Spring Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

IIA-CIA-Part1 Questions and Answers

Question # 6

For a new board chair who has not previously served on the organization's board, which of the following steps should first be undertaken to ensure effective leadership to the board?

A.

Chair should learn the current organizational culture of the company.

B.

Chair should learn the current risk management system of the company.

C.

Chair should determine the appropriateness of the current strategic risks.

D.

Chair should gain an understanding of the needs of key stakeholders.

Full Access
Question # 7

Which of the following would be the most appropriate first step for the board to take when developing an effective system of governance?

A.

Determine the organization’s overall risk appetite.

B.

Establish a governance committee.

C.

Delegate authority to members of senior management.

D.

Identify key stakeholders and their expectations

Full Access
Question # 8

According to IIA guidance, which of the following is the strongest indicator of deficiencies in the risk management process?

A.

The periodic evaluation of risk ratings is primarily dependent on subjective assessments.

B.

Separate evaluations of the risk management process were conducted, but the results were never integrated.

C.

Management's primary objective is minimizing changes to the structure and operation of the risk management process.

D.

Many aspects of the related enterprise risk management program are informal and undocumented.

Full Access
Question # 9

An internal auditor discovered that a former colleague from the internal audit activity now works in a junior position in a department scheduled for an upcoming audit. How can the auditor best ensure his objectivity for this engagement?

A.

Recommend mat the chief audit executive outsource the upcoming audit engagement

B.

Proceed with the audit engagement in accordance with the internal audit manual

C.

Increase the amount of fieldwork in order to build greater credibility for audit conclusions

D.

Declare a conflict of interest and hand over the engagement to another auditor

Full Access
Question # 10

The internal audit activity is responsible for conducting fraud investigations. A potential fraud instance was identified during an audit engagement. The chief audit executive appoints a lead investigate. Which of the following would most likely be the next step?

A.

Ask internal auditors to gather all relevant information evidence

B.

Identify and interview witnesses first potential suspects later.

C.

Conduct a fraud risk assessment to the most vulnerable areas.

D.

Determine me competencies needed and assess whatever team members have a conflict of interest.

Full Access
Question # 11

Of all the common characteristics of frauds, which of the following can the organization influence the most?

A.

Pressure or incentive.

B.

Rationalization

C.

Opportunity

D.

Commitment.

Full Access
Question # 12

Which of the following best describes the board’s role in establishing effective organizational governance?

A.

The board is involved in approving operational policy

B.

The board monitors key processes and procedures

C.

The board has oversight responsibility for organizational resources

D.

The board approves management's detailed plans and objectives

Full Access
Question # 13

Which of the following should catch the internal auditor's attention as a potential red flag for fraud?

A.

The accounting unit keeps detailed records and preserves supporting documentation in excess of company requirements

B.

One of the subsidiaries has more bank accounts than any other comparable subsidiary

C.

The same external audit firm has been with the company for three years without rotation

D.

The arithmetic median tenure of employees working at production facilities is 15 years

Full Access
Question # 14

According to the Standards, in today's technology and business environments, how much computer and information systems-related knowledge and skills must an internal auditor have to be effective in fulfilling his job responsibilities?

A.

Auditors must have an IT specialty in at least one of their organization's key information technology systems.

B.

Auditors must be proficient in data analysis and computer assisted audit techniques for their organization.

C.

Auditors must understand their organization's integrated test facilities and generalized audit software.

D.

Auditors must understand their organization's IT governance, risk, and control processes.

Full Access
Question # 15

Which of the following should be considered in developing a risk and control model for use in an engagement?

A.

The risk and control model should be globally accepted by the profession.

B.

The risk and control model should be strictly adhered to in performing the engagement.

C.

The risk and control model should be tailored to the organization that will be the subject of the engagement.

D.

The risk and control model should be developed individually by the auditor for use on individual audit projects within the planned engagement.

Full Access
Question # 16

Which of the following is an example of a directive control?

A.

Segregation of duties.

B.

Exception reports.

C.

Training programs.

D.

Supervisory review.

Full Access
Question # 17

According to IIA guidance, an internal audit charter should detail which of the following?

A.

The objectives and goals of management

B.

The process used by the CAE to manage the organization's internal controls

C.

The nature of services that the internal audit activity will provide to external third parties

D.

The responsibilities of the audit committee

Full Access
Question # 18

Which of the following is an appropriate role for the internal audit activity?

A.

Ensuring the organization's key risks are managed through appropriate controls.

B.

Assisting the organization in maintaining effective controls.

C.

Implementing new controls to promote continuous improvement.

D.

Validating control assessments performed by the external auditor.

Full Access
Question # 19

Which of the following is a primary responsibility of senior management with respect to ethical violations?

A.

Senior management provides oversight for the organization's ethical climate.

B.

Senior management promotes an ethical culture in the organization.

C.

Senior management assesses the effectiveness of the organization’s ethical programs.

D.

Senior management reviews major ethical policies in the organization for compliance

Full Access
Question # 20

A business unit manager was impressed by the competence of the internal auditor who was conducting an assurance engagement in his area and the manager made the auditor an attractive job offer to begin after the audit was completed The auditor later told her auditor in charge that she was considering the offer. Which of the following IIA Code of Ethics principles was most likely violated?

A.

Integrity

B.

Confidentiality

C.

Objectivity

D.

No violation was committed

Full Access
Question # 21

An internal auditor is finalizing an audit report on the effectiveness of the organization's overall system of internal control. Several audit tests were performed, and the only issue identified was that the CEO frequently asks employees to make exceptions or bypass the organization's standard written policies and procedures. Which of the following conclusions is most appropriate for the auditor to report?

A.

The auditor should indicate that the system of internal control is not effective.

B.

The auditor should indicate that the system of internal control is generally effective, except for the minor issue identified.

C.

The auditor should indicate that the system of internal control is effective.

D.

The auditor cannot express a conclusive opinion in the audit report.

Full Access
Question # 22

An internal auditor has documented several instances in which management asked employees to ad against the policies and procedures. Which of the following is the most appropriate next step?

A.

Report the non-compliance cases to the board of directors.

B.

Recommend that management update its policies and procedures based on the circumstances.

C.

Investigate the rationale for management's actions.

D.

Recommend those employees to report the cases through the designed whistleblowing channel for the appropriate treatment.

Full Access
Question # 23

Which of the following internal controls best mitigates the risk of corruption schemes between employees and vendors?

A.

Establishing policies that prohibit an employee from receiving gifts from an interested party.

B.

Having employees sign annual attestations that they adhere to the organization's code of ethics.

C.

Having strong management oversight of the purchasing and accounts payable functions.

D.

Conducting regular examinations of documentation both paper and electronic.

Full Access
Question # 24

Which of the following describes a responsibility of operating management in an organization's corporate social responsibility (CSR) efforts?

A.

Responsible for implementing CSR principles and overseeing of CSR performance.

B.

Responsible for performing periodic internal self-verifications of reported CSR results.

C.

Responsible for performing analysis and comparison of CSR reports and performance.

D.

Responsible for ongoing CSR reporting and accomplishing of performance targets.

Full Access
Question # 25

Which of the following organizations is adopting an acceptance technique in terms of its risk response?

A.

An organization that takes no action in managing the possible exposure to an earthquake.

B.

An organization that opts out of investing in a new region due to volatility in foreign exchange rates.

C.

An organization that takes out insurance policies to protect its property and equipment.

D.

An organization that deploys policies and procedures to guide business activities and practices

Full Access
Question # 26

Which of the following best demonstrates organizational independence of the internal audit activity?

A.

The chief audit executive reports directly to the board

B.

Internal auditors may not disclose personal data of the audit client

C.

Internal auditors may not accept gifts from management of the area under review

D.

Internal auditors must observe the law and make required disclosures

Full Access
Question # 27

According to IIA guidance, which of the following statements is true regarding internal auditors' knowledge, skills and other competencies?

A.

The chief audit executive (CAE) must obtain competent advice and assistance if the internal audit activity lacks the knowledge, skills, or other competencies needed to complete the audit engagement

B.

Internal auditors must have sufficient knowledge to evaluate the risk of fraud and the manner in which it is managed by the organization and should have the expertise of a fraud investigator

C.

Internal auditors need to have basic knowledge of key IT risks and controls and available technology-based audit techniques in order to perform their assigned work

D.

The CAE must refuse a consulting engagement if the internal audit activity lacks the knowledge, skills, or other competencies needed to perform all or part of the engagement

Full Access
Question # 28

Which of the following best illustrates the principle of due professional care?

A.

The internal audit activity uses key performance indicators for all staff members after all audit engagements.

B.

The internal auditors provide assurance to third parties indicating that their work was properly supervised.

C.

The internal auditors demonstrate they have an understanding of engagement objectives and scope.

D.

The internal auditors are heavily involved in training and development to enhance their skills.

Full Access
Question # 29

Which of the following activities best demonstrates an internal auditor’s commitment to developing professional competencies?

A.

Requesting to be part of all engagements on the annual audit plan.

B.

Attending a series of locally offered training courses.

C.

Completing a skills assessment and development plan for targeted training needs,

D.

Attending a webinar on how to use data analytics

Full Access
Question # 30

Which of the following is most likely to result in the impairment of independence for the internal audit activity?

A.

The chief audit executive (CAE) has a dual reporting relationship within the organization.

B.

The CAE performs an audit of a functional area that is also under the CAE's oversight.

C.

The CAE has unrestricted access to information throughout the organization and to the board.

D.

The board is involved in decisions to hire or remove the CAE and in drafting and approving an internal audit charter.

Full Access
Question # 31

According to IIA guidance which of the following statements regarding ethics is true?

A.

Business ethics may vary within an organization with both domestic and foreign operations

B.

Business ethics are universal n nature and organizations across the world are expected to comply with smear standards

C.

A business ethics policy for an organization s established solely to direct me behavior and expectations of employees

D.

Business ethics of an organization must remain independent torn those of supplier’s customers and business partners

Full Access
Question # 32

At what point in time can an organization conclude that the established organizational governance framework was correctly implemented?

A.

When the internal auditor conducts observations and fieldwork.

B.

When management completes the risk assessment.

C.

When the internal auditor evaluation shows its soundness.

D.

When the organization's goals and objectives are met.

Full Access
Question # 33

Which of the following written documents typically offers the best evidence that internal auditors exercise due professional care in conformance with the Standards?

A.

Internal audit charter.

B.

Workpaper.

C.

Audit report.

D.

Code of ethics.

Full Access
Question # 34

Which of the following options describes the reason that conformance with The IIA's Code of Ethics is mandatory for internal auditors?

A.

Ethical compliance provides the basis for stakeholder confidence in the competence of the internal audit activity and of professional internal auditors.

