Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Internal Audit Engagement Question and Answers

Internal Audit Engagement

Last Update Jul 26, 2026
Total Questions : 747

We are offering FREE IIA-CIA-Part2 IIA exam questions. All you do is to just go and sign up. Give your details, prepare IIA-CIA-Part2 free exam questions and then go for complete pool of Internal Audit Engagement test questions that will help you more.

IIA-CIA-Part2 pdf

IIA-CIA-Part2 PDF

$36.75  $104.99
IIA-CIA-Part2 Engine

IIA-CIA-Part2 Testing Engine

$43.75  $124.99
IIA-CIA-Part2 PDF + Engine

IIA-CIA-Part2 PDF + Testing Engine

$57.75  $164.99
Questions 1

According to IIA guidance, which of the following individuals should receive the final audit report on a compliance engagement for the organization ' s cash disbursements process?

Options:

A.  

The accounts payable supervisor, accounts payable manager, and controller.

B.  

The accounts payable manager, purchasing manager, and receiving manager.

C.  

The accounts payable supervisor, controller, and treasurer.

D.  

The accounts payable manager, chief financial officer, and audit committee.

Discussion 0
Questions 2

A newly appointed chief audit executive (CAE) of a small organization is developing a resource management plan Which of the following approaches would be most beneficial to help the CAE obtain details of the Internal audit activity ' s collective knowledge skills, and other competencies?

Options:

A.  

Review or establish a documented skills assessment of the internal audit staff and gather information from post-audit surveys

B.  

Obtain from the human resources department the job descriptions and position requirements for all internal audit staff

C.  

Conduct an objective written test of the internal audit staff to assess their knowledge and skills related to core internal audit competencies

D.  

Request the internal audit staff to submit a document that summarizes their most recent performance appraisals and post audit reviews

Discussion 0
Questions 3

The board has asked the internal audit activity (IAA) to be involved in the organization ' s enterprise risk management process. Which of the following activities is appropriate for IAA to perform without safeguards?

Options:

A.  

Coach management in responding to risks.

B.  

Develop risk management strategies for board approval.

C.  

Facilitate identification and evaluation of risks.

D.  

Evaluate risk management processes.

Discussion 0
Questions 4

A newly appointed chief audit executive (CAE) of a small organization is developing a resource management plan. Which of the following approaches would be most beneficial to help the CAE obtain details of the internal audit activity ' s collective knowledge, skills, and other competencies?

Options:

A.  

Review or establish a documented skills assessment of the internal audit staff and gather information from post-audit surveys.

B.  

Obtain from the human resources department the job descriptions and position requirements for all internal audit staff.

C.  

Conduct an objective written test of the internal audit staff to assess their knowledge and skills related to core internal audit competencies.

D.  

Request the internal audit staff to submit a document that summarizes their most recent performance appraisals and post audit reviews.

Discussion 0
Questions 5

Internal auditors map a process by documenting the steps in the process, which provides a framework for understanding. Which of the following is a reason to use narrative memoranda?

Options:

A.  

To create a detailed risk assessment.

B.  

To identify individuals who perform key roles.

C.  

To explain a simple process.

D.  

To document which outputs support other activities.

Discussion 0
Questions 6

An internal auditor is examining the organization ' s internal control processes. Which of the following would the auditor do to test the reliability of a customer database1?

Options:

A.  

Perform a site visit to see whether the organization ' s servers are operational

B.  

Interview end users to determine whether they understand how to use the database information

C.  

Determine whether policies are in place on how to use the database information

D.  

Review for indications of potential issues with the database information

Discussion 0
Questions 7

Which of the following recommendations made by the internal audit activity (IAA) is most likely to help prevent fraud?

Options:

A.  

A review of password policy compliance found that employees frequently use the same password more than once during a year. The IAA recommends that the access control software reject any password used more than once during a 12-month period.

B.  

A review of internal service-level agreement compliance in financial services found that requests for information frequently are fulfilled up to two weeks late. The IAA recommends that the financial services unit be eliminated for its ineffectiveness.

C.  

A vacation policy compliance review found that employees frequently leave on vacation before their leave applications are signed by their manager. The IAA recommends that the manager attend to the leave applications in a more timely fashion.

D.  

A review of customer service-level agreements found that orders to several customers are frequently delivered late. The IAA recommends that the organization extend the expected delivery time advertised on its website.

Discussion 0
Questions 8

At the conclusion of a quality assurance review, the chief audit executive (CAE) was informed that several audits included incomplete workpapers, and some workpapers were not completed within the established timeframe. How should the CAE address the issue of incomplete workpapers?

Options:

A.  

Delete incomplete workpapers from the audit folder.

B.  

Establish a task force to complete workpapers for audits that are contested.

C.  

Develop guidelines and procedures for completing workpapers.

D.  

Verify that the workpapers that support audit findings are complete; if so, no further action is required.

Discussion 0
Questions 9

An internal audit intends to create a risk and control matrix to better understand the organization ' s complex manufacturing process. With which of the following approaches would the auditor most likely start?

Options:

A.  

Assess management responses to key risk exposures

B.  

Analyze the costs and benefits of key controls

C.  

Evaluate the design adequacy of known controls

D.  

Conduct a walk-through of all related activates

Discussion 0
Questions 10

During an assurance engagement an internal auditor uses benchmarking research to support preparation of a report to stakeholders that contains significant findings about control deficiencies. Which of the following skills did the auditor demonstrate?

Options:

A.  

Internal audit management

B.  

Conflict negotiation.

C.  

Critical thinking

D.  

Persuasion and collaboration

Discussion 0
Questions 11

Which of the following is essential for ensuring that the internal audit activity ' s findings and recommendations receive adequate consideration?

Options:

A.  

Reporting results of audits with recommendations to management.

B.  

Providing formal follow-up procedures to ensure that management complies with an action plan or accepted risk of not taking action.

C.  

Reporting quarterly to management that the audit plan is focused on higher exposures of risk.

D.  

Discussing audit findings with independent auditors.

Discussion 0
Questions 12

An organization ' s internal audit plan includes a recurring assurance review of the human resources (HR) department. Which of the following statements is true regarding preliminary communication between the auditor in charge (AIC) and the HR department?

1. The AIC should notify HR management when the draft audit plan is being developed, as a courtesy.

2. The AIC should notify HR management before the planning stage begins.

3. The AIC should schedule formal status meetings with HR management at the start of the engagement.

4. The AIC should finalize the scope of the engagement before communicating with HR management.

Options:

A.  

1 and 3

B.  

1 and 4

C.  

2 and 3

D.  

2 and 4

Discussion 0
Questions 13

Which of the following should be included in a privacy audit engagement?

1. Assess the appropriateness of the information gathered.

2. Review the methods used to collect information.

3. Consider whether the information collected is in compliance with applicable laws.

4. Determine how the information is stored.

Options:

A.  

1 and 3 only

B.  

2 and 4 only

C.  

1, 3, and 4 only

D.  

1, 2, 3, and 4

Discussion 0
Questions 14

An internal auditor discovered fraud while performing an audit of an organization ' s procurement process. Which of the following describes the greatest benefit of using forensic auditing techniques in this scenario?

Options:

A.  

Enhanced capability to prevent frauds from occurring.

B.  

Greater assurance that procurement frauds will be detected in a timely manner

C.  

Improved capability of evaluating fraud risks within the organization.

D.  

Greater understanding of fraud through better evidence collection

Discussion 0
Questions 15

An organization uses the management-by-objectives method, whereby employee performance is based on defined goals. Which of the following statements is true regarding this approach?

Options:

A.  

It is particularly helpful to management when the organization is facing rapid change.

B.  

It is a more successful approach when adopted by mechanistic organizations.

C.  

it is more successful when goal-setting Is performed not only by management, but by all team members, including lower-level staff

D.  

it is particularly successful in environments that are prone to having poor employer-employee relations

Discussion 0
Questions 16

How do internal auditors generally determine the priority of the areas within the engagement scope?

Options:

A.  

By calculating the period of time when the area was last audited try internal auditors

B.  

By totaling the monetary value of the processes within the organization in the scope of the engagement

C.  

By counting the number of red flags indicating the potential fraudulent activities within the area.

D.  

By estimating the likelihood of a risks occurring and the potential impact of that risk on the organization

Discussion 0
Questions 17

Which of the following is the most important concept to be included in a consulting engagement agreement?

Options:

A.  

Define the duties and responsibilities needed from management to perform the engagement.

B.  

Disclose the fact that auditors who perform the work may not be subject matter experts in the topic of the review.

C.  

Clarify that matters discovered during the engagement may also be reported to senior management and the audit committee.

D.  

Disclose the fact that follow-up reviews may be conducted to ensure that recommendations are implemented adequately.

Discussion 0
Questions 18

An internal auditor has been assigned to facilitate a risk and control self-assessment for the finance group. Which of the following is the most appropriate role that she should assume when facilitating the workshop?

Options:

A.  

Express an opinion on the participants ' inputs and conclusions as the assessment progresses.

B.  

Provide appropriate techniques and guidelines on how the exercise should be undertaken.

C.  

Evaluate and report on all issues that may be uncovered during the exercise.

D.  

Screen and vet participants so that the most appropriate candidates are selected to participate in the exercise.

Discussion 0
Questions 19

According to IIA guidance, which of the following statements best justifies a chief audit executive ' s request for external consultants to complement internal audit activity (IAA) resources?

Options:

A.  

The organization ' s audit universe is extensive and diverse.

B.  

There has been an increase in unanticipated requests for advisory work.

C.  

Previous work provided by the external service provider has been of great quality and value.

D.  

A recent benchmarking study found that using external service providers is a common practice of similarly-sized IAAs in other organizations.

Discussion 0
Questions 20

Which of the following is the best approach for the internal audit function to communicate moderate and high risk observations to management?

Options:

A.  

Prepare a formal observation worksheet for all observations identified and send to management to review and provide feedback at the end of fieldwork.

B.  

Verbally communicate the high risk observations to management when identified and prepare a documented worksheet that includes the root cause, effect, and recommendations.

C.  

Prepare a formal observation worksheet for the high risk observations and a separate worksheet for the medium risk observations in an email to management.

D.  

Verbally communicate all observations to management at the end of fieldwork and provide a formal worksheet for review and feedback.

Discussion 0
Questions 21

An internal auditor is conducting a financial audit. Which of the following audit procedures is most appropriate when existing internal controls are weak?

Options:

A.  

Analytical procedures.

B.  

Detail testing.

C.  

Test of design.

D.  

Test of control.

Discussion 0
Questions 22

Which of the following is a detective control for managing the risk of fraud?

Options:

A.  

Awareness of prior incidents of fraud.

B.  

Contractor non-disclosure agreements.

C.  

Verification of currency exchange rates.

D.  

Receipts for employee expenses.

Discussion 0
Questions 23

An internal control questionnaire would be most appropriate in which of the following situations?

Options:

A.  

Testing controls where operating procedures vary.

B.  

Testing controls in decentralized offices.

C.  

Testing controls in high risk areas.

D.  

Testing controls in areas with high control failure rates.

Discussion 0
Questions 24

A manufacturing organization specializes in the production of evaporated milk and breakfast cereals. The manufacturing processes create significant loss in the form of waste and byproducts. The provision for normal production loss is known to senior management, but little action is taken when abnormal production losses occur. The organization sells its production byproducts to fish farmers at a reduced price. The byproducts are a widely recognized and used product in the fish farming industry. The organization has a policy that also allows its employees to purchase the byproducts at a negligible price. Based on the above, which of the following risks should the internal audit function consider when planning an engagement of the production process?

Options:

A.  

The production team may be incentivized to increase production losses.

B.  

The production team may work overtime and be overworked.

C.  

Increased misappropriation of finished products.

D.  

Risk that the finished product quality may be impaired.

Discussion 0
Questions 25

A customer has supplied personal information to a bank to facilitate opening an account. The bank is part of a larger group of companies with core businesses including general insurance, life insurance, and investment products. Considering that the customer has closed his only account with the bank and the statutory data retention period has elapsed, which of the following actions by the bank is most likely to align with appropriate data privacy principles?

Options:

A.  

The bank destroys all records containing a customer ' s personal information without informing the customer.

B.  

Based on an assessment of likely products of interest to the customer, the bank shares the customer’s personal information with other companies within the group and informs the customer.

