Month End Sale - Special 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75onlydt

IIA-CIA-Part1 Questions and Answers

Question # 6

Which of the following actions would be most effective to help an internal auditor determine how successful the organization has been in communicating the existence of its ethics hotline?

A.

Reviewing the number of anonymous hotline allegations against employee complaints.

B.

Surveying employees to determine whether they are aware of the hotline.

C.

Benchmarking the average time to investigate hotline complaints.

D.

Tracking the number of hotline allegations per total number of employees.

Full Access
Question # 7

An internal auditor is preparing for an overseas engagement. As part of the engagement, the auditor will conduct interviews with managers from various regional offices around the world.

Which of the following is the most important for the auditor to consider in establishing good relationships with regional managers?

A.

That cultural norms at the corporate headquarters may apply to most of the regional offices.

B.

That business relationships at the corporate headquarters match those at each of the regional offices.

C.

That viewpoints expressed from the corporate headquarters are consistent among the regional offices.

D.

That communication skills used at the corporate headquarters should be adapted for each of the regional offices.

Full Access
Question # 8

The internal audit activity is asked to provide consulting services regarding the risks related to implementing a proposed new Inventory management system. Which of the following would be a key consideration of the internal audit activity in accepting this engagement?

A.

Ask the inventory manager to determine whether the work planned would be sufficient to meet the consulting engagement objectives.

B.

Ensure that the method used to communicate the results of the consulting engagement is consistent with the board ' s preferred method.

C.

Determine whether the benefits to be derived from the requested assessment would exceed the cost of providing the consulting service.

D.

Use email and telephone conversations to convey the results of the engagement, as these may prove to be the most efficient methods for communicating.

Full Access
Question # 9

Which of the following measures could directly improve the general understanding of fraud risk within an organization?

A.

Request that the internal audit function conduct regular fraud risk assessments.

B.

Include fraud risk in the organization wide risk management program.

C.

Formalize fraud reporting mechanisms.

D.

Provide education about tactics used by fraudsters.

Full Access
Question # 10

According to MA guidance, which of the following is the most accurate statement regarding the internal audit charter?

A.

The IIA ' s Code of Ethics must exist outside of the charter to maintain independence.

B.

The charter must be approved by both senior management and the board.

C.

The nature of consulting services does not need to be defined in the Internal audit charter.

D.

The charter provides a framework for performing a broad range of value-added audit services.

Full Access
Question # 11

According to IIA guidance, who should chief audit executives report to regarding the internal audit function’s human resources daily matters, such as vacations?

A.

Chief risk officer.

B.

Chief finance officer.

C.

Chief executive officer.

D.

Chief operational officer.

Full Access
Question # 12

An engagement supervisor noticed that a newly hired internal auditor struggles with large data samples because he appears reluctant to apply available spreadsheet statistical functions and tends to perform testing of transactions manually In which of the following areas does the internal auditor most likely need training?

A.

Critical thinking.

B.

International Professional Practices Framework

C.

Professional ethics

D.

Business acumen

Full Access
Question # 13

A third-party provider ' s questionable labor practices have exposed the organization to reputational risks and regulatory risks. Which of the organization ' s risk management practices was most likely ineffective?

A.

The organization ensured that the third-party vendor provided the best pricing for the requested services.

B.

The organization conducted quality control reviews of provided services to ensure industry standards were met.

C.

The organization performed a due diligence review of all vendors during the bid review process.

D.

The organization planned to issue a resolution concerning the third-party provider ' s labor practices.

Full Access
Question # 14

Which of the following is the primary engagement responsibility of an entry-level internal auditor?

A.

Leadership.

B.

Documentation.

C.

Analysis.

D.

Reporting.

Full Access
Question # 15

Which of the following statements is true regarding reporting results of the quality assurance and improvement program to senior management and the board?

A.

Internal assessments must be reported to the board at least every five years

B.

If supported by assessment results, reporting provides assurance that internal auditors demonstrate conformance with the Code of Ethics

C.

Following the reporting the board must give the internal audit activity five years to correct any deviations

D.

A report, including the results of both internal and external assessments must be provided to the board annually

Full Access
Question # 16

A newly hired chief audit executive is reviewing available documentation to provide evidence of conformance with the standard for continuing professional development. Which of the following documents is the most reliable source for this purpose?

A.

The organization ' s training policy.

B.

A list of auditors who requested to attend the next audit conference.

C.

Self-assessments against an internally developed audit benchmark

D.

In house training manual

Full Access
Question # 17

An internal audit team received the following feedback from operational management via a post-engagement survey " Management agrees with all audit findings However, the audit team did not consider our input on the best way to resolve the issues”

This feedback is an indication that the internal audit activity may need to improve which of the following interpersonal skills?

A.

Leadership

B.

Conflict management

C.

Communication

D.

Influence

Full Access
Question # 18

Which of the following activities aligns with The IIA ' s Core Principles for the Professional Practice of Internal Auditing?

A.

The chief audit executive reports to senior management for compensation decisions and communications of audit results to the board

B.

Final reports from consulting engagements show the summary of findings, and the internal auditor’s advice is clearly distinct and separate from management ' s decisions

C.

Internal auditors rotate through operations and management positions then perform audit engagements on these areas to ensure timely application of their knowledge

D.

Due to limited resources, internal auditors prioritize assurance on internal controls and risk management and exclude evaluating governance processes, which are deemed outside of their core responsibilities

Full Access
Question # 19

A new board member, who is unfamiliar with internal auditing, asks the chief audit executive about the purpose of the internal audit function.

Which explanation is accurate?

A.

To identify problems faced by the organization.

B.

To strengthen the organization through independent and objective engagements.

C.

To ensure that the organization meets its goals and objectives.

D.

To enhance the identification, detection, and elimination of fraud.

Full Access
Question # 20

Which of the following statements is true regarding control activities ' ?

A.

Control activities are defined by management through risk mitigation strategies

B.

Control activities should be defined for all business processes

C.

If two organizations have identical objectives and structures their control activities would be the same

D.

Organizations that are less regulated generally have more complex control activities than highly regulated organizations

Full Access
Question # 21

An internal auditor was offered expensive tickets to a sporting event by the manager of an area that she was currently auditing. The auditor politely declined. Which of the following fundamental principles of the MA Code of Ethics did she display?

A.

Confidentiality.

B.

Independence.

C.

Competency.

D.

Objectivity

Full Access
Question # 22

Which of the following statements best demonstrates application of due professional care during an assurance engagement?

A.

The engagement detected irregularities and noncompliance instances.

B.

The engagement supervisor had no significant comments in the supervisory review.

C.

The audit procedures were systematically planned, executed, and documented.

D.

The engagement objectives were designed to assist the engagement client.

Full Access
Question # 23

Which of the following actions by the internal auditor best addresses the effectiveness of a control?

A.

Determine whether the control creates delays in business processes or duplication of effort.

B.

Determine whether the control design is appropriate and operating as intended.

C.

Determine whether the degree of effort required to perform the control is reasonable.

D.

Determine whether the cost of the control is appropriate for the significance of the risk it addresses.

Full Access
Question # 24

Senior management purchased surveillance cameras and installed them over a door that provides entry to an area where according to a recent internal audit report, hazardous materials exist and there is a high risk of explosion Which type of control was implemented in this situation?

A.

A corrective control

B.

A detective control

C.

A preventive control

D.

A directive control

Full Access
Question # 25

According to IIA guidance, which of the following statements is true regarding the internal audit activity ' s quality assurance and improvement program (QAIP)?

A.

Internal assessments rely solely on the review of completed audit engagements for demonstrated performance

B.

The chief audit executive is responsible for assessing the suitability and competence of an external assessor.

C.

QAIP results must first be discussed with the board and approval obtained for distribution to senior management

D.

At the board ' s discretion, the frequency of external assessments can exceed the five-year guideline

Full Access
Question # 26

An internal auditor is trying to evaluate what could go wrong after determining that a risk management technique is operating effectively. What type of risk is the auditor assessing?

A.

Inherent risk.

B.

Residual risk.

C.

Impact risk.

D.

Detection risk.

Full Access
Question # 27

The internal audit activity conducted an organization wide risk assessment. One of the most significant risks identified is associated with the oil price market. The chief audit executive (CAE) is considering including in the annual audit plan an assessment of the effectiveness of oil price risk management. The manager responsible commented that the assessment was not needed, as market risks were regularly addressed by the financial risk committee. If the CAE decides to include this activity in the annual audit plan anyway, how should it be recorded?

A.

A consulting engagement independent of the financial risk committee ' s review.

B.

A risk assessment.

C.

An assurance engagement.

D.

A joint consulting engagement with input from the financial risk committee.

Full Access
Question # 28

The results of an assessment of the adequacy of controls would be considered incomplete or misleading unless the internal auditor considers which of the following?

A.

Number of mitigating controls.

B.

Effectiveness of the control environment

C.

Use of computer-assisted auditing techniques.

D.

IT security controls

Full Access
Question # 29

Which of the following must be considered by the chief audit executive before writing the internal audit charter?

A.

Internal auditors ' level of competencies and skills.

B.

The manner in which the internal audit activity is viewed by the board.

C.

Evaluation of staff certifications and continued development.

D.

Effectiveness of the quality assurance and improvement program.

Full Access
Question # 30

Which of the following is a legitimate role for the internal audit activity in the organization ' s risk management process ' ?

A.

Championing the establishment of a risk management framework

B.

Creating and implementing new risk management processes

C.

Maintaining sole responsibility for risk management within the organization

D.

Setting the risk appetite of the organization

Full Access
Question # 31

An organization ' s board recommends revising the internal audit charter by adding requirements regarding the hiring and compensation of the chief audit executive as well as information on approving the internal audit budget. Which of the following is the board most likely defining in the charter?

A.

Functional and administrative responsibilities of internal audit activity.

B.

Authority and objectivity of internal audit activity.

C.

Independence and objectivity of internal audit activity.

D.

Assurance and improvement of internal audit activity.

Full Access
Question # 32

Which principle of the HA Code of Ethics focuses on continuing education and professional development?

A.

Due professional care

B.

Professionalism

C.

Proficiency

D.

Competency

Full Access
Question # 33

An organization allows the same individuals to physical access inventory and purchase new assets when supplies are depleted. Which of the following would best help the organization manage the risk of fraud?

A.

Accounting personnel should regularly perform reconciliation between invoices and purchase orders

B.

Accounting personnel should conduct a periodic inventory count and reconcile inventory movements

C.

internal auditors should review Vie frequency and volume of purchased assets to detect trends in the inventory levels

D.

Management should established a policy requiring new inventory asset purchases to be made on serialized order forms with copies retained

Full Access
Question # 34

Recently an organization’s internal audit activity discovered ghost employees who receive payments Senior management decides to strengthen the internal control measures to address this Which of the following is considered an effective control to mitigate payments to ghost employees?

A.

Staff transfers are reviewed by the recruiting manager and approved by the head of human resources

B.

New staff requisition forms are authorized by operational management and acknowledged by the head of human resources

C.

Staff salary payments and accounting records are approved by the head of accounting and acknowledged by the head of human resources

D.

The staff salary payment list is reviewed by the head of payroll and endorsed by the head of human resources

Full Access
Question # 35

An internal auditor for a manufacturing company is asked by a separate consulting company to work for them on an as-needed basis outside of his normal working hours to develop policies and procedures for a customer of the consulting company. The two companies are not competitors.

If the auditor agrees to take on the additional work, which of the following statements is true?

A.

This would not be a violation of The IIA’s standards of ethics and professionalism.

B.

This would constitute a breach of confidentiality, as the auditor has knowledge of the policies and procedures of the manufacturing company obtained in the course of his work.

C.

This would constitute an integrity issue because the auditor is still employed by the manufacturing company.

D.

This would be an impairment to objectivity because auditors cannot assume operational responsibilities, such as creating corporate processes and procedures.

Full Access
Question # 36

According to IIA guidance, which of the following best demonstrates that the chief audit executive is properly reporting the results of the quality assurance and improvement program to senior management and the board?

A.

Providing a written conformance statement to both senior management and the board.

B.

Giving copies of both external and internal assessments to the board.

C.

Keeping files of reports of ongoing external assessment monitoring.

D.

Retaining copies of board meeting minutes showing that discussions of assessments took place.

Full Access
Question # 37

Which of the following could increase risks to the organization’s control environment?

A.

Strong board of directors oversight.

B.

Incentive-based compensation structures.

C.

Lower than average employee turnover.

D.

Implementation of a fraud hotline.

Full Access
Question # 38

An internal auditor is reviewing the organization’s procurement processes. The procurement manager states that suppliers’ bank details are verified by phone call directly with the supplier before being updated in the procurement system. The organization has around 3,000 suppliers. The auditor is skeptical that a phone call is made for each supplier when bank details are changed.

The auditor decides to verify the manager’s statement by analyzing the change to one supplier’s bank details.

Which piece of evidence would convince the auditor that the control described by the procurement manager is effective?

A.

A commercial registration document of the supplier to verify its existence.

