity agreed to perform biennial reciprocal external assessments to provide greater assurance at a reduced cost.

D.  

A change in senior management or internal audit leadership may change expectations and commitment to conformance

Discussion 0
Questions 178

According to IIA guidance, which of the following statements about analytical procedures is true?

Options:

A.  

Analytical procedures compare information against expectations

B.  

Analytical procedures begin after the engagements planning phase.

C.  

Analytical procedures provide internal auditors with explainable results.

D.  

Analytical procedures are computer-assisted audit techniques

Discussion 0
Questions 179

Which of the following best describes the four components of a balanced scorecard?

Options:

A.  

Customers, innovation, growth, and internal processes.

B.  

Business objectives, critical success factors, innovation, and growth.

C.  

Customers, support, critical success factors, and learning.

D.  

Financial measures, learning and growth, customers, and internal processes.

Discussion 0
Questions 180

Which of the following statements is true regarding the chief audit executive's (CAT$) responsibilities after completing an assurance or consulting engagement?

Options:

A.  

The CAE must establish a follow-up process tor both assurance and consulting engagements to monitor that management actions have been effectively implemented to address observations

B.  

The CAE must communicate the results of assurance and consulting engagements lo whoever can ensure that the results are given due consideration.

C.  

The CAE must acknowledge satisfactory performance when communicating the results of assurance and consulting engagements

D.  

The CAE may delegate the responsibility for communicating the results of consulting engagements although this responsibility cannot be delegated for assurance engagements

Discussion 0
Questions 181

Which of the following is a disadvantage of using flowcharts during a risk assessment?

Options:

A.  

People cannot quickly understand the processes via flowcharts

B.  

Flowcharts are not applicable for evaluating the design of controls

C.  

Some serious risks that are not part of the linear process can be missed

D.  

Flowcharts do not enable auditors to identify missing controls

Discussion 0
Questions 182

Which of the following is essential for ensuring that the internal audit activity's findings and recommendations receive adequate consideration?

Options:

A.  

Reporting results of audits with recommendations to management.

B.  

Providing formal follow-up procedures to ensure that management complies with an action plan or accepted risk of not taking action.

C.  

Reporting quarterly to management that the audit plan is focused on higher exposures of risk.

D.  

Discussing audit findings with independent auditors.

Discussion 0
Questions 183

During an audit of the human resources department, an internal auditor adopts benchmarking to test the employee turnover rate. How should the internal auditor apply this technique?

Options:

A.  

Compare turnover m the organization to published turnover rates of peer organizations.

B.  

Compare turnover in one period with turnover in the previous period in the organization

C.  

Compare turnover in the period to total employees in the organization

D.  

Compare turnover with the auditor's general knowledge of the organization

Discussion 0
Questions 184

An internal auditor discovered that sales contracts with business clients were not stored in the electronic document management database instead they were scanned and saved in a nonsystematic manner to server folders Which of the following would be an appropriate consequence for the internal auditor to include in the documented observation?

Options:

A.  

The document management policy requires business client data to be stored in a specific management database

B.  

Sales contracts were stored improperly because the office manager was not trained to use the electronic database and prefers to avoid it

C.  

if the organization becomes subject to litigation the agreed pricing terms and conditions of the contracts may be difficult to prove

D.  

All staff should be appropriately trained and required to follow the organization's established policies and procedures pertaining to document management

Discussion 0
Questions 185

An internal auditor selects a sample of paid invoices and matches them to receiving reports. What is the most likely purpose for this procedure?

Options:

A.  

To ensure all customer shipments are billed appropriately.

B.  

To ensure invoices are only paid for goods received.

C.  

To ensure all liabilities have been satisfied.

D.  

To ensure invoices are only paid for goods ordered.

Discussion 0
Questions 186

An internal auditor of a construction organization found that completed inspection results, required by the organization's policy, were missing from the computer system. Which of the following, if included in the audit report, would demonstrate that the auditor performed a root cause analysis of this observation?

Options:

A.  

Some inspection results were missing from the computer system.

B.  

The results of lengthy inspections were more likely to be omitted from the computer system.