B.

Ethical compliance is necessary for internal auditors and the internal audit activity to accept responsibility for providing g absolute assurance about the organization's risk management.

C.

Ethical compliance provides the basis for stakeholder trust and confidence in the validity of the profession of internal auditing and the internal audit activity's findings.

D.

The internal audit activity's ethical compliance sets the tone for the ethical compliance by the organization's board, management, and employees.

Full Access
Question # 35

Which of the following would be most helpful to measure whether an internal audit activity successfully provides risk-based assurance?

A.

Percentage of highly significant risks covered by internal audit plan.

B.

Percentage of previously unknown risks identified per engagement.

C.

Percentage of internal audit staff skilled in alignment with the organization's structure and key risks.

D.

Percentage of observations made in assurance engagements compared to advisory engagements.

Full Access
Question # 36

According to ISO 31000, which of the following statements is correct?

A.

The board is responsible for setting the organizational attitude through tone at the top,

B.

The internal audit activity will provide assurance over operating effectiveness but not over the design of risk management activities,

C.

The internal audit activity can give objective assurance on any part of the risk management framework for which it is responsible.

D.

The framework is designed to be effective for organizations no matter how small.

Full Access
Question # 37

Which of the following documents are internal auditors most likely to be asked to sign as a demonstration of due professional care?

A description of their job responsibilities,

A.

A non-disclosure agreement.

B.

An annual declaration of commitment to

C.

The IIA s Code of Ethics.

D.

The internal audit charter.

Full Access
Question # 38

Which of the following describes a primary responsibility for the internal audit activity in helping management maintain effective controls?

A.

Promoting continuous evaluation

B.

Promoting continuous monitoring

C.

Promoting continuous improvement

D.

Promoting continuous reporting

Full Access
Question # 39

Wi ch of the following circumstances would most likely be considered a potential red flag for fraud by the internal audit activity?

A.

The monthly payroll reports are not vetted to ensure terminated employees have been removed from the payroll system

B.

The volume of nonroutine journal entries has steadily increased over time.

C.

The database of approved suppliers has not been reviewed the last year

D.

The recent employee survey indicates that some employees remain unaware of the organization’s whistieblower hotline.

Full Access
Question # 40

The board of a newly established organization was discussing the contents of the draft internal audit charter One board member suggested adding to the charter an obligation for the internal audit activity to develop controls in business procedures. The board member explained that the new organization needs professional-level developers, internal auditors have the necessary skills and competencies, and the internal audit activity is well positioned to assume this responsibility. Which of the following would be a potential concern if the board member’s suggestion is adopted?

A.

Due professional care.

B.

Internal audit objectivity.

C.

Risk management assurance.

D.

Professional development.

Full Access
Question # 41

Which of the following best describes a proactive role for the internal audit activity with regard to the organization's ethics program?

A.

Becoming a voting member of the organization's internal ethics council.

B.

Performing an annual organizationwide employee survey.

C.

Reviewing all departmental ethics-related policies.

D.

Conducting annual ethics training for all employees.

Full Access
Question # 42

An organization is testing a new IT system for digital data storage and security. The internal audit activity has been asked to evaluate the system in a consulting engagement. Although several internal auditors on staff are qualified to perform basic assessments of IT systems, none are familiar with the new system. Which of the following is a legitimate response to the prospective client?

1. Decline the engagement.

2. Proceed with the engagement, performing only those parts of the engagement that the internal auditors are qualified to perform.

3. Accept the engagement and develop the additional competencies in-house prior to the engagement's starting date.

4. Make arrangements to obtain assistance from a competent IT auditing expert.

A.

1 and 4 only.

B.

2 and 3 only.

C.

1. 2, and 3 only.

D.

1, 3, and 4 only.

Full Access
Question # 43

Which of the following scenarios would cause a chief audit executive (CAE) to immediately discontinue using any statements that would indicate conformance with the Standards in an audit report?

A.

The internal audit activity used a risk-based approach to create the internal audit plan.

B.

The engagement supervisor considered requests from senior management regarding engagements to include in the internal audit plan.

C.

The CAE only accepted engagements that the internal audit activity collectively had the knowledge to perform.

D.

The area under review restricted the internal audit activity's ability to access records, impacting the audit results.

Full Access
Question # 44

Which of the following policies promotes internal audit objectivity?

A.

The chief audit executive (CAE) reports functionally to the CEO

B.

The CAE s compensation is approved by the chief financial officer

C.

The CAF's appointment is determined by the CEO

D.

The CAE reports administratively to the chief operating officer

Full Access
Question # 45

A chief audit executive (CAE) identifies that the internal audit activity lacks a necessary skill to perform a management request for a consulting engagement. According to IIA guidance, which of the following is the most appropriate action the CAE should take regarding the request?

A.

Assign the engagement to a more senior internal auditor.

B.

Decline the engagement request.

C.

Allow the internal auditors to acquire the needed skills while performing the engagement.

D.

Supervise the assigned internal auditors throughout the engagement.

Full Access
Question # 46

According to IIA guidance, which of the following actions best demonstrates due professional care by an internal auditor when she discovers a number of fraud-related red flags during an audit engagement?

A.

Conclude the engagement and inform management that fraud has occurred

B.

Perform further testing to verify the existence of fraud.

C.

Suspend the engagement and undertake a formal fraud investigation.

D.

Notify the board of the possible fraud immediately

Full Access
Question # 47

Under which of the following circumstances should the final audit report include a disclosure of nonconformance with the Standards?

A.

An external quality assessment of the internal audit activity is performed only once every five years.

B.

The internal auditor provided negative assurance, because he found no evidence of misconduct.

C.

The annual internal audit plan includes some consulting engagements that are based on opportunities rather than risks to the organization.

D.

A new internal auditor moved into the internal audit activity from the payroll department and was immediately assigned to the payroll audit.

Full Access
Question # 48

With regard to organizational governance assurance, which of the following is an appropriate role for the internal audit activity'?

A.

Assess compliance with the organization's code of conduct

B.

Oversee the governance and risk management processes

C.

Initiate new organizational control processes

D.

Provide advice on organizational governance activities

Full Access
Question # 49

According to The IIA’s Code of Ethics, which of the following best describes the principle of integrity?

A.

Auditors shall observe the law and make disclosures expected by the law and the profession

B.

Auditors shall disclose all material facts known to them that if not disclosed may distort the reporting of activities under review

C.

Auditors shall engage only in those services for which they have the necessary knowledge skills and experience

D.

Auditors shall be prudent in the use and protection of information acquired in the course of their duties

Full Access
Question # 50

To encourage internal audit objectivity, which of the following is an appropriate policy the chief audit executive should establish?

A.

Internal auditors should report their audit findings directly to the audit committee.

B.

To receive an outstanding performance rating, internal auditors are required to generate audit findings.

C.

Prior to hiring a new internal auditor, the chief audit executive must determine whether the auditor owns stock in the organization.

D.

Internal auditors are permitted to audit an entity managed by a close friend or relative, as long as they notify the chief audit executive.

Full Access
Question # 51

Which of the following is true regarding the use of a formal risk management framework?

1. It facilitates a methodical approach to risk mitigation.

2. It defines and standardizes the terminology used in risk communication.

3. It establishes the risk tolerance levels to be accommodated in the strategy.

4. It facilitates the alignment of risk mitigation strategies with management priorities.

A.

1. 2. and 3.

B.

1.2. and 4.

C.

1.3. and 4.

D.

2. 3, and 4.

Full Access
Question # 52

Which of the following would be considered a primary control to reduce the risk associated with setting up duplicate vendors?

A.

Receipt of a signed and approved vendor setup form.

B.

Segregation of duties between setting up vendors and making vendor payments.

C.

System validation and edit checks on vendor identification number

D.

A vendor setup policy and procedure.

Full Access
Question # 53

Which of the following tests would most likely help discover a fictitious invoice?

A.

Compare vendor addresses to employee addresses.

B.

Match cancelled checks to invoices.

C.

Search for duplicate payment amounts.

D.

Check employee bank records against invoice amounts.

Full Access
Question # 54

Which of the following is an example of impairment to internal auditor independence or objectivity'?

A.

Assurance engagements for functions over which the chief audit executive (CAE) has responsibility are overseen by a party outside the internal audit activity

B.

Internal auditors provide consulting services relating to operations for which they had previous responsibilities

C.

Internal auditors provide consulting services relating to operations for which they have current responsibilities

D.

Consulting engagements for functions over which the CAE has responsibility are overseen by a party outside the internal audit activity

Full Access
Question # 55

Which of the following actions is the internal audit activity best positioned within the organization to perform?

A.

Determine organizational risk tolerances

B.

Monitor the organization's risk mitigations

C.

Determine the likelihood and impact of risks

D.

Advise the board on risk management issues

Full Access
Question # 56

The chief audit executive of an organization assigns audit resources to undertake a consulting engagement requested by senior management the previous year, and a scheduled assurance audit of the procurement process Which of the following appropriately differentiates the two engagements?

A.

The details of assurance services are expected to be included in the risk-based audit plan; this is not the case for consulting services.

B.

The objectivity of assurance services is impaired when undertaken by internal auditors who have had recent prior responsibility in the area under review; this is not the case for consulting services

C.

The performance of assurance services may be outsourced for competency gaps: this is not the case for consulting services.

D.

The results of assurance services are required to be monitored; this is not the case for consulting services

Full Access
Question # 57

According to IIA guidance which of the following statements is true regarding the internal audit charier?

A.

The charier should be revised and re-approved whenever a new chief audit executive (CAE) is appointed or at the request of the board

B.

The charier should be re-approved every five years, in conjunction with the external quality assessment

C.

The charier can be revised at the discretion of the CAE whenever 4 is determined that its content no longer supports the achievement of objectives

D.

The charier should be reviewed and resubmitted for board approval annually together with the audit plan

Full Access
Question # 58

Which of the following best demonstrates internal auditors performing their work with proficiency?

A.

Internal auditors meet with operational management at each phase of the audit process.

B.

Internal auditors adhere to The IIA’s Code of Ethics.

C.

Internal auditors work collaboratively with their engagement team.

D.

Internal auditors complete a program of continuing professional development.

Full Access
Question # 59

Which of the following best describes organizational governance processes?

A.

Processes employed by internal and external assurance providers to authorize, direct, and provide oversight to management to better enable the meeting of organizational objectives

B.

Processes employed by the board of directors to authorize and provide guidance and oversight to management to promote the achievement of organizational objectives.

C.

Processes employed by the board of directors and senior management to mitigate risks to acceptable levels.

D.

Processes employed by risk owners to mitigate risks to acceptable levels within the organization's risk appetite

Full Access
Question # 60

Which of the following is an indicator of ineffective third-party risk management?