B.

Details of the last bank payment made to the selected supplier and verification against the bank account invoice.

C.

An annual confirmation email from each member of the procurement team to the procurement manager stating that bank details were confirmed.

D.

Documentation of the call made with the supplier that includes the details of both parties and the information to be verified.

Full Access
Question # 39

According to IIA guidance, which of the following actions by the chief audit executive (CAE) best demonstrates the organizational independence of the internal audit activity?

A.

The CAE seeks senior management approval of the internal audit charter

B.

The CAE obtains senior management ' s approval to hire staff

C.

The CAE reports significant issues to the organization ' s CEO

D.

The CAE provides the board with an annual budget for approval

Full Access
Question # 40

Which of the following situations best describes an internal auditor who may have violated the IIA Code of Ethics principle of confidentiality?

A.

The auditor intentionally omitted from his resume that he was fired from his previous job for fraud allegations,

B.

The auditor decided not to notify her supervisor that her brother-in-law was responsible for the project the auditor was expected to evaluate.

C.

The auditor asked the audit client to copy requested files to her personal unencrypted memory stick because it was faster and more convenient.

D.

The auditor was assigned to analyze the organization ' s incentive program and spent long hours reviewing other employees’ bonuses,

Full Access
Question # 41

Which of the following is an example of an entity-level control pertaining to the finance area of an organization ' ?

A.

Key account reconciliation such as bank reconciliation

B.

Segregation of duties between posting and reviewing journal entnes

C.

A signing authority matrix for spending approvals

D.

The establishment of a finance and audit committee

Full Access
Question # 42

Which of the following controls would most likely prevent fraud related to the overpayment of vendors?

A.

Require supervisory review of all invoices and cash disbursements exceeding a stated threshold.

B.

Require the matching of a purchase order, receiving report, and invoice before payment.

C.

Require all checks to be signed by more than one person.

D.

Require all invoices to be paid within 30 days by check only.

Full Access
Question # 43

During a brainstorming session, employees stated that dishonest vendors could submit fictitious invoices to the organization, and such an invoice may be authorized for payment because the employees responsible might be clicking approval boxes without going into the details.

Given this information, which of the following controls should be tested during the audit engagement?

A.

Confirmation of receipt of goods or services.

B.

Automatic processing of approved payments to the bank.

C.

Segregation of duties in accounts payable.

D.

Detection of preferential treatment of vendors.

Full Access
Question # 44

Which of the following actions by an internal auditor would be the most relevant to determine the effectiveness of controls?

A.

Participate in a fraud risk-assessment session as an in-house facilitator.

B.

Send regular written updates to senior management on new control-related regulations.

C.

Lead a seminar on internal controls and provide numerous examples to the audience.

D.

Conduct a surprise inventory count at the raw materials warehouse.

Full Access
Question # 45

Which situation would best demonstrate that the organization maintains a strong ethical culture?

A.

Management schedules ethics training for their areas as time permits.

B.

All employees receive an ethics manual upon being hired to guide their behavior.

C.

Compensation for sales staff is independent of performance targets.

D.

An external hotline exists for employees to report noncompliance issues.

Full Access
Question # 46

Due to the increased operational responsibility of the CEO the chief audit executive (CAE) of an organization currently reports to the chief financial officer (CFO) What is the likely impact of such a situation?

A.

There may be limitation in the scope of engagements that can be undertaken

B.

The CFO could provide expert advice when auditing areas under his purview

C.

The internal audit activity is adequately positioned when the CAE reports to a member of executive management

D.

The expertise of finance staff can be called upon during an audit of finance-related areas

Full Access
Question # 47

Which of the following statements is true regarding the disclosure of results of the quality assurance and improvement program?

A.

If the results of both internal and external assessments support conformance with the Standards, the internal audit activity must communicate this to the board and senior management in writing.

B.

If it has been in existence fewer than five years and has no documented external assessment, the internal audit activity may not indicate that it is operating in conformance with the Standards.

C.

If nonconformance affects its ability to fulfill its professional responsibilities or stakeholder expectations, the internal audit activity should disclose nonconformance as well as its impact.

D.

If an external assessment reflects an overall conclusion of nonconformance, the internal audit activity may continue to communicate that it conforms with theStandards if it discloses a remediation plan, including timeline with subsequent validation.

Full Access
Question # 48

Which of the following would be most helpful to measure whether an internal audit activity successfully provides risk-based assurance?

A.

Percentage of highly significant risks covered by internal audit plan.

B.

Percentage of previously unknown risks identified per engagement.

C.

Percentage of internal audit staff skilled in alignment with the organization ' s structure and key risks.

D.

Percentage of observations made in assurance engagements compared to advisory engagements.

Full Access
Question # 49

A newly appointed chief audit executive (CAE) is tasked with creating a new internal audit activity within the organization. Which of the following would the CAE need to include in the new internal audit charter?

A.

The requirement to provide an annual cost analysis that justifies having an internal audit activity

B.

The specific engagements that the internal audit activity will perform for the organization

C.

The board s oversight role and responsibilities pertaining to the internal audit activity

D.

The relevant regulations that will guide the internal audit activity ' s regulatory compliance assessments

Full Access
Question # 50

Which of the following activities would breach the principles of The IIA ' s Code of Ethics?

A.

The internal auditor is keeping personal notes from an engagement conducted on the organization ' s information system security for future use.

B.

The internal auditor is performing an engagement of the purchasing department where he used to work five years ago.

C.

The internal auditor is using information from a recent engagement to assist with a friend ' s business.

D.

The internal auditor is discussing relevant information involving questionable vendors with a government regulatory agency.

Full Access
Question # 51

During a payroll audit, a staff internal auditor suspects that signatures on some of the documents being sampled for examination are not authentic. Which of the following actions should the auditor take before proceeding with the examination?

A.

Suggest to the payroll manager that the suspicious documents should be sent to the organization ' s security department for forensic review.

B.

Keep the suspicious documents in the workpaper file until the end of the engagement, and then discuss the suspicions with the payroll manager.

C.

Discuss the suspicious documents with payroll staff to seek their views on the authenticity of the signatures.

D.

Review the suspicious documents with the chief audit executive and seek advice concerning further examination.

Full Access
Question # 52

A whistle blower notified internal audit of a conflict of interest between an organization ' s employee and a major supplier. Which of the following steps should be undertaken first?

A.

Interview the employee identified by the whistleblower.

B.

Attain an understanding of the employee ' s role, responsibilities, and relationship with the supplier.

C.

Notify senior management, the board, and the external auditor about the alleged fraud

D.

Review all the orders issued to the supplier to investigate potential fraud.

Full Access
Question # 53

Of all the common characteristics of frauds, which of the following can the organization influence the most?

A.

Pressure or incentive.

B.

Rationalization

C.

Opportunity

D.

Commitment.

Full Access
Question # 54

The internal auditor obtained large volumes of transaction history data for accounts on which he suspected that some fraudulent transactions occurred. Which of the following actions best demonstrates due professional care by the internal auditor?

A.

The internal auditor carefully scrutinized the data by manually reviewing each transaction to ensure that all irregularities were identified.

B.

The internal auditor employed the use of data analytics tools to sort, analyze, and detect anomalies in the data

C.

The internal auditor started the data analysis process by selecting a random sample of transactions on which to perform further tests.

D.

The internal auditor requested that the branch supervisor assist in identifying fraudulent transactions, as he was most familiar with the accounts being audited.

Full Access
Question # 55

The same internal auditor has audited the regional purchasing department annually for the last three years. The audits have shown several significant control deficiencies that have not been corrected by management. New management is in charge of this regional purchasing department, and it is time to audit the department again. What concerns should be considered prior to assigning the audit to the same auditor?

A.

Intimidation threats may compromise the auditor ' s objectivity due to multiple negative audit reports completed by the auditor.

B.

The auditor has reviewed the department annually for the last three years, leading to familiarity, which can impact the internal audit activity ' s independence.

C.

A negative cognitive bias may be in place that affects the employee ' s objectivity due to the recent audits with uncorrected control deficiencies.

D.

The auditor may have formed a cultural bias, as the department under review is in the auditor ' s geographic area.

Full Access
Question # 56

In which of the following circumstances would the internal auditor likely decide that a control does not need to be tested for effectiveness?

A.

The control is already supported by appropriate secondary controls.

B.

There are weaknesses in the control design.

C.

The control has already been tested by management.

D.

Management attests that there have been no changes to the control since the last audit.

Full Access
Question # 57

Which of the following statements is true regarding the quality assurance and improvement program (QAIP)?

A.

Reporting on the QAIP to the board should occur at least once every five years

B.

The responsibility for the selection of an external assessor rests with the board

C.

The qualifications of the assessors must be communicated to the board

D.

The reporting of outcomes of the QAIP can be delegated to senior audit staff

Full Access
Question # 58

An accounts payable clerk has recently transferred Into the internal audit activity and has been assigned to an engagement related to accounts payable processes for which he was previously responsible Which of the following is the best action for the new internal auditor to take?

A.

If it is an assurance engagement accept the assignment because direct knowledge of the existing accounts payable processes will provide depth and add more value

B.

If it is a consulting engagement decline the assignment and ask to be reassigned, because in a consulting engagement the auditor must not assess operations for areas in which they were previously responsible

C.

If it is a consulting engagement accept the assignment because direct knowledge of the existing accounts payable processes will provide depth and add more value

D.

If it is an assurance engagement accept the assignment becausethe chief audit executive had knowledge of the internal auditor ' s previous role when this engagement was assigned

Full Access
Question # 59

In order for an internal auditor to assess the opportunity for fraud to occur in an organization, which of the following does the auditor first need to understand?

A.

Fraud prevention.

B.

Fraud detection.

C.

Corporate culture.

D.

Forensic analysis techniques.

Full Access
Question # 60

Which of the following is most likely to result in the impairment of independence for the internal audit activity?

A.

The chief audit executive (CAE) has a dual reporting relationship within the organization.

B.

The CAE performs an audit of a functional area that is also under the CAE ' s oversight.

C.

The CAE has unrestricted access to information throughout the organization and to the board.

D.

The board is involved in decisions to hire or remove the CAE and in drafting and approving an internal audit charter.

Full Access
Question # 61

An internal auditor believes that the internal audit activity ' s independence is impaired. Which of the following actions should the internal auditor take first?

A.

Report the impairment to senior management

B.

Discuss the impairment with the audit manager

C.

Ascertain the best approach to disclose the impairment.

D.

Decide on the extent of impact of the impairment

Full Access
Question # 62

Which responsibility is most appropriate for the internal audit function, according to the Global Internal Audit Standards?

A.

Reporting internal audit engagement findings to regulatory agencies.

B.

Providing risk-based advice to the organization’s stakeholders.

C.

Conducting accounting audit engagements as requested by the chief financial officer.

D.

Designing and implementing new organizational policies.

Full Access
Question # 63

Which of the following strategies for professional development best demonstrates an internal auditor’s competency ' ?

A.

Completed education credits

B.

Membership in professional organizations

C.

Subscriptions to sources of relevant professional information

D.

Professional development and training plans

Full Access
Question # 64

An organization opened its warehouse to sell written-off surplus and outdated office furniture to the general public. Prices were negotiable, and customers could pay by cash, check, or credit card. Receipts were available upon request, and were issued by the inventory manager upon collection of payment. At the end of the day, the manager forwarded all of the funds he had collected to the finance department for deposit. Which of the following types of fraud is most likely to occur under these circumstances?

A.

Asset misappropriation.

B.

Bribery.

C.

Falsifying records.

D.

Skimming

Full Access
Question # 65

Which of the following is true for consulting engagements ' ?

A.

The internal audit activity must ensure management actions have been effectively implemented or risk accepted

B.

A work program for the engagement is not required but may be developed

C.

The nature of consulting services does not have to be in the internal audit charter

D.

Risks identified from the engagement must be considered when evaluating the organization ' s risk management processes

Full Access
Question # 66

Which of the following will help the chief audit executive (CAE) of a large organization ensure that the independence of the internal audit function is maintained?

A.

The board is required to approve the salary package for all audit staff.

B.

The internal audit charter is approved by the CAE.

C.

The internal audit budget and resource plan are approved by the board.

D.

The decision regarding the appointment or termination of the CAE belongs to the CEO.

Full Access
Question # 67

Which of the following would be the most appropriate first step for the board to take when developing an effective system of governance?

A.

Determine the organization’s overall risk appetite.

B.

Establish a governance committee.

C.

Delegate authority to members of senior management.

D.

Identify key stakeholders and their expectations

Full Access
Question # 68

A chief audit executive (CAE) is concerned that the internal audit activity is not receiving adequate training and continuing education. Which of the following approaches should the CAE take?

A.

Implement a uniform professional development plan for the internal audit activity.

B.

Create a formal development agreement with each individual staff auditor.

C.

Require each internal auditor to obtain the same professional certifications.

D.

Require training and developmental activities that are sponsored by The HA.

Full Access
Question # 69

The management team of an agricultural organization has prioritized corporate social responsibility (CSR) initiatives. Which of the following would be considered a CSR activity?