C.  

Flaws in the computer system prevented employees from saving their inspection results.

D.  

Employees did not ensure that inspection results were completed in the computer system.

Discussion 0
Questions 187

The internal audit activity has requested that new vendor information be summarized once per week in a single report, and that all invoices each week for these vendors be automatically flagged in the invoice processing system. Which of the following computerized audit techniques is the internal audit activity most likely applying?

Options:

A.  

Enabling continuous auditing.

B.  

Employing generalized audit software.

C.  

Facilitating electronic workpapers.

D.  

Using machine learning.

Discussion 0
Questions 188

Which of the following statements about including consulting engagements in the annual internal audit plan is true?

Options:

A.  

All requests for consulting engagements must be included in the annual internal audit plan

B.  

Assurance engagements must be included in the annual internal audit plan but there is no requirement to include consulting engagements

C.  

Consulting engagements do not need to be included m the annual internal audit plan unless requested by the board

D.  

The acceptance of proposed consulting engagements into the annual internal audit plan may depend on their ability to add value

Discussion 0
Questions 189

Which of the following should an internal auditor document to support an assurance engagement’s conclusions?

Options:

A.  

Evidence of all data used in an engagement

B.  

Internal audit policies and workpaper templates

C.  

Workpapers, cross-referenced to audit observations

D.  

Satisfaction ratings from management of the area under review

Discussion 0
Questions 190

Which of the following is true about surveys?

Options:

A.  

A survey with open-ended questions is weaker than a structured interview

B.  

A survey with closed-ended questions can produce quantifiable evidence

C.  

A survey's participants are likely to volunteer information that was not specifically requested

D.  

A survey, like inspections and confirmations are best used to test the operating effectiveness of controls

Discussion 0
Questions 191

In which of the following populations would the internal auditor most likely choose to use a stratified sampling approach?

Options:

A.  

Inventory comprised of the same items stored in different warehouses

B.  

Batches of materials that must be confirmed as meeting quality standards

C.  

Revenue that is earned by an organization through cash receipts or as receivable.

D.  

Tax reports submitted to meet the requirements of the local taxation authority

Discussion 0
Questions 192

Which of the following statements accurately describes the Standards requirement for ret internal audit records?

Options:

A.  

Retention requirements for internal audit records should be compliant with ones set for external audit records

B.  

Retention requirements should take into account the medium in which internal audit records are stored

C.  

Retention requirements should be set by the chief audit executive and aligned will the organization s process and procedures

D.  

Retention requirements should set a minimum period of the for records storage and the process of archiving documents

Discussion 0
Questions 193

Which of the following factors would be the most critical in determining which engagements should be included in the annual internal audit plan?

Options:

A.  

Whether an audit is explicitly required by the internal audit charter

B.  

The extent to which the work to be performed is an assurance or consulting engagement

C.  

The organization's annual risk management strategy

D.  

Risks that are identified by operations staff or senior management

Discussion 0
Questions 194

The audit manager asked the internal auditor to perform additional testing because several irregularities were found in the financial information. Which of the following would be the most appropriate analytical review for the auditor to perform?

Options:

A.  

Compare the firm's financial performance with organizations in the same industry

B.  

Interview all managers involved in preparing the financial statements

C.  

Perform a bank reconciliation to confirm the cash balance in the financial statements.

D.  

Trace each financial transaction to the original supporting document

Discussion 0
Questions 195

Which of the following would present the most critical external risk to an organization?

Options:

A.  

The organization experiences a merger, and the management team is reorganized and redistributed globally

B.  

The organization launches a product into new global markets

C.  

After minimal testing, the organization implements a new system to replace a legacy system

D.  

Regulators announce broad legislative reforms applicable to the industry within which the organization operates

Discussion 0
Questions 196

During a consulting engagement an internal auditor wants to determine whether all principal stakeholders are involved in a project. Which tool should the auditor use?

Options:

A.  

RACI (responsible, accountable, consult and inform) chart

B.  

Flowchart

C.  

SWOT{strengths. weaknesses opportunities, and threats) analysis

D.  