A.

Sourcing of third parties does not follow public procurement law.

B.

Violations of service conditions trigger either fines or termination.

C.

Due diligence of third parties is conducted only after contract signing.

D.

The right-to-audit clause is limited by personal data protection regulations.

Full Access
Question # 61

The internal audit activity is asked to provide consulting services regarding the risks related to implementing a proposed new Inventory management system. Which of the following would be a key consideration of the internal audit activity in accepting this engagement?

A.

Ask the inventory manager to determine whether the work planned would be sufficient to meet the consulting engagement objectives.

B.

Ensure that the method used to communicate the results of the consulting engagement is consistent with the board's preferred method.

C.

Determine whether the benefits to be derived from the requested assessment would exceed the cost of providing the consulting service.

D.

Use email and telephone conversations to convey the results of the engagement, as these may prove to be the most efficient methods for communicating.

Full Access
Question # 62

With regard to governance, which of the following is a board-level responsibility rather than a management responsibility?

A.

Obtaining assurance on external financial, regulatory, and internal audits.

B.

Complying with laws, regulations, and codes.

C.

Assigning authority and responsibilities organization wide.

D.

Monitoring and measuring performance.

Full Access
Question # 63

Operational management in the IT department has developed key performance indicator reports, which are reviewed in detail during monthly staff meetings. This activity is designed to prevent which of the following conditions?

A.

Knowledge/skills gap,

B.

Monitoring gap.

C.

Accountability/reward failure,

D.

Communication failure.

Full Access
Question # 64

A newly appointed chief audit executive (CAE) started analyzing the organization's policies in an attempt to customize them to address internal audit specifics. Which of the following organizationwide practices is most likely to be acceptable to the CAE?

A.

Internal auditors1performance evaluation is primarily based on both client satisfaction surveys and cost savings identified from the audits.

B.

Standard training for each employee, including internal auditors, is 10 hours per year.

C.

To enhance efficiency, internal auditors should not be rotated regularly among engagements.

D.

Hiring practices include requiring potential auditors to disclose any significant stock ownership in the organization.

Full Access
Question # 65

A chief audit executive added more money to the IT training budget to ensure the organization's internal auditors were able to perform data analytics while performing an audit. Which core competency is being addressed?

A.

Data analytics

B.

IT fraud detection.

C.

Continuing professional development

D.

Due professional care.

Full Access
Question # 66

Which of the following is a consulting service the internal audit activity can perform with respect to the organization's risk management?

A.

Delivering assurance on the risk management system

B.

Facilitating risk assessment workshops

C.

Evaluating principal risk reporting

D.

Deciding on the appropriate risk response

Full Access
Question # 67

An internal audit activity uses a rotational program to recruit high-performing staff members from other parts of the organization One of these individuals is nearing the end of her four-year internal audit rotation The chief audit executive assigned her to an assurance engagement in the business area she will be going into when she leaves the internal audit activity Which of the following statements is

true regarding this scenario?

A.

Accepting the assignment is a violation of internal audit independence

B.

Accepting the assignment will improve competencies and develop relationships that will be needed in her next assignment

C.

Accepting the assignment creates the appearance of an impairment to her professional judgment and detectivity

D.

Accepting the assignment on the assurance engagement would be a breach of due professional care

Full Access
Question # 68

An organization's operations management is aware of existing internal control deficiencies but they lack the competency to execute internal control measures. Which of the following actions if taken by the internal audit activity is appropriate to assist operating management in achieving continuous improvement on internal controls?

A.

Foster the importance of the control environment

B.

Provide training on controls and on self-monitoring processes

C.

Recommend installing an enterprisewide risk management system.

D.

Conduct more assurance assignments on high risk areas

Full Access
Question # 69

Which of the following fraud schemes is often an off-book fraud*?

A.

Payroll fraud

B.

Disbursement fraud

C.

Corruption

D.

Information misrepresentation

Full Access
Question # 70

Which of the following statements is true regarding management's use of judgement to design, implement, and conduct internal control?

A.

The use of judgment enhances management's ability to make better decisions about internal control, but cannot guarantee perfect outcomes.

B.

Introducing judgment generally diminishes management's ability to make good decisions about internal control.

C.

It is inappropriate for management to exercise judgement in areas such as specifying and using suitable accounting principles.

D.

It is inappropriate for management to exercise judgement in assessing whether components are present, functioning, and operating together

Full Access
Question # 71

Which of the following is an example of an impairment to an internal auditor's independence?

A.

An internal auditor delays reporting material financial statement audit findings until after his parents sell all of their stock in the company

B.

Following the restructuring of the organization, the internal audit activity now reports functionally to the chief financial officer

C.

A new member of the internal audit activity, who was the accounts payable supervisor for two years, is asked to consult on the implementation of a new accounts payable system

D.

Believing there must be errors in a given balance sheet account the internal auditor decides to expand his testing

Full Access
Question # 72

According to IIA guidance, the internal audit activity must be free from interference in which of the following areas in order to maintain organizational independence?

A.

Monitoring resources.

B.

Compensating the chief audit executive.

C.

Determining scope.

D.

Allocating internal costs.

Full Access
Question # 73

Which of the following would decrease or be reduced if an organization establishes and implements excessive internal controls?

A.

Production cycle time.

B.

Activities that add no value.

C.

Staff productivity.

D.

Complexity of operations.

Full Access
Question # 74

An organization’s board of directors has decided that the internal audit activity must have greater access to different pans of the organization in order to perform their assurance work effectively Which of !he following areas is the board seeking to improve by making this change?

A.

Internal audit authority.

B.

Internal audit reporting structure.

C.

Internal audit independence and objectivity.

D.

Internal audit interaction with the board

Full Access
Question # 75

When a plant manager from within the organization is hired as a rotational internal auditor within the internal audit activity which area should he most likely be trained for immediately?

A.

Industry knowledge

B.

Project management

C.

Leadership skills

D.

Risk assessments

Full Access
Question # 76

Which competency is required of all staff internal auditors prior to the commencement of an IT audit?

A.

The ability to assess IT governance.

B.

The ability to provide an explanation on the risk profile of the organization to the board and senior management.

C.

The ability to ensure that proposals for improvements to internal controls are balanced with organizational objectives and capabilities.

D.

The ability to assess the potential for fraud risk and identifying common types of fraud associated with the engagement.

Full Access
Question # 77

Which of the following would be the most effective fraud prevention control?

A.

Email alert sent to management for checks issued over $100,000.

B.

Installation of a video surveillance system in a warehouse prone to inventory loss.

C.

New hire training to explain fraud and employee misconduct.

D.

Daily report that identifies unsuccessful system log-in attempts

Full Access
Question # 78

Which of the following would best assist the internal audit activity in assessing whether an organization's responses to risk are aligned with its risk appetite?

A.

Analyzing the results of successful testing of controls and monitoring procedures implemented by management

B.

Determining that there are no gaps between the internal auditors' risk assessment and the risk assessment performed by the organization

C.

Obtaining evidence that employees throughout the organization are aware of the organization s risk appetite

D.

Verifying that previously identified organizational risks were documented in board meeting minutes

Full Access
Question # 79

Who is responsible for setting the risk appetite?

A.

External auditors.

B.

Chief risk officer.

C.

Operations management.

D.

Board of directors.

Full Access
Question # 80

The board of directors of a global organization has found an increased number of reported cases of unethical practices since last year. To assist the board in gaining a better understanding of the degree of ethics awareness within the organization, which of the following actions should be undertaken?

A.

Request the internal audit activity to perform an ethics-related assurance engagement.

B.

Offer in-house ethics-related training seminars for employees to attend.

C.

Reaffirm the importance of the organization's code of ethics to all employees.

D.

Conduct an organizationwide employee survey on ethical practices

Full Access
Question # 81

Which of the following types of fraud tests would be most effective if an internal auditor was looking for possible fictitious vendors?

A.

Checking for invoice amounts that do not match that of the purchase order.

B.

Searching for identical invoice numbers and payment amounts.

C.

Running checks to uncover post office box addresses matching employee addresses.

D.

Comparing prices across vendors to see whether one vendor is unreasonably high.

Full Access
Question # 82

Which of the following controls would be most useful to prevent an employee from using the organization's funds for inappropriate expenditures and falsifying financial records to conceal the fraud?

A.

Segregating duties in the payroll processes.

B.

Confirming receipt of goods or services.

C.

Performing background checks on newly hired employees.

D.

Requiring management approval for expenses.

Full Access
Question # 83

Which of the following organizations has reached the most mature level of corporate social responsibility?

A.

An organization that is able to provide goods and services society needs and thus maximizes profit to its owners.

B.

An organization that ensures compliance to legal frameworks of the countries in which it operates and sells its products.

C.

An organization that is willing to make contributions not mandated by law or economics and expects no payback.

D.

An organization that requires its decision makers to act with equity, fairness, and respect for the rights of individuals.

Full Access
Question # 84

Evidence discovered during the course of an engagement suggests that multiple incidents of fraud have occurred. There do not appear to be sufficient controls in place to prevent reoccurrence. Which of the following is the internal auditor's most appropriate next step?

A.

Immediately notify management of the area under review and the other internal auditors involved in the engagement.

B.

Discuss the situation with the engagement supervisor to determine whether fraud investigation experts are required to investigate the matter properly.

C.

Fully document in the workpapers the evidence that has been discovered and recommend appropriate controls to address the fraud.

D.

Provide the evidence that was discovered to local law enforcement for possible prosecution of the suspected fraud.

Full Access
Question # 85

Which of the following statements best represents the duo professional care that is required of internal auditor’s?

A.

Internal auditors should perform assurance procedures to ensure that all significant risks are identified.

B.

Internal auditor should not perform consulting engagements for operations for which they had previous responsibilities.

C.

Internal auditors should consider the cost of assurance in relation to the potential benefits.

D.

Internal auditors should device internal audit programs to confirm that the results are accurate.

Full Access
Question # 86

According to IIA guidance, which of the following statements is true regarding the internal audit activity’s responsibilities in providing consulting services?

A.

The chief audit executive is responsible for deciding the priority of consulting services in the internal audit plan

B.

The scope of consulting services is determined primarily by the internal auditor with input from management of the area under review

C.

The board defines the internal audit activity’s responsibilities over consulting activities

D.

Adding value to an organization requires the internal audit activity to initiate a consulting engagement

Full Access
Question # 87

Which of the following is an example of a management control technique?

A.

A budget.

B.

A risk assessment.

C.

The board of directors.

D.

The control environment

Full Access
Question # 88

Which of the following is an appropriate roe fa the internal audit activity?

A.

Ensuring the organization's key risks are managed through appropriate controls.