A.

Offering a one-off donation to an environmental charity for its expansion efforts

B.

Organizing organization volunteers to provide periodic plantation skill sharing to farmers

C.

Providing special year-end monetary bonuses to the organization ' s employees at all levels

D.

Arranging a free-of-charge picnic for all of the organization ' s employees and their family members

Full Access
Question # 70

Which of the following best demonstrates conformance with the Standards regarding the internal audit activity ' s purpose authority, and responsibility?

A.

Discussion and formal presentation of the internal audit charter to the board of directors

B.

Certification by external auditors on the purpose, authority and responsibility of the internal audit activity

C.

Approval of senior management that the internal audit activity is functioning as originally designed

D.

Self-assessment of the internal audit activity completed by the chief audit executive

Full Access
Question # 71

According to IIA guidance, which of the following is ultimately responsible for seeing that the internal control system of an organization’s social responsibility program is effective?

A.

Senior management

B.

Internal audit activity.

C.

All employees.

D.

Board of directors.

Full Access
Question # 72

Management of an area under review is aggressive, upset, and questioning the knowledge and experience of the organization ' s internal auditors, as the audit results highlight critical findings. The relationship between the internal audit activity and management has continued to degenerate. as previous audit reports also showed a large number of issues. What would be the best strategy for working through the current audit results while also attempting to repair the relationship with management?

A.

Take an accommodating approach and change the overall rating of the audit report.

B.

Take a compromising approach by modifying the tone of the report, while maintaining the critical findings.

C.

Take an assertive approach and be persistent in attempting to convince the director.

D.

Take an assisting approach and offer to assist with the implementation of action plans.

Full Access
Question # 73

An internal auditor of a small manufacturing organization helps with a fraud investigation of accounts payable. The auditor notes that the accounts payable manager is very friendly and trusting with accounts payable staff, so the manager rarely checks the staff’s work.

Which component of the fraud triangle is most relevant in this scenario?

A.

Pressure.

B.

Opportunity.

C.

Rationalization.

D.

Objectives.

Full Access
Question # 74

Which of the following is a detective control?

A.

An organization requires certain employees who occupy sensitive positions to sign attestation to the code of conduct on an annual basis.

B.

A compliance specialist carries out quarterly reviews of an organization ' s compliance with regulatory requirements.

C.

A front desk officer in an organization requires that visitors are identified by the host before access is granted.

D.

An internal audit activity deploys audit management policies and procedures for team members.

Full Access
Question # 75

Which of the following best describes the differences between internal auditors and external auditors?

A.

External auditors are concerned about misstatements in the organization ' s financial statements, while internal auditors are concerned about fraudulent activities that could impact the organization’s financial statements

B.

External auditors are required to hold an accounting designation and are responsible for continuing their education, while internal auditors are required to hold an internal audit designation.

C.

External auditors focus on the accuracy and understandability of financial statements, while internal auditors help the organization accomplish its objectives by evaluating and improving the effectiveness of the control process.

D.

External auditors are not employees of the organization, while internal auditors are employees who have in-depth knowledge of the business, making their opinion more reliable to the board and senior management.

Full Access
Question # 76

Which of the following would provide the best support for internal auditors to meet their continuing professional development requirements?

A.

Access to online internal audit and business skills courses.

B.

Records of self-assessment reports completed by the internal audit staff.

C.

Cosourcing arrangements with external providers on specific engagements.

D.

Performance reviews comparing internal auditors ' achievements against specified goals.

Full Access
Question # 77

Which of the following is (he most effective way any organization can ensure proper governance over its internal controls?

A.

By adopting the best practices of similar organizations in the industry.

B.

By adjusting their internal control framework as business practices evolve.

C.

By introducing the universally accepted COSO internal control framework.

D.

By encouraging the internal audit activity to provide training on internal controls.

Full Access
Question # 78

Which of the following would be the best choice for a continuing professional development requirement for a newly created internal audit activity?

A.

Require all internal auditors to create a training plan based on a competency self-assessment.

B.

Require internal auditors to complete all of their training through webinars, to increase efficiency and avoid traveling

C.

Require all internal auditors to become a member of The Institute of Internal Auditors.

D.

Require internal auditors to create a training plan based on their areas of interest

Full Access
Question # 79

The internal audit activity completed its analysis of sample transactions to determine occurrences of double billings According to If A guidance, which of the following best demonstrates that internal auditors exercised due professional care during the review?

A.

Internal auditors found no instances of double billing and concluded there were no significant risks in this area.

B.

Internal auditors documented the scope and methodology of the data testing.

C.

Internal auditors discussed with management how data is safeguarded.

D.

Internal auditors received formal performance feedback from the engagement supervisor.

Full Access
Question # 80

An Internal auditor accepted a role as an engagement supervisor on a highly specialized and technical engagement for which she did not have the expertise. Which of the following fundamental principles of The IIA ' s Code of Ethics did she violate?

A.

Objectivity.

B.

Confidentiality.

C.

Competency.

D.

Due professional care.

Full Access
Question # 81

Once an organization ' s risks are identified, what would be the next step to ensure resources are properly allocated to manage those risks?

A.

Risk responses must be selected.

B.

Risks must be assessed.

C.

The risk universe must be established.

D.

Risk responses must be aligned.

Full Access
Question # 82

Which situation demonstrates an internal auditor’s due professional care?

A.

Repeating audit procedures from similar engagements to reduce planning time by not having to consider changes in operations or risks.

B.

Focusing on all discrepancies in operations, even if they cannot affect the achievement of the objectives of the organization.

C.

Using technology to enhance the effectiveness of audit procedures, taking cost versus benefit into account.

D.

Not using external expert consultation to keep audit costs low.

Full Access
Question # 83

Which of the following corporate social responsibility strategies is associated with responding to outside pressure by assuming additional responsibility?

A.

Accommodation.

B.

Reaction.

C.

Defense.

D.

Proaction.

Full Access
Question # 84

In which of the following scenarios would it be appropriate for the chief audit executive (CAE) to report that the internal audit activity conforms with the Standards?

A.

It A new internal audit activity was formed four years ago. An external assessment was never performed, but successive internal assessments were performed and support the conclusion that the internal audit activity conforms with the Standards

B.

An internal self-assessment completed yesterday found that the internal audit activity did not conform with the Standards when carrying out its work. However, the preceding independent external assessment supports the conclusion that the internal audit activity conforms with the Standards.

C.

To reduce costs, the CAE excluded the use of external assessors from the internal audit activity ' s quality assurance and improvement program for the past seven years.However, the CAE concluded that the internal audit activity conforms with the Standards because all internal assessments over the period have supported this conclusion.

D.

The results of the last external assessment of the internal audit activity, performed a little over five years ago, indicated that the internal audit activity conforms with the Standards. The most recent internal assessment performed within the past year also indicates conformance.

Full Access
Question # 85

An e-commerce organization decides to conclude a contracting relationship with a service provider. The service provider offered continuous 24/7 after-sales troubleshooting services to customers.

What type of review can the internal audit function perform to assure that the service provider fulfilled its contractual obligations?

A.

Third-party review.

B.

Due diligence review.

C.

Benchmarking review.

D.

Organizational culture review.

Full Access
Question # 86

Which of the following statements is true regarding an organization ' s code of ethics?

A.

It should be written with primary consideration given to using a rule-based approach.

B.

It should be of two variations: one applicable internally and one applicable for third parties.

C.

Its operational effectiveness cannot be tested using traditional audit and rating systems such as maturity models.

D.

It should require an annual attestation of compliance with the code of conduct by all employees.

Full Access
Question # 87

Which of the following is a true statement regarding whistleblowing?

A.

Whistleblowing is one of several possible ethical structures an organization can undertake to encourage ethical behavior.

B.

Whistleblowing programs help employees deal with ethical questions and instill ethical values into everyday behavior

C.

Whistleblowers are current or former employees who are disgruntled and looking to retaliate.

D.

Whistleblowers should inform the organization about actual criminal circumstances, not assumed allegations

Full Access
Question # 88

Which of the following scenarios represents an impairment to the independence of the internal audit function?

A.

The audit manager is a close relative of the organization’s chief operating officer.

B.

The internal audit function’s budget is reviewed and approved by management.

C.

The internal auditor performing an engagement in accounts payable advises on the implementation of accounts payable software and its controls design.

D.

Staff internal auditors are offered stock options, rather than cash, as bonuses.

Full Access
Question # 89

According to IIA guidance, which policy, established by the chief audit executive, would most likely ensure internal audits are conducted with due professional care?

A.

The initial review of workpapers should be conducted after the final engagement report is issued.

B.

Independent internal assessments of the internal audit activity should be performed by entry-level staff as part of on-the-job training.

C.

Internal audit staff should be informed regularly of changes to policies and procedures.

D.

Training documents should be destroyed at the end of the year to create space for the next year ' s training documents.

Full Access
Question # 90

An internal audit activity includes in its audit reports the assertion that its work is performed in conformance with the International Standards for the Professional Practice of Internal Auditing ( Standards). A recent external quality assessment concluded that the internal audit activity had substantial deficiencies that impact its overall operations.

According to IIA guidance, which of the following is the most appropriate action for issuing future audit reports?

A.

Refrain from indicating that the internal audit activity operates in conformance with the Standards until the chief audit executive confirms that the internal audit activityhas addressed all areas of nonconformance and the audit committee has been notified.

B.

Refrain from indicating that the internal audit activity operates in conformance with the Standards until another external assessment confirms that the significant areas of nonconformance have been addressed.

C.

Indicate that the internal audit activity operates in partial conformance with the Standards t as the internal audit activity has a quality assurance and improvement program in place to address deficiencies and has met the requirement for conducting an external assessment.

D.

Update and reissue previous audit reports, removing the assertion that the internal audit activity operates in conformance with the Standards, and distribute them to ail parties who received the original reports.

Full Access
Question # 91

According to IIA guidance, which of the following actions is a chief audit executive required to take with regard to reporting the results of the quality assurance and improvement program?

A.

Report external assessments upon completion of such assessments

B.

Report external assessments at least annually

C.

Report ongoing monitoring quarterly

D.

Report post-engagement reviews at least once every five years

Full Access
Question # 92

Which data analytics competency is critical for new internal auditors to possess in order to plan and perform internal audit engagements in conformance with the Standards?

A.

Describe data analytics and the application of data analytics methods in internal auditing.

B.

Apply data analytics methods in internal auditing.

C.

Evaluate the use of data analytics in an internal audit.

D.

Understand the definition of data analytics only.

Full Access
Question # 93

Which of the following audit types will be most applicable if senior management believes that the ongoing enterprise wide resource planning system development project is not progressing well and actual costs exceed budgeted ones?

A.

Readiness assessment.

B.

Project management methodology assessment.

C.

Risk assessment

D.

A post-implementation review.

Full Access
Question # 94

Which of the following demonstrates that the internal audit activity exercises due professional care?

A.

Supervisors provide feedback to internal auditors after workpapers are reviewed

B.

A self-assessment is conducted through the quality assurance and improvement program every five years

C.

Internal auditors are required to give absolute assurance of regulatory compliance

D.

The chief audit executive reports functionally to the board

Full Access
Question # 95

According to IIA guidance, which of the following threats to objectivity is described as familiarity ' ?

A.

An internal auditor is a close friend or relative of the manager or an employee of the audit client

B.

An internal auditor has a long-term business relationship with the audit client.

C.

An internal auditor has an economic stake in the performance of the organization

D.

An internal auditor is exposed to or perceived to be exposed to pressures from external parties

Full Access
Question # 96

Which of the following are some of the requirements of the quality assurance and improvement program (QAIP)?

A.

The OAIP should be conducted at least once every three years, and must be performed by an external assessor.

B.

The OAIP should be conducted on an ongoing basis, and can be completed as a self-assessment,

C.

he QAIP should include both internal assessments performed by staff and external assessments performed by independent, objective individuals

D.

The OAIP should be performed with scoping limitations established by the board.

Full Access
Question # 97

Wi ch of the following circumstances would most likely be considered a potential red flag for fraud by the internal audit activity?

A.

The monthly payroll reports are not vetted to ensure terminated employees have been removed from the payroll system

B.

The volume of nonroutine journal entries has steadily increased over time.

C.

The database of approved suppliers has not been reviewed the last year

D.

The recent employee survey indicates that some employees remain unaware of the organization’s whistieblower hotline.

Full Access
Question # 98

An internal auditor is assessing the effectiveness of the organization ' s risk management practices. She checks to see whether risk management is an integral part of decision making and whether risk management is transparent, responsive to change, and addresses uncertainty. According to IIA guidance on risk management frameworks, which of the following approaches is the auditor most likely using?

A.

Maturity model approach.

B.

Process element approach.

C.

Key principles approach.

D.

Key performance indicators approach.

Full Access
Question # 99

Which of the following best demonstrates the board of directors ' governance over internal control?

A.

The board bears direct responsibility for developing and implementing the internal control system.

B.