C.  

The bank retains customer information to facilitate easier verification of personal information in the event that the customer returns to reopen his account. The customer is not informed.

D.  

The customer ' s personal information is used for market research by an external company and the customer is informed prior to publishing the results of the market research.

Discussion 0
Questions 26

Due to price risk from the foreign currency purchase of aviation fuel, an airliner has purchased forward contracts to hedge against fluctuations in the exchange rate. When recalculating the exchange losses from individual purchases of jet fuel, which of the following details does the internal auditor need to validate?

1. The hedge documentation designating the hedge.

2. The spot exchange rate on the transaction date.

3. The terms of the forward contract.

4. The amount of fuel purchased.

Options:

A.  

1 and 2

B.  

1 and 4

C.  

2 and 3

D.  

3 and 4

Discussion 0
Questions 27

An engagement work program o of greatest value to audit management when which of the following is true?

Options:

A.  

The work program provides more detailed support for the audit report

B.  

The work program helps determined the required amount of audit resources

C.  

The work program helps ensure tie achievement of the engagement objectives

D.  

The work program assists the auditor n developing and managing audit tests

Discussion 0
Questions 28

An organization owns vehicles that are kept off-site by employees to pick up and deliver orders. An internal auditor selects a specific vehicle from the fixed asset register for

testing. Which of the following would best provide sufficient, indirect evidence for the auditor to confirm the existence of the vehicle?

Options:

A.  

Review logs of the vehicles assigned to employees for the delivery of goods during the engagement period.

B.  

Visit the home address of the specific employee to see the selected vehicle.

C.  

Compare the registered details of the vehicle in the fixed asset register to a date-stamped photograph of the vehicle.

D.  

Seek independent confirmation of the vehicle ' s details from one of the delivery employees.

Discussion 0
Questions 29

An organization obtains maintenance personnel from a third-party service provider. The third-party service provider submits monthly timetables of contracted maintenance personnel and bills the organization on an hourly basis. Which of the following will most likely help an internal auditor validate the number of hours billed by the third-party service provider?

Options:

A.  

Conduct a due diligence review of the third-party service provider

B.  

Ask the third-party service provider to provide internal time-keeping records

C.  

Obtain access logs from entrances to the organization ' s facilities

D.  

Interview the manager responsible for contracting external personnel

Discussion 0
Questions 30

According to IIA guidance, which of the following steps should precede the development of audit engagement objectives?

Options:

A.  

Identification of controls.

B.  

Scope establishment.

C.  

Risk assessment.

D.  

Review of resources.

Discussion 0
Questions 31

Which of the following is a true statement regarding the use of flowcharts as an audit tool?

Options:

A.  

Flowcharts are typically not well suited to support information provided by a risk and control matrix.

B.  

Flowcharts are preferred to narratives, as they can provide much greater detail on the design and operation of a process.

C.  

Flowcharts are best applied to linear process flows but cannot address all risks related to the process.

D.  

Flowcharts describe process steps but cannot provide the level of detail needed to adequately assess the design of the process.

Discussion 0
Questions 32

During audit engagement planning, an internal auditor is determining the best approach for leveraging computer-assisted audit techniques (CAATs). Which of the following approaches maximizes the use of CAATs and why?

Options:

A.  

Tracing, because it would enable the auditor to verify quickly that the record counts were properly included in the compilation.

B.  

Inspection, because it would enable the auditor to verify how management enters the data into the application for processing.

C.  

Testing data, because it would enable the auditor to ensure that the application processes the transaction as described by management.

D.  

Reperformance, because it enables the auditor to verify that the application performed the calculation correctly.

Discussion 0
Questions 33

Which of the following would be the most helpful to a chief audit executive when developing a talent management strategy?

Options:

A.  

Gap analysis

B.  

Staff preferences

C.  

Maturity analysis

D.  

Extent of external audit coverage

Discussion 0
Questions 34

New environmental regulations require the board to certify that the organization ' s reported pollutant emissions data is accurate. The chief audit executive (CAE) is planning an audit to provide assurance over the organization ' s compliance with the environmental regulations. Which of the following groups or individuals is most important for the CAE to consult to determine the scope of the audit?

Options:

A.  

The audit committee of the board.

B.  

The environmental, health, and safety manager.

C.  

The organization ' s external environmental lawyers.

D.  

The organization ' s insurance department.

Discussion 0
Questions 35

Which of the following statements generally true regarding audit engagement planning?

Options:

A.  

The best source tor detailed process information is senior management

B.  

Audit objectives should be general and do not change.

C.  

Computer-assisted audit techniques are typically not useful during engagement planning

D.  

Internal auditors should prepare a dented audit program for testing controls

Discussion 0
Questions 36

' Internal policy prohibits employees from entering into contacts with financial obligations without proper approval.

A project manager signed a change to an important service agreement without obtaining the proper approval As a result the organization is receiving $5,000 per month less for its services.’’

Which of the following should be added to the observation?

Options:

A.  

The reason for not following the internal policy

B.  

A description of what constitutes proper approval

C.  

The annual impact of the changed agreement on cash flows

D.  

Details regarding when the change to the agreement was signed

Discussion 0
Questions 37

A newly promoted chief audit executive (CAE) is faced with a backlog of assurance engagement reports to review for approval. In an attempt to attach a priority for this review, the CAE scans the opinion statement on each report. According to IIA guidance, which of the following opinions would receive the lowest review priority?

1. Graded positive opinion.

2. Negative assurance opinion.

3. Limited assurance opinion.

4. Third-party opinion.

Options:

A.  

1 and 3

B.  

1 and 4

C.  

2 and 3

D.  

2 and 4

Discussion 0
Questions 38

In an assurance engagement focused on the adequacy of organizationwide risk management practices, which of the following best describes a primary area of interest for the engagement?

Options:

A.  

The effectiveness of process-level and transaction-level controls.

B.  

Conflicts of interest within the organizational structure of the senior management.

C.  

The alignment of management decisions with the level of risk the organization is willing to accept.

D.  

The actions of upper management in response to the internal audit acth/lty ' s reporting

Discussion 0
Questions 39

Which of the following situations is most likely to heighten an internal auditors professional skepticism regarding potential fraud?

Options:

A.  

A procurement manager does not have the expected academic credentials for his position

B.  

A salesperson frequently complains about the organization ' s policy on sales commissions.

C.  

The accounts payable supervisor has requested advances against her monthly salary on several occasions

D.  

A financial accountant is absent from work frequently due to regular medical procedures

Discussion 0
Questions 40

According to the Standards, which of the following is true regarding the auditor ' s inclusion of management ' s satisfactory performance in the final audit report?

Options:

A.  

Acknowledgement of satisfactory performance is encouraged but not required.

B.  

There are no standards to address the inclusion of satisfactory performance.

C.  

Satisfactory performance should only be acknowledged with the advice of corporate counsel.

D.  

Auditors must include satisfactory performance with the approval of the board.

Discussion 0
Questions 41

The audit engagement objective is to identify vendors who might be involved in money laundering processes or tax evasion schemes. How would the internal auditor use data analytics to fulfill this objective?

Options:

A.  

Run reports listing all payments made in countries other than vendor locations

B.  

Run reports listing all credit limit overrides

C.  

Run reports listing all instances of delayed revenue recognition

D.  

Run three-way match reports, matching invoices, purchase orders, and receiving reports

Discussion 0
Questions 42

During an organization’s management meetings, employees who report bad news and significant risks are treated as if they were to blame for those circumstances. As a result, employees tend to postpone delivering bad news to management for as long as possible. Which of the following should be addressed to improve this culture?

Options:

A.  

Tone at the top

B.  

Risk accountability

C.  

Risk leadership

D.  

Code of ethics

Discussion 0
Questions 43

Acceding to MA guidance, when of the Mowing strategies would like provide the most assurance to the chief audit executive (CAE) that the internal audit activity ' s recommendations are being acted upon?

Options:

A.  

The CAF obtains a formal response from senior management regarding the corrective actions they plan to take w address the recommendations.

B.  

The CAE develops a tracking system to monitor the stains of engagement recommendations reported to management for action

C.  

The CAE communicates with impacted department managers to determine whether corrective actions have addressed engagement recommendations

D.  

The CAE works with the engagement supervisor to monitor the recommendations issued to management for corrective action

Discussion 0
Questions 44

Which of the following manual audit approaches describes testing the validity of a document by following it backward to a previously prepared record?

Options:

A.  

Tracing

B.  

Reperformance

C.  

Vouching

D.  

Walkthrough

Discussion 0
Questions 45

According to IIA guidance, which of the following corporate social responsibility (CSR) evaluation activities may be performed by the internal audit activity?

1.Consult on CSR program design and implementation

2.Serve as an advisor on CSR governance and risk management.

3.Review third parties for contractual compliance with CSR terms

4Identify and mitigate risks to help meet the CSR program objectives

Options:

A.  

1,2, and 3.

B.  

1.2. and 4.

C.  

1, 3, and 4.

D.  

2. 3. and 4.

Discussion 0
Questions 46

A snow removal company is conducting a scenario planning exercise where participating employees consider the potential impacts of a significant reduction in annual snowfall for the coming winter. Which of the following best describes this type of risk?

Options:

A.  

Residual

B.  

Net

C.  

inherent.

D.  

Accepted.

Discussion 0
Questions 47

An organization ' s board would like to establish a formal risk management function and has asked the chief audit executive (CAE) to be involved in the process. According to IIA guidance, which of the following roles should the CAE not undertake?

Options:

A.  

Manage and coordinate risk management processes.

B.  

Audit risk management processes.

C.  

Become involved in risk oversight committees, monitoring activities, and status reporting.

D.  

Accept management ' s responsibility for risk management without board approval.

Discussion 0
Questions 48

Which of the following statements is true regarding managements use of judgement to design, implement, and conduct internal control?

Options:

A.  

The use of judgment enhances managements ability to make better decisions about internal control, but cannot guarantee perfect outcomes.

B.  

introducing judgment generally diminishes managements ability to make good decisions about internal control

C.  

It is inappropriate for management to exercise judgement in areas such as specifying and using suitable accounting principles.

D.  

It is inappropriate for management to exercise judgement in assessing whether components are present, functioning, and operating together

Discussion 0
Questions 49

Which of the following reasonably represents best practices regarding what should be the level of internal audit resource investment in monitoring and following up on engagement outcomes?

Options:

A.  

Limited resources should be employed since the actual engagement is already completed and the onus of corrective actions rests with management

B.  

No resources should be exclusively deployed for that at all rather it should be planned as part of future engagements in the same area

C.  

Resources should only be provided towards this if doing so does not result in depletion of resources for new engagements planned in the current period

D.  

Resources should be allocated to this without conditions as long as doing so meets the expectations of management and the judgment of the chief audit executive.

Discussion 0
Questions 50

Which method of examining entity-level controls involves gathering information from work groups that represent different levels in an organization?

Options:

A.  

Questionnaires.

B.  

Surveys.

C.  

Structured interviews

D.  

Facilitated team workshops

Discussion 0
Questions 51

The only internal auditor, who was part of a larger team of individuals trained in the testing and reading of the organization’s quality control equipment, has resigned. With a scheduled audit of the quality department not yet completed for this year, what alternative approach should the internal audit function take in this scenario?

Options:

A.  

Explain the situation to senior management and remove the audit from the audit plan until next year

B.  

Conduct the audit of the quality department but adjust the audit program to remove the quality control testing

C.  

Engage one of the other trained employees to participate in the audit review of the quality department

D.  

Request that external auditors include this area as part of their review and provide independent assurance

Discussion 0
Questions 52

Which of the following represents the best method for confirming that vendor invoices were for authorized purchases?

Options:

A.  

Vouching vendor invoices to payments made.

B.  

Sorting invoices by purchase orders and comparing for successive duplicate invoices.

C.  

Comparing a random sample of vendor invoices to purchase orders.

D.  

Sorting payments by invoice to detect successive duplicate invoices.

Discussion 0
Questions 53

According to IIA guidance, which of the following statements is true regarding due professional care?

Options:

A.  

Internal auditors must exercise due professional care to ensure that all significant risks will be identified.

B.  

Internal auditors must apply the care and skill expected of a reasonably prudent and competent internal auditor.

C.  

