Internal Audit Fundamentals Questions and Answers
Which of the following is an example of impairment to internal auditor independence or objectivity ' ?
Which of the following is the most appropriate way to ensure that a newly formed internal audit activity remains free from undue influence by management?
Which of the following approaches will internal audit utilize when developing a set of performance standards to measure an organization’s risk management process against?
Which of the following statements is true regarding the disclosure of results of the quality assurance and improvement program?
According to IIA guidance, during the development of an internal audit charter, which is true regarding acceptable organizational roles?
Which of the following is true regarding internal audit role ' s in The IIA ' s Three Lines Model?
A whistleblower reveals to the chief audit executive (CAE) detailed allegations of potential fraud at the senior management level. Although the CAE has some experience in the area, she chooses to retain an external fraud expert to conduct the investigation. When asked by the director of finance to defend the expenditure, which of the following statements represents the CAE ' s best response?
The organization s procurement manager asks the internal auditor to deliver training to the procurement team on the organization’s third-party risk management process. Which of the following is the most appropriate response?
In which of the following scenarios would the internal auditor’s objectivity be best protected?
A chief audit executive has decided to use the process element approach to evaluate the organization’s risk management process.
According to IIA guidance, which of the following provides evidence that the risk evaluation element is in place?
The chief audit executive (CAE) decided to conduct a self-assessment with independent validation. Which of the following is the most likely reason the CAE selected this course of action?
A newly appointed chief audit executive (CAE) is tasked with creating a new internal audit activity within the organization. Which of the following would the CAE need to include in the new internal audit charter?
Which of the following represents a deficiency in the control environment?
Which of the following is an acceptable supplement to promote professional development within the internal audit function?
An internal auditor is assessing the effectiveness of the organization ' s risk management practices She checks to see whether risk management is an intégrai part of decision making and whether risk management is transparent, responsive to change and addresses uncertainty. According to HA guidance on risk management frameworks, which of the following approaches is the auditor most likely using?
Which of the following organizations is adopting an acceptance technique in terms of its risk response?
Which of the following statements is true regarding a key difference between assurance and consulting services provided by the internal audit activity?
According to NA guidance, which of the following is true regarding typical fraud schemes?
1. A diversion occurs when an employee has an undisclosed personal economic interest in a transaction that adversely affects
the organization.
2. Tax evasion is intentional reporting of false or misleading information on a tax return by an organization to reduce taxes owed.
3. Skimming involves stealing cash or assets from the organization and is normally concealed by adjusting the organization’s
records.
4, Disbursement fraud occurs when a person causes the organization to issue a payment for fictitious goods or services.
Which of the following will help the chief audit executive (CAE) of a large organization ensure that the independence of the internal audit function is maintained?
The same internal auditor has audited the regional purchasing department annually for the last three years. The audits have shown several significant control deficiencies that have not been corrected by management. New management is in charge of this regional purchasing department, and it is time to audit the department again. What concerns should be considered prior to assigning the audit to the same auditor?
After an engagement was completed and the final communication was issued, it came to the attention of the engagement supervisor that additional work was required to review some significant risks in the processes of the area under review.
How should the engagement supervisor proceed after completing the additional work?
According to IIA guidance, which of the following actions is a chief audit executive required to take with regard to reporting the results of the quality assurance and improvement program?
Which of the following statements is true regarding the internal audit activity ' s quality assurance and improvement program (QAIP)?
Which of the following best describes the internal audit activity’s responsibility within a risk and control framework?
A manufacturing organization ' s chief audit executive (CAE) was approached by the head of security from one of the manufacturer ' s third party suppliers The head of security requested internal audit records from a recent audit engagement involving the third-party supplier The head of security believed those records contained information that would enable to identify employees of the third-party supplier who may be involved m fraudulent activities What is the most appropriate course of action for the CAE?
Which of the following activities would breach the principles of The IIA ' s Code of Ethics?
An existing Internal audit charter is currently under review for revision. Who is responsible for assuring that all required components are included?
According to NA guidance, which of the following actions by the chief audit executive would best ensure that internal auditors demonstrate due professional care?
According to IIA guidance, the nature and scope of assurance and consulting services to be offered must be clearly delineated in which of the following internal audit documents?
With regard to the internal audit activity ' s quality assurance and improvement program, which of the following topics would the chief audit executive include on the quarterly board meeting agenda?
What controls could be implemented as a preventive measure against malicious insider threats, such as an unauthorized employee obtaining electronic customer sales information and later selling them to a competitor?
According to IIA guidance, who should chief audit executives report to regarding the internal audit function’s human resources daily matters, such as vacations?
An organization sells products through distributors. The organization ' s chief audit executive insists that the organization ' s code of conduct be applicable to their distributors as well. Which of the following risks would this mitigate?
It is important for the chief audit executive to consider the level of competence of the internal audit staff because their competence influences which of the following?
An internal auditor found that his organization did not make a disclosure that is required by law. However, the auditor decided not to raise an audit finding. Which of the following Code of Ethics principles was violated?
An accounts payable clerk has recently transferred Into the internal audit activity and has been assigned to an engagement related to accounts payable processes for which he was previously responsible Which of the following is the best action for the new internal auditor to take?