Workflow analysis

Discussion 0
Questions 197

An internal auditor is preparing for an auditor of newly implemented software that is used by 3,000 employees in South America and Europe. What would be the best way for the auditor to gather relevant feedback?

Options:

A.  

interview IT management in both regions

B.  

Inspect regional user software training records

C.  

Interview propel management and the vendor responsible for implementation

D.  

Distribute surveys to software users in both regions

Discussion 0
Questions 198

According to IIA guidance, which of the following is least likely to be a key financial control in an organization's accounts payable process?

Options:

A.  

Require the approval of additions and changes to the vendor master listing, where the inherent risk of false vendors is high.

B.  

Monitor amounts paid each period and compare them to the budget to identify potential issues.

C.  

Compare employee addresses to vendor addresses to identify potential employee fraud.

D.  

Monitor customer quality complaints compared to the prior period to identify vendor issues.

Discussion 0
Questions 199

Which of the following statements is true regarding the use of internal control questionnaires (ICOs)?

Options:

A.  

ICQs are efficient because they minimize the need for follow-up with survey respondents

B.  

Controls with positive survey responses can be eliminated from further testing

C.  

Answers to survey questions can be easily misinterpreted

D.  

ICQs offer limited value for organizations with uniform procedures

Discussion 0
Questions 200

After completing an assurance engagement, the chief audit executive (CAE) concludes that management has accepted a level of risk that may be unacceptable to the

organization. What is the most appropriate first step for the CAE to take?

Options:

A.  

Discuss the issue with senior management.

B.  

Discuss the issue only with the CEO.

C.  

Inform the board.

D.  

Discuss the issue with the members of management responsible for the risk area.

Discussion 0
Questions 201

Which of the following best describes how an internal auditor would use a flowchart during engagement planning?

Options:

A.  

To prepare for testing the effectiveness of controls

B.  

To plan for evaluating potential losses

C.  

To prepare a sampling plan for the engagement

D.  

To evaluate the design of controls

Discussion 0
Questions 202

The audit plan of an internal audit function includes an assurance engagement of the organization’s cybersecurity protocols. However, the engagement supervisor assigned to execute the engagement identifies that the internal auditors with competencies in cybersecurity are scheduled for upcoming leave and are involved in other engagements. Those auditors would not be available to participate in the cybersecurity engagement. Which of the following would be the appropriate action for the engagement supervisor?

Options:

A.  

Reassign the competent auditors immediately.

B.  

Notify the board that the cybersecurity engagement cannot be performed due to a lack of competent resources.

C.  

Suspend the cybersecurity engagement due to the lack of internal auditors with relevant competencies.

D.  

Seek advice from the chief audit executive on appropriate actions related to the cybersecurity engagement.

Discussion 0
Questions 203

A manager has allowed a subordinate employee to have greater control and responsibility over the tasks that he performs This is an example of which of the following?

Options:

A.  

Job enlargement

B.  

Job enrichment

C.  

Horizontal loading of the job.

D.  

Job rotation.

Discussion 0
Questions 204

An internal audit team was conducting an assurance engagement to review segregation of duties in the purchasing function. The internal auditors reviewed a sample of purchase orders from the past two year and discovered that 2 percent were signed by employees who were operating in a designated acting capacity due to employee absence. According to IIA guidance, which of the following attributes of information would most likely assist the auditor in deciding whether to report this finding?

Options:

A.  

Sufficiency

B.  

Reliability

C.  

Relevance

D.  

Usefulness

Discussion 0
Questions 205

According to IIA guidance, which of re following actions should the internal auditor take immediately after having considered fraud scenarios and identified and prioritized fraud risks?

Options:

A.  

Determine which controls if any are in place to mitigate the fraud risks

B.  

Follow protocol for internal reporting and investigating fraud allegations

C.  

Research frauds that nave occurred t\ similar organizations

D.  

Incorporate the fraud risk assessment into the engagement plan

Discussion 0
Questions 206

An accounts payable clerk has recently transferred into the internal audit activity and has been assigned to an engagement related to accounts payable processes for which he was previously responsible Which of the following is the best action for the new internal auditor to take?