B.

Assisting the organization in maintaining effective controls.

C.

implementing new controls to promote continuous improvement

D.

Validating control assessments performed by the external auditor.

Full Access
Question # 89

According to IIA guidance, which of the following statements is true regarding risk management in an organization?

A.

The risk management function has the sole responsibility for identifying and managing risks in all departments

B.

Risk management is a core responsibility of the internal audit activity

C.

The internal audit activity should consider the organization’s maturity, structure, and the competitive environment to establish the organization’s risk appetite

D.

The internal audit activity may use a risk management or control framework to assist in risk identification

Full Access
Question # 90

A risk assessment showed that the cost of addressing a particular risk in the organization's human resources department is greater than the perceived benefit. Which risk response approach should the organization take in this scenario?

A.

Reduce the risk.

B.

Transfer the risk.

C.

Accept the risk.

D.

Share the risk.

Full Access
Question # 91

During an audit of an organization's accounts payable area, an internal auditor identified anomalies in the information examined that may indicate potential fraud. Which test should the auditor perform first to verify this?

A.

Verify the completeness and integrity of the data being analyzed.

B.

Identify duplicated organizational transactions.

C.

Analyze all transactions within the targeted area.

D.

Check control totals that have may have been falsified.

Full Access
Question # 92

An internal auditor is updating the risk register for risks identified during a recent organizational risk assessment. According to the Standards, which of the following would the auditor include in the risk register?

A.

Management’s acceptance of inadequate controls for cybersecurity risk.

B.

Discussions with senior management relating to a new revenue stream.

C.

Mitigating controls implemented by the engagement supervisor

D.

Project manager planned hours versus time spent for all prior year projects

Full Access
Question # 93

Which of the following scenarios best illustrates the concept of due professional care?

A.

After establishing engagement objectives and reviewing a process, the internal auditor assured process owners that all significant risk events were identified and tested using a systematic, disciplined approach.

B.

After conducting an audit based upon a predefined scope and objective, the internal auditor guaranteed management that the system of internal controls in an audited area operates effectively.

C.

As head of the internal audit activity, the chief audit executive reported functionally to the organization's board and administratively to senior management.

D.

As head of the internal audit activity, the chief audit executive ensures that engagement supervisors conduct post-engagement staff meetings.

Full Access
Question # 94

A senior executive at a government-owned organization received an invitation to attend a public exhibition where he can learn about new trucks relevant to the organization's business. As a special perk, the executive is offered an opportunity to drive a luxury vehicle manufactured by one of the exhibiting companies. Prior to the event, the executive asked for the chief audit executive s (CAE’s) advice. What should the CAE recommend as the most appropriate course of action for the executive?

A.

Attend the event, but decline the offer to use the luxury vehicle

B.

Decline the invitation to the exhibition.

C.

Ask the board to decide on the issue.

D.

Select a lower-level employee to enjoy the luxury vehicle instead

Full Access
Question # 95

Which of the following fundamental principles of The IIA's Code of Ethics is best described as performing work honestly diligently and responsibly?

A.

Integrity

B.

Proficiency

C.

Due Professional Care

D.

Competency

Full Access
Question # 96

Which of the following circumstances would most likely be considered a potential red flag for fraud by the internal audit activity?

A.

The monthly payroll reports are not vetted to ensure terminated employees have been removed from the payroll system.

B.

The volume of nonroutine journal entries has steadily increased over time.

C.

The database of approved suppliers has not been reviewed in the last year.

D.

The recent employee survey indicates that some employees remain unaware of the organization’s whistleblower hotline.

Full Access
Question # 97

Which of the following is the most effective way for internal auditors to determine whether ethical values are followed throughout the organization?

A.

Review the organization's ethical value structure and reporting procedures.

B.

Review what the organization considers to be ethical behavior, such as the employee code of conduct.

C.

Review employee survey responses and follow up on those that suggest weaknesses in the ethical climate.

D.

Review the organization's records to ensure all employees have signed statements that they will follow ethical practices.

Full Access
Question # 98

Which of the following controls would best mitigate the risk of fraud in the bidding process?

A.

Have a bidding committee open the tender bids.

B.

Restrict the time to submit tender bids.

C.

Keep minutes of pre-bid meetings.

D.

Allow the higher tenders to rebid.

Full Access
Question # 99

Which of the following would be the most effective in helping to detect fraud?

A.

Code of conduct.

B.

Exit interviews.

C.

Fraud awareness training

D.

Employee promotion policy.

Full Access
Question # 100

The chief audit executive (CAE) of a new internal audit activity is creating an internal audit charter According to IIA guidance, which of the following terms is most likely to

be included in the charter?

A.

Senior management will be present whenever the CAE interacts with the board, to ensure effective communication among all three parties.

B.

Internal auditors will advise on the design of control policies and procedures in any area where the organization does not possess the requisite expertise,

C.

Internal auditors will demonstrate competence, concern, and the dedication expected of a professional,

D.

Internal auditors will receive performance-based compensation, including bonuses for reporting more than a stipulated number of observations.

Full Access
Question # 101

When performing an audit of the risk management process an auditor makes the observations listed below. Which poses the greatest risk to the organization?

A.

The identified risks have not undergone a detailed review to ensure completeness in the past two years.

B.

The controls in place to mitigate the risks are not tested on an annual basis to confirm operating effectiveness.

C.

The process in place to identify and evaluate new risks to the organization is informal and poorly documented.

D.

The identified risks have not been ranked to establish their importance and risk management priority.

Full Access
Question # 102

Which of the following is most likely to impair the organizational independence of the internal audit activity?

A.

The chief audit executive (CAE) reports administratively to the chief financial officer.

B.

The CAE oversees the effectiveness of the organization’s risk management function.

C.

The CAE reports functionally to the CEO.

D.

The CAE managed the finance department for the past five years.

Full Access
Question # 103

Which of the following activities would breach the principles of The IIA's Code of Ethics?

A.

The internal auditor is keeping personal notes from an engagement conducted on the organization's information system security for future use.

B.

The internal auditor is performing an engagement of the purchasing department where he used to work five years ago.

C.

The internal auditor is using information from a recent engagement to assist with a friend's business.

D.

The internal auditor is discussing relevant information involving questionable vendors with a government regulatory agency.

Full Access
Question # 104

The internal audit activity is responsible for conducting fraud investigations. A potential fraud instance was identified during an audit engagement. The chief audit executive appoints a lead investigator. Which of the following would most likely be the next step?

A.

Ask internal auditors to gather all relevant information and evidence.

B.

Identify and interview witnesses first and potential suspects later.

C.

Conduct a fraud risk assessment to identify the most vulnerable areas.

D.

Determine the competencies needed and assess whether team members have a conflict of Interest.

Full Access
Question # 105

A telecommunications organization is planning to cease operations in one or the markets in which it operates due to increasing volatility and uncertainties. Which of the following risk management techniques is the organization selecting?

A.

Risk acceptance.

B.

Risk avoidance.

C.

Risk sharing.

D.

Risk reduction.

Full Access
Question # 106

Due to extreme liquid fuel price fluctuations, management decided to designate a specific price below which liquid fuel shall not be sold to customers, but instead shall be pumped into storage tanks. Which of the following risk responses has management selected?

A.

Risk reduction.

B.

Risk transfer.

C.

Risk acceptance.

D.

Risk avoidance.

Full Access
Question # 107

Which statement is accurate regarding reporting on the quality assurance and improvement program (OAIP) to conform with the International Standards for the Professional Practice of Internal Auditing?

A.

The chief audit executive (CAE) should report all stages of the OAlP's development and key milestones.

B.

The CAE should report only corrective action plans that meet external assessor or stakeholder requirements.

C.

The CAE should establish the form and content of program communication so that it is in alignment with the internal audit activity charter.

D.

The CAE should disclose program details only after both internal and external assessments have been completed.

Full Access
Question # 108

During an assurance engagement the internal audit team discovers that employees performing a control do not understand the principles behind it. Before the engagement concludes, at management's request the audit team facilitates several formal training sessions to help explain those principles to the employees. Which of the following best describes the engagement provided by the internal audit activity in this scenario?

A.

Assurance services

B.

Blended services

C.

Consulting services

D.

Prohibited services

Full Access
Question # 109

Which of the following would a chief audit executive most likely use to identify a need for improvement in a staff internal auditor's business acumen?

A.

A quality assessment review.

B.

An internal audit client survey.

C.

A control self-assessment.

D.

A peer review of the internal audit activity.

Full Access
Question # 110

Which of the following strategies would be the most effective to share an organization's risk of losses through foreign currency transactions related to the accounts payable process?

A.

Using a hedging strategy.

B.

Implementing controls to follow up on deviations.

C.

Purchasing liability insurance.

D.

Purchasing foreign currency reserves.

Full Access
Question # 111

Which of the following can be used to minimize employees’ resentment of controls?

A.

Making sure employees are exempt from participating in control creation

B.

Implementing controls without lengthy explanations of their purpose

C.

Developing general constricting controls rather than detailed ones

D.

Not using controls to achieve goals

Full Access
Question # 112

According to the IIA Code of Ethics, which of the following best describes the conduct of an internal auditor who demonstrates the principle of competency?

A.

The auditor is prudent in the use and protection of information acquired in the course of his work.

B.

The auditor does not accept anything that may impair or be presumed to impair his professional judgment.

C.

The auditor does not perform services in a particular area when he lacks skills in that area.

D.

The auditor performs work with honesty, diligence, and responsibility.

Full Access
Question # 113

According to NA guidance, which of the following describes the primary reason to implement environmental and social safeguards within an organization?

A.

To enable Triple Bottom Line reporting capability.

B.

To facilitate the conduct of risk assessment.

C.

To achieve and maintain sustainable development.

D.

To fulfill regulatory and compliance requirements.

Full Access
Question # 114

An organization's board has approved an expansion plan into a new market. The board acknowledged that if the expansion is not successful, the organization would encounter large monetary losses consisting of legal fees, research and development costs, rent expenses, and labor fees. Which of the following has the board approved?

A.

The risk response.

B.

The risk tolerance.

C.

The residual risk.

D.

The inherent risk.

Full Access
Question # 115

Which of the following relates to the concept of due professional care?

A.

An auditor attempts to obtain information needed to complete an assurance engagement but is denied access.

B.

The appointment of the chief audit executive is ratified by the board.

C.

An auditor demonstrates a good understanding of the steps involved in carrying out a consulting engagement.

D.

The internal audit resource plan is only approved by the chief financial officer.

Full Access
Question # 116

In an assurance engagement focused on the adequacy of organizationwide risk management practices, which of the following best describes a primary area of interest for the engagement?

A.

The effectiveness of process-level and transaction-level controls.