Due professional care requires the internal auditor to conduct extensive examinations and verifications to ensure fraud does not exist.

D.  

Due professional care is displayed during a consulting engagement when the internal auditor focuses on potential benefits of the engagement rather than the cost

Discussion 0
Questions 54

The head of customer service asked the chief audit executive (CAE) whether eternal auditors could assist her staff with conducting a risk self-assessment in the customer service department. The CAE promised to meet with customer service managers analyze relevant business processes, and come up with a proposal. Who is most likely to be the final approver of the engagement objectives and scope?

Options:

A.  

Senior management of the organization

B.  

The chief audit executive

C.  

The head of customer service

D.  

The board of directors

Discussion 0
Questions 55

When auditing an organization ' s cash-handling activates which of the following is the most reliable form of testimonial evidence an internal auditor can obtain?

Options:

A.  

Testimony from the cashier who performs the processes being reviewed

B.  

Testimony from me cashier ' s supervisor who knows how processes should be performed

C.  

Testimony from a knowledgeable person who is independent of the cashiering duty

D.  

Testimony from a manager who oversees all cashiering activities being reviewed

Discussion 0
Questions 56

Which type of engagement would be the most appropriate to assess the maturity and rigor of the organizationwide risk management process of a target entity that

management is considering acquiring?

Options:

A.  

A due diligence engagement.

B.  

An operational audit engagement.

C.  

A feasibility study engagement.

D.  

A risk and control self-assessment engagement.

Discussion 0
Questions 57

An organization invests excess short-term cash in trading securities Which of the following actions should an internal auditor take to test the valuation of those securities ' *

Options:

A.  

Use the equity method to recalculate the investment carrying value

B.  

Confirm the securities held by the broker.

C.  

Perform a calculation of premium or discount amortization.

D.  

Compare the carrying value with current market quotations

Discussion 0
Questions 58

Which of the following statements is true regarding internal control questionnaires?

Options:

A.  

Internal control questionnaires are useful m evaluating the effectiveness of standard operating procedures

B.  

internal control questionnaires provide reliable documents allowing internal auditors to cover many control procedures in little time

C.  

Internal control questionnaires can be used by internal auditors as an interview guide

D.  

Internal control questionnaires provide direct audit evidence which may need corroboration

Discussion 0
Questions 59

What would be the effect if an organization paid one of its liabilities twice during the year, in error?

Options:

A.  

Assets, liabilities, and owners ' equity would be understated.

B.  

Assets, net income, and owners’ equity would be unaffected

C.  

Assets and liabilities would be understated.

D.  

Assets, net income, and owners’ equity would be understated, but liabilities would be overstated

Discussion 0
Questions 60

While planning for an accounts payable audit an internal auditor performs an entity level controls analysis. Which of the following statements is true regarding me approach used by the auditor?

Options:

A.  

It enables the auditor to identify the inherent risks to the effective operation of accounts payable process controls.

B.  

It enables the auditor to understand the framework of the activities and associated accounts payable subprocesses

C.  

it enables the auditor to understand the accounts payable process and its flow, including key steps and systems.

D.  

It enables the auditor to categorize the population of transactions within the accounts payable process

Discussion 0
Questions 61

Which of the following statements is true regarding internal controls?

Options:

A.  

For assurance engagements internal auditors should plan to assess the effectiveness of all entity-level controls

B.  

Poorly designed or deficient entity-level controls can prevent well-designed process controls from working as intended.

C.  

During engagement planning, internal auditors should not discuss the identified key risks and controls with management of the area under review to prevent tipping off probable audit lasts

D.  

Reviewing process maps and flowcharts is an appropriate method for the internal a auditor to identify all key risks and controls during engagement planning

Discussion 0
Questions 62

During follow-up. the internal auditor discovered that operational management did not implement effective actions to address a significant control breach If the issue is left unresolved it may result in regulatory sanctions and damage the organization ' s reputation What is the most appropriate next step for the chief audit executive to lake?

Options:

A.  

Report the matter to the board

B.  

Implement the recommended control to address the exposure

C.  

Discuss the matter with senior management

D.  

Ask the regulatory agency to persuade management to address the issue

Discussion 0
Questions 63

A chief audit executive (CAE) is trying to balance the internal audit activity ' s needs for technical audit skills budget efficiency and staff development opportunities. Which of the following would best assist the CAE in achieving this balance1?

Options:

A.  

Strategic sourcing

B.  

Loan staff arrangement

C.  

Flat organizational structure

D.  

Hierarchical organizational structure

Discussion 0
Questions 64

An internal auditor is conducting an assurance engagement. One engagement objective is to evaluate the project manager’s effectiveness at controlling project costs. Which of the following audit tests should be included in the engagement program?

Options:

A.  

Prepare a bank reconciliation statement for all the bank accounts of the organization

B.  

Track a sample of project payments from accounts payable to concluded agreements and authorization rights

C.  

Validate the accuracy of assumptions and inputs used for calculations in the project’s feasibility model

D.  

Investigate whether the budget of the project was approved timely as required by internal policies

Discussion 0
Questions 65

When a significant finding is noted early during a review of the accounts payable function, which next course of action is best for communicating the issue?

Options:

A.  

Intern accounting management via an interim memorandum update

B.  

Note the item in the workpapers for inclusion in the final audit report

C.  

Call a meeting and discuss me issue with the audit committee

D.  

Alert the CEO as soon as the issue is discovered

Discussion 0
Questions 66

To which of the following aspects should the chief audit executive give the most consideration while communicating an identified unacceptable risk to management?

Options:

A.  

The organization’s attitude to hierarchy.

B.  

The organization ' s whistleblowing strategy.

C.  

The organization’s ongoing risk monitoring process.

D.  

The organization’s risk management policy.

Discussion 0
Questions 67

Which of the following steps should an internal auditor complete when conducting a review of an electronic data interchange application provided by a third-party service?

1.Ensure encryption keys meet ISO standards.

2.Determine whether an independent review of the service provider ' s operation has been conducted.

3.Verify that the service provider ' s contracts include necessary clauses.

4.Verify that only public-switched data networks are used by the service provider

Options:

A.  

1 and 3.

B.  

1 and 4

C.  

2 and 3.

D.  

2 and 4.

Discussion 0
Questions 68

During an audit of the accounts receivable (AR) process, an internal auditor noted that reconciliations are still not performed regularly by the AR staff, a recommendation that was made following a previous audit. Monitoring by the financial reporting function has failed to detect the shortcoming. Both the financial reporting function and AR report to the controller, who is responsible for implementing action plans. Which of the following supports the internal auditor ' s decision to combine both observations into one reported finding?

Options:

A.  

The observation was made during the same audit, and the action plan has a common owner.

B.  

The observation relates to the same control activity within a common process.

C.  

The observation has a common control, and it was noted in a prior audit.

D.  

The observation has a common process, and the action plan for the observation has a common owner.

Discussion 0
Questions 69

Which of the following has the greatest effect on the efficiency of an audit?

Options:

A.  

The complexity of deficiency findings.

B.  

The adequacy of preliminary survey information.

C.  

The organization and content of workpapers.

D.  

The method and amount of supporting detail used for the audit report.

Discussion 0
Questions 70

An internal auditor has discovered that duplicate payments were made to one vendor. Management has recouped the duplicate payments as a corrective action. Which of the following describes management’s action in this case?

Options:

A.  

A condition-based action plan.

B.  

A cause-based action plan.

C.  

A root cause-based action plan.

D.  

An effect-based action plan.

Discussion 0
Questions 71

In which of following scenarios is the internal auditor performing benchmarking?

Options:

A.  

The auditor compares information from one period with the same information from the poor period

B.  

The auditor compares new information to his general knowledge of the organization

C.  

The auditor compares information he collected with simmer information from another source

D.  

The auditor compares expected outcomes with actual results

Discussion 0
Questions 72

During a previous audit engagement, an internal auditor recommended that management implement a whistleblowing process. During follow-up, the auditor discovered that the process has been outsourced. Which of the following is the most appropriate response for the internal auditor?

Options:

A.  

Insist on establishing an internal whistleblowing process, as originally recommended, because this is a key control.

B.  

Review the agreement with the third-party service provider and ensure that appropriate controls are in place.

C.  

Raise the issue to a higher level of management, as outsourcing the process was not previously discussed or agreed upon.

D.  

Take no action, as management has accepted the risk of moving to a third party for this whistleblowing process.

Discussion 0
Questions 73

During an internal audit engagement, which of the following is true regarding the decision to use statistical sampling or nonstatistical sampling?

Options:

A.  

The decision affects the test procedures performed.

B.  

The auditor ' s response to errors detected will be influenced.

C.  

The competence of the evidence obtained is greater with statistical sampling.

D.  

Nonstatistical sampling may be more cost effective.

Discussion 0
Questions 74

Which of the following is the most important determinant of the objectives and scope of assurance engagements?

Options:

A.  

The organizational chart, business objectives and policies and procedures of the area to be reviewed.

B.  

The most recent risk assessment conducted by management of the area to be reviewed.

C.  

The requests of operational and senior management throughout the organization.

D.  

The preliminary risk assessment performed by internal auditors planning the engagement

Discussion 0
Questions 75

Which of the following actions should the internal audit activity take during an audit engagement when examining the effectiveness of risk management processes?

Options:

A.  

Evaluate how the organization manages fraud risk.

B.  

Establish procedures for improving risk management processes.

C.  

Ensure risk responses are aligned with industry standards

D.  

Verify that organizational objectives are aligned with each departments objectives.

Discussion 0
Questions 76

An internal auditor is analyzing sates records and is concerned whether a transaction is recorded in the coned period. The accounting manager explains that the external auditor approved the records and produces an email from the external audit team leader. How should tie internal auditor respond?

Options:

A.  

Ask the external auditor to review the same transaction again as an independent third party

B.  

Consult account accounting principles, standards, and relevant guidelines in regard to timing of the entry

C.  

Interview the chief financial officer and obtain her opinion on how the transactions should be recorded

D.  

Compare the recording of this transaction to now similar ones were executed last year

Discussion 0
Questions 77

Which of the following types of resources is the most important and challenging to identify and allocate in order to perform an audit engagement?

Options:

A.  

External resources.

B.  

IT resources.

C.  

Human resources.

D.  

Monetary budget.

Discussion 0
Questions 78

According to IIA guidance, which of the following is a limitation of a heat map?

Options:

A.  

Impact cannot be represented on a heat map unless it is quantified in financial terms.

B.  

Impact and likelihood at times cannot be differentiated as to which is more important.

C.  

A heat map cannot be used unless a risk and control matrix has been developed.

D.  

Qualitative factors cannot be incorporated into a heat map.

Discussion 0
Questions 79

While auditing an organization ' s credit approval process, an internal auditor learns that the organization has made a large loan to another auditors relative. Which course of action should the auditor take?

Options:

A.  

Proceed with the audit engagement, but do not include the relative ' s information.

B.  

Have the chief audit executive and management determine whether the auditor should continue with the audit engagement.

C.  

Disclose in the engagement final communication that the relative Is a customer

D.  

Immediately withdraw from the audit engagement

Discussion 0
Questions 80

The internal audit activity is currently working on several engagements, including a consulting engagement on the management process in the human resources department. Which of the following actions should the chief audit executive take to most efficiently and effectively ensure the quality of the engagement?

Options:

A.  

Assign an experienced manager to monitor the whole engagement process.

B.  

Employ fieldwork peer review to enhance the work quality.

C.  

Require internal auditors to follow a standardized work program.

D.  

Personally supervise the engagement

Discussion 0
Questions 81

A healthcare organization ' s chief audit executive (CAE) noted that the organization ' s IT team relies heavily on a vendor. Therefore an IT vendor assessment review was added to the annual audit plan. During the review, the audit team discovered that the vendor had not been performing proper monitoring to ensure that the subcontractors it hired comply with the organization requirements. The organization ' s chief information officer (ClO) does not agree with the audit team ' s recommendation for the IT team to monitor the compliance level of vendor subcontractors. How should the audit team proceed to resolve this situation?

Options:

A.  

Write a risk acceptance memo for the CIO to sign acknowledging the observation and indicating a willingness to accept the risk.

B.  

Provide an example of the attestation form that vendors must use. Then, recommend that the IT team require vendors to submit the attestation form on a regular basis.

C.  