Options:

A.  

If it is an assurance engagement, accept the assignment because direct knowledge of the existing accounts payable processes will provide depth and add more value

B.  

If it is a consulting engagement, decline the assignment and ask to be reassigned, because in a consulting engagement the auditor must not assess operations for areas in which they were previously responsible.

C.  

if it is a consulting engagement, accept the assignment because direct knowledge of the existing accounts payable processes will provide depth and add more value

D.  

If it is an assurance engagement, accept the assignment because the chief audit executive had knowledge of the internal auditor's previous role when this engagement was assigned.

Discussion 0
Questions 207

Which of the following steps should an internal auditor complete when conducting a review of an electronic data interchange application provided by a third-party service?

Ensure encryption keys meet ISO standards.

Determine whether an independent review of the service provider's operation has been conducted.

Verify that the service provider’s contracts include necessary clauses.

Verify that only public-switched data networks are used by the service provider.

Options:

A.  

1 and 3.

B.  

1 and 4.

C.  

2 and 3.

D.  

2 and 4.

Discussion 0
Questions 208

According to IIA guidance, which of the following is true regarding the exit conference for an internal audit engagement?

Options:

A.  

A primary purpose of the exit conference is to provide for the timely communication of observations that call for immediate management action.

B.  

Both the chief audit executive and the chief executive over the activity or function reviewed must attend the exit conference to validate the findings.

C.  

The exit conference provides only anticipated results for inclusion in the final audit communication.

D.  

During the exit conference, the performance of the internal auditors who executed the engagement is reviewed.

Discussion 0
Questions 209

Which of the following best describes the internal audit activity's responsibility within a risk and control framework?

Options:

A.  

The internal audit activity constitutes the first line of defense in effective risk management.

B.  

The internal audit activity provides direction regarding internal controls implementation.

C.  

The internal audit activity verifies that management has met its responsibility for implementing effective controls.

D.  

The internal audit activity implements the internal control framework and advises management regarding best practices

Discussion 0
Questions 210

A company makes a product at a cost of $26 per unit, of which $10 is fixed cost. The product is usually sold for $30 per unit; however, the company has been approached by a new customer who would like to purchase 3,500 units for $18 each Further, the company would Incur additional cost to deliver the units to this customer If the company has the excess manufacturing capacity and all other factors are constant, what is the additional cost that the company would Incur in order to make a profit of $1.50 per unit for this order?

Options:

A.  

$0.50

B.  

$1.50

C.  

$2 50

D.  

$3.50

Discussion 0
Questions 211

Organizations that adopt just-in-time purchasing systems often experience which of the following?

Options:

A.  

A slight increase in carrying costs.

B.  

A greater need for inspection of goods as the goods arrive

C.  

A greater need for linkage with a vendors computerized order entry system.

D.  

An Increase in the number of suitable suppliers

Discussion 0
Questions 212

Senior management is challenging regulatory fines that were assessed to the organization due to questionable business practices. Their actions and the fines could have an adverse effect on the organization's ability to continue business. How would the chief audit executive respond?

Options:

A.  

Assume responsibility for quantifying and minimizing the residual risks to the organization.

B.  

Assess the level of financial risks that may affect the organization's stability.

C.  

Inform the regulatory agency about senior management's action and seek guidance.

D.  

Proceed with a consulting engagement to benchmark similar organizations' business practices in the region.

Discussion 0
Questions 213

An audit observation states the following:

"Despite the rules of the organization there is no approved credit risk management policy in the subsidiary. The subsidiary is concluding contacts with clients who have very high credit ratings. The internal audit team tested 50 contacts and 17 showed clients with a poor credit history"

Which of the following components are missing in the observation?

Options:

A.  

Cause and effect.

B.  

Effect and criteria

C.  

Condition and cause

D.  

Criteria and condition.

Discussion 0
Questions 214

An internal auditor is testing the success of the IT support department in meeting the service levels guaranteed to small, medium and large customers. The customer's size classification is based on its annual expenditures with the organization and the nature and extent of services it receives. Which of the following sampling techniques would be the most suitable to select customers for this test?