B.

Conflicts of interest within the organizational structure of the senior management.

C.

The alignment of management decisions with the level of risk the organization is willing to accept.

D.

The actions of upper management in response to the internal audit activity's reporting

Full Access
Question # 117

The board requested the chief audit executive (CAE) to provide consulting services for a new systems implementation project Which of the following statements is true regarding this scenario?

A.

The CAE should avoid making decisions on risk responses within risk management processes.

B.

The CAE may only provide consulting and not assurance services in risk management processes

C.

The CAE may manage the project risks on behalf of management in this particular situation

D.

The CAE should avoid giving assurance on risk management processes in this particular situation

Full Access
Question # 118

Internal audit is performing an engagement to determine whether there were indications of questionable bidding on a city s infrastructure project. As part of the engagement the internal audit activity became aware that certain firms tend to receive the contracts for large city projects. How should the internal audit activity proceed with the engagement and identify questionable bidding practices?

A.

Obtain the city s vendor listing to determine whether there was an adequate number of firms available to solicit bids for protects

B.

Obtain at of the city s financial records to identify any firms that received payments for contracted goods and services.

C.

Obtain the city's contracting files to determine whether the city demonstrated efforts to solicit bids from various interested firms.

D.

Obtain the city’s official public meeting minutes to determine whether there were concerns about the contracting practices

Full Access
Question # 119

Which of the following describes the most appropriate match between a potential temporary guest auditor candidate and an upcoming audit assignment?

A.

A purchasing manager with two years of prior audit experience in public practice to lead a contracts management audit

B.

A communications officer who worked in the marketing department during the last six months to conduct a customer loyalty program audit

C.

A manager of social responsibility who has a nursing background to participate m a health and safety audit for the corporate office and plant facilities

D.

An accounting manager who discovered and reported fraud committed by a payables clerk to conduct a performance audit of accounts payable

Full Access
Question # 120

A global manufacturing company has three regional offices. The chief audit executive (CAE) is concerned about the cost of an upcoming external quality assessment of the internal audit activity. The last external assessment was performed six years ago. Recently, the internal audit staff at one of the regional offices performed an internal assessment. To ensure conformance with the Standards, what is the most appropriate action for the CAE to take?

A.

Request from the audit committee an additional budget and an extension so that the external assessment could be performed next year.

B.

Review the results of the internal assessment, identify weaknesses, and implement improvements at the remaining offices.

C.

Request the regional office that performed the internal assessment to perform an assessment of the remaining offices.

D.

Request that an external assessor validate the results of the internal assessment and review the remaining offices.

Full Access
Question # 121

Which of the following statements is true regarding external quality assessments?

A.

They can be performed by self-assessment with independent external validation, but they must be performed every three years.

B.

When a new chief audit executive (CAE) is appointed, an external quality assessment should be undertaken during the CAE’s first year of office.

C.

An external quality assessment must be conducted at least once every five years by a qualified, independent assessor or assessment team.

D.

An external assessment by a qualified professional from outside of the organization can be performed in place of an internal assessment.

Full Access
Question # 122

Which of the following would most likely be classified as a consulting engagement?

A.

Examining the internal control effectiveness of the marketing department

B.

Assessing the adequacy of the IT system's business process design

C.

Facilitating a self assessment of the organizations business risk and control identification

D.

Reviewing the application controls in the human resources system

Full Access
Question # 123

Which of the following is an indicator that the organization's risk management process is effective?

A.

The organization's risk appetite, mission, and objectives are clearly outlined.

B.

The organization's risk management practices are assessed as mature.

C.

The organization has adopted risk management frameworks and global models.

D.

The organization's significant risks are identified and adequately assessed.

Full Access
Question # 124

Which data analytics competency is critical for new internal auditors to possess in order to plan and perform internal audit engagements in conformance with the Standards?

A.

Describe data analytics and the application of data analytics methods in internal auditing.

B.

Apply data analytics methods in internal auditing.

C.

Evaluate the use of data analytics in an internal audit.

D.

Understand the definition of data analytics only.

Full Access
Question # 125

According to MA guidance, which of the following gives the internal audit activity the authority to request supporting documentation for the invoices of a third-party service provider?

A.

The internal audit policy manual.

B.

The internal audit charter.

C.

The board of directors.

D.

The quality assurance and improvement program.

Full Access
Question # 126

Which of the following should an internal auditor take into consideration when making a judgement regarding whether management selected appropriate risk responses?

A.

Significant risks

B.

Risk capacity

C.

Risk appetite

D.

Risk tolerance

Full Access
Question # 127

An external assessment was performed as part of the organization's quality assurance and improvement program. Which of the following conclusions confirms that the internal audit activity is in conformance with the Standards'?

A.

The chief audit executive is well qualified and has responsibilities over operational areas that the internal audit activity assesses.

B.

Periodic self-assessments are assigned to entry-level internal audit staff to support their continuing professional development.

C.

All audit workpapers are reviewed and signed by the engagement supervisor before the audit report is issued.

D.

Employees who rotate into the internal audit activity from other areas of the organization are assigned to audit areas where they previously worked, to take advantage of their operational expertise and experience.

Full Access
Question # 128

Which of the following is an example of an entity-level control pertaining to the finance area of an organization'?

A.

Key account reconciliation such as bank reconciliation

B.

Segregation of duties between posting and reviewing journal entnes

C.

A signing authority matrix for spending approvals

D.

The establishment of a finance and audit committee

Full Access
Question # 129

Which of the following should a general internal auditor be able to characterize as an IT-related risk?

A.

Computer servers are in a room that is accessible to all employees,

B.

An IT architect avoids taking vacations and sharing his workload with coworkers,

C.

Hours billed by IT developers exceed 24 hours daily.

D.

Audit logs are lacking in a system that processes personal data.

Full Access
Question # 130

To achieve conformance with the Standards, the chief audit executive must include which of the following activities in the quality assurance and improvement program (QAIP)?

A.

Require board oversight of the QAIP.

B.

Assess Standards conformance for each individual engagement.

C.

Conduct a self assessment at least once every five years.

D.

Report the results of the QAIP to senior management

Full Access
Question # 131

During the audit of taxation processes in the organization internal auditors have verified that all employees of the finance department received training on taxation guidelines. The training is mandatory and is automatically assigned via email invitation to all new employees in the department. Which type of controls have the auditors tested?

A.

Directive

B.

Preventive

C.

Detective

D.

Automatic

Full Access
Question # 132

Which of the following would be considered a monitoring activity in organization wide risk management?

A.

Validate the results of management's self-assessment.

B.

Perform reviews of personnel.

C.

Maintain rigorous and comprehensive documentation.

D.

Obtain authorizations and signatures.

Full Access
Question # 133

A fraud investigation was completed by management, and a proven fraud was communicated to relevant authorities. According to IIA guidance, which of the following roles would be most appropriate for the internal audit activity to undertake after the investigation?

A.

Plan employee sessions and team building strategies for the organization to improve awareness of fraud among employees

B.

Review the investigation and implement any improvements to the process.

C.

Conduct lessons learned sessions to ascertain how the fraud occurred and which controls failed.

D.

Determine why the fraud was not detected earlier and design controls to strengthen early detection.

Full Access
Question # 134

Which of the following is most accurate concerning corporate social responsibility?

A.

A moral agent in an organization makes decisions that are based on the rules and regulations of the organization as they apply to human resources decisions

B.

The utilitarian approaching deciding on ethical dilemmas is concerned with choosing the simplest solution that will apply to the most people

C.

Ethics are not defined by laws but they are not a matter of free choice ethics are based on standards of conduct derived from shared principles and values

D.

The individualism approach to ethical decision making is focused on implementing a customized long-term outcome that is most beneficial for the entire organization

Full Access
Question # 135

Who has the ultimate responsibility of implementing the organization’s governance system?

A.

Stakeholders

B.

The board

C.

The chief executive officer

D.

Internal auditors

Full Access
Question # 136

An internal auditor is reviewing employee travel expenses from the previous six months for fraud. Which of the following tests would best detect instances where personal travel has been claimed?

A.

Verifying whether claims have been properly authorized for payment

B.

Verifying whether claims are properly supported by invoices or other documents.

C.

Confirming that all claims are within the limits of the organization's travel policy.

D.

Reconciling claims against business the requests that were approved by supervisors

Full Access
Question # 137

The internal audit activity is asked to review the effectiveness of controls around the disposal of chemical waste. However, the internal auditors on staff lack the necessary skills to conduct this review. Which of the following would be the most appropriate approach?

A.

An internal auditor who recently attended a three-day workshop on chemical waste disposal, and therefore has the most knowledge on the topic, should lead the engagement.

B.

A team of available internal auditors should be assembled and should consult with an external nonaudit expert on chemical waste disposal to plan and conduct the engagement.

C.

A team of the most knowledgeable auditors could be assembled and use the engagement work program from the previous year to gather additional insight regarding recommended audit procedures.

D.

A nonaudit employee from the chemical disposal area may share his expertise with the audit team, provided the internal audit manager conducts a detailed review of all engagement work performed.

Full Access
Question # 138

An existing Internal audit charter is currently under review for revision. Who is responsible for assuring that all required components are included?

A.

The audit committee.

B.

The head of legal and compliance.

C.

The chief audit executive.

D.

Senior management.

Full Access
Question # 139

According to IIA guidance, which of the following statements is true of assurance services provided by the internal audit activity?

A.

Internal auditors cannot assess an operation for which they were responsible within the previous year.

B.

Management of the area under review must agree with the engagement objectives, scope, and techniques.

C.

The engagement results will vary in form and content depending upon the needs and wishes of the engagement client.

D.

The only parties involved in the engagement are the internal auditor and management of the area under review.

Full Access
Question # 140

An internal audit activity is using the auditing-by-element approach to audit the organization's controls around corporate social responsibility. Which of the following would be an element for the internal audit activity to consider?

A.

Working conditions.

B.

Employees' families.

C.

Marketplace competition.

D.

Shareholders and investors

Full Access
Question # 141

An internal audit team was assigned to review the organization's information security protocol. After fieldwork was completed, an internal auditor identified an error in the review of security access. The error could affect the overall results of the engagement. Which of the following is the most appropriate course of action for the internal auditor?

A.

Proceed with addressing the error and report any corrections to the engagement supervisor during the scheduled exit meeting.

B.

Issue the audit report to senior management on schedule but include a disclaimer about the error.

C.

Proceed with the scheduled closing of the engagement without consideration of the identified error.

D.

Inform the engagement supervisor of the error and allow the supervisor to determine the appropriate action to take.

Full Access
Question # 142

There is a growing perception that employees generally evade their responsibilities. What impact will an internal auditor most likely see during an engagement?