Escalate the issue to the audit committee, as the CIO is unwilling to implement the recommended action plan.

D.  

Escalate the issue to the CAE to assess whether the ClO ' s reasoning is acceptable.

Discussion 0
Questions 82

According to IIA guidance, when of the Mowing statements is true regarding an engagement supervisor ' s use of review notes?

Options:

A.  

The engagement supervisor ' s review notes should be retained m the final documental or even after they are addressed.

B.  

The engagement supervisor ' s review notes cannot be used as evidence of engagement supervision

C.  

The engagement supervisor ' s review notes could be cleared from all final documentation after they are addressed

D.  

The engagement supervisor ' s review notes must be maintained in a checklist separate from tie final documentation

Discussion 0
Questions 83

When reviewing workpapers, engagement supervisors may ask for additional evidence or clarification via review notes. According to IIA guidance, which of the following statements is true regarding the engagement supervisors review notes?

Options:

A.  

The review notes may be cleared from the final documentation once the engagement supervisors concerns have been addressed

B.  

Management of the area under review must address the engagement supervisors review notes before the audit report can be finalized.

C.  

The chief audit executive must initial or sign the engagement supervisors review notes to provide evidence of appropriate engagement supervision.

D.  

Review notes provide documented proof that the engagement is supervised properly and must be retained for the quality assurance and improvement program

Discussion 0
Questions 84

An internal auditor was reviewing the procurement department ' s tender documentation for completeness He documented all discrepancies but the procurement manager disagreed with his findings Upon further review, the internal auditor noted that all discrepancies had been corrected in the tender database. Which of the following courses of action would have prevented this situation?

Options:

A.  

The auditor should have ensured the preservation of audit evidence by taking screenshots or extracting tender documents

B.  

The auditor should have extracted a list of logs and identified any actions that were executed in the database during the audit

C.  

The auditor should have instructed procurement workers that changes to the database during the course of the audit were strictly forbidden

D.  

The internal auditor should have created a more thorough work program, which would address audit criteria and potential causes in more detail

Discussion 0
Questions 85

According to IIA guidance, which of the following is based on the results of a preliminary assessment of risks relevant to the area under review?

Options:

A.  

Audit findings

B.  

Audit resources

C.  

Audit objectives

D.  

Audit plan

Discussion 0
Questions 86

Which of the following internal audit activities is performed in the design evaluation phase?

Options:

A.  

The internal auditor reviews prior audits and workpapers

B.  

The internal auditor identifies the controls over segregation of duties.

C.  

The internal auditor checks a process for completeness.

D.  

The internal auditor communicates the audit results to management

Discussion 0
Questions 87

According to IIA guidance, organizations have the most influence on which element of fraud?

Options:

A.  

Opportunity.

B.  

Rationalization.

C.  

Pressure.

D.  

Incentives.

Discussion 0
Questions 88

Senior management requested that the internal audit activity perform a consulting project to assist in making a decision on a new software system. Which of the following would be used to determine the engagement objectives?

Options:

A.  

An assessment of risks to the business objectives

B.  

An understanding of the engagement client ' s expectations

C.  

The probability of significant errors fraud or noncompliance

D.  

Criteria previously established by the board

Discussion 0
Questions 89

A corporate merger decision prompts the cruel audit executive (CAE) to propose interim changes lo the existing annual audit plan to account for emerging risks. When of the following is the most appropriate action for the CAE to take regarding the changes made to the audit plan?

Options:

A.  

Present the revised audit plan directly to the board for approval

B.  

Communicate with the chief financial officer and present the revised audit plan to the CEO for approval

C.  

Present the revised audit plan directly to the CEO for approval

D.  

Communicate with the CCO and present the revised audit plan to the board for approval

Discussion 0
Questions 90

An examination of the accounts payable function evidenced multiple findings with respect to segregation of duties. After management ' s response and action plan are received and documented in the final report, which of the following is most appropriate?

Options:

A.  

Follow up after the applicable changes have been incorporated to validate management’s response.

B.  

Include the items in the scope of the next scheduled audit of the accounts payable function.

C.  

Because management agreed with the findings, no further action is deemed necessary.

D.  

Have an internal audit staff member placed into the accounting department until corrections are made.

Discussion 0
Questions 91

According to IIA guidance, which of the following would be the best first step to manage risk when a third party is overseeing the organization’s network and data ' ?

Options:

A.  

Creating a comprehensive reporting system for vendors to demonstrate their ongoing due diligence in network operations.

B.  

Drafting a strong contract that requires regular vendor control reports and a right-to-audit clause

C.  

Applying administrative privileges to ensure right-to-access controls are appropriate

D.  

Creating a standing cybersecurity committee to identify and manage risks related to data security.

Discussion 0
Questions 92

Which of the following is one of the advantages of organizing the risk universe by processes?

Options:

A.  

Interfaces between organizational units are captured during audits by processes

B.  

Audits by processes are less time-consuming

C.  

During audits by processes, managers are more open at interviews

D.  

The advantage of audits by processes is true completeness

Discussion 0
Questions 93

What is the purpose of an internal control questionnaire?

Options:

A.  

To gather information from a sample of people who are geographically dispersed

B.  

To assess risks that could prevent an audited area from achieving its objectives.

C.  

To evaluate tie level of compliance of remote offices with centrally designed procedures

D.  

To perform testing of controls more frequently

Discussion 0
Questions 94

An internal auditor believes that the internal audit activity ' s independence is impaired Which of the following actions should the internal auditor take first?

Options:

A.  

Report the impairment to senior management

B.  

Discuss the impairment with the audit manager.

C.  

Ascertain the best approach to disclose the impairment.

D.  

Decide on the extent of impact of the impairment

Discussion 0
Questions 95

Which of the following offers the best explanation of why the auditor in charge would assign a junior auditor to complete a complex part of the audit engagement?

Options:

A.  

The senior auditors are unavailable, as they are currently working on other portions of the engagement

B.  

The auditor in charge believes that the junior auditor should obtain a specific type of experience.

C.  

The audit engagement has a tight deadline and the work must be completed timely.

D.  

The auditor in charge is unable to identify audit staff with all of the required skills needed to complete the engagement

Discussion 0
Questions 96

Which of the following is the primary purpose of financial statement audit engagements?

Options:

A.  

To assess the efficiency and effectiveness of the accounting department.

B.  

To evaluate organizational and departmental structures, including assessments of process flows related to financial matters.

C.  

To provide a review of routine financial reports, including analyses of selected accounts for compliance with generally accepted accounting principles.

D.  

To provide an analysis of business process controls in the accounting department, including tests of compliance with internal policies and procedures.

Discussion 0
Questions 97

Which of the following are advantages of flowcharts over internal control questionnaires ' '

1 Flowcharts reduce the need to test whether employees are observing internal control processes

2 Flowcharts provide a visual depiction of the processes in the area under review 3. Flowcharts identify and prioritize internal control design weaknesses.

4 Flowcharts highlight the control points to help internal auditors evaluate control design

Options:

A.  

1 and 3 only

B.  

2 and 4 only.

C.  

1.2. and 3 only

D.  

2. 3 and 4 only

Discussion 0
Questions 98

During an assurance engagement, an internal auditor noted that the time staff spent accessing customer information in large Excel spreadsheets could be reduced significantly through the use of macros. The auditor would like to train staff on how to use the macros. Which of the following is the most appropriate course of action for the internal auditor to take?

Options:

A.  

The auditor must not perform the training, because any task to improve the business process could impact audit independence.

B.  

The auditor must create a new, separate consulting engagement with the business process owner prior to performing the improvement task.

C.  

The auditor should get permission to extend the current engagement, and with the process owner ' s approval, perform the improvement task.

D.  

The auditor may proceed with the improvement task without obtaining formal approval, because the task is voluntary and not time-intensive.

Discussion 0
Questions 99

During the planning process for a human resources audit, an internal auditor obtains an organizational chart. The auditor observes a flat organizational structure. Which of the below risks should the auditor consider for this engagement?

Options:

A.  

Transactions and decision-making require multiple approvals, resulting in processing delays.

B.  

Career and promotion paths are not easily visible and defined.

C.  

Communication is likely to be top-down, with little feedback from lower-level employees.

D.  

Employees have little autonomy, which may result in employee turnover or low morale.

Discussion 0
Questions 100

According to HA guidance, which of the following statements regarding audit workpapers is true?

Options:

A.  

Audit reports should include the workpapers as a reference for the audit conclusions.

B.  

The internal auditor ' s workpapers are the primary reference for reported control deficiencies.

C.  

Ad-hoc communications with management of the area under review should be excluded from the workpapers.

D.  

Both draft and final versions of workpapers should be saved at the end of the engagement

Discussion 0
Questions 101

Management has taken immediate action to address an observation received during an audit of the organization ' s manufacturing process Which of the following is true regarding the validity of the observation closure?

Options:

A.  

Valid closure requires evidence that ensures the corrected process will function as expected in the future

B.  

Valid closure requires the client lo address not only the condition, but also the cause of the condition

C.  

Valid closure of an observation ensures it will be included in the final engagement report

D.  

Valid closure requires assurance from management that the original problem will not recur in the future

Discussion 0
Questions 102

Which of the following statements best demonstrates application of due professional care during an assurance engagement?

Options:

A.  

The engagement detected irregularities and noncompliance instances.

B.  

The engagement supervisor had no significant comments in the supervisory review.

C.  

The audit procedures were systematically planned: executed, and documented.

D.  

The engagement objectives were designed to assist the engagement client

Discussion 0
Questions 103

Which of the following activities Is most likely to require a fraud specialist to supplement the knowledge and skills of the internal audit activity?

Options:

A.  

Planning an engagement of the area in which fraud is suspected.

B.  

Employing audit tests to detect fraud

C.  

Interrogating a suspected fraudster.

D.  

Completing a process review to improve controls to prevent fraud.

Discussion 0
Questions 104

If an engagement supervisor discovers insufficient information to draw a conclusion in workpapers, which action should she take first?

Options:

A.  

Assign another auditor to complete the audit step and produce a new error-free workpaper.

B.  

Document the problem as a review comment and continue with the audit.

C.  

Discuss the matter with the auditor who produced the workpapers and improve the training manual.

D.  

Complete the audit step herself to ensure accuracy and take additional steps to improve the audit training plan.

Discussion 0
Questions 105

Which of the following statements is true regarding engagement planning?

Options:

A.  

The scope of the engagement should be planned according to the internal audit activity’s budget and then aligned to the risk universe.

B.  

The audit engagement objectives should be based on operational management ' s view of risk objectives.

C.  

The planning phase of the engagement should be completed and approved before the fieldwork of the engagement begins.

D.  

The main purpose of the engagement work program is to determine the nature and timing of procedures required to gather audit evidence.

Discussion 0
Questions 106

During the filework phase of an assurance engagement the internal auditor decides that she wants to adjust the audit work program. Which of the following is the most appropriate next step for the auditor to take9

Options:

A.  

Request additional information needed from management of the area under review.

B.  

Obtain approval from the engagement supervisor

C.  

Obtain the required resources, including IT. to complete the work

D.  

Discuss the change in scope with management of the area under review.

Discussion 0
Questions 107

During an audit, the chief audit executive reviews and approves changes to the audit program. Which of the following describes this activity?

Options:

A.  

Engagement reporting

B.  

Continuous monitoring

C.  

Engagement supervision

D.  

Engagement risk assessment

Discussion 0
Questions 108

An internal auditor e assessing the design of a control and has identified a potential significant weakness. The auditor shared his concern with management however management does not agree that the weakness is significant. What should the internet auditor do next?

Options:

A.  

Perform additional audit work to better articulate the risk

B.  

Report the finding that management has accepted a level of risk that is unacceptable.

C.  

Proceed to testing how effectively the control is opening.

D.  

Because the design weakness has been identified no additional audit work is needed

Discussion 0
Questions 109

A large retail organization, which sells most of its products online, experiences a computer hacking incident. The chief IT officer immediately investigates the incident and concludes that the attempt was not successful. The chief audit executive (CAE) learns of the attack in a casual conversation with an IT auditor. Which of the following actions should the CAE take?

1. Meet with the chief IT officer to discuss the report and control improvements that will be implemented as a result of the security breach, if any.

2. Immediately inform the chair of the audit committee of the security breach, because thus far only the chief IT officer is aware of the incident.