The majority of board members are experienced and qualified members of the organization ' s executive management team.

C.

The board may be assisted by an audit committee, chaired by the chief audit executive.

D.

The board is responsible for succession planning for the CEO and other key members of the executive management team.

Full Access
Question # 100

Which of the following specifications in an internal audit charter is the most important factor in the internal audit activity’s independence?

A.

Description of internal audit activity ' s responsibilities

B.

Definition of internal auditing

C.

Statement of internal audit activity ' s authority

D.

Description of internal audit activity ' s reporting structure

Full Access
Question # 101

While auditing an organization ' s credit approval process, an internal auditor learns that the organization has made a large loan to another auditor ' s relative. Which course of action should the auditor take?

A.

Proceed with the audit engagement, but do not include the relative ' s information.

B.

Have the chief audit executive and management determine whether the auditor should continue with the audit engagement.

C.

Disclose in the engagement final communication that the relative is a customer.

D.

Immediately withdraw from the audit engagement.

Full Access
Question # 102

The internal audit function is auditing the organization’s procurement process. In planning for the engagement, a fraud risk was identified for payments to employee-owned vendors.

Which of the following procedures would most likely identify this situation?

A.

Agreeing on approval documentation for payments to vendors.

B.

Interviewing procurement staff to understand the vendor management process.

C.

Performing data analytics to identify vendor payments to an employee address.

D.

Ensuring changes to the vendor master file are reviewed and approved.

Full Access
Question # 103

An internal audit of warehouse inventory revealed no material deficiencies. However, management later discovered fraud, which occurred during the period that was audited, and determined that a major control deficiency allowed the fraud to occur. Given management ' s discovery, which of the following statements is valid?

A.

The internal auditors violated the standard for due professional care because they did not detect the fraud, even though it occurred during the period that was reviewed.

B.

The internal auditors should have had sufficient knowledge of fraud to identify red flags indicating possible fraud.

C.

The internal auditors could not have detected the fraud due to collusion among employees in the inventory unit.

D.

The internal auditors are not responsible for considering fraud risk, which is a management responsibility.

Full Access
Question # 104

At a conference, an interna! auditor presented a new computer-assisted audit technique developed by his organization. The presentation included sample data derived from performing audit engagements for the organization. Travel costs were paid by the conference organizers, and the trip was approved by the chief audit executive (CAE).

However, neither management nor the CAE was aware that the internal auditor would be making a presentation based on work completed for the organization. According to IIA guidance, which of the following statements is most relevant regarding the actions of the auditor?

A.

The auditor did not violate the standard of objectivity because the presentation had no impact on the organization.

B.

The auditor violated the principle of confidentiality by disclosing information about the organization without approval.

C.

The auditor should have obtained permission before using the material, but did not violate the IIA Code of Ethics or Standards,

D.

The auditor breached the conflict of interest standard by accepting payment for travel costs

Full Access
Question # 105

A chief audit executive (CAE) recruited a few new internal auditors to reduce the resource gaps identified in this year ' s internal audit plan. One of the new recruits has several years of experience with the organization. Ten months ago. she served as a senior supervisor in the finance department. However, for the past 10 months, she has been helping the organization with implementing a new IT system. What approach should the CAE take for the upcoming financial statement controls audit?

A.

Assign the new auditor to assist with conducting the fieldwork. but ensure that her work is reviewed by the CAE.

B.

Assign the new auditor to assist with developing the audit program, but ensure that the audit program is executed by other audit staff.

C.

Ensure that the new auditor ' s previous manager, and other close former coworkers, are excused during the audit.

D.

Ensure that the new auditor is responsible only for the supervisory review, but not the execution of the audit field work.

Full Access
Question # 106

Which of the following scenarios best illustrates a rationalization as the root cause of potential fraud?

A.

Managers who have been with the organization for several decades become aware that newly hired, younger managers are being moved more quickly into senior positions.

B.

The controller at a nationwide manufacturing company recently opted to no longer require two-week mandatory vacations for accounting staff.

C.

Security cameras that monitor cash handling at the register are not functioning.

D.

The organization is slowly phasing out three mature products that produce the highest commissions for the sales staff

Full Access
Question # 107

Which of the following is an example of an impairment to an internal auditor ' s independence?

A.

An internal auditor delays reporting material financial statement audit findings until after his parents sell all of their stock in the company

B.

Following the restructuring of the organization, the internal audit activity now reports functionally to the chief financial officer

C.

A new member of the internal audit activity, who was the accounts payable supervisor for two years, is asked to consult on the implementation of a new accounts payable system

D.

Believing there must be errors in a given balance sheet account the internal auditor decides to expand his testing

Full Access
Question # 108

An internal audit activity maintains a quality assurance and improvement program that includes annual self-assessments. The internal audit activity includes in each engagement report a clause that the engagement is conducted in conformance with the International! Standards for the Professional Practice of Internal Auditing (Standards). Which of the following justifies inclusion of this clause in the reports?

A.

Internal audit activity policies and engagement records provide relevant, sufficient, and competent evidence that the statement is correct.

B.

The audit committee has reviewed the annual self-assessment results and approved the use of the clause.

C.

The self-assessment results were validated by a qualified external review team three years prior.

D.

The internal audit charter, approved by the audit committee, requires conformance with the Standards

Full Access
Question # 109

Which of the following functions does an internal audit charter serve?

A.

It provides a formal, written agreement with management and the board regarding the organization’s internal audit function.

B.

It provides all internal auditors with unlimited access to records, personnel, and physical property.

C.

It provides senior management with formal criteria for periodic assessments of the adequacy of the internal audit function’s purpose, authority, and responsibility.

D.

It provides the internal audit function with the authority to perform any fraud investigation engagement that can enhance or protect the value of the organization.

Full Access
Question # 110

What is an appropriate first step in an internal auditor’s fraud risk assessment to evaluate how the organization manages such risk?

A.

Develop preventive and detective controls

B.

Identify potential fraud scenarios

C.

Assess the impact and likelihood of fraud risks

D.

Determine fraud risk responses

Full Access
Question # 111

The internal audit activity was denied access to expenditure and budget reports because they were considered to be confidential. This situation would result in which of the following limitations of the internal audit activity?

A.

Independence

B.

Integrity

C.

objectivity

D.

Authority

Full Access
Question # 112

Which of the following should a general internal auditor be able to characterize as an IT-related risk?

A.

Computer servers are in a room that is accessible to all employees,

B.

An IT architect avoids taking vacations and sharing his workload with coworkers,

C.

Hours billed by IT developers exceed 24 hours daily.

D.

Audit logs are lacking in a system that processes personal data.

Full Access
Question # 113

Which of the following approaches will internal audit utilize when developing a set of performance standards to measure an organization’s risk management process against?

A.

Key principles approach

B.

Process elements approach

C.

Holistic approach

D.

Maturity model approach

Full Access
Question # 114

Which level of corporate social responsibility does whistleblowing in companies primarily support?

A.

Ethical responsibility.

B.

Economic responsibility.

C.

Legal responsibility.

D.

Discretionary responsibility.

Full Access
Question # 115

During a complex financial compliance engagement, a senior internal auditor determines that current audit procedures are not sufficient for adequate testing She consults with a colleague and learns that a spreadsheet application contains a helpful tool She proceeds to use the tool to properly complete the evaluation Which of the following best describes the core competency displayed by the senior auditor?

A.

Business acumen

B.

Persuasion and collaboration

C.

Critical thinking

D.

Communication

Full Access
Question # 116

Which of the following is an appropriate roe fa the internal audit activity?

A.

Ensuring the organization ' s key risks are managed through appropriate controls.

B.

Assisting the organization in maintaining effective controls.

C.

implementing new controls to promote continuous improvement

D.

Validating control assessments performed by the external auditor.

Full Access
Question # 117

Which of the following scenarios represents a top-down flow of information regarding corporate governance?

A.

The chief audit executive receives supply chain audit reports from an internal audit manager.

B.

The chief administrative officer reviews the payroll calendar prepared by the payroll manager.

C.

The chief information officer receives cybersecurity reports from the IT manager.

D.

The board approves the new annual budget prepared by the CEO.

Full Access
Question # 118

Which of the following best demonstrates the authority of the internal audit activity?

A.

Suggesting alternatives to decision makers.

B.

Improving the integrity of information.

C.

Determining the scope of internal audit services

D.

Achieving engagement objectives.

Full Access
Question # 119

Which of the following accurately describes the concept of inherent risk?

A.

Risk factors that exist when controls are in place and operating effectively

B.

Internal risk factors assuming no controls are in place

C.

Risk factors that cannot be mitigated because they are innate to a process

D.

Combination of internal and external risk factors in their pure state assuming no controls are in place

Full Access
Question # 120

Due to toe increased operational responsibility of the CEO. The chief audit executive (CAE) of an organization currently reports to the chief financial officer (CFO). What is the likely imped of such a situation?

A.

There may be limitation m the scope of engagements that can be undertaken

B.

The CPO could provide expert advice when auditing areas under his purview

C.

The internal audit activity is adequately positioned when the CAE reports to a member of executive management

D.

The expense of finance staff can be catted upon during an audit of finance-related areas

Full Access
Question # 121

According to the 11A Code of Ethics, which of the following is required with regard to communicating results?

A.

The internal auditor should present material information to appropriate personnel within the organization without revealing confidential matters that could be detrimental to the organization.

B.

The internal auditor should disclose all material information obtained by the date of the final engagement communication.

C.

The internal auditor should obtain all material information within the established time and budget parameters.

D.

The internal auditor should reveal material facts that could potentially distort the reporting of activities under review.

Full Access
Question # 122

Which of the following scenarios demonstrates an impairment to internal audit independence?

A.

The internal auditor s denied access to partner information from management of me area under review

B.

The internal auditor tarts to disclose a potential conflict of interest relationship with management of the area under review

C.

The internal auditor concludes that controls operate effectively, although he did not gather supporting evidence

D.

The internal auditor was assigned to an assurance review of an area for which he previously had responsibilities

Full Access
Question # 123

A fraud investigation was completed by management, and a proven fraud was communicated to relevant authorities. According to IIA guidance, which of the following roles would be most appropriate for the internal audit activity to undertake after the investigation?

A.

Plan employee sessions and team building strategies for the organization to improve awareness of fraud among employees

B.

Review the investigation and implement any improvements to the process.

C.

Conduct lessons learned sessions to ascertain how the fraud occurred and which controls failed.

D.

Determine why the fraud was not detected earlier and design controls to strengthen early detection.

Full Access
Question # 124

An organization is implementing a new cybersecurity policy and has established a committee to ensure stakeholder alignment across the organization ' s infrastructure, network, and security teams. The head of the committee has asked the chief audit executive if the internal audit activity could play a role in these efforts. According to HA guidance, which of the following is the most appropriate response?

A.

It is not appropriate for the internal audit activity to play a role because its independence must be protected.

B.

The internal audit activity should not participate because there are no IT auditors on staff.

C.

The internal audit activity is knowledgeable about risk and therefore should prioritize the organization ' s responses and control activities for the committee.

D.

The internal audit activity may assist the committee and consult with management on the organization ' s responses and control activities.

Full Access
Question # 125

According to IIA guidance, which of the following is the strongest indicator of deficiencies in the risk management process?

A.

The periodic evaluation of risk ratings is primarily dependent on subjective assessments.

B.

Separate evaluations of the risk management process were conducted, but the results were never integrated.

C.

Management ' s primary objective is minimizing changes to the structure and operation of the risk management process.

D.

Many aspects of the related enterprise risk management program are informal and undocumented.

Full Access
Question # 126

The chief audit executive (CAE) annually develops a budget and resource plan and submits it to the board for approval. This action best fulfills which of the following responsibilities of the CAE?

A.

The responsibility to maintain organizational independence.

B.

The responsibility to perform engagements with due professional care.

C.

The responsibility to communicate corrective action plans to the board.

D.

The responsibility to define the purpose of the internal audit activity.

Full Access
Question # 127

Which of the following statements is true regarding organizational independence of the internal audit activity (IAA)?

A.

Reporting to a higher level within the organization reduces the potential scope of engagements that can be undertaken by the IAA.

B.

The benefit of the IAA ' s organizational independence is realized primarily via reduced costs for the external auditor.

C.

Independence is impaired when the scope of the IAA is subject to changes required by senior management.

D.

Inadequate organizational independence can result in the chief audit executive being able to fire staff without consulting the audit committee.

Full Access
Question # 128

Senior management has decided to adopt the key principles approach of the ISO 31000 risk management framework. According to IIA guidance, which of the following principles is most appropriate when implementing the risk management process in a dynamic agency?

A.

Everyone in the agency has a primary responsibility for identifying and managing risks as part of the risk management process.

B.

The risk management process, while evaluating risk, should develop a mechanism to rank the relative importance of each risk.

C.

The risk management process should be regularly reviewed and respond to changes in the environment, to remain relevant.

D.

The risk management process should use a formal technique to consider the consequence and likelihood of each risk.