An internal audit function within a commercial bank performs an annual audit of the bank’s anti-money laundering compliance program as required by anti-money laundering regulations. This report is submitted to regulators annually as proof that the audit was performed.
Which of the following concepts is illustrated in this scenario?
Which of the following practices is generally most effective to protect internal audit objectivity?
In terms of governance, which of the following best characterizes the relationship between senior management, the board, and owners or investors?
Which of the following would be the best choice for a continuing professional development requirement for a newly created internal audit activity?
According to IIA guidance, which of the following statements is true regarding internal auditors ' knowledge, skills and other competencies?
According to IIA guidance, which of the following actions best demonstrates that due professional care has been considered by the internal audit activity when conducting a review of an organization ' s assets?
Which situation would best demonstrate that the organization maintains a strong ethical culture?
Due to extreme liquid fuel price fluctuations, management decided to designate a specific price below which liquid fuel shall not be sold to customers, but instead shall be pumped into storage tanks. Which of the following risk responses has management selected?
Which of the following scenarios represents a top-down flow of information regarding corporate governance?
Of all the common characteristics of frauds, which of the following can the organization influence the most?
In an assurance engagement focused on the adequacy of organizationwide risk management practices, which of the following best describes a primary area of interest for the engagement?
Which of the following engagements would be considered an appropriate consulting service?
According to IIA guidance, which of the following is the primary reason the chief audit executive discusses the internal audit charter with senior management and the board?
The chief audit executive (CAE) of a new internal audit activity is creating an internal audit charter According to IIA guidance, which of the following terms is most likely to
be included in the charter?
Which of the following statements is true regarding control activities?
An organization is considering the acquisition of a target organization. Senior management asks the internal audit function to advise on the target organization’s information security practices.
What type of internal audit service is this?
Which of the following organizations has reached the most mature level of corporate social responsibility?
Which of the following would a chief audit executive most likely use to identify a need for improvement in a staff internal auditor ' s business acumen?
Which of the following statements would typically be included in the responsibility section of the internal audit charter?
Which of the following is a way to demonstrate an individual internal auditor ' s competency through continuing professional development?
A telecommunications organization is planning to cease operations in one or the markets in which it operates due to increasing volatility and uncertainties. Which of the following risk management techniques is the organization selecting?
Which of the following most accurately describes corporate social responsibility at an organization?
Upon completion of an external quality assessment, which of the following would the chief audit executive be required to report to the board?
According to The IIA’s Code of Ethics, which of the following scenarios offers the best example of violating the principle of integrity?
An experienced internal auditor is planning an assurance engagement of the organization ' s sales activities. During process walkthroughs and interviews, many sales representatives expressed concerns about management ' s escalating demands to meet the organization ' s sales goals. According to the MA guidance, which of the following is the best application of due professional care in planning the engagement?
An organization is conducting a fraud risk assessment as part ol its risk management program. Which of the following steps is the organization most likely to perform first?
The chief audit executive (CAE) of a multinational corporation has been assigned to assist management in identifying an internal control framework for the organization. The CAE wants to ensure the framework is comprehensive and will effectively meet the needs of various stakeholders.
Which factor should the CAE primarily consider?
Which of the following is the most appropriate reason for a chief audit executive to conduct an external assessment more frequently than five years?
A chief audit executive ensures that the internal audit activity provides annual training to management on internal controls. Where is the nature of these services defined?
The results of an assessment of the adequacy of controls would be considered incomplete or misleading unless the internal auditor considers which of the following?
Which of the following primarily sets the foundation for effective corruption risk mitigation?
Which of the following drivers of fraud is directly controllable by an organization?
Which of the following is a strategic risk that internal auditors should consider when performing a third-party risk management engagement?
Which principle of the HA Code of Ethics focuses on continuing education and professional development?
A new chief audit executive realized that the internal audit charter has not been updated in five years and only includes the Core Principles for the Professional Practice of Internal Auditing, the Code of Ethics, and the Standards. What mandatory component is missing?
Which of the following situations is most likely to threaten the independence of the internal audit activity?
Which of the following scenarios violates The IIA ' s standard regarding internal audit independence?
According to IIA guidance which of the following statements is true regarding the internal audit charier?
Which of the following best describes a purpose for the internal audit charter?
According to the Standards, which of the following demonstrates the proficiency of an internal auditor?
Which of the following documents most directly describes the guidelines for and importance of the objectivity of internal auditors?
According to IIA guidance, which of the following statements is true regarding risk management in an organization?
The internal audit activity is undergoing a self-assessment as part of its quality assurance and improvement program. Which of the following observations must be addressed in order for the internal audit activity to achieve conformance with the Standards?
The internal audit activity is responsible for conducting fraud investigations. A potential fraud instance was identified during an audit engagement. The chief audit executive appoints a lead investigate. Which of the following would most likely be the next step?
Which of the following actions should an organization take to detect an emerging risk of potential fraud?
When testing a sample of payroll records during an engagement, an internal auditor suspects mat fraud has been committed. What should be the next step?