A.

Supervisors are likely to reduce their level of supervision and increase span of control.

B.

Employees are likely to be supervised closely and given little freedom.

C.

Peer employees are likely to trust one another, but distrust management.

D.

Employees are likely to join forces to accomplish their duties as teams.

Full Access
Question # 143

Which of the following statements is true with regard to the quality assurance and improvement program (GAIP)?

A.

As the head of the organization, the CEO selects and appoints the external quality assessment team to perform the OAIP reviews.

B.

The chief audit executive determines the scope and frequency of both internal and external quality assessments based on the availability and capacity of resources in accordance with the annual internal audit plan.

C.

Minutes of meetings held with senior management and the board to discuss the scope and frequency of internal and external assessments support the OAIP reporting requirement.

D.

The internal audit activity needs to assess whether each engagement on the annual internal audit plan is conducted in conformance with the Standards.

Full Access
Question # 144

Which of the following is the best reason why the engagement supervisor should take care in explaining to local management the criteria that will be used to measure the effectiveness of the control environment?

A.

The assessment will cover soft controls and company values.

B.

The assessment will focus on the policy for a particular process.

C.

The assessment will lack a defined scope

D.

The assessment will probably uncover fraud risks.

Full Access
Question # 145

What is the primary reason for establishing a continuing professional development program within an organization's internal audit activity?

A.

To ensure all internal audit responsibilities can be met

B.

To ensure all audit staff members are capable of performing a quality self-assessment.

C.

To ensure that each auditor maintains responsibility for his own professional development.

D.

To attract the best and most talented candidates in the profession

Full Access
Question # 146

The head of human resources notified the internal audit activity that a key account manager was fired because he did not register a large number of contracts with clients As a result the organization was unaware of its duties and would suffer some financial loss Which of the following should be expected from a competent internal auditor who is analyzing this situation?

A.

The ability to apply forensic methods to obtain legally admissible evidence

B.

The ability to conduct admission-seeking interviews with potential suspects

C.

The ability to evaluate whether such attributes as intent and personal gain were present

D.

The ability to retrieve concealed or deleted information from the former employee's laptop

Full Access
Question # 147

Following a quality assurance review of a small internal audit activity, the external reviewer and the chief audit executive (CAE) cannot agree on the importance of several deficiencies noted during the review. Which of the following would be the most appropriate next step for the reviewer to take?

A.

Remove the areas of disagreement from the scope of the engagement and seek informal compromises with the CAE.

B.

Issue the report to senior management, noting the deficiencies for immediate resolution.

C.

Issue the report, noting the deficiencies with comments that address the areas of disagreement.

D.

Request arbitration from the audit committee to resolve discrepancies prior to issuing the final report

Full Access
Question # 148

Which of the following best demonstrates organizational independence of the internal audit activity?

A.

The chief audit executive (CAE) reports functionally to the CEO.

B.

The CAE's compensation is approved by the chief financial officer.

C.

The CAE's appointment Is determined by the CEO

D.

The CAE reports administratively to the chief operating officer.

Full Access
Question # 149

According to IIA guidance, which of the following is ultimately responsible for seeing that the internal control system of an organization’s social responsibility program is effective?

A.

Senior management

B.

Internal audit activity.

C.

All employees.

D.

Board of directors.

Full Access
Question # 150

Which of the following describes the internal audit activity's most appropriate role in an organization's risk management process?

A.

Reporting to the board on management's assessment of current risks

B.

Establishing a risk management policy and framework for the organization

C.

Assigning responsibility for identifying and managing significant risks

D.

Developing key controls to mitigate risks across the organization

Full Access
Question # 151

Which of the following is the best example of a computer forensic audit activity?

A.

An internal auditor compared vendor addresses to employee home addresses.

B.

An internal auditor used analytical software to trace all disbursements processed on weekends.

C.

An internal auditor tried to circumvent the logical access controls of the purchasing system.

D.

An internal auditor recovered emails of an employee who was suspected of fraudulent activities

Full Access
Question # 152

Which of the following best describes the type of organizational culture known as adaptability culture'?

A.

A results-oriented culture that values competitiveness and personal initiative

B.

A culture that emerges in quick-response and high-risk decision-making environments

C.

A culture that is characterized by low involvement with environmental and health issues

D.

A culture that places high value on participation and meeting the needs of employees.

Full Access
Question # 153

Which of the following would be considered an impairment to an internal auditor's objectivity when performing a review of the organization's procurement function'?

A.

The internal auditor worked on the implementation of the accounting system within the organization before joining the internal audit activity last year

B.

The internal auditor is part of a multidisciplinary team tasked to assist with a new project implementation checklist within the organization

C.

The internal auditor worked as a sourcing specialist before joining the internal audit activity last year

D.

The internal auditor participates in a cross-departmental team for information and data security within the organization

Full Access
Question # 154

According to IIA guidance, which of the following actions is a chief audit executive required to take with regard to reporting the results of the quality assurance and improvement program?

A.

Report external assessments upon completion of such assessments

B.

Report external assessments at least annually

C.

Report ongoing monitoring quarterly

D.

Report post-engagement reviews at least once every five years

Full Access
Question # 155

In an internal audit charter, which of the following statements regarding the chief audit executive (CAE) would be most directly related to describing the responsibilities of the internal audit activity*?

A.

The CAE shall report functionally to the board and administratively to the chief financial officer

B.

The CAE and the Internal audit activity shall have full access to any and all records and personnel of the organization that are relevant to audit engagements

C.

The CAE and the internal audit activity shall be independent and objective in performing their work.

D.

The CAE shall report periodically on the performance of the internal audit activity relative to its plan

Full Access
Question # 156

An organization established 20 years ago has had its internal audit activity in place for the last three years. Which of the following would allow the internal audit activity to accurately state that it is in conformance with the Standards'?

A.

Documented assessment was performed by the audit committee and confirmed conformance.

B.

Internal and external assessments are performed annually, and nonconformance results are reported to the board.

C.

The independent and objective judgement of the chief audit executive confirmed conformance with the Standards.

D.

Documented internal assessments are performed periodically and confirm conformance.

Full Access
Question # 157

Which of the following is the most appropriate way to ensure that a newly formed internal audit activity remains free from undue influence by management?

A.

Appoint the chief audit executive as a member of the board.

B.

Adopt written policies and procedures for the internal audit activity, approved by the board.

C.

Ensure the chief audit executive reports administratively to the audit committee.

D.

Establish the internal audit activity’s position within the organization in an audit charter.

Full Access
Question # 158

Which of the following most accurately describes the role of the board when it comes to organizational governance?

A.

Responsibility for outcome of the process.

B.

Responsibility to be involved in management of the organization.

C.

Responsibility to determine who is accountable for outcomes.

D.

Responsibility to identify risks in the organization’s business environment

Full Access
Question # 159

A chief audit executive has reported to the board that the internal audit activity is lacking financial accounting knowledge for specific audit projects. Upon approval from the board which of the following hiring approaches is best in this situation?

A.

An inbound rotational program

B.

A full-time permanent recruitment

C.

An outbound rotational program

D.

A guest auditor program

Full Access
Question # 160

An internal auditor wants to compare her organization’s governance processes to those of a well-known governance model. Which of the following approaches would the auditor take for this purpose?

A.

Perform a gap analysis to assess me differences between the approaches

B.

Assess the governance processes using computerized modeling techniques

C.

identify any differences between the processes using a variance analysis

D.

Benchmark the governance processes using a capability maturity modal

Full Access
Question # 161

An automobile manufacturer will become one of the first in the industry to adopt a new inventory management software. Despite the system being new to the market, senior management believes that the benefits are great enough to offset the potential risks. Which of the following aspects of risk management does senior management’s decision best illustrate?

A.

Residual risk.

B.

Inherent risk.

C.

Risk tolerance.

D.

Risk appetite.

Full Access
Question # 162

Which of the following is true about corporate social responsibility (CSR)?

A.

Social and environmental considerations are required parts of an organization's decision making

B.

The Global Reporting Initiative provides standards on required disclosures of CSR.

C.

CSR activities are overseen and managed by operational management.

D.

Internal auditors can provide assurance on reported sustainability results.

Full Access
Question # 163

A chief audit executive (CAE) is concerned that the internal audit activity is not receiving adequate training and continuing education. Which of the following approaches should the CAE take?

A.

Implement a uniform professional development plan for the internal audit activity.

B.

Create a formal development agreement with each individual staff auditor.

C.

Require each internal auditor to obtain the same professional certifications.

D.

Require training and developmental activities that are sponsored by The HA.

Full Access
Question # 164

An organization employs ongoing monitoring and is considering implementing periodic evaluations to assess the continuing effectiveness of its risk management process. Which of the following statements Is true with regard to such periodic evaluations?

A.

Periodic evaluations are considered to be less objective than ongoing monitoring.

B.

Periodic evaluations can be more effective than ongoing monitoring.

C.

Periodic evaluation frequency may depend on the results of ongoing monitoring.

D.

Periodic evaluations frequently identify problems more quickly than ongoing monitoring.

Full Access
Question # 165

Which of the following best describes a consulting engagement rather an assurance engagement?

A.

Bank internal auditors review an activity checklist to determine that the loan officer followed proper procedures.

B.

The chief financial officer asks for the internal auditor's opinion regarding whether the new accounting pronouncements were properly and comprehensively adopted

C.

An internal auditor is assigned to assess whether a proposed new initiative to convert a customer service system would be cost effective.

D.

Senior management asks the internal audit activity to review compliance with customer data security regulations

Full Access
Question # 166

Which of the following skills is most important for an internal auditor who facilitates control self-assessment workshops to possess?

A.

Groupthink.

B.

Collaboration skills.

C.

Process analysis skills.

D.

Project management skills.

Full Access
Question # 167

Which of the following statements is true regarding the quality assurance and improvement program (QAIP)?

A.

Reporting on the QAIP to the board should occur at least once every five years

B.

The responsibility for the selection of an external assessor rests with the board

C.

The qualifications of the assessors must be communicated to the board

D.

The reporting of outcomes of the QAIP can be delegated to senior audit staff

Full Access
Question # 168

What is the main difference between a consulting engagement versus an assurance engagement?

A.

The nature of services provided are defined in the internal audit charter.

B.

Internal auditors must maintain objectivity while performing their work.

C.

The objectives and scope of the engagement typically are directed by management.

D.

Internal auditors may assume management responsibilities.

Full Access
Question # 169

To meet the resource requirements of this year’s internal audit plan, the chief audit executive (CAE) has recruited additional staff auditors, including an employee who resigned as a senior supervisor from the accounts payable department two months ago. There is a scheduled accounts payable review that the CAE wants to start within the next five months. Which approach should the CAE take, knowing the expertise of his new recruit in the area intended to be audited?