Full Access
Question # 129

An automobile manufacturer will become one of the first in the industry to adopt a new inventory management software. Despite the system being new to the market, senior management believes that the benefits are great enough to offset the potential risks. Which of the following aspects of risk management does senior management’s decision best illustrate?

A.

Residual risk.

B.

Inherent risk.

C.

Risk tolerance.

D.

Risk appetite.

Full Access
Question # 130

The level of authority for the internal audit activity is granted by which of the following?

A.

The chief audit executive.

B.

The internal audit charter.

C.

The International Professional Practices Framework.

D.

The IIA ' s Code of Ethics.

Full Access
Question # 131

According to IIA guidance, which of the following actions best demonstrates that due professional care has been considered by the internal audit activity when conducting a review of an organization ' s assets?

A.

Determining whether any opportunity exists for senior executives to misappropriate property or funds

B.

Planning and executing fieldwork In a complete and timely manner to identify all significant risks

C.

Verifying whether the board of directors has implemented effective internal controls

D.

Having senior management determine whether the degree of work planned is sufficient to meet engagement objectives

Full Access
Question # 132

Which of the following best demonstrates that the internal audit activity is using due professional care?

A.

The internal audit activity reports directly to the board on the engagements it performs.

B.

Internal auditors undertake the necessary training to complete their audit work.

C.

The completion of engagements is based on the assumption that fraudulent activities may exist.

D.

Internal auditors consider the use of technology-based audit and other data analysts techniques

Full Access
Question # 133

Which of the following should be implemented to promote independence of the internal audit activity?

A.

Internal auditors do not review an area where they previously worked

B.

The internal audit charter is reviewed and updated annually

C.

The chief audit executive reports functionally to the board

D.

Management does not influence the consulting services provided by the internal audit activity

Full Access
Question # 134

An audit client who was unsatisfied with the audit report rating called the chief audit executive (CAE) and complained that the internal auditor who performed the audit was biased because his spouse, who worked in the area under review, was on a list of employees to be terminated. Which of the following measures would be most appropriate to prevent this situation from arising?

A.

Initiating an internal investigation to clarify whether a biased judgment took place.

B.

Requiring the internal auditors to disclose any potential conflicts of interest.

C.

Requiring that the audit client disclose any potential conflicts of interest with the auditor.

D.

Requiring human resources manager to submit all future job applicants ' data in order to identify relatives of auditors.

Full Access
Question # 135

Which of the following is an acceptable supplement to promote professional development within the internal audit function?

A.

Incorporate an expert from the area under review to help scope the engagement.

B.

Increase the frequency of engagements in specific areas to help internal auditors learn about them.

C.

Gather and incorporate knowledge from subject matter experts within the organization.

D.

Spend time learning how management establishes risk tolerance levels.

Full Access
Question # 136

Which of the following is a key determinant used by external auditors to decide whether they can rely on work performed by the internal audit activity?

A.

The auditors ' independence.

B.

The auditors ' objectivity.

C.

The auditors ' integrity.

D.

The auditors ' confidentiality.

Full Access
Question # 137

An internal audit team was assigned to review the organization ' s information security protocol. After fieldwork was completed, an internal auditor identified an error in the review of security access. The error could affect the overall results of the engagement. Which of the following is the most appropriate course of action for the internal auditor?

A.

Proceed with addressing the error and report any corrections to the engagement supervisor during the scheduled exit meeting.

B.

Issue the audit report to senior management on schedule but include a disclaimer about the error.

C.

Proceed with the scheduled closing of the engagement without consideration of the identified error.

D.

Inform the engagement supervisor of the error and allow the supervisor to determine the appropriate action to take.

Full Access
Question # 138

An internal auditor has completed an assurance engagement Which of the following is most likely true regarding the engagement?

A.

During audit planning, the auditor provided the client with the scope of the engagement for their agreement

B.

The results of the engagement were included in a written report that was issued to the client who requested the engagement

C.

During audit planning, the auditor determined that the engagement scope would include a review of the security and privacy of payroll records

D.

The client requested the review of a new payroll system in order to improve the security of the system

Full Access
Question # 139

An internal auditor for a construction organization suspects that fraud is occurring, as inventory replacement costs for hand tools and additional materials have been consistently exceeding the budget at two large job sites.

Based on this information, which type of fraud is most likely occurring at these job sites?

A.

Disbursement fraud.

B.

Skimming.

C.

Diversion.

D.

Misappropriation.

Full Access
Question # 140

According to IIA guidance, during the development of an internal audit charter, which is true regarding acceptable organizational roles?

A.

Only the board and legal counsel should provide input.

B.

Both the board and senior management should provide input.

C.

The board may provide input but should do so only through the audit committee.

D.

Senior management should not provide input.

Full Access
Question # 141

Following a quality assurance review of a small internal audit activity, the external reviewer and the chief audit executive (CAE) cannot agree on the importance of several deficiencies noted during the review. Which of the following would be the most appropriate next step for the reviewer to take?

A.

Remove the areas of disagreement from the scope of the engagement and seek informal compromises with the CAE.

B.

Issue the report to senior management, noting the deficiencies for immediate resolution.

C.

Issue the report, noting the deficiencies with comments that address the areas of disagreement.

D.

Request arbitration from the audit committee to resolve discrepancies prior to issuing the final report

Full Access
Question # 142

An organization holds 40% of its long-term assets in stocks and wants to hedge for the possibility of potential losses in the foreseeable future.

Which of the following statements is true regarding this risk management approach?

A.

By hedging, the organization must exit its long-term investment position before the risk event occurs.

B.

By hedging, the organization must reduce its portfolio to limit the financial impact of the risk event.

C.

By hedging, the organization should liquidate part of its assets to protect investments.

D.

By hedging, the organization would be able to offset the impact from the risk event.

Full Access
Question # 143

According to NA guidance, which of the following describes the primary reason to implement environmental and social safeguards within an organization?

A.

To enable Triple Bottom Line reporting capability.

B.

To facilitate the conduct of risk assessment.

C.

To achieve and maintain sustainable development.

D.

To fulfill regulatory and compliance requirements.

Full Access
Question # 144

According to IIA guidance, which of the following statements regarding the internal audit charter is true?

A.

The nature of consulting services typically is not included in the charter.

B.

The chief audit executive must formally review the charter at least once a year

C.

The nature of assurances provided to parties outside of the organization typically is not included in the charter.

D.

The charter typically defines the internal audit activity ' s position within the organization.

Full Access
Question # 145

Which of the following actions should an organization take to detect an emerging risk of potential fraud?

A.

Adopt reward and recognition programs that promote good behaviors

B.

Undertake background checks for new employees as part of the hiring process

C.

Establish an anonymous platform for reporting suspected unethical behaviors

D.

Institute periodic educational training on expected ethical behaviors

Full Access
Question # 146

Outsourcing a business activity is considered which of the following risk management techniques?

A.

Sharing a risk.

B.

Avoiding a risk.

C.

Reducing a risk.

D.

Mitigating a risk

Full Access
Question # 147

A chief audit executive (CAE) has no direct access to the board. According to IIA guidance, which of the following is the most appropriate way for the CAE to react?

A.

Ensure all subsequent audit reports include a disclaimer as to the lack of access to the board,

B.

Focus on operational audit work and disregard lack of direct access to the members of the board.

C.

Initiate changes to the internal audit charter to report to senior management for the time being,

D.

Engage in written communications with the board and present relevant issues in writing

Full Access
Question # 148

The accounting department asked the chief audit executive (CAE) to perform a review of suspicious transactions. The CAE was an accounting manager for the organization six months ago.

How should she respond to the request?

A.

Decline, if it is a consulting engagement, because she recently worked in the organization ' s accounting department.

B.

Accept, if it is an assurance engagement, as she has been out of the department long enough to not impair objectivity.

C.

Inform the accounting department that the engagement can take place in the future, once she has been removed from accounting for a longer period of time.

D.

Accept, if it is a consulting engagement with agreed-upon scope and services to be provided by the internal audit activity.

Full Access
Question # 149

An auditor for a large wholesaler is evaluating the controls over the approval and oversight of credit sales. Which of the following procedures would be a control weakness?

A.

The credit department is responsible for approving shipments to all customers

B.

The finance committee of the board of directors periodically reviews credit standards

C.

Customers who fail to meet credit requirements must pay cash for shipments upon delivery

D.

The sales department is responsible for determining the credit ratings of customers

Full Access
Question # 150

Upon completion of an external quality assessment, which of the following would the chief audit executive be required to report to the board?

A.

The total time spent to accomplish the external assessment

B.

The detailed evaluation results of the external assessment

C.

The competency and independence of the external assessment team

D.

The timetable and schedule of the next external assessment

Full Access
Question # 151

An organization is in the process of hiring a new chief audit executive (CAE). Which of the following can the potential candidates expect to be a part of the recruiting process or in place when the CAE is hired?

A.

There are checks to determine the existence of any potential conflict of interest.

B.

The CAE reports functionally to the highest level of management, the CEO.

C.

The CAE’s compensation depends on the performance of the organizational departments.

D.

Hiring and termination of the CAE is dependent on the decision of senior executives.

Full Access
Question # 152

Which of the following is an indicator that the organization ' s risk management process is effective?

A.

The organization ' s risk appetite, mission, and objectives are clearly outlined.

B.

The organization ' s risk management practices are assessed as mature.

C.

The organization has adopted risk management frameworks and global models.

D.

The organization ' s significant risks are identified and adequately assessed.

Full Access
Question # 153

Management is concerned with the organization’s disposal of pollutants into the city’s water treatment facility.

Which of the following types of engagements and objectives is most appropriate to address the concern?

A.

An assurance engagement to determine the most economical facilitation of pollutant disposal.

B.

A due diligence engagement to determine the most economical facilitation of pollutant disposal.

C.

A performance engagement to determine whether the organization is meeting city financial regulations.

D.

An assurance engagement to determine whether the organization is meeting city regulations.

Full Access
Question # 154

According to IIA guidance, which of the following best demonstrates due professional care?

A.

Staffing audit engagements with internal auditors who possess professional designations.

B.

Relying on prior audit work to save planning time and costs.

C.

Performing assurance procedures to guarantee all significant risks are identified.

D.

Assessing the cost of assurance in relation to the potential benefits.

Full Access
Question # 155

Which of the following would be a preventive control for helping to manage fraud in an organization?

A.

Reviews of reports to determine which issued payments lack evidence of supervisory review.

B.

A monthly review of new vendors performed by management for reasonableness.

C.

Bank reconciliations performed on a monthly basis by the accounting department.

D.

A code of conduct and whistleblower policy that must be signed by all employees annually.

Full Access
Question # 156

A business unit manager was impressed by the competence of the internal auditor who was conducting an assurance engagement in his area and the manager made the auditor an attractive job offer to begin after the audit was completed The auditor later told her auditor in charge that she was considering the offer. Which of the following IIA Code of Ethics principles was most likely violated?

A.

Integrity

B.

Confidentiality

C.

Objectivity

D.

No violation was committed

Full Access
Question # 157

Which of the following documents are internal auditors most likely to be asked to sign as a demonstration of due professional care?

A description of their job responsibilities,

A.

A non-disclosure agreement.

B.

An annual declaration of commitment to

C.

The IIA s Code of Ethics.

D.

The internal audit charter.

Full Access
Question # 158

An organization has limited resources to spend on corporate social responsibility initiatives. Which is the most suitable approach to determine how these resources should be used?

A.

Support a mix of environmental economic and social initiatives to ensure a balanced approach is taken

B.

Survey employees and external stakeholders to see which causes are best suited to the organization.

C.

Select corporate social responsibility initiatives that support the overall strategic goals of the organization

D.

Conduct a financial analysis to determine where the most impact can be made with the budget available

Full Access
Question # 159

According to IIA guidance, which of the following most appropriately justifies the CEO’s decision that the internal audit activity shall be responsible for risk management and investigation at a multinational organization?

A.

The recommendation of the parent office external auditors.

B.

The provisions of the internal audit charter

C.

The authority of the CEO.

D.

The level of proficiency of the chief audit executive

Full Access
Question # 160

Which of the following would be a red flag for potential issues in the control environment?

A.

Segregation of duties during preparation of the financial statements

B.

Compensation structures that are based on commissions

C.

A low rate of turnover in key financial positions

D.

The presence of a whistleblower policy and fraud hotlinea

Full Access
Question # 161

While preparing the audit plan for an automobile manufacturing company, the chief audit executive (CAE) noted that the company ' s engineering department received a high risk ranking. However, the internal audit activity is understaffed, and current staff do not possess the necessary skills to adequately assess the effectiveness of the engineering department. What is the most appropriate course of action for the CAE to take?

A.

Include the engineering department on the audit plan, use the available internal audit resources to conduct the review, and exclude procedures that cannot be adequately assessed.

B.

Advise management to accept the assessed risk until the internal auditors are able to review the area adequately.

C.

Recruit internal auditors with the required competencies and wait until they are employed before including this audit on the internal audit plan.

D.