3. Meet with the IT auditor to develop an appropriate audit program to review the organization ' s Internet-based sales process and key controls.

4. Include the incident in the next quarterly report to the audit committee.

Options:

A.  

1 and 2

B.  

1 and 3

C.  

2 and 4

D.  

3 and 4

Discussion 0
Questions 110

In a health care organization the internal audit activity provides overall assurance on governance, risk and control The chief audit executive advises and influences senior management, and the audit strategy leverages the organization ' s management of risk According to HA guidance which of the following stages of internal audit maturity best describes this organization?

Options:

A.  

Infrastructure.

B.  

Emerging.

C.  

Managed.

D.  

Initial.

Discussion 0
Questions 111

To effectively communicate the acceptance of risk in an organization a chief audit executive must first consider which of the following?

Options:

A.  

The organization ' s view on risk tolerance

B.  

The organization ' s principal risk events.

C.  

The organization ' s risk response strategies

D.  

The organization ' s major control activities

Discussion 0
Questions 112

A team of internal auditors is assigned to audit the employee relations process in an organization, which includes employee conduct and disciplinary hearings. Which of the following audit approaches would provide the auditors with the best evidence to determine the degree to which disciplinary decisions are complying with documented policy?

Options:

A.  

Review a random sample of concluded disciplinary reports to assess how the policy was applied in each case.

B.  

Interview a sample of impacted employees for their opinions on the clarity and fairness of the policy.

C.  

Observe several disciplinary hearings to determine whether they are in compliance with the policy.

D.  

Conduct an interview to assess the disciplinary hearing chairman’s understanding of the policy and its appropriate use.

Discussion 0
Questions 113

The board of directors expressed concerns about potential external risks that could impact the organization s ability to meet its annual objectives and goals The board requested consulting services from the internal audit activity to gain insight regarding the external risks Which of the following engagement objectives would be appropriate to fulfill this request?

Options:

A.  

Assess the organization ' s ability to minimize potential external risks

B.  

Assess the organization ' s process of vetting vendors that provide necessary services to the organization

C.  

Assess the organization ' s risk impacts from the markets in which it operates

D.  

Assess the organization ' s controls implemented that would help minimize risks

Discussion 0
Questions 114

Management requested internal audit consulting services. During fieldwork significant control issues were identified by the internal audit team. Which of the following is an appropriate response from the chief audit executive?

Options:

A.  

End the consulting engagement and report the results to management as planned

B.  

Report the significant control issues to senior management and the board and recommend corrective action

C.  

Mutually agree with the engagement client on corrective actions

D.  

Focus on the consulting engagement and schedule an assurance engagement next to address the control issues

Discussion 0
Questions 115

An internal auditor is performing testing to gather evidence regarding an organization ' s inventory account balance and is mindful of the possibility that the sample used might support the conclusion that the recorded account balance is not materially misstated when, in fact, it is The auditor ' s concern best describes which of the following risks?

Options:

A.  

Incorrect rejection risk.

B.  

Incorrect acceptance risk.

C.  

Tolerable misstatement risk

D.  

Anticipated misstatement risk

Discussion 0
Questions 116

Which of the following computerized audit tools or techniques should be used if the internal auditor wants to extract specific files and records in the database?

Options:

A.  

An expert or decision support system

B.  

Generalized audit software

C.  

A system utility program

D.  

An integrated test facility

Discussion 0
Questions 117

Which of the following best describes how an internal auditor would use a flowchart during engagement planning?

Options:

A.  

To prepare for testing the effectiveness of controls

B.  

To plan for evaluating potential losses

C.  

To prepare a sampling plan for the engagement

D.  

To evaluate the design of controls

Discussion 0
Questions 118

During the preliminary survey of the procurement department, an internal auditor noted a major control weakness in the organization ' s ordering and receiving process. According to IIA guidance, which of the following is the most appropriate action the internal auditor should take?

Options:

A.  

Issue a final report on the control weakness to senior management.

B.  

Bring the control weakness to the attention of the process owner for resolution.

C.  

Note the control weakness for discussion during the exit meeting.

D.  

Carry out an investigation of the control weakness for disciplinary action.

Discussion 0
Questions 119

An internal auditor is tasked with evaluating the adequacy of the organization ' s inventory fraud controls. What is the most relevant information that the auditor can obtain from the documentation of cyclic counting for this purpose?

Options:

A.  

Accounting adjustments of inventories are approved by the management in accordance with a signature policy

B.  

Root causes of inventory differences are analyzed and corrective measures are followed

C.  

High value items are inventoried more frequently throughout the year

D.  

Value of accounting adjustments matches with the value of inventory differences and are made in a timely manner

Discussion 0
Questions 120

Which of the following methods is most closely associated to year over year trends?

Options:

A.  

Horizontal analysts

B.  

Vertical analysis.

C.  

Common-size analysis.

D.  

Ratio analysis.

Discussion 0
Questions 121

According to IIA guidance, which of the following strategies would add the least value to the achievement of the internal audit activity ' s (IAA ' s) objectives?

Options:

A.  

Align organizational activities to internal audit activities and measure according to the approved IAA performance measures.

B.  

Establish a periodic review of monitoring and reporting processes to help ensure relevant IAA reporting.

C.  

Use the results of IAA engagement and advisory reporting to guide current and future internal audit activities.

D.  

Establish a format and frequency for IAA reporting that is appropriate and aligns with the organization ' s governance structure.

Discussion 0
Questions 122

An internal audit activity has to confirm the validity of the activities reported by a grantee that received a chantable contribution from the organization Which of the following methods would best help meet this objective?

Options:

A.  

Visiting the grantee to assess whether the execution of the project was in line with the defined grant scope.

B.  

Verifying that the grantee ' s final report is in line with what was depicted in the initial budget request.

C.  

Reconciling general ledger accounts used by management of the area under review for reflecting expenses on charitable contributions

D.  

Interviewing employees of the corporate affairs department, which is responsible for charitable activities

Discussion 0
Questions 123

An audit observation noted that annual inventory counts of biofuel was not being performed appropriately Fuel yards were not visited and physical amounts of biofuel were not reconciled with accounting data Management of the division understood the issue and promised to resolve the problem When should the internal auditor schedule a follow-up review?

Options:

A.  

As soon as possible, no later than two months after the audit

B.  

When convenient for both parties

C.  

When management has indicated that the issue has been resolved

D.  

Before financial year end

Discussion 0
Questions 124

Which of the following must be in existence as a precondition to developing an effective system of internal controls?

Options:

A.  

A monitoring process

B.  

A risk assessment process.

C.  

A strategic objective-setting process.

D.  

An information and communication process

Discussion 0
Questions 125

Who is responsible for ensuring internal auditors continuing professional development*

Options:

A.  

Individual internal auditors

B.  

Chief audit executive.

C.  

The board

D.  

Engagement supervisors

Discussion 0
Questions 126

Which of the following would best prevent phishing attacks on an organization?

Options:

A.  

An intrusion detection system

B.  

Use of firewalls

C.  

Regular security awareness training

D.  

Application hardening

Discussion 0
Questions 127

An internal auditor wants to assess the completeness of sales invoices issued by the organization over a period of time Providing that at the necessary data and analytics software is which of the following types of analyse would be appropriate to satisfy the auditor ' s objective?

Options:

A.  

Payment terms analysis

B.  

Duplicates analysts

C.  

Aging analysis

D.  

Gap analysis

Discussion 0
Questions 128

The chief audit executive (CAF) determined that the residual risk identified in an assurance engagement is acceptable. When should this be communicated to senior management?

Options:

A.  

When the CAE reports the audit outcome to senior management.

B.  

When the residual risk is identified before the engagement is complete.

C.  

Immediately, as residual risk should be communicated as soon as possible

D.  

When management of the area under review has resolved and mitigated the residual risk

Discussion 0
Questions 129

According to IIA guidance,which of the following is true about the supervising internal auditor ' s review notes?

• They are discussed with management prior to finalizing the audit.

• They may be discarded after working papers are amended as appropriate.

• They are created by the auditor to support her fieldwork in case of questions.

• They are not required to support observations issued in the audit report.

Options:

A.  

1 and 3 only

B.  

1 and 4 only

C.  

2 and 3 only

D.  

2 and 4 only

Discussion 0
Questions 130

In a small internal audit function, a single auditor is responsible for conducting the entire audit engagement. In this situation, what is the benefit of using a checklist as part of an engagement work program?

Options:

A.  

Allocation of tasks and responsibilities within the team.

B.  

Facilitation of review by business representatives involved.

C.  

Overview of results from previous audits.

D.  

Retention of an audit trail regarding completion of tasks.

Discussion 0
Questions 131

Which of the following describes the primary objective of an internal audit engagement supervisor?

Options:

A.  

Uphold the quality of the internal audit actively

B.  

Provide engagement progress updates to management of the area under review

C.  

Assure risks and controls are identified and assessed

D.  

Ensure timely completion of the engagement

Discussion 0
Questions 132

Which of the following is one of the differences between probability-proportional-to-size (PPS) and attribute sampling?

Options:

A.  

PPS sampling s used to reach conclusions regarding monetary amounts, attribute sampling is not.

B.  

PPS sampling is used to roach conclusions regarding rates of occurrence, attribute sampling is not.

C.  

PPS sampling a applied within the context of testing controls attribute sampling s not.

D.  

Attribute sampling is affected by the monetary book value of the population PPS sampling is not

Discussion 0
Questions 133

The internal audit function is performing an assurance engagement on the organization’s environmental, social, and governance (ESG) program. The engagement objective is to determine whether the ESG program’s activities are meeting the program’s established goals. The internal audit function has completed a risk and control assessment of the ESG program ' s activities. What is the appropriate next step?

Options:

A.  

Conclude whether the ESG program ' s activities are meeting the established goals

B.  

Communicate the results of the assessment to senior management

C.  

Develop recommendations based on the results of the assessment

D.  

Perform testing on the activities selected based on the assessment

Discussion 0
Questions 134

An internal auditor s testing tor proper authorization of contracts and finds that the rate of deviations discovered in the sample is equal to the tolerable deviation rate. When of the following is the most appropriate conclusion for the internal auditor to make based on this result?

Options:

A.  

The internal auditor concludes that management may be placing undue reliance on me specified control

B.  

The internal auditor concludes that the specified control is more effective than it really is.

C.  

The internal auditor concludes that the specified control is acceptably effective

D.  

The internal auditor concludes that additional testing will be required to evaluate the specified control

Discussion 0
Questions 135

Internal control questionnaires are used to achieve which of the following objectives?

Options:

A.  

To ascertain the operating effectiveness of a procedure

B.  

To verify the accuracy of Information in a report

C.  

To assess the controls mitigating major risks

D.  

To determine whether specified contra procedures are in place

Discussion 0
Questions 136

Which of the following best describes the guideline for preparing audit engagement workpapers?

Options:

A.  

Workpapers should be understandable to the auditor in charge and the chief audit executive

B.  

Workpapers should be understandable to the audit client and the board.

C.  

Workpapers should be understandable to another internal auditor who was not involved in the engagement.

D.  

Workpapers should be understandable to external auditors and regulatory agencies

Discussion 0
Questions 137

The audit committee has asked the chief audit executive (CAE) to conduct an ad hoc forensic investigation of the purchasing department within a month due to the significance and urgency of a recently discovered risk The internal audit activity currently has no available staff with relevant experience or qualifications Which of the following is the CAE ' s best option for fulfilling the internal audit activity ' s responsibilities in this case?

Options:

A.  

Outsource the investigation to independent professional consultants

B.  

Select certain internal auditors and remove them from their current assignments so that they can begin a forensic investigation course

C.  

Recruit additional internal auditors possessing relevant qualification and experience

D.  

Decline the engagement at this time

Discussion 0
Questions 138

Which of the following internal audit activities is performed in the design evaluation phase?

Options:

A.  

The internal auditor reviews prior audits and workpapers.

B.  

The internal auditor identifies the controls over segregation of duties.

C.  

The internal auditor checks a process for completeness.

D.  

The internal auditor communicates the audit results to management.

Discussion 0
Questions 139

A rapidly expanding retail organization continues to be tightly controlled by its original small management team. Which of the following is a potential risk in this vertically centralized organization?

Options:

A.  