A.

Have the new internal auditor’s previous boss be excused from the area during fieldwork.

B.

Have the new internal auditor be responsible for the planning of the audit as well as the review of the audit fieldwork.

C.

Have the new internal auditor assigned to other responsibilities and not work on the accounts payable audit engagement.

D.

Have the new internal auditor assist with conducting the fieldwork, but ensure that her work is reviewed by the CAE.

Full Access
Question # 170

During a payroll audit, the internal auditor discovered that several individuals who have the same position classification as he are earning a significantly higher salary. The auditor noted the names and amounts of each, and he planned to prepare a request to the chief audit executive for a salary increase based on this information. Which of the following IIA Code of Ethics principles was violated in this scenario?

A.

Competency.

B.

Objectivity,

C.

Integrity.

D.

Confidentiality

Full Access
Question # 171

At the beginning of an IT development project key risks were identified and assessed and risk owners were appointed Six months later the IT development team reported that the project Is significantly over budget, it will not be completed on time and key personnel had left the organization. Which of the following risk management practices should be improved for future projects?

A.

Risk response.

B.

Risk assessment

C.

Risk monitoring.

D.

Risk avoidance.

Full Access
Question # 172

In which of the following situations may the internal audit activity report conformance with the Standards?

A.

An internal audit activity has been in existence at least five years and has not completed an external assessment,

B.

An internal auditor was assigned to an audit engagement but did not meet individual objectivity requirements.

C.

The internal audit activity prepared an internal audit plan that was not risk-based.

D.

The internal audit activity has been in existence fewer than five years, but periodic self-assessments were conducted.

Full Access
Question # 173

An internal auditor is trying to evaluate what could go wrong after determining that a risk management technique is operating effectively. What type of risk is the auditor assessing?

A.

Inherent risk.

B.

Residual risk.

C.

Impact risk.

D.

Detection risk.

Full Access
Question # 174

Which of the following is considered to be a threat to the internal auditor's objectivity?

A.

The auditor drafted the operational procedures of the area that she is currently auditing.

B.

The auditor received a bonus that was approved by the board of directors.

C.

The assigned auditor recommended operational procedures for the organization.

D.

The assigned auditor rotated out of the same business activity three years ago

Full Access
Question # 175

Which of the following statements best demonstrates application of due professional care during an assurance engagement?

A.

The engagement detected irregularities and noncompliance instances.

B.

The engagement supervisor had no significant comments in the supervisory review.

C.

The audit procedures were systematically planned, executed, and documented.

D.

The engagement objectives were designed to assist the engagement client.

Full Access
Question # 176

Which of the following is a legitimate requirement for an internal audit activity’s quality assurance and improvement program (QAIP)?

A.

Quality assessments should be performed by individuals with sufficient knowledge of the internal audit practices

B.

External quality assessments should be conducted every seven years

C.

All quality assessments should be either conducted or validated by an independent assessment team

D.

The results of the QAIP should be communicated to shareholders annually

Full Access
Question # 177

A snow removal company is conducting a scenario planning exercise where participating employees consider the potential impacts of a significant reduction in annual snowfall for the coming winter. Which of the following best describes this type of risk?

A.

Residual.

B.

Net.

C.

Inherent.

D.

Accepted.

Full Access
Question # 178

The organization's chief audit executive (CAE) is planning an immediate assurance engagement following several product recalls. However, the internal audit staff does not have the required Knowledge and experience to adequately assess all the relevant processes and procedures. According to 11A guidance, which of the following actions should the CAE take under these circumstances?

A.

Use the current available resources to conduct the review and exclude those procedures that can't currently be performed.

B.

Implement an accelerated training plan to provide the audit staff with the necessary skills and knowledge to conduct the engagement.

C.

Encourage management to accept the assessed risk until the internal audit activity is able to adequately review the area.

D.

Obtain assistance for the audit team from other internal assurance providers who possess the requisite expertise in the area.

Full Access
Question # 179

An internal auditor creates a professional development plan to obtain more experience in the organization's environmental, social, and corporate governance initiatives. Which of the following would the auditor include in the plan to support these objectives?

A.

A plan to study for and obtain a certification in nonprofit management.

B.

A deadline within the individual development plan to meet the overall engagement objectives.

C.

A plan to perform a variety of engagements to develop general skills that could be used to assess environmental, social, and governance initiatives.

D.

A request to attend the organization's committee meeting that is focused on strategic community awareness.

Full Access
Question # 180

During an assurance engagement an internal auditor discovered that risk limits risk limit were set for a new market expansion project Management of the area under review was eager to comply and submitted a potential risk limit value for the auditor's review and approval. Which of the following would be an appropriate course of action for the auditor to take?

A.

Review the submission and if no further remarks exist approve the risk limits

B.

Provide advice if needed and ask management of the area under review to forward to senior management and the board for approval

C.

Develop risk limit calculation criteria and ask management of the area under review to resubmit the values.

D.

Avoid providing any advice or review until the audit report is issued

Full Access
Question # 181

According to IIA guidance, which of the following training methods is considered most effective in assisting new entry-level internal auditors in achieving competence with internal audit practices in the workplace?

A.

Pursuance of an internal audit certification.

B.

Enrollment in internal audit practice webinars.

C.

Attendance of internal audit workshops.

D.

Involvement in a variety of audit assignments.

Full Access
Question # 182

Which statement accurately describes the authority of the internal audit activity as outlined in the audit charter?

A.

The chief audit executive (CAE) shall report directly to the board and administratively to the CEO.

B.

The CAE shall provide senior management and the board with performance updates quarterly.

C.

The internal audit team shall have full access to the organization's records, physical property, and personnel required to conduct audit engagements.

D.

The internal audit activity shall maintain a quality assurance and improvement program in conformance with the Standards.

Full Access
Question # 183

Which of the following frauds is most likely to occur in the accounts payable function?

A.

Factitious vendors are entered into the system, possibly resulting in improper disbursements.

B.

Bad debt expense is intentionally omitted from the financial statements.

C.

Certain costs are capitalized, rather than expensed.

D.

A related party receives benefits not appropriate in an arm's-length transaction.

Full Access
Question # 184

According to IIA guidance, which of the following statements is true regarding reporting the results of the quality assurance and improvement program?

A.

Results of internal assessments need to be reported to the board at least once every five years.

B.

The external assessor must present the findings from the external assessment to senior management and the board upon completion.

C.

Deficiencies within the internal audit activity must be reported to the board as soon as they are noted.

D.

Results of ongoing monitoring of the internal audit activity's performance must be reported to senior management and the board at least annually

Full Access
Question # 185

While conducting an engagement in the procurement department, the internal auditor noticed that the department head’s travel reports showed minor travel expenses, and there were no charges for hotels, meals, or transportation. However, the auditor knew that the department head frequently traveled worldwide to meet with suppliers and visit their production sites. Which of the following would be the most appropriate next step for the auditor?

A.

The auditor should make a note of the issue for follow-up when employee travel expenses are audited.

B.

The auditor should analyze trends and changes among the organization’s suppliers over the past few years.

C.

The auditor should investigate whether there are any special arrangements regarding senior management travel.

D.

The auditor should analyze the list of destinations the department head visited to estimate typical costs.

Full Access
Question # 186

Which of the following would show appropriate disclosure of nonconformance with the Standards?

A.

The chief audit executive (CAE) documented in the personnel file a critical conflict of interest involving an internal auditor on an upcoming contracting engagement.

B.

The CAE discussed with the board an issue regarding the internal audit activity performing an IT engagement without proper skills and knowledge.

C.

The CAE met with the peer review team to discuss an internal auditor's failure to meet the annual requirements for continuing professional education.

D.

The CAE revealed to operational managers that he failed to appropriately consider risks while he was developing the audit plan.

Full Access
Question # 187

A manufacturing organization's chief audit executive (CAE) was approached by the head of security from one of the manufacturer's third party suppliers The head of security requested internal audit records from a recent audit engagement involving the third-party supplier The head of security believed those records contained information that would enable to identify employees of the third-party supplier who may be involved m fraudulent activities What is the most appropriate course of action for the CAE?

A.

Obtain approval from the manufacturer's audit committee regarding the release of audit records

B.

Release the records but first remove all data regarding the manufacturing organization s internal actions and procedures

C.

Deny access to the records as the third party supplier s security learn should be able to investigate then own employees.

D.

Consult with the manufacturer's senior management to determine whether releasing tie records would be appropriate

Full Access
Question # 188

IT management requires all employees in the IT department to attend annual training on the department's mission, values, and key performance measures. This activity is designed to prevent which of the following conditions?

A.

Knowledge/skills gap.

B.

Monitoring gap.

C.

Accountability/reward failure.

D.

Communication failure.

Full Access
Question # 189

During a review of employee benefits, a staff internal auditor observed an ambiguity in the incentive compensation policy. If reported, it could negatively impact the internal auditor's compensation. Which of the following would encourage the internal auditor to be objective in his work?

A.

Periodic reinforcement of the internal audit activity's code of ethics disclosure practices.

B.

External assessments of the internal audit activity every five years.

C.

Audit committee review of every engagement report at the conclusion of the audit.

D.

Internal audit charter approved by the board.

Full Access
Question # 190

Which of the following internal control components has COSO identified as the most important?

A.

Information and communication

B.

Risk assessment

C.

Control activities

D.

Control environment

Full Access
Question # 191

Which of the following describes two duties that should not be performed by the same person?

A.

Posting cash receipts and cash payments to the general ledger.

B.

Posting bad debt write-offs and reconciling the accounts payable subsidiary ledger.

C.

Distributing payroll checks and approving sales returns for credit.

D.

Recording cash receipts and preparing bank reconciliations.

Full Access
Question # 192

When would on-the-job training be more effective?

A.

When participants already have a certain degree of experience and knowledge.

B.

When it makes up the largest part of the training budget.

C.

When it includes ongoing feedback and coaching from experienced team members.

D.

When it is standardized for the whole entire staff.

Full Access
Question # 193

Which of the following activities would an internal auditor perform as a consulting engagement for an organization?

A.

Advising new internal auditors working for the organization on how to develop strategies on planning audits for the upcoming fiscal year

B.

Assessing whether the organization's corporate social responsibility program is meeting its yearly goals to reduce carbon emissions.

C.

Briefing the organization's department managers on how to implement risk management processes into their daily operations.

D.

Communicating with senior management to better understand how new purchasing controls will minimize payment processing time.

Full Access
Question # 194

Nearing the completion of fieldwork, an internal auditor shared the draft report findings with management prior to the closing meeting. During the closing meeting, management expressed dissatisfaction in that they were not familiar with some of the findings. Management also noted that some aspects of the report seemed confusing. Which of the following competencies appears to have been lacking in this scenario?