Proceed with a review of the engineering department but supplement the internal audit team with nonauditors from an external engineering company who have the required skills to assist

Full Access
Question # 162

An internal audit activity is using the auditing-by-element approach to audit the organization ' s controls around corporate social responsibility. Which of the following would be an element for the internal audit activity to consider?

A.

Working conditions.

B.

Employees ' families.

C.

Marketplace competition.

D.

Shareholders and investors

Full Access
Question # 163

How can the internal audit function demonstrate professional competency?

A.

Providing relevant recommendations in line with current activities, trends, or emerging issues to engagement clients.

B.

Ensuring that individual members of the internal audit function have the same technical skills.

C.

Conforming to the independence required by the Global Internal Audit Standards.

D.

Developing reputation and expertise among different functions within the organization in order to secure other responsibilities when they depart from internal auditing.

Full Access
Question # 164

Which of the following would be addressed in the internal audit charter?

A.

Expertise requirements for internal auditors

B.

Functional and administrative reporting lines for the chief audit executive

C.

Audit engagements to be completed in the next fiscal year

D.

Budget requirements for each engagement

Full Access
Question # 165

Which of the following assists the board and senior management in seeing that the internal audit function supports the goals and principles of the organization?

A.

Audit risk assessment.

B.

Audit program.

C.

Audit charter.

D.

Audit objectives.

Full Access
Question # 166

An internal auditor is providing consulting services on an area he was responsible for three years ago. Part of the consulting scope covers a review of a performance measuring system that the auditor helped to develop. What is the best course of action for the auditor to take concerning the consulting service?

A.

Accept the consulting services only after receiving approval to do so from the board.

B.

Accept the consulting services. The objectivity won ' t be impaired if it has been more than a year since he last worked in the area under review.

C.

Refrain from providing the consulting service because he was responsible for that area and his objectivity will be impaired,

D.

Disclose the potential impairment to the customer before accepting the consulting engagement

Full Access
Question # 167

During an assurance engagement, an internal auditor identified that a developer of the organization ' s enterprise resource planning (ERP) system had intentionally modified the production code to commit a fraudulent transaction. Which control activity should be implemented to prevent such issues in the future?

A.

Segregate duties between code development and migrating changes into production.

B.

Conduct fraud training for the IT team responsible for the ERP system.

C.

Penalize the developer who committed the fraud by terminating employment.

D.

Restrict developers ' access to the ERP system ' s test environment.

Full Access
Question # 168

According to IIA guidance, which of the following is most critical to ensuring that an organization ' s risk management program remains effective over time?

A.

Ensuring a fully executed assurance role for the internal audit activity.

B.

Conducting risk evaluations that include ranking the relative importance of each risk.

C.

Establishing a risk management function and appointing a chief risk officer.

D.

Conducting a combination of ongoing risk reviews and individual evaluations.

Full Access
Question # 169

Which of the following would be considered a primary control to reduce the risk associated with setting up duplicate vendors?

A.

Receipt of a signed and approved vendor setup form.

B.

Segregation of duties between setting up vendors and making vendor payments.

C.

System validation and edit checks on vendor identification number

D.

A vendor setup policy and procedure.

Full Access
Question # 170

Which of the following is an advantage of using nongovernmental organization (NGO) members on an assurance team when auditing corporate social responsibility?

A.

Typically less time is needed to train the NGO members on the audit process.

B.

NGO members are often more unbiased and objective

C.

A report with a positive statement from an NGO member is deemed to be more credible. As opposed to auditors.

D.

NGO members are licensed to audit corporate social responsibility.

Full Access
Question # 171

A chief audit executive assigned an internal auditor to perform an assurance engagement. The auditor concluded with a major audit finding based on hearsay evidence Which of the following competencies did the auditor appear to be lacking?

A.

Effective communication skills

B.

Risk-based assurance knowledge

C.

Demonstration of due professional care.

D.

Demonstration of ethical behavior

Full Access
Question # 172

Which of the following controls would be most useful to prevent an employee from using the organization ' s funds for inappropriate expenditures and falsifying financial records to conceal the fraud?

A.

Segregating duties in the payroll processes.

B.

Confirming receipt of goods or services.

C.

Performing background checks on newly hired employees.

D.

Requiring management approval for expenses.

Full Access
Question # 173

Which of the following describes the most appropriate match between a potential temporary guest auditor candidate and an upcoming audit assignment?

A.

A purchasing manager with two years of prior audit experience in public practice to lead a contracts management audit

B.

A communications officer who worked in the marketing department during the last six months to conduct a customer loyalty program audit

C.

A manager of social responsibility who has a nursing background to participate m a health and safety audit for the corporate office and plant facilities

D.

An accounting manager who discovered and reported fraud committed by a payables clerk to conduct a performance audit of accounts payable

Full Access
Question # 174

Which of the following would likely have the greatest influence on the long-term quality of an organization’s control environment?

A.

Regulatory compliance.

B.

Business performance.

C.

Financial reconciliations.

D.

Accountability structure.

Full Access
Question # 175

The internal auditor of a small manufacturer noted that the accounting department has insufficient staff to achieve proper segregation of duties. What type of controls would the auditor likely recommend to management to specifically address this problem?

A.

Entity-level.

B.

Preventive.

C.

Directive.

D.

Compensating.

Full Access
Question # 176

With regard to IT governance, which of the following is the most effective and appropriate role for the internal audit activity?

A.

Independently evaluate the skills and experience of potential chief information officer candidates to assess the best fit based on the organization ' s risk appetite.

B.

Evaluate the organization’s governance standards and assess IT-related activities to identify gaps and develop policies, ensuring alignment with the organization’s risk appetite.

C.

Assist management in interpreting complex IT-related privacy and security risk exposures and evaluating potential mitigation strategies.

D.

Assess whether governance activities are aligned with the organization ' s risk appetite and take into consideration emerging risks

Full Access
Question # 177

Which of the following best describes the risk contained in an initial public offering for a new stock?

A.

Residual risk.

B.

Net risk.

C.

Inherent risk.

D.

Underlying risk.

Full Access
Question # 178

During a procurement process audit the internal audit activity undertakes a fraud risk assessment and considers a range of possible fraud scenarios within the process. Which of the following scenarios constitutes a pressure to commit fraud?

A.

An employee believes his poor compensation package justifies engaging in unethical behavior.

B.

The head of the department is the only signatory to purchase orders issued to third party contractors.

C.

Some employees strongly believe monetary gifts from vendors is a means of saving for life after employment.

D.

One of the employees was found to have an obsession with expensive jewelry

Full Access
Question # 179

Who is held responsible for oversight of the organization ' s risk management framework?

A.

Operational management.

B.

Board of directors.

C.

Internal auditors.

D.

Head of risk management.

Full Access
Question # 180

According to IIA guidance, which of the following would be included in an internal audit charter to help establish the authority of the internal audit activity?

A.

Outline expectations for communicating the results of all aspects of the internal audit activity.

B.

Declare the internal audit activity’s accountability for safeguarding assets and confidentiality.

C.

Document the chief audit executive’s (CAE ' s) reporting line

D.

Document agreement between the CAE and the individual to whom the CAE reports

Full Access
Question # 181

An organization’s board of directors has decided that the internal audit activity must have greater access to different pans of the organization in order to perform their assurance work effectively Which of !he following areas is the board seeking to improve by making this change?

A.

Internal audit authority.

B.

Internal audit reporting structure.

C.

Internal audit independence and objectivity.

D.

Internal audit interaction with the board

Full Access
Question # 182

Which of the following is an example of the chief audit executive (CAE) demonstrating due professional care?

A.

The CAE relies on CAEs in other organizations to understand how due professional care should be executed in her internal audit activity

B.

The CAE meets with the board of directors on a quarterly basis to provide a status update.

C.

The CAE assesses the audit staff ' s knowledge and skills annually to determine whether additional resources are needed to fulfill the internal audit plan.

D.

The CAE provides absolute assurance to line management during each eternal audit engagement

Full Access
Question # 183

A global organization established a new internal audit activity and the recently hired chief audit executive needs to develop an internal audit manual for internal auditors Among the following policies in the manual, which would facilitate internal auditors in upholding their objectivity?

A.

Internal auditors shall attend professional workshops to refresh internal audit norms and concepts

B.

Internal auditors ' performance is synchronized with satisfaction ratings given by audit clients

C.

Internal auditors take prior audit results into account when conducting current audit engagements

D.

Internal auditors observe the audit client’s expectations when scoping audit engagements

Full Access
Question # 184

During fieldwork, an internal auditor located a significant internal control issue. Without identifying the origins of the issue, the auditor concluded the engagement and included the issue in the final audit report. To enhance audit quality, which of the following skills should the internal auditor improve?

A.

Business acumen.

B.

Critical thinking.

C.

Communication.

D.

Audit report writing.

Full Access
Question # 185

Which of the following is an indicator of ineffective third-party risk management?

A.

Sourcing of third parties does not follow public procurement law.

B.

Violations of service conditions trigger either fines or termination.

C.

Due diligence of third parties is conducted only after contract signing.

D.

The right-to-audit clause is limited by personal data protection regulations.

Full Access
Question # 186

According to IIA guidance, which of the following is necessary for internal auditors to comply with the requirements for proficiency?

1. Sufficient consideration of current activities, trends, and emerging issues to effectively carry out their professional responsibilities.

2. Ability to provide relevant advice and recommendations to management and the board.

3. Understanding of key IT risks and controls and the ability to identify fraud using technology-based audit techniques.

4. Knowledge, skills, and other competencies necessary to perform individual responsibilities during the engagement.

A.

1 and 4 only.

B.

1, 2, and 3 only.

C.

1, 2, and 4 only.

D.

2, 3. and 4 only

Full Access
Question # 187

During his quarterly meeting with the chief audit executive (CAE), it was recommended to an experienced staff internal auditor that he complete a communication and leadership training. The training was also included in the auditor’ yearly professional development plan. The auditor is confused, as he believes he should attend trainings on technical areas rather than spend time on communication and leadership.

According to IIA guidance, which of the following statements regarding this scenario is true?

A.

Professional development includes participating in conferences, seminars, training programs, online courses, webinars, and certifications on technical areas only.

B.

The CAE is solely responsible for ensuring that each auditor is competent to adequately meet job requirements.

C.

The professional development plan may encompass a variety of trainings, including communication and leadership training most suitable for the individual auditor’s professional development.

D.

It is mandatory to complete all trainings as part of the professional development plan.

Full Access
Question # 188

According to IIA guidance, which of the following roles for the internal audit function regarding risk management are acceptable with appropriate safeguards in place?

A.

Setting the organization’s risk appetite.

B.

Determining appropriate risk responses.

C.

Implementing necessary risk responses.

D.

Maintaining and developing the risk management framework.

Full Access
Question # 189

Which of the following is a limitation of detective internal controls in fraud management?

A.

Implementation costs tend to be higher than the expected benefits.

B.

They tend to be easy for fraudsters to circumvent.

C.

They are not designed to improve efficiency of operations.

D.

They are not effective in preventing fraud.

Full Access
Question # 190

With regard to organizational governance assurance, which of the following is an appropriate role for the internal audit activity ' ?

A.

Assess compliance with the organization ' s code of conduct

B.

Oversee the governance and risk management processes

C.

Initiate new organizational control processes

D.

Provide advice on organizational governance activities

Full Access
Question # 191

Due to unfavorable economic conditions management decided to postpone new investments for the next year. Which of the following best describes the risk management strategy used to address this situation?

A.

Risk mitigation

B.

Risk avoidance

C.

Risk reduction

D.

Risk transfer

Full Access
Question # 192

Which of the following is the best example of a risk appetite statement concerning an investment portfolio?

A.

We will request CEO approval for investments greater than S20 million and board approval for investments greater than $50 million.

B.

We will hedge 95 percent of our U S. currency exposure and 100 percent of our European currency exposure.

C.

We have a moderate tolerance for investment earnings volatility with a target value at risk of S50 million.

D.

We will report to the risk committee all credit losses greater than S10 million and all market value losses greater than S20 million.

Full Access
Question # 193

Which of the following best demonstrates that an internal auditor is applying due professional care when planning an assurance engagement?

A.

Assessing the risk of noncompliance with laws and regulations

B.

Following the policies as prescribed by the internal audit manual.

C.

Advising management of the area under review on how to mitigate internal control risks.

D.

Conducting the engagement on the presupposition that fraud exists.

Full Access
Question # 194

Which of the following statements is most accurate with respect to the required elements of the quality assurance and improvement program?

A.

Internal assessments provide sufficient objectivity to provide evidence to the board that the internal audit activity understands the organization’s control processes.

B.

Quality assessments focus on the internal audit activity ' s structure, relationships with stakeholders, compliance with the Standards, and internal audit staff proficiency.

C.

In order to comply with the Standards, the internal audit activity must obtain an objective assessment of its processes and function at least once a year.

D.

Internal auditors completing internal assessments must demonstrate certification to perform quality assessments.