Lack of coordination among different business units

B.  

Operational decisions are inconsistent with organizational goals.

C.  

Suboptimal decision-making.

D.  

Duplication of business activities.

Discussion 0
Questions 140

Which of the following resources would be most effective for an organization that would like to improve how it informs stakeholders of its social responsibility performance?

Options:

A.  

ISO 26000

B.  

Global Reporting Initiative.

C.  

Open Compliance and Ethics Group.

D.  

COSO’s enterprise risk management framework.

Discussion 0
Questions 141

Which of the following is the most appropriate reason for a chief audit executive to conduct an external assessment more frequently than five years?

Options:

A.  

Significant changes in the organization ' s accounting policies or procedures would warrant timely analysis and feedback.

B.  

More frequent external assessments can serve as an equivalent substitute for internal assessments.

C.  

The parent organization ' s internal audit activity agreed to perform biennial reciprocal external assessments to provide greater assurance at a reduced cost.

D.  

A change in senior management or internal audit leadership may change expectations and commitment to conformance

Discussion 0
Questions 142

Which of the following is critical to the success of an effective interview?

Options:

A.  

Present audit evidence and information to support the internal auditor’s line of questioning.

B.  

Establish credibility, trust, and rapport.

C.  

Develop flowcharts and review them with the interviewee.

D.  

Observe the process and discuss it with the interviewee.

Discussion 0
Questions 143

According to IIA guidance, which of the following statements is true regarding the authority of the chief audit executive (CAE) to release previous audit reports to outside parties?

Options:

A.  

The CAE can release prior internal audit reports with the approval of the board and senior management.

B.  

The CAE can employ judgment and release prior audit results as they deem appropriate and necessary.

C.  

The CAE can only release prior information outside the organization when mandated by legal or statutory requirements.

D.  

The CAE can release prior information provided it is as originally published and distributed within the organization.

Discussion 0
Questions 144

Which of the following is an example of internal benchmarking?

Options:

A.  

Book value per common share ratio is lower than that of the prior year.

B.  

Staff turnover ratio is higher than the comparable organization in the same industry.

C.  

Utilities expense of the sales unit is higher than that of the customer service unit.

D.  

Sales are significantly higher than the industry’s average for five years.

Discussion 0
Questions 145

The newly appointed chief audit executive (CAE) of a large multinational corporation, with seasoned internal audit departments located around the world, is reviewing responsibilities for engagement reports. According to IIA guidance, which of the following statements is true?

Options:

A.  

The CAE is required to review, approve, and sign every engagement report.

B.  

The CAE is required to review, approve, and sign all regulatory compliance engagement reports only

C.  

The CAE may delegate responsibility for reviewing, approving and signing engagement reports, but should review the reports after they are issued.

D.  

The internal audit charter must identify authorized signers of engagement reports.

Discussion 0
Questions 146

Which of the following statements is true regarding the final assurance engagement report issued to management?

Options:

A.  

Ratings are only used to assess the condition of an observation made by an internal auditor.

B.  

Audit findings may be communicated to management prior to issuance of the final approved audit report.

C.  

Communications must be relevant logical, and free from errors before they are disseminated.

D.  

The audit report must present the information in the following order (1) audit scope, (2) engagement objectives, and (3) engagement results

Discussion 0
Questions 147

The internal audit activity has requested that new vendor information be summarized once per week in a single report, and that all invoices each week for these vendors be automatically flagged in the invoice processing system. Which of the following computerized audit techniques is the internal audit activity most likely applying?

Options:

A.  

Enabling continuous auditing.

B.  

Employing generalized audit software.

C.  

Facilitating electronic workpapers.

D.  

Using machine learning.

Discussion 0
Questions 148

Which of the following approaches would best help an internal auditor determine whether a retailer database of 100,000 customers has nay duplicate accounts?

Options:

A.  

Stratifying the customer information

B.  

Extracting the customer information

C.  

Filtering the customer information

D.  

Sorting the customer information

Discussion 0
Questions 149

Which of the following is not a primary reason for outsourcing a portion of the internal audit activity?

Options:

A.  

To gain access to a wider variety of skills, competencies and best practices.

B.  

To complement existing expertise with a required skill and competency for a particular audit engagement.

C.  

To focus on and strengthen core audit competencies.

D.  

To provide the organization with appropriate contingency planning for the internal audit function.

Discussion 0
Questions 150

A technology organization is developing an artificial intelligence (AI) program for use on its social media platform. The AI program is meant to help content creators with images and posts that will acquire followers more efficiently. The internal audit function is planning an engagement of the AI program development. Which of the following should be considered a significant, immediate, and inherent risk?

Options:

A.  

The AI program becomes self-reliant and no longer requires human assistance to perform tasks for the organization.

B.  

The AI program advancements allow for it to generate original images for use by content creators and other individuals.

C.  

The AI program captures images found online that are created and owned by individuals and other organizations.

D.  

The AI program will have to comply with the national regulation expected to come in force in two years ' time.

Discussion 0
Questions 151

While reviewing the organization’s financial year-end processes, an internal auditor discovered an erroneous journal entry. If the error is not addressed, it will result in a material misstatement of the financial records. The internal auditor needs an additional four weeks to complete the audit engagement. How should the auditor communicate this finding?

Options:

A.  

The auditor should issue an interim report to management prior to completion of the audit and issuance of the final report.

B.  

The auditor should include this item in the final audit report, marked with an asterisk, indicating that it is a high-risk item.

C.  

The auditor should discuss the finding with the appropriate accounting staff who can make the correction immediately, and if corrected before the engagement is concluded, the finding would not need to be included in the audit report.

D.  

The auditor is obligated to bypass management and immediately report the error directly to regulatory authorities.

Discussion 0
Questions 152

Evidence discovered during the course of an engagement suggests that multiple incidents of fraud have occurred. There do not appear to be sufficient controls in place to prevent reoccurrence. Which of the following is the internal auditor ' s most appropriate next step?

Options:

A.  

Immediately notify management of the area under review and the other internal auditors involved in the engagement

B.  

Discuss the situation with the engagement supervisor to determine whether fraud investigation experts are required to investigate the matter properly.

C.  

Fully document in the workpapers the evidence that has been discovered and recommend appropriate controls to address the fraud

D.  

Provide the evidence that was discovered to local lav/ enforcement for possible prosecution of the suspected fraud

Discussion 0
Questions 153

Which of the following statements about internal audit ' s follow-up process is true?

Options:

A.  

The nature, timing, and extent of follow-up for assurance engagements is standardized to ensure quality performance.

B.  

The actions of external auditors and other external assurance providers is not encompassed by internal audit ' s follow-up process.

C.  

Internal auditors have responsibility for determining if management and the board have implemented the recommended action or otherwise accepted the risk.

D.  

The follow-up process must be complete and documented in the working papers in order to conclude the engagement.

Discussion 0
Questions 154

An internal auditor discovered that equipment used to monitor air quality was not maintained according to the established maintenance schedule. If the issue is not addressed, the equipment may not provide accurate information on pollutant levels, which could result in regulatory sanctions and reputational damage. The auditor discussed the issue with both the manager in charge and the CEO, who explained that they understand the risk, but it has become too expensive to maintain the equipment as scheduled. In this situation, what should the chief audit executive do?

Options:

A.  

Add value to the organization by taking initiative and implementing corrective actions to mitigate the identified risks.

B.  

Communicate to the board the current situation, including the risk exposure to the organization.

C.  

Discuss the matter with external auditors and request that they persuade management to address the issue.

D.  

Contact the regulatory agency and inform them of the risk exposure.

Discussion 0
Questions 155

Which of the followings statements describes a best practice regarding assurance engagement communication activities?

Options:

A.  

All assurance engagement observations should be communicated to the audit committee.

B.  

All assurance engagement observations should be included in the main section of the engagement communication.

C.  

During the " communicate " phase of an assurance engagement, it is best to define the methods and timing of engagement communications.

D.  

A detailed escalation process should be developed during the planning stage of an assurance engagement.

Discussion 0
Questions 156

The chief audit executive (CAE) should determine whether the internal audit activity has confirmed the status of all of management ' s corrective actions Doing so would help the CAE assess which of the following?

Options:

A.  

Disclosure risk.

B.  

Residual risk

C.  

Compliance risk

D.  

Inherent risk

Discussion 0
Questions 157

A bicycle manufacturer incurs a combination of fixed and variable costs with the production of each bicycle. Which of the following statements is true regarding these costs?

Options:

A.  

if the number of bicycles produced is increased by 15 percent, the variable cost per unit will increase proportionally

B.  

The fixed cost per unit will vary directly based on the number of bicycles produced during the production cycle.

C.  

The total variable cost will vary proportionally and inversely with the number of bicycles produced during a production run.

D.  

if the number of bicycles produced is increased by 30 percent, the fixed cost per unit will decline.

Discussion 0
Questions 158

An internal auditor has been asked to join a project team to help design controls in a software application to address specific risks that have been identified by the team Which of the following actions is most appropriate for the internal auditor to perform?

Options:

A.  

Facilitate a control assessment to ensure all application risks were appropriately identified

B.  

Advise the project team on how to develop effective controls

C.  

Direct the project team to implement the appropriate controls within the software application

D.  

Provide assurance that the design of the controls will mitigate the identified application risks

Discussion 0
Questions 159

Which of the following actions should the chief audit executive take when senior management decides to accept risks by choosing to do business with a questionable vendor?

Options:

A.  

Persuade senior management to take appropriate action.

B.  

Cancel issuing the engagement report due to the assumed risks.

C.  

Accept senior management’s assumption of the risks.

D.  

Discuss the issue with the board for them to take appropriate action.

Discussion 0
Questions 160

Which of the following is an inherent risk of issuing an opinion on the overall effectiveness of internal control?

Options:

A.  

The results of individual engagements do not support a satisfactory opinion on the effectiveness of internal control.

B.  

The results of the individual engagements do not support a positive assurance opinion on the effectiveness of internal control

C.  

The audit risk and associated legal implications increase

D.  

The reliance on other assurance providers increases

Discussion 0
Questions 161

Which of the following is required to classify, label, organize, and search big data stored and used in an organization?

Options:

A.  

Metadata

B.  

Data security

C.  

A business application

D.  

Data owner

Discussion 0
Questions 162

Which of the following statements best describes the difference between risk appetite and risk tolerance?

Options:

A.  

Risk appetite applies to specific objectives, while risk tolerance refers to an organization ' s general attitude toward risk.

B.  

Risk appetite refers to the degree of risk acceptance for a particular objective, while risk tolerance is one approach to risk management

C.  

Risk appetite refers to an organization’s general level of acceptance, while risk tolerance is a more specific and subordinate concept

D.  

There is no significant difference between the two terms

Discussion 0
Questions 163

Which of the following statements is true regarding different competitive strategies?

Options:

A.  

An organization that adopts a cost leadership competitive strategy generally maintains standard operating procedures to ensure efficiency.

B.  

An organization that adopts a differentiation strategy generally maintains a targeted strategic approach to its operations.

C.  

An organization that adopts a focus strategy is known for taking the lead in technological advancement.

D.  

An organization that adopts a cost leadership strategy is known for cherishing employees who think creatively and emphasize uniqueness.

Discussion 0
Questions 164

For which of the following fraud engagement activities would it be most appropriate to involve a forensic auditor?

Options:

A.  

Independently evaluating conflicts of interests.

B.  

Assessing contracts for relevant terms and conditions.

C.  

Performing statistical analysis for data anomalies.

D.  

Preparing evidentiary documentation.

Discussion 0
Questions 165

Which of the following statements is true regarding engagement planning?

Options:

A.  

The engagement objectives are the boundaries for the engagement, which outline what will be included in the review

B.  

The risk-based objectives of the engagement can be determined once the scope of the engagement has been formed

C.  

For a consulting engagement, planning typically occurs after the engagement objectives and scope have already been determined

D.  

For an assurance engagement, once the scope is established and testing has begun, the scope cannot be modified.

Discussion 0
Questions 166

For a new board chair who has not previously served on the organization’s board, which of the following steps should first be undertaken to ensure effective leadership to the board*?

Options:

A.  

Chair should learn the current organizational culture of the company.

B.  

Chair should learn the current risk management system of the company

C.  

Chair should determine the appropriateness of the current strategic risks.