A.

Communication.

B.

Business acumen.

C.

Persuasion.

D.

Critical thinking.

Full Access
Question # 195

Once an organization's risks are identified, what would be the next step to ensure resources are properly allocated to manage those risks?

A.

Risk responses must be selected.

B.

Risks must be assessed.

C.

The risk universe must be established.

D.

Risk responses must be aligned.

Full Access
Question # 196

The level of authority for the internal audit activity is granted by which of the following?

A.

The chief audit executive.

B.

The internal audit charter.

C.

The International Professional Practices Framework.

D.

The IIA's Code of Ethics.

Full Access
Question # 197

The chief audit executive (CAE) has assigned an internal auditor to an upcoming engagement. Which of the following requirements would most likely indicate that the internal auditor was assigned to an assurance engagement?

A.

The assigned internal auditor must determine the objectives, scope, and techniques of the engagement.

B.

The CAE must personally obtain the needed skills, knowledge, or other competencies if the internal auditor does not have them.

C.

The assigned internal auditor must not assume management responsibilities while performing the engagement

D.

The assigned internal auditor must maintain objectivity while performing the engagement.

Full Access
Question # 198

An internal auditor in a busy internal audit activity reviews her continuing professional development records toward the end of the year and is concerned to find she has undertaken limited training and formal professional development. Which of the following actions is the most appropriate for her to take?

A.

Remind the chief audit executive (CAE) that he is responsible for her continuing professional development and needs to address the issue

B.

Contact her professional organization and explain that she does not need formal professional development, as she is being developed sufficiently through undertaking audit engagements.

C.

Accept that she is unlikely to meet continuing professional development requirements but look to attend training courses at the next available time.

D.

Accept that she is responsible for her own continuing professional development, develop a professional plan, and discuss it with the CAE.

Full Access
Question # 199

An accounts payable clerk who has access to the vendor master file replaced the payment details of a legitimate vendor with those of a friend before processing the payment through the organization's cashier. Immediately afterward, he restored the original vendor information. Which of the following controls could have prevented this fraud?

A.

Approval of master file change requests by the accounts payable supervisor

B.

Comparison of the check register to original invoices.

C.

Segregation of duties between accounts payable and the cashier.

D.

Frequent issuance of account statements sent to the vendors.

Full Access
Question # 200

Which of the following approaches will internal audit utilize when developing a set of performance standards to measure an organization’s risk management process against?

A.

Key principles approach

B.

Process elements approach

C.

Holistic approach

D.

Maturity model approach

Full Access
Question # 201

An internal auditor was assigned to work in the procurement department for six months to gam m-depth knowledge about the procurement process. Which of the following personnel development practices was applied in this situation?

A.

Cosourcing

B.

Inbound rotation

C.

Guest auditor

D.

Outbound rotation

Full Access
Question # 202

A newly hired internal auditor is most likely to need further education in the area of business acumen in which of the following situations?

A.

She was transferred from the managerial accounting department of the same organization.

B.

She was recruited from the internal audit activity of another organization that operates in a different industry.

C.

She was offered a permanent position after she had worked with the organization for two years in a temporary auditor-in-training position.

D.

She previously served on the organization's external audit team and was recruited to the internal audit activity following the current year's financial audit.

Full Access
Question # 203

Which of the following is a way to demonstrate an individual internal auditor's competency through continuing professional development?

A.

Create different training budgets for each of the internal auditors

B.

Define average training hours per auditor as a team performance measure

C.

Analyze internal audit client survey feedback following audits

D.

Review training records for all internal auditors

Full Access
Question # 204

Which of the following best describes the approach the internal audit activity should take to assess and make appropriate recommendations to improve the organization?

A.

To evaluate an organization s governance processes for making strategic and operational decisions eternal auditors should review the organization s policies and processes related to staff compensation

B.

To determine how an organization provides oversight of its risk management and control activities internal auditors should review board meeting minutes and the board policy manual

C.

To assess how an organization promotes ethics and values both internally and among its external business partners, internal auditors should review the organization' s related objectives programs and activities

D.

To evaluate how an organization ensures effective performance management and accountability internal auditors should review previously conducted risk assessments

Full Access
Question # 205

Which of the following statements is true regarding control activities'?

A.

Control activities are defined by management through risk mitigation strategies

B.

Control activities should be defined for all business processes

C.

If two organizations have identical objectives and structures their control activities would be the same

D.

Organizations that are less regulated generally have more complex control activities than highly regulated organizations

Full Access
Question # 206

According to MA guidance, which of the following is the most accurate statement regarding the internal audit charter?

A.

The IIA's Code of Ethics must exist outside of the charter to maintain independence.

B.

The charter must be approved by both senior management and the board.

C.

The nature of consulting services does not need to be defined in the Internal audit charter.

D.

The charter provides a framework for performing a broad range of value-added audit services.

Full Access
Question # 207

According to IIA guidance, which of the following actions best demonstrates that due professional care has been considered by the internal audit activity when conducting a review of an organization's assets?

A.

Determining whether any opportunity exists for senior executives to misappropriate property or funds

B.

Planning and executing fieldwork In a complete and timely manner to identify all significant risks

C.

Verifying whether the board of directors has implemented effective internal controls

D.

Having senior management determine whether the degree of work planned is sufficient to meet engagement objectives

Full Access
Question # 208

Which of the following offers the feast evidence that the internal audit activity has achieved organizational independence?

A.

An independent third party has assessed the organization's system of internal controls to be adequate and effective.

B.

The chief audit executive reports both functionally and administratively to the CEO.

C.

The internal audit charter is drafted properly and approved by the appropriate parties.

D.

The mission statement and strategy of the internal audit activity demonstrates alignment to organizational objectives.

Full Access
Question # 209

Management has implemented a segregation-of-duties policy for handling inventory. Which of the following fraud risks would be more concerning to an internal auditor following the implementation of this new policy?

A.

The risk of collusion between parties.

B.

The risk of falsified reconciliations.

C.

The risk of low-liquidity inventory.

D.

The risk of damages to the inventory.

Full Access
Question # 210

To comply with the proficiency standard, which of the following would the chief audit executive likely consider as the primary hiring criterion when choosing a new internal auditor?

A.

The auditor's demonstrated problem-solving skills.

B.

The auditor's skills compared to those already possessed by other audit staff.

C.

The auditor's ability to be self-motivated and a good team player.

D.

The length and consistency of the auditor's work experience.

Full Access
Question # 211

Which of the following would be considered an indicator that an organization's ethics program is not yet well developed?

A.

Disciplinary actions for ethics compliance violations are reviewed by the internal audit activity for consistency.

B.

Communication of ethics compliance expectations is the responsibility of employees' direct managers.

C.

The organization's code of ethics and related compliance policy are reviewed annually for potential updates.

D.

The board of directors reviews ethics oversight metrics for violations and compliance.

Full Access
Question # 212

An organization is implementing a new cybersecurity policy and has established a committee to ensure stakeholder alignment across the organization's infrastructure, network, and security teams. The head of the committee has asked the chief audit executive if the internal audit activity could play a role in these efforts. According to HA guidance, which of the following is the most appropriate response?

A.

It is not appropriate for the internal audit activity to play a role because its independence must be protected.

B.

The internal audit activity should not participate because there are no IT auditors on staff.

C.

The internal audit activity is knowledgeable about risk and therefore should prioritize the organization's responses and control activities for the committee.

D.

The internal audit activity may assist the committee and consult with management on the organization's responses and control activities.

Full Access
Question # 213

Which of the following scenarios best illustrates the Fraud Triangle component known as "perceived opportunity"?

A.

Substantial bonuses are awarded if financial targets are met.

B.

Duties are not properly segregated.

C.

Employees may perceive favoritism and feel overlooked and resentful.

D.

Bonuses may not be paid this year.

Full Access
Question # 214

Which of the following best describes the risk created when a manager bypasses organizational policies and procedures in order to meet an organization’s objective?

A.

Accountability/reward risk.

B.

Monitoring failure risk.

C.

Communication failure risk.

D.

Knowledge/skills risk

Full Access
Question # 215

In which scenario might it be considered problematic for the chief audit executive (CAE) to provide assurance services over the payroll function?

A.

The CAE previously undertook a consulting assignment in that area to improve processes,

B.

A couple of years ago, the CAE performed accounting functions for the payroll department.

C.

Prior to becoming the CAE, the CAE was the payroll manager.

D.

The assurance review was initiated following issues identified during a consulting assignment requested by management.

Full Access
Question # 216

A new company’s risk management function is developing its cybersecurity risk management program Which of the following actions should be the first priority when developing the program?

A.

Start building a cybersecurity culture and set the desired behavior using a bottom-up approach

B.

Determine the cybersecurity framework that will establish and report on the effectiveness of the program

C.

Define the cybersecurity risk appetite and perform a cost-benefit analysis of the program

D.

Raise cybersecurity awareness across various departments outside of the IT department

Full Access
Question # 217

Which type of engagement requires that the client agrees with the techniques used by the internal audit activity?

A.

A performance audit.

B.

A sensitive fraud investigation.

C.

A compliance audit

D.

A consulting service.

Full Access
Question # 218

Recently an organization’s internal audit activity discovered ghost employees who receive payments Senior management decides to strengthen the internal control measures to address this Which of the following is considered an effective control to mitigate payments to ghost employees?

A.

Staff transfers are reviewed by the recruiting manager and approved by the head of human resources

B.

New staff requisition forms are authorized by operational management and acknowledged by the head of human resources

C.

Staff salary payments and accounting records are approved by the head of accounting and acknowledged by the head of human resources

D.

The staff salary payment list is reviewed by the head of payroll and endorsed by the head of human resources

Full Access
Question # 219

An internal auditor at a multinational organization is reviewing the effectiveness of the organization's risk management framework. In this scenario, which of the following statements is true?

A.

The auditor should consider local cultures and customs in various regions when assessing control effectiveness.

B.

Regardless of their location, employees at all levels share responsibility for designing effective controls to mitigate risks.

C.

To achieve an effective internal control environment, the organization's risk management plan must be documented and communicated to all levels throughout each region.

D.

Setting clear objectives is a precondition to effectively identifying, assessing, and responding to the organization's risks.

Full Access
Question # 220

Which of the following is an advantage of using nongovernmental organization (NGO) members on an assurance team when auditing corporate social responsibility?

A.

Typically less time is needed to train the NGO members on the audit process.

B.

NGO members are often more unbiased and objective

C.

A report with a positive statement from an NGO member is deemed to be more credible. As opposed to auditors.

D.

NGO members are licensed to audit corporate social responsibility.

Full Access