Full Access
Question # 195

An internal auditor assigned to a supplier management process engagement reviews the risk assessment with the process owner The auditor inquires about the risk response for potentially engaging unqualified third-party service providers The process owner responds that due diligence checks are undertaken to make sure that third parties possess requisite competencies before they are engaged Which of the following risk management techniques is the process owner using?

A.

Risk avoidance

B.

Risk reduction

C.

Risk sharing

D.

Risk acceptance

Full Access
Question # 196

According to IIA guidance, which of the following training methods is considered most effective in assisting new entry-level internal auditors in achieving competence with internal audit practices in the workplace?

A.

Pursuance of an internal audit certification.

B.

Enrollment in internal audit practice webinars.

C.

Attendance of internal audit workshops.

D.

Involvement in a variety of audit assignments.

Full Access
Question # 197

Which of the following best demonstrates conformance with the Standards relating to continuing professional development of internal auditors?

A.

Regulatory approval from an accrediting agency.

B.

Self-assessments against a competency framework.

C.

Approval and signoff from the board of directors.

D.

A review by external auditors on an annual basis

Full Access
Question # 198

The organization discusses the need to change its accounting software.

In which of the following stages would an internal auditor’s advisory review most benefit the organization?

A.

Pre-release stage.

B.

Implementation stage.

C.

Post-release stage.

D.

Conceptual stage.

Full Access
Question # 199

Senior management requested that the internal audit function conduct an advisory engagement to evaluate the design and implementation of the project for setting up a new accounting system.

Which approach should the auditors perform that relates only to an advisory engagement?

A.

Collaborate with senior management to define the objective and scope of the engagement rather than completing a risk assessment.

B.

Identify the criteria to be used to evaluate the aspects of the activity under review defined in the engagement objectives.

C.

Include in the engagement conclusions the auditors’ judgment regarding the effectiveness of governance, risk management, and control processes.

D.

Identify the types and quantity of resources necessary to achieve the engagement objectives.

Full Access
Question # 200

An internal auditor interviews for a position within the organization’s IT department while simultaneously conducting an audit of the area’s ability to manage the organization’s user network accounts.

This presents a conflict of which of the following principles?

A.

Confidentiality.

B.

Objectivity.

C.

Competency.

D.

Integrity.

Full Access
Question # 201

Which of the following is the best example of an ongoing independent monitoring activity?

A.

Management quality assurance activities

B.

Internal audit fraud prevention and detection activities

C.

Management and supervisory activities

D.

External audit quality assurance activities

Full Access
Question # 202

What should an internal audit function do when performing an advisory engagement for an organization?

A.

Document an understanding with management of the area under review regarding objectives, scope, respective responsibilities, and other expectations for all engagements.

B.

Agree with management of the area under review regarding the nature and scope of the engagement.

C.

Assume managerial responsibility when performing the advisory engagement.

D.

Develop an annual advisory plan per the results of a risk assessment by internal audit function.

Full Access
Question # 203

Which of the following most accurately describes corporate social responsibility at an organization?

A.

An organizational locus on improving the overall environment, even it is to the detriment of the local community.

B.

A philosophy driven by employees that flows up to senior management and the board of directors.

C.

An overall commitment of the organization to improve the quality of life for not only the employees but the community at large.

D.

A policy of ensuring that the organization is socially responsible, even if it leads to unprofitability due to increased costs.

Full Access
Question # 204

An organization ' s operations management is aware of existing internal control deficiencies but they lack the competency to execute internal control measures. Which of the following actions if taken by the internal audit activity is appropriate to assist operating management in achieving continuous improvement on internal controls?

A.

Foster the importance of the control environment

B.

Provide training on controls and on self-monitoring processes

C.

Recommend installing an enterprisewide risk management system.

D.

Conduct more assurance assignments on high risk areas

Full Access
Question # 205

In a small organization, management is unable to achieve adequate segregation of duties for its cash-handling procedures Therefore hidden surveillance cameras were installed to monitor cash-handling activities Which of the following best describes this type of control?

A.

Corrective control

B.

Process-level control

C.

Compensating control

D.

Preventive control

Full Access
Question # 206

Which of the following is included in the risk identification process?

A.

Screening for the impact and likelihood or whether the risk is controllable.

B.

Weighing the likelihood that an event or condition will happen.

C.

Disclosing all plausible events or conditions that could occur.

D.

Determining controllability of an event or condition.

Full Access
Question # 207

Which of the following practices, applied by the chief audit executive {CAE), most likely indicates an effective continuing professional educational program for the internal audit activity?

A.

The CAE tasks internal auditors with coordinating assurance activities with other providers across the organization.

B.

The CAE encourages auditors to volunteer to support research work of the local professional institute.

C.

The CAE requires auditors to periodically attest to the profession ' s Code of Ethics.

D.

The CAE reminds auditors to ensure workpapers are completed for audit engagements.

Full Access
Question # 208

According to The IIA ' s Competency Framework, which competency is considered the mandatory minimum for internal auditors to possess when performing internal audit engagements?

A.

To recognize red flags that indicate fraud.

B.

To recommend controls to prevent fraud.

C.

To apply forensic auditing techniques to detect fraud.

D.

To evaluate the potential for fraud.

Full Access
Question # 209

An internal auditor notes that inventory counts are conducted on Mondays only and that all documentation is on paper as there are no computers in the underground warehouses. Also she notices that the person responsible for receiving the goods is the same one who distributes materials and spare parts Finally, she sees that spare parts are written off and taken by the heads of mining units to different underground locations to wait for their turn to be installed. Which of the described findings requires more consideration from a fraud risk perspective?

A.

The job responsibilities of the warehouse employee compromise segregation of duties

B.

Spare parts are written off before their actual usage and installation

C.

Warehouse management is conducted on paper and requires further investigation

D.

The inventory counts take place on specific days of the week for no apparent reason

Full Access
Question # 210

A new chief audit executive realized that the internal audit charter has not been updated in five years and only includes the Core Principles for the Professional Practice of Internal Auditing, the Code of Ethics, and the Standards. What mandatory component is missing?

A.

Statement of Independence.

B.

Operating Procedures of Internal Auditing.

C.

Definition of Internal Auditing.

D.

Attestation of Quality Assurance.

Full Access
Question # 211

An internal auditor at a multinational organization is reviewing the effectiveness of the organization ' s risk management framework. In this scenario, which of the following statements is true?

A.

The auditor should consider local cultures and customs in various regions when assessing control effectiveness.

B.

Regardless of their location, employees at all levels share responsibility for designing effective controls to mitigate risks.

C.

To achieve an effective internal control environment, the organization ' s risk management plan must be documented and communicated to all levels throughout each region.

D.

Setting clear objectives is a precondition to effectively identifying, assessing, and responding to the organization ' s risks.

Full Access
Question # 212

The CEO has delegated several responsibilities to the internal audit activity. Which of the following directives should concern the chief audit executive the most?

A.

Internal auditors shall perform engagement-level risk assessments

B.

Internal auditors shall perform risk management activities.

C.

Internal auditors shall perform risk-based engagements

D.

Internal auditors shall perform organization wide risk assessments

Full Access
Question # 213

Which action by senior management indicates to the internal auditor that there may be fraudulent activities occurring within the organization?

A.

Setting unrealistic targets for staff to achieve

B.

Granting external audit firms access to staff and records.

C.

Automating some processes and allowing others to be performed manually

D.

Enforcing a zero-tolerance policy for misconduct

Full Access
Question # 214

Which of the following should play a leading role in overseeing ihe ethical atmosphere of an organization?

A.

Internal audit activity.

B.

Operating management.

C.

Senior management.

D.

Board of directors.

Full Access
Question # 215

Which of the following requests, if accepted by the internal audit activity, would impair its independence?

A.

A request to develop workshops on corporate governance for management.

B.

A request to act as liaison with external auditors.

C.

A request to determine appropriate risk management responses for management.

D.

A request to provide counseling services on ethical matters.

Full Access
Question # 216

To meet the resource requirements of this year’s internal audit plan, the chief audit executive (CAE) has recruited additional staff auditors, including an employee who resigned as a senior supervisor from the accounts payable department two months ago. There is a scheduled accounts payable review that the CAE wants to start within the next five months. Which approach should the CAE take, knowing the expertise of his new recruit in the area intended to be audited?

A.

Have the new internal auditor’s previous boss be excused from the area during fieldwork.

B.

Have the new internal auditor be responsible for the planning of the audit as well as the review of the audit fieldwork.

C.

Have the new internal auditor assigned to other responsibilities and not work on the accounts payable audit engagement.

D.

Have the new internal auditor assist with conducting the fieldwork, but ensure that her work is reviewed by the CAE.

Full Access
Question # 217

The board, senior management, and the chief audit executive (CAE) discussed that the CAE will remain functionally responsible for the risk management function until a better solution can be implemented.

Which of the following statements is the most appropriate reaction to this arrangement?

A.

The CAE should dispute the arrangement as internal audit will not be independent of risk management, which should also be subject to audit.

B.

The board should implement alternative processes to obtain assurance related to the risk management function.

C.

Since the issue was discussed at the highest level of authority, no additional reaction is needed.

D.

Senior management should change the status of the risk management function in the organization to be the same level as the internal audit function to limit impairment to independence.

Full Access
Question # 218

Which of the following would be considered a monitoring activity in organization wide risk management?

A.

Validate the results of management ' s self-assessment.

B.

Perform reviews of personnel.

C.

Maintain rigorous and comprehensive documentation.

D.

Obtain authorizations and signatures.

Full Access
Question # 219

An internal auditor has completed an assurance engagement. Which of the following is most likely true regarding the engagement?

A.

During audit planning the auditor provided the client with the scope of the engagement for their agreement

B.

The results of tie engagement were included m a written report mat was issued to the cleint who requested me engagement

C.

During audit planning the auditor determined that the engagement scope would include a review of the security and privacy of payroll records

D.

The client requested the review of a new payroll system in order to improve the security of fie system

Full Access
Question # 220

Which of the following best describes organizational governance processes?

A.

Processes employed by internal and external assurance providers to authorize, direct, and provide oversight to management to better enable the meeting of organizational objectives

B.

Processes employed by the board of directors to authorize and provide guidance and oversight to management to promote the achievement of organizational objectives.

C.

Processes employed by the board of directors and senior management to mitigate risks to acceptable levels.

D.

Processes employed by risk owners to mitigate risks to acceptable levels within the organization ' s risk appetite

Full Access
Question # 221

A chief audit executive has reported to the board that the internal audit activity is lacking financial accounting knowledge for specific audit projects. Upon approval from the board which of the following hiring approaches is best in this situation?

A.

An inbound rotational program

B.

A full-time permanent recruitment

C.

An outbound rotational program

D.

A guest auditor program

Full Access
Question # 222

Who is ultimately responsible for the organization’s daily execution of governance processes?

A.

The board.

B.

The internal audit function.

C.

Management.

D.

The risk committee.

Full Access
Question # 223

Nine months ago, an employee who was responsible for collections in the accounts receivables department joined the internal audit team. There is an accounts receivables assurance audit scheduled as part of this year ' s approved audit plan, which will include a review of the collections unit. With the knowledge and experience of this individual in the area, which of the following is the best approach for the chief audit executive (CAE) to take?

A.

Have the auditor formerly with the collections unit assist with planning and documenting the audit field work.

B.

Have the auditor formerly with the collections unit not participate on the audit team.

C.

Have the auditor formerly with the collections unit conduct the fieldwork and ensure it is reviewed by the CAE.

D.

Have the auditor formerly with the collections unit review all fieldwork done to ensure that there was adequate coverage.

Full Access
Question # 224

Which of the following should an internal auditor take into consideration when making a judgement regarding whether management selected appropriate risk responses?

A.

Significant risks

B.

Risk capacity

C.

Risk appetite

D.

Risk tolerance

Full Access
Question # 225

An internal auditor is reviewing the results of an employee survey at a mining company. Which of the following would alert the auditor to a potential ethics issue?

A.

Women account for 20% of the total number of employees in the company.

B.

Thirty percent of employees feel confident in raising concerns without a fear of retaliation.

C.

Most employees believe that transparent and fair decision-making forms the basis of business ethics.

D.

Employees with longer work experience believe that they deserve more privileges than new hires.

Full Access
Question # 226

The chief audit executive (CAE) is drafting the annual internal audit plan and seeks input from senior management and the external auditor prior to submitting it for approval to the board. According to MA guidance, which of the following statements is true regarding this scenario?

A.

The CAE ' s actions are likely to impair the Independence of the internal audit activity.

B.

The CAE acted appropriately, and the independence of the internal audit activity was not impaired.

C.

The CAE should have developed the audit plan without outside influence to maintain objectivity.

D.

The CAE acted appropriately, as he has authority to determine who reviews and approves the audit plan.

Full Access
Question # 227

Which requirement should the chief audit executive consider when communicating results of the quality assurance and improvement program to the board of a large

organization?

A.

The internal assessment results should be discussed once every five years,

B.

The rating conclusions and the impact from results of the external assessment should be explained,

C.

The results of the external assessment should be discussed every seven years,

D.