D.  

Chair should gain an understanding of the needs of key stakeholders.

Discussion 0
Questions 167

An internal auditor performed a review that focused on the organization’s process for vetting vendors. The internal auditor’s testing identified that 120 out of 130 vendors had a business relationship with the organization’s procurement manager that violated conflict-of-interest policies. Which of the following conclusions could the internal auditor draw from these results?

Options:

A.  

The organization is exposed to significant fraud and abuse risks as a result of the vendor and employee business relationships.

B.  

Due to improper relationships and favoritism, vendors are not providing goods or services at a reasonable price to meet the objectives.

C.  

The organization’s conflict-of-interest policies are not clear or well communicated throughout the organization.

D.  

Improper relationships and favoritism means that controls are not effective and significant fraud occurs.

Discussion 0
Questions 168

An internal auditor wanted to determine whether the organization ' s 200 employees are charging their work hours accurately to the correct project. The internal auditor selected a sample of 30 employee time reports for testing. Based on the testing, the internal auditor determined the following:

- 5 Time reports were incorrect.

- 21 Time reports were correct.

- 4 Time reports were not supported.

Options:

A.  

The organization has significant flaws in its reporting of employee time, which could lead to the overstatement of project labor costs. The organization ' s failure to report accurate and complete employee time could lead to potential fraud and abuse.

B.  

The organization needs to ensure that all reporting of employee time is accurate and complete for each of its projects By dang so the organization can minimize potential issues related to overstating employee tames and labor project costs.

C.  

The organization overstated project costs due to inaccurate and incomplete reporting of employee time charged to the affected accounts As a result the organization cannot ensure at protects costs are accurately reported to stakeholders

D.  

The organization generally ensured that employee hours charged to each project were accurate and complete. However, there were instances of employee time reports that were incorrect or not supported to justify the multiple project labor coats

Discussion 0
Questions 169

Which of the following activities demonstrates an example of the chief audit executive performing residual risk assessment?

Options:

A.  

Cost-benefit analysis of management not implementing a recommendation to address an observation.

B.  

Inquiry of corrective action to be completed within a certain period

C.  

Reporting the status of every observation for every engagement in a detailed manner.

D.  

Soliciting management ' s feedback after completion of the audit engagement.

Discussion 0
Questions 170

During an audit of suspense accounts the internal auditor found that there were no written policies on how suspense accounts should be treated. The auditor also found that suspense account balances were cleared once per week, not daily. Which of the following is the most appropriate first response by the auditor?

Options:

A.  

The auditor should conclude that suspense accounts were not being cleared on a timely basis because they should be cleared daily

B.  

The auditor should ask management whether any undocumented policies exist and. if so, determine whether they are adequate

C.  

The auditor should conclude that the clearing of suspense accounts was timely and appropriate because weekly clearing is sufficient.

D.  

The auditor should rely on his professional judgment and experience to develop criteria for evaluating the existing controls over suspense accounts

Discussion 0
Questions 171

Which informal ion- gathering method would be most efficient for an internal auditor to determine whether specified control procedures are in place?

Options:

A.  

Interviews

B.  

Observations

C.  

Reperformance

D.  

Internal control questionnaires

Discussion 0
Questions 172

An organization must maintain a current ratio of at least 1.2 to comply with debt covenants. Its current ratio is now 0.9. Which year-end transaction can increase the current ratio?

Options:

A.  

Paying off an overdraft debt using funds from another bank current account.

B.  

Purchasing inventory using funds from long-term bank loans.

C.  

Acquiring a new car through leasing.

D.  

Factoring short-term accounts receivable in exchange for cash.

Discussion 0
Questions 173

It is close to the fiscal year end for a government agency, and the chief audit executive (CAE) has the following items to submit to either the board or the chief executive officer (CEO) for approval. According to IIA guidance, which of the following items should be submitted only to the CEO?

Options:

A.  

The internal audit risk assessment and audit plan for the next fiscal year.

B.  

The internal audit budget and resource plan for the coming fiscal year.

C.  

A request for an increase of the CAE ' s salary for the next fiscal year.

D.  

The evaluation and compensation of the internal audit team.

Discussion 0
Questions 174

Which of the following is not an outcome of control self-assessment?

Options:

A.  

Informal, soft controls are omitted, and greater focus is placed on hard controls.

B.  

The entire objectives-risks-controls infrastructure of an organization is subject to greater monitoring and continuous improvement.

C.  

Internal auditors become involved in and knowledgeable about the self-assessment process.

D.  

Nonaudit employees become experienced in assessing controls and associating control processes with managing risks.

Discussion 0
Questions 175

When setting the scope for the identification and assessment of key risks and controls in a process, which of the following would be the least appropriate approach?

Options:

A.  

Develop the scope of the audit based on a bottom-up perspective to ensure that all business objectives are considered.

B.  

Develop the scope of the audit to include controls that are necessary to manage risk associated with a critical business objective.

C.  

Specify that the auditors need to assess only key controls, but may include an assessment of non-key controls if there is value to the business in providing such assurance.

D.  

Ensure the audit includes an assessment of manual and automated controls to determine whether business risks are effectively managed.

Discussion 0
Questions 176

Which of the following best describes the risk contained in an initial public offering for a new stock?

Options:

A.  

Residual risk.

B.  

Net risk.

C.  

Inherent risk.

D.  

Underlying risk

Discussion 0
Questions 177

When estimating the impact of an inherent risk, which of the following should internal auditors consider?

Options:

A.  

The probability and frequency of occurrence

B.  

Financial and nonfinancial factors related to the risk

C.  

The number of risks identified on the heat map

D.  

The residual risk following implementation of appropriate controls

Discussion 0
Questions 178

Considering the five-attribute approach to documenting deficiencies in an area under review which of the following answers the question. " What should be in place?’’

Options:

A.  

Action plan

B.  

Recommendation

C.  

Condition

D.  

Criteria

Discussion 0
Questions 179

What is the primary reason that audit supervision includes approval of the engagement report?

Options:

A.  

To ensure the objectives of the area under review are met.

B.  

To ensure senior management supports the report ' s conclusions.

C.  

To ensure report style and grammar are appropriate.

D.  

To ensure report findings are substantiated.

Discussion 0
Questions 180

Which of the following is an appropriate documentation of proper engagement supervision?

Options:

A.  

A completed engagement workpaper review checklist.

B.  

The supervisor ' s review notes on engagement workpapers.

C.  

The email exchanges between the audit team and the supervisor.

D.  

A supervisor ' s approval of resources allocated to the engagement

Discussion 0
Questions 181

An internal auditor determined that the organization ' s accounting system was designed to reject duplicate invoices if they were issued with identical invoice numbers. However, if an invoice number was changed by at least one digit, the system would accept the duplicate invoice as new. Which of the following would be the most appropriate criteria to refer to in the audit observation?

Options:

A.  

Each invoice for goods or services acquired by the organization must be recorded only once in the accounting system.

B.  

The accounting system lacks efficient controls for the identification of duplicate invoices.

C.  

Disbursements may be made inappropriately, and liabilities may be overstated.

D.  

The accounting system is at the end of its lifetime and is no longer developed by the provider.

Discussion 0
Questions 182

For an action plan to be effective, it should be designed primarily to address which of the following elements of an observation?

Options:

A.  

Condition

B.  

Root cause

C.  

Criteria

D.  

Recommendation

Discussion 0
Questions 183

According to IIA guidance, which of the following statements is true regarding engagement planning?

Options:

A.  

For both assurance and consulting engagements, planning typically occurs after the engagement objectives and scope have already been determined.

B.  

The expectations and objectives of an assurance engagement are usually determined by, or in conjunction with, the engagement client.

C.  

Internal auditors may not need to complete a preliminary risk assessment for a consulting engagement as they would when planning an assurance engagement.

D.  

For both consulting and assurance engagements, internal auditors usually form the engagement objectives prior to completing the preliminary risk assessment.

Discussion 0
Questions 184

Which of the following components should be included in an audit finding?

1. The scope of the audit.

2. The standard(s) used by the auditor to make the evaluation.

3. The engagement ' s objectives.

4. The factual evidence that the internal auditor found in the course of the examination.

Options:

A.  

1 and 2

B.  

1 and 3 only

C.  

2 and 4

D.  

1, 3, and 4

Discussion 0
Questions 185

An internal auditor wants to compare performance information from one quarter to another. Which analytics procedure would the auditor use?

Options:

A.  

Ratio analysis

B.  

Trend analysis

C.  

Vertical analysis

D.  

Benchmarking analysis

Discussion 0
Questions 186

An internal auditor submitted a report containing recommendations for management to enhance internal controls related to investments. To follow up, which of the following is the most appropriate action for the internal auditor to take?

Options:

A.  

Observe corrective measures.

B.  

Seek a management assurance declaration.

C.  

Follow up during the next scheduled audit.

D.  

Conduct appropriate testing to verify management responses.

Discussion 0
Questions 187

Which procedure should an internal auditor perform to determine the audit objective?

Options:

A.  

Meet with the board to discuss emerging issues and concerns

B.  

Conduct a risk assessment of the area under review

C.  

Establish the boundaries of the engagement

D.  

Outline what will be included in the review

Discussion 0
Questions 188

Which of the following is the primary reason to develop an audit work program?

Options:

A.  

To alert operational management to the types of audit tests that will likely be performed.

B.  

To help the engagement team understand which tasks have to be performed and how.

C.  

To assist with communicating all relevant audit findings, conclusions, and recommendations to operational management.

D.  

To facilitate the supervision of the audit engagement and enable the chief audit executive to provide relevant feedback.

Discussion 0
Questions 189

Which of the following is an advantage of an internal audit activity coordinating with a management-defined risk universe?

Options:

A.  

Increased completeness, including risk categories like political, supplier, and social media.

B.  

Business managers can identify and assess risks that occur within each category.

C.  

The internal audit activity can rely on management ' s risk assessment.

D.  

Organizationwide audits are required since risk events within categories occur in many different ways.

Discussion 0
Questions 190

Which of the following is the most appropriate approach for the internal audit activity to follow up on management action plans?

Options:

A.  

Create a tracking system for follow up

B.  

Ensure that follow-up activities are performed at least weekly.

C.  

Delegate follow-up activities to qualified administrative staff within the business unit

D.  

Ensure that follow-up activities are performed by the most senior auditor on staff

Discussion 0
Questions 191

Which of the following is an effective approach for internal auditors to take to improve collaboration with audit clients during an engagement?

1. Obtain control concerns from the client before the audit begins so the internal auditor can tailor the scope accordingly.

2. Discuss the engagement plan with the client so the client can understand the reasoning behind the approach.

3. Review test criteria and procedures where the client expresses concerns about the type of tests to be conducted.

4. Provide all observations at the end of the audit to ensure the client is in agreement with the facts before publishing the report.

Options:

A.  

1 and 2 only

B.  

1 and 4 only

C.  

2 and 3 only

D.  

3 and 4 only

Discussion 0
Questions 192

Which of the following behaviors could represent a significant ethical risk if exhibited by an organization ' s board?

1. Intervening during an audit involving ethical wrongdoing.

2. Discussing periodic reports of ethical breaches.

3. Authorizing an investigation of an unsafe product.

4. Negotiating a settlement of an employee claim for personal damages.

Options:

A.  

1 and 2

B.  

1 and 4

C.  

2 and 3

D.  

3 and 4

Discussion 0
Questions 193

Which of the following information is most appropriate for the chief audit executive to share when coordinating audit plans with other internal and external assurance providers?

Options:

A.  

Objectives scope and timing at a high level to support coordination while adhering to confidentiality requirements

B.  

The area and timing of the audit engagement to ensure confidentially and avoid conflict of interest.

C.  

All plan information, including risk assessments, planned tests and past results to maximize the opportunity for coordination with internal and external providers.

D.  

No information should be shared with internal and external provider as it could introduce bias into the engagement results.

Discussion 0
Questions 194

How should an internal auditor approach preparing a detailed risk assessment during engagement planning?

Options:

A.  

Complete the risk assessment independently to prevent conflicts of interest with the function being reviewed.

B.  

Work with external auditors to ensure that the risk assessment includes items reflected on the independent auditor ' s report.

C.  

Work with management of the function being reviewed, as management would be most familiar with the business objectives and related risks.

D.  