Options:

A.  

Interval sampling

B.  

Cluster sampling

C.  

Stop-and-go sampling

D.  

Stratified sampling

Discussion 0
Questions 215

Which of the following data analysis techniques is used to identify inappropriately matching values, such as names, addresses, and account numbers in disparate systems?

Options:

A.  

Stratification of numeric values

B.  

Gap testing

C.  

Joining different data sources

D.  

Duplicate testing

Discussion 0
Questions 216

Which of the following is critical to the success of an effective interview?

Options:

A.  

Present audit evidence and information to support the internal auditor’s line of questioning.

B.  

Establish credibility, trust, and rapport.

C.  

Develop flowcharts and review them with the interviewee.

D.  

Observe the process and discuss it with the interviewee.

Discussion 0
Questions 217

Which of the following represents the best example of a strategic goal?

Options:

A.  

Customer satisfaction index has to be 90% each quarter.

B.  

Ten rapid charging stations will be installed next year.

C.  

The organization aims to decrease the budget by 10%.

D.  

The organization will be carbon neutral within 5 years.

Discussion 0
Questions 218

A chief audit executive (CAE) is determining which engagements to include on the annual audit plan. She would like to consider the organization's attitude toward risk and the degree of difficulty in achieving objectives. Which of the following resources should the CAE consult?

Options:

A.  

The corporate risk register.

B.  

The strategic plan.

C.  

Internal and external audit reports.

D.  

The board's meeting records.

Discussion 0
Questions 219

The chief audit executive can illustrate the value of the internal audit activity by reporting which of the following to the board?

Options:

A.  

The overall performance resulting from the internal audit balanced scorecard

B.  

The number of outstanding and overdue management actions

C.  

The experience of the organization's internal auditors

D.  

The number of audits in the annual audit plan relative to similar organizations

Discussion 0
Questions 220

Which of the following offers the best explanation of why the auditor in charge would assign a junior auditor to complete a complex part of the audit engagement?

Options:

A.  

The senior auditors are unavailable, as they are currently working on other portions of the engagement

B.  

The auditor in charge believes that the junior auditor should obtain a specific type of experience.

C.  

The audit engagement has a tight deadline and the work must be completed timely.

D.  

The auditor in charge is unable to identify audit staff with all of the required skills needed to complete the engagement

Discussion 0
Questions 221

Which of the following statements about assurance maps is correct?

Options:

A.  

An assurance map is used by the chief audit executive to coordinate assurance activities with other internal and external assurance providers

B.  

An assurance map is a picture of all assurance engagements performed by the internal audit activity across the organization

C.  

An assurance map is used by the engagement supervisor to coordinate the roles of various internal audit team members assigned to assurance engagements

D.  

An assurance map lists the procedures and testing activities performed by an internal audit team during an assurance engagement

Discussion 0
Questions 222

At a construction company, an internal auditor is planning an audit of the company's process for designing and building grid connections The process involves customers making payments m three parts

• The first payment of 10% after approval of the customer s application

• The second payment of 70% prior to construction

• The third payment of 20% after construction is complete

Which of the following key controls should the auditor test to ensure that the company is not taking any unwanted credit risks?

Options:

A.  

Controls that ensure that grid connection design is finalized before construction is approved to begin

B.  

Controls that ensure construction orders are initiated after the second invoice is paid

C.  

Controls that ensure all three invoices are calculated correctly according to the total project cost

D.  

Controls that ensure that applications are verified for approval prior to initiating design and construction

Discussion 0
Questions 223

Which of the following should be described in the recognition element of a typical internal audit repot?

Options:

A.  

Positive aspects of the process or area under review

B.  

A brief synopsis of the process of area under review

C.  

Outcomes and ratings of the process or area under review

D.  

Report issuance and the communication process of the engagement.

Discussion 0
Questions 224

Which method of examining entity-level controls involves gathering information from work groups that represent different levels in an organization?

Options:

A.  

Questionnaires.

B.  

Surveys.

C.  

Structured interviews

D.  

Facilitated team workshops

Discussion 0