The qualifications and independence of the internal assessment team should be discussed

Full Access
Question # 228

The chief audit executive (CAE) has decided to outsource an audit of the organization ' s cloud governance in the annual audit plan. Why would the CAE outsource this audit?

A.

Lack of internal audit staff proficiency.

B.

Lack of audit planning.

C.

Lack of internal assessments.

D.

Lack of due professional care.

Full Access
Question # 229

During an audit of company expenses, the internal auditor performed a test using data analytics and identified a violation of the company ' s expenses policy. The auditor who discovered the issue considered it a potential fraudulent transaction and informed the chief financial officer (CFO). The CFO dismissed the concern because he did not understand the data analytics test that was performed and the transaction was of a low value. Given this situation, which skills or competencies should this internal auditor seek to improve?

A.

Skills in evaluating the risk of fraud.

B.

Knowledge of key IT risks and controls

C.

Soft skills such as communication and negotiation.

D.

Knowledge and understanding of the company ' s expenses policy

Full Access
Question # 230

Which of the following scenarios would most likely impair the internal audit function’s independence?

A.

An internal auditor assisted external auditors with a review of the payables department. The auditor worked in the payables department a little over a year ago.

B.

The chief audit executive had responsibility for the risk management function and helped coordinate an audit of that area by a third-party consultant.

C.

The chief audit executive was urged by the chief financial officer to scale down an accounts payable audit due to limited funds to cover audit costs.

D.

A new internal auditor was part of a team reviewing an area for which she was responsible less than a year ago. The advisory engagement was requested by management.

Full Access
Question # 231

According to IIA guidance, which of the following is accurate regarding the chief audit executive ' s (CAE ' s) requirement to report the results of quality assessments?

1. The CAE must report the results of external assessments at least annually.

2. The CAE must report the results of ongoing monitoring at least annually.

3. The CAE must report the results of quality assessments to senior management.

4. The CAE must report the results of quality assessments to the board.

A.

1 and 3 only.

B.

2 and 4 only.

C.

1,2. and 3.

D.

2,3, and 4.

Full Access
Question # 232

A new chief audit executive wants to develop a formal internal control framework for her organization. She uses globally accepted frameworks as a guide. Which of the following would she likely find critical in creating the new framework for her organization?

A.

Independent assessments.

B.

Continuous monitoring.

C.

Business continuity and backups.

D.

Organization wide objectives.

Full Access
Question # 233

According to IIA guidance, which of the following statements is true regarding mentoring programs designed to assist internal auditors with their professional development?

A.

The mentor must have a higher position in the organization than the mentee

B.

An auditor s supervisor is best positioned to serve as the auditor ' s mentor

C.

Meetings between a mentor and a mentee should be formal and well documented

D.

Auditors at the same level may be assigned different mentors and some auditors may have no mentor

Full Access
Question # 234

Which of the following statements best describes how the internal audit activity obtains reasonable assurance that significant risks in the organization are identified and assessed?

A.

The internal auditors review the organization ' s strategic plan, business plan, and policies, and have discussions with the board and senior management.

B.

The internal auditors evaluate the adequacy and timeliness of management ' s reporting of risk management results.

C.

The internal auditors interview staff at various levels and determine whether the organization ' s objectives, significant risks, and risk appetite are articulated sufficiently.

D.

The internal auditors review recently completed risk assessments and related reports issued by senior management, external auditors, and other sources.

Full Access
Question # 235

An internal audit team analyzed the organization ' s value-at-risk model during an assurance engagement and suggested several useful improvements. Management was impressed by the internal audit team’s work and requested additional actions. Which of the following requested actions would impact internal audit independence most severely if fulfilled?

A.

Assess the effectiveness of the model at least semi-annually.

B.

Modify model inputs and suggest courses of action based on outcomes.

C.

Employ acquired experience to test other models used by the company.

D.

Validate whether model outputs serve the purpose stated by the model.

Full Access
Question # 236

Which of the following fraud prevention measures is most likely to trigger undesired adverse behavior if improperly designed?

A.

Disclosure of outside business activities

B.

Ethics training programs

C.

Compensation programs

D.

Exit interviews

Full Access
Question # 237

In the COSO internal control framework, which of the following components serves as the foundation for the other components?

A.

Control activities.

B.

Control environment.

C.

Risk assessment.

D.

Monitoring

Full Access
Question # 238

An organization ' s fraud policies and procedures dictate that the internal audit activity does not have primary responsibility for conducting fraud investigations and should, in fact, refrain from involvement in investigations. Which of the following activities would be considered acceptable for internal auditors to perform of this organization?

A.

Evaluate the effectiveness of fraud investigations

B.

Oversee and monitor senior management s approach to manage fraud risks

C.

Set the tone for fraud risk management within an organization

D.

Evaluate whether the financial statements are free of material misstatement due to fraud

Full Access
Question # 239

In a small company with a small budget, the board and senior management asked the chief audit executive (CAE) to develop specific controls prompted by a new regulatory requirement affecting a specific process. The CAE was also directed to report functionally to senior management. An audit engagement on this process was already set in the internal audit plan. Which of the following represents an impairment to the internal audit activity ' s independence?

A.

The development of controls by the CAE.

B.

The audit engagement regarding this process.

C.

The functional reporting of the CAE to senior management.

D.

The small budget.

Full Access
Question # 240

Management is installing security cameras to identify unauthorized physical access to the organization ' s warehouse. This is an example of which of the following types of controls?

A.

Detective controls.

B.

Key controls.

C.

Primary controls.

D.

Preventive controls

Full Access
Question # 241

Which of the following statements is true regarding corporate social responsibility (CSR)?

A.

Many of the areas explored by CSR are normally included in an audit universe or annual audit plan,

B.

Despite significant corporate resources spent on CSR reporting, investors generally do not rely on CSR information.

C.

Unlike many other areas of reporting responsibilities impacting stakeholders, CSR is largely voluntary.

D.

Typically, operating management does not have a major role to play based on the public nature of reporting

Full Access
Question # 242

Management has implemented a segregation-of-duties policy for handling inventory. Which of the following fraud risks would be more concerning to an internal auditor following the implementation of this new policy?

A.

The risk of collusion between parties.

B.

The risk of falsified reconciliations.

C.

The risk of low-liquidity inventory.

D.

The risk of damages to the inventory.

Full Access
Question # 243

Who is responsible for ensuring internal auditors’ continuing professional development?

A.

Individual internal auditors.

B.

Chief audit executive.

C.

The board.

D.

Engagement supervisors.

Full Access
Question # 244

Which of the following statements is true regarding organizational culture and an audit of the control environment?

A.

For multinational organizations it is important to ensure that the organizational culture is consistent at all locations

B.

Because the chief audit executive (CAE) is part of the organizational culture, external auditors should be engaged to evaluate the control environment

C.

If there are unresolved scope restrictions, the CAE should consider whether to pursue the audit and note the scope restrictions in the audit report

D.

Because it will create a conflict of interest relating to the control environment, senior management should not be consulted during the audit

Full Access
Question # 245

The internal audit activity audited an organization ' s risk management function multiple times, and the recommendations that were made remain unaddressed by the head of risk management. Which of the following would be the next step for the internal audit activity?

A.

The internal audit activity should add value by implementing the recommendations on management ' s behalf.

B.

The chief audit executive (CAE) must discuss this matter with senior management and the board

C.

The CAE should determine which recommendations to implement based on the severity of the associated risks.

D.

The internal audit activity, led by the CAE. should assume responsibility for risk management function.

Full Access
Question # 246

The chief audit executive (CAE) of a new internal audit activity is creating an internal audit charter According to IIA guidance, which of the following terms is most likely to

be included in the charter?

A.

Senior management will be present whenever the CAE interacts with the board, to ensure effective communication among all three parties.

B.

Internal auditors will advise on the design of control policies and procedures in any area where the organization does not possess the requisite expertise,

C.

Internal auditors will demonstrate competence, concern, and the dedication expected of a professional,

D.

Internal auditors will receive performance-based compensation, including bonuses for reporting more than a stipulated number of observations.

Full Access
Question # 247

Which statement is correct about effective internal auditing?

A.

It requires that senior management and the board establish reporting responsibilities for the chief audit executive (CAE).

B.

It aligns with the Global Internal Audit Standards as the exclusive authoritative guide when performing engagements.

C.

It involves communication with the board and senior management on a continuous basis to ensure engagements are relevant.

D.

It allows the CAE to plan engagements that meet the organization’s strategies and objectives.

Full Access
Question # 248

To assure that the technical proficiency of internal auditors is appropriate for the audit engagements to be performed, a chief audit executive should:

A.

Consider the scope of work and level of responsibility when establishing criteria for education and experience in filling internal audit positions.

B.

Ensure that each newly hired auditor is qualified in all of the disciplines needed to accomplish the department’s audit mission.

C.

Oversee a training program that matches the actual training provided with the interests of individual auditors.

D.

Require all of the audit staff to pursue a minimum number of continuing professional education hours each year

Full Access
Question # 249

During a quality assessment of the internal audit activity an auditor is assessing whether the independence of the internal audit activity is at risk of being compromised. According to IIA guidance, which of the following would provide the best source of evidence for such an assessment?

A.

An organizational chart showing the reporting line of the chief audit executive to the CEO

B.

The internal audit charter as endorsed by the organization’s governing body

C.

A review of the audit opinions issued from a sample of recent audit engagements

D.

An assessment of the scope of the audit work performed by the internal au < M activity

Full Access
Question # 250

According to IIA guidance, which of the following is the primary reason the chief audit executive discusses the internal audit charter with senior management and the board?

A.

To provide guidance and solicit feedback on managing the internal audit activity as expected by various stakeholders.

B.

To provide an understanding of the Mission of Internal Audit and The IIA ' s mandatory guidance elements.

C.

To provide an update on the internal audit activity ' s quality of engagement supervision.

D.

To provide information on existing internal audit planning, changes to the internal audit plan, and the rationale for the changes

Full Access
Question # 251

Which of the following statements is true regarding external quality assessments?

A.

They can be performed by self-assessment with independent external validation, but they must be performed every three years.

B.

When a new chief audit executive (CAE) is appointed, an external quality assessment should be undertaken during the CAE’s first year of office.

C.

An external quality assessment must be conducted at least once every five years by a qualified, independent assessor or assessment team.

D.

An external assessment by a qualified professional from outside of the organization can be performed in place of an internal assessment.

Full Access
Question # 252

Which of the following best describes the type of organizational culture known as adaptability culture ' ?

A.

A results-oriented culture that values competitiveness and personal initiative

B.

A culture that emerges in quick-response and high-risk decision-making environments

C.

A culture that is characterized by low involvement with environmental and health issues

D.

A culture that places high value on participation and meeting the needs of employees.

Full Access
Question # 253

Which of the following is a consulting service the internal audit activity can perform with respect to the organization ' s risk management?

A.

Delivering assurance on the risk management system

B.

Facilitating risk assessment workshops

C.

Evaluating principal risk reporting

D.

Deciding on the appropriate risk response

Full Access
Question # 254

A chief audit executive (CAE) has been asked by the board to evaluate the effectiveness of ethical programs created by management. Which of the following would be the most appropriate action for the CAE to take?

A.

Compare the design of the organization ' s ethical programs with best practices.

B.

Verify that a code of conduct and related policies exist and are communicated.

C.

Use employee surveys to assess whether ethical programs are achieving desired outcomes.

D.

Compare the cost of the ethical programs with the achieved outcomes.

Full Access
Question # 255

According to IIA guidance, which of the following activities is appropriate for an internal auditor to perform with regard to the organization ' s corporate social responsibility (CSR) program?

1. Determine whether the organization has adequate controls to achieve its CSR objectives.

2. Facilitate a management self-assessment of CSR controls and results.

3. Consult on the project design and implementation for the CSR program.

4. Exclude CSR-related external risks that are beyond the control of the organization.

A.

1 and 2 only.

B.

1, 2 and 3 only.

C.

2, 3, and 4 only.

D.

3 and 4 only.

Full Access
Question # 256

Which of the following statements demonstrates that internal auditors are in conformance with the standard of due professional care?

A.

Internal auditors have shown they have the freedom to carry out their responsibilities.

B.

Internal auditors have demonstrated the skills needed to carry out the audit engagement.

C.

Internal auditors have strictly followed a formal audit process in conducting their work.

D.

Internal auditors have demonstrated an unbiased mental attitude.

Full Access
Question # 257

The organization ' s chief audit executive (CAE) is planning an immediate assurance engagement following several product recalls. However, the internal audit staff does not have the required Knowledge and experience to adequately assess all the relevant processes and procedures. According to 11A guidance, which of the following actions should the CAE take under these circumstances?

A.

Use the current available resources to conduct the review and exclude those procedures that can ' t currently be performed.

B.

Implement an accelerated training plan to provide the audit staff with the necessary skills and knowledge to conduct the engagement.

C.

Encourage management to accept the assessed risk until the internal audit activity is able to adequately review the area.

D.

Obtain assistance for the audit team from other internal assurance providers who possess the requisite expertise in the area.

Full Access