Consult with the compliance department, which typically has a more comprehensive view of the organization.

Discussion 0
Questions 195

When constructing a staffing schedule for the internal audit activity (IAA), which of the following criteria are most important for the chief audit executive to consider for the effective use of audit resources?

1. The competency and qualifications of the audit staff for specific assignments.

2. The effectiveness of IAA staff performance measures.

3. The number of training hours received by staff auditors compared to the budget.

4. The geographical dispersion of audit staff across the organization.

Options:

A.  

1 and 3

B.  

1 and 4

C.  

2 and 3

D.  

2 and 4

Discussion 0
Questions 196

Which of the following could increase risks to the organization’s control environment?

Options:

A.  

Strong board of directors oversight.

B.  

Incentive-based compensation structures

C.  

Lower than average employee turnover.

D.  

Implementation of a fraud hotline

Discussion 0
Questions 197

According to IIA guidance, which of the following is least likely to be a key financial control in an organization ' s accounts payable process?

Options:

A.  

Require the approval of additions and changes to the vendor master listing, where the inherent risk of false vendors is high.

B.  

Monitor amounts paid each period and compare them to the budget to identify potential issues.

C.  

Compare employee addresses to vendor addresses to identify potential employee fraud.

D.  

Monitor customer quality complaints compared to the prior period to identify vendor issues.

Discussion 0
Questions 198

While reviewing the workpapers and draft report from an audit engagement, the chief audit executive (CAE) found that an important compensating control had not been considered adequately by the audit team when it reported a major control weakness. Therefore, the CAE returned the documentation to the auditor in charge for correction. Based on this information, which of the following sections of the workpapers most likely would require changes?

Effect of the control weakness.

Cause of the control weakness.

Conclusion on the control weakness.

Recommendation for the control weakness.

Options:

A.  

1, 2, and 3.

B.  

1, 2, and 4.

C.  

1, 3, and 4.

D.  

2, 3, and 4.

Discussion 0
Questions 199

Which of the following analytical procedures should an internal auditor use to determine whether monthly expenses for the accounting department are reasonable?

Options:

A.  

Review year-over-year trending of total dollars spent in each period.

B.  

Review changes to the vendor master file for suspicious activity.

C.  

Review the percentage of on-time payments against prior periods.

D.  

Review total expenses for accounting against other department expenses in the organization.

Discussion 0
Questions 200

What is a control implication for an organization that adopts a flat structure?

Options:

A.  

Mid-level employees are urged to innovate.

B.  

Available time for supervision is limited.

C.  

There are many hierarchical levels.

D.  

The organizational structure is dispersed vertically.

Discussion 0
Questions 201

Which of the following is the primary reason a chief audit executive should network with an organization’s executives?

Options:

A.  

To better understand and influence executives ' planning.

B.  

To make executives aware of the benefits that the internal audit activity can provide.

C.  

To assist executives in setting the organization’s risk appetite.

D.  

To have a better understanding of the training needed to strengthen the audit team.

Discussion 0
Questions 202

Which of the following best illustrates the primary focus of a risk-based approach to control self-assessment?

Options:

A.  

To evaluate controls regarding the computer security of an oil refinery.

B.  

To examine the processes involved in exploring, developing, and operating a gold mine.

C.  

To assess the likelihood and impact of events associated with operating a finished goods warehouse.

D.  

To link a financial institution ' s business objectives to a work unit responsible for the associated risk.

Discussion 0
Questions 203

During an audit of the accounts payable process, an internal auditor was assigned to confirm the quantity of goods received on receiving documents to invoices for those goods and subsequent postings in the accounting system. Which of the following procedures would be most appropriate for this test?

Options:

A.  

Independent confirmation

B.  

Tracing

C.  

Vouching

D.  

Reperformance

Discussion 0
Questions 204

The internal audit manager has been delegated the task of preparing the annual internal audit plan for the forthcoming fiscal year All engagements should be appropriately categorized and presented to the chief audit executive for review Which of the following would most likely be classified as a consulting engagement?

Options:

A.  

Evaluating procurement department process effectiveness

B.  

Helping in the design of the risk management program

C.  

Assessing financial reporting control adequacy

D.  

Reviewing environmental, social, and governance reporting compliance

Discussion 0
Questions 205

Which of the following statements accurately describes the Standards requirement for ret internal audit records?

Options:

A.  

Retention requirements for internal audit records should be compliant with ones set for external audit records

B.  

Retention requirements should take into account the medium in which internal audit records are stored

C.  

Retention requirements should be set by the chief audit executive and aligned will the organization s process and procedures

D.  

Retention requirements should set a minimum period of the for records storage and the process of archiving documents

Discussion 0
Questions 206

Internal auditors map a process by documenting the steps in the process, which provides a framework for understanding Which of the following is a reason to use narrative memoranda?

Options:

A.  

To create a detailed risk assessment

B.  

To identify individuals who perform key roles

C.  

To explain a simple process.

D.  

To document which outputs support other activities.

Discussion 0
Questions 207

Following an IT systems audit, management agreed to implement a specific control in one of the IT systems. After a period, the internal auditor followed up and learned that management had not implemented the agreed management action due to the decision to move to another IT system that has built-in controls, which may address the risks highlighted by the internal audit. Which of the following is the most appropriate action to address the outstanding audit recommendation?

Options:

A.  

The auditor examines the system documentation of the new system to verify that the risk has been addressed in the new system, then reports to senior management the closure of the issue.

B.  

The auditor accepts management ' s explanation that the previously identified issue is adequately addressed by the new IT system, as management understands the concern and is most knowledgeable about the new system, and closes the outstanding issue.

C.  

The auditor advises management that replacing the IT system does not dismiss the prior obligation to implement the agreed action plan, and escalates the issue to senior management and the board.

D.  

The auditor requires management to provide details regarding the process for selecting the new IT system and whether other systems were evaluated, and closure of the issue would depend on the new information provided.

Discussion 0
Questions 208

Which type of assurance engagement is conducted to determine whether a process or area is performing as intended, accomplishing its objectives, and doing so in an efficient and economical way?

Options:

A.  

Compliance audit.

B.  

Operational audit.

C.  

Financial audit.

D.  

Provider audit.

Discussion 0
Questions 209

The internal audit activity is planning an assurance engagement for a foreign subsidiary. According to IIA guidance, which of the following would be included in the preliminary communication to management of the area under review?

Options:

A.  

The scope of the engagement, the estimated time frame, and the names of the auditors.

B.  

The estimated time frame, the names of the auditors, and the resources and travel budget.

C.  

The names of the auditors, the resources and travel budget, and the scope of the engagement.

D.  

The resources and travel budget, the scope of the engagement, and the estimated time frame.

Discussion 0
Questions 210

Which of the following is a significant governance issue that should be reported by the chief audit executive to the board?

Options:

A.  

There is no risk management and control process and risk management is solely tie responsibility of operational managers

B.  

The organisation’s code of conduct is distributed to employees each year however employees are not required to attest that they will operate In compliance with the code.

C.  

Reconciliation of planned board meeting agendas to meeting minutes finds that one meeting was canceled, and the agenda topics were covered at the following meeting.

D.  

The review of the five-year strategic plan shows that the details of the plan have not been dearly communicated to employees throughout the organization

Discussion 0
Questions 211

Following an audit, management developed an action plan to improve controls over the handling of scrap metal. Which of the following would be the most appropriate course of action for the auditor to follow up?

Options:

A.  

Conduct another audit engagement to ensure all risks related to the sales of scrap metal have been mitigated.

B.  

Ensure new procedures have been documented, approved, and distributed to the employees responsible.

C.  

Perform retesting to confirm that new procedures address the previously identified deficient control activities.

D.  

Analyze the new procedures, then report to senior management whether the associated risks have been managed.

Discussion 0
Questions 212

According to IIA guidance, which of the following most appropriately justifies the CEO’s decision that the internal audit activity shall be responsible for risk management and Investigation at multinational organization?

Options:

A.  

The recommendation of the parent office external auditors.

B.  

The provisions of the internal audit charter.

C.  

The authority of the CEO.

D.  

The level of proficiency of the chief audit executive

Discussion 0
Questions 213

An internal auditor is assessing whether a vendor onboarding procedure is being followed in all business units. The procedure has been centrally designed and depicts activities and validations that must be performed at every step. Which of the following is the most suitable way to compile an internal control questionnaire?

Options:

A.  

Develop statements that are based on the procedure requirements and ask respondents to select yes or no responses

B.  

Develop open questions that inquire about the appropriateness and efficacy of the procedure

C.  

Develop closed questions asking managers to describe the onboarding process in detail

D.  

Develop multiple response questions where a respondent has to identify one correct answer out of four

Discussion 0
Questions 214

Flowcharts are useful during audit planning because they contain information that may help internal auditors with which of the following?

Options:

A.  

Understanding management ' s risk tolerance.

B.  

Understanding business processes.

C.  

Determining the size of the audit team needed to perform the review.

D.  

Understanding organizational objectives.

Discussion 0
Questions 215

An audit client responded to recommendations from a recent consulting engagement. The client indicated that several recommended process improvements would not be implemented. Which of the following actions should the internal audit activity take in response?

Options:

A.  

Escalate the unresolved issues to the board, because they could pose significant risk exposures to the organization.

B.  

Confirm the decision with management and document this decision in the audit file.

C.  

Document the issue in the audit file and follow up until the issues are resolved.

D.  

Initiate an assurance engagement on the unresolved issues.

Discussion 0
Questions 216

Which of the following conditions are necessary for successful change management?

1. Decisions and necessary actions are taken promptly.

2. The traditions of the organization are respected.

3. Changes result in improvement or reform.

4. Internal and external communications are controlled.

Options:

A.  

1 and 2

B.  

1 and 3

C.  

2 and 3

D.  

2 and 4

Discussion 0
Questions 217

According to an internal audit observation, the organization’s rules of record management require all contracts to be registered and stored in a specific electronic system. One subsidiary has thousands of client contracts on paper, which are kept in the office because there are not enough assistants to scan the contracts into the system. Which of the following component should be added to this observation?

Options:

A.  

Criteria

B.  

Cause

C.  

Effect

D.  

Condition

Discussion 0
Questions 218

Which of the following is the advantage of using internal control questionnaires (ICQs) as part of a preliminary survey for an engagement?

Options:

A.  

ICQs provide testimonial evidence.

B.  

ICQs are efficient.

C.  

ICQs provide tangible evidence to be quantified.

D.  

ICQs put observations into perspective.

Discussion 0
Questions 219

According to IIA guidance, which of the following statements is true regarding audit workpapers?

Options:

A.  

Review notes on audit workpapers must be retained to provide a record of questions raised by the reviewer.

B.  

Audit workpaper documentation policies are reviewed and approved by the audit committee.

C.  

Management of the department being audited should review the prepared workpapers for accuracy.

D.  

Audit workpaper preparation contributes to the professional development of the internal audit staff.

Discussion 0
Questions 220

According to IIA guidance, which of the following best describes the purpose of a planning memorandum for an audit engagement?

Options:

A.  

It documents the audit steps and procedures to be performed.

B.  

it documents preliminary information useful to the audit team.

C.  

It documents events that could hinder the achievement of process objectives.

D.  

It documents existing measures that manage risks in the area under review

Discussion 0
Questions 221

An internal auditor concluded that delays in an ongoing construction project have cost the organization $10 million to date. Which documents should be included in the audit workpapers to provide sufficient evidence to support the conclusion?

Options:

A.  

Payment and work milestones

B.  

Pictures from the construction site

C.  

Initial sprint planning

D.  

Project internal rate of return

Discussion 0
Questions 222

Which of the following is the primary reason for internal auditors to conduct interim communications with management of the area under review?

Options:

A.  

To demonstrate good project oversight

B.  

To provide timely discussion of results

C.  

To demonstrate internal auditor proficiency

D.  

To follow up on previously requested information

Discussion 0
Questions 223

Which of the following statements is true regarding the management-by-objectives method?

Options:

A.  

Management by objectives is most helpful in organizations that have rapid changes

B.  

Management by objectives is most helpful in mechanistic organizations with rigidly defined tasks.

C.  

Management by objectives helps organizations to keep employees motivated.

D.  

Management by objectives helps organizations to distinguish clearly strategic goals from operational goals

Discussion 0