Due to toe increased operational responsibility of the CEO. The chief audit executive (CAE) of an organization currently reports to the chief financial officer (CFO). What is the likely imped of such a situation?
An internal auditor believes that a weakness exists in the control environment relating to the delegation of authority and responsibility within the management structure. Which of the following actions should the internal auditor first consider in this matter?
An internal auditor has completed an assurance engagement Which of the following is most likely true regarding the engagement?
A snow removal company is conducting a scenario planning exercise where participating employees consider the potential impacts of a significant reduction in annual snowfall for the coming winter. Which of the following best describes this type of risk?
Which of the following statements is true regarding managing an internal audit function?
An organization uses hedging to address foreign currency risk.
Which of the following best describes this risk strategy?
An internal auditor is trying to evaluate what could go wrong after determining that a risk management technique is operating effectively. What type of risk is the auditor assessing?
Which of the following is the most effective way for internal auditors to determine whether ethical values are followed throughout the organization?
Which of the following is the first step in the process of identifying relevant fraud risk factors?
Management decided to post the organization ' s newly established code of conduct on its website. This decision is primarily intended to mitigate which of the following risks?
Which of the following statements is true regarding control activities ' ?
A chief audit executive (CAE) has been asked by the board to evaluate the effectiveness of ethical programs created by management. Which of the following would be the most appropriate action for the CAE to take?
The level of authority for the internal audit activity is granted by which of the following?
Which of the following is the best reason why the engagement supervisor should take care in explaining to local management the criteria that will be used to measure the effectiveness of the control environment?
An internal auditor assessed that the risk of steel theft at a plant is high. In response, the plant ' s management introduced a number of controls, including fences around the facility, a metal detector at the entrance, and monthly steel inventory counts. If the controls operate as intended, which of the following outcomes would the internal auditor hope to see?
According to IIA guidance, which of the following statements is true regarding ISO 31000?
An internal auditor is performing testing to gather evidence regarding an organization’s inventory account balance and is mindful of the possibility that the sample used might support the conclusion that the recorded account balance is not materially misstated when, in fact, it is. The auditor ' s concern best describes which of the following risks?
Which of the following indicates an appropriate disclosure of a potential nonconformance with the Standards?
A chief audit executive (CAE) is concerned that the internal audit activity is not receiving adequate training and continuing education. Which of the following approaches should the CAE take?
An internal auditor performed a consulting engagement last year which included assisting with management ' s design of controls over the procurement function. How should the chief audit executive plan an assurance engagement on the adequacy of the internal control system in the procurement function in the current year?
To comply with the proficiency standard which of the following would the chief audit executive likely consider as the primary hiring criterion when choosing a new internal auditor?
An organization is in the process of hiring a new chief audit executive (CAE). Which of the following can the potential candidates expect to be a part of the recruiting process or in place when the CAE is hired?
Which of the following actions by the internal audit activity requires disclosure to the board of nonconformance with the Standards?
Which of the following is most likely to result in the impairment of independence for the internal audit activity?
Which of the following disclosures must the chief audit executive (CAE) include when communicating the results of the quality assurance and improvement program to senior management and the board?
The board requested the chief audit executive (CAE) to provide consulting services for a new systems implementation project Which of the following statements is true regarding this scenario?
The internal audit activity conducted an organization wide risk assessment. One of the most significant risks identified is associated with the oil price market. The chief audit executive (CAE) is considering including in the annual audit plan an assessment of the effectiveness of oil price risk management. The manager responsible commented that the assessment was not needed, as market risks were regularly addressed by the financial risk committee. If the CAE decides to include this activity in the annual audit plan anyway, how should it be recorded?
Which of the following would best illustrate to the chief audit executive that due professional care was exercised by internal auditors during an engagement?
An internal auditor is reviewing the organization’s procurement processes. The procurement manager states that suppliers’ bank details are verified by phone call directly with the supplier before being updated in the procurement system. The organization has around 3,000 suppliers. The auditor is skeptical that a phone call is made for each supplier when bank details are changed.
The auditor decides to verify the manager’s statement by analyzing the change to one supplier’s bank details.
Which piece of evidence would convince the auditor that the control described by the procurement manager is effective?
According to IIA guidance, which of the following actions by the chief audit executive (CAE) best demonstrates the organizational independence of the internal audit activity?
An internal auditor has received negative feedback regarding the auditor’s lack of general knowledge about the organization’s business during an annual performance review.
What would be the auditor’s best course of action to address the feedback?
A sales manager was recently bypassed for a promotion. He feels entitled to a higher salary and is angry that management does not recognize his contributions. To make up for this perceived injustice, he begins to record false expenses on his travel expense reports. This scenario best illustrates which of the following fraud risk factors?
Which of the following accurately describes the concept of inherent risk?
Which of the following actions would an internal auditor perform primarily during a consulting engagement of a debt collections process?
An internal auditor has documented several instances in which management asked employees to ad against the policies and procedures. Which of the following is the most appropriate next step?
With regard to IT governance, which of the following is the most effective and appropriate role for the internal audit activity?
Which of the following statements is true regarding external quality assessments?
Which of the following would be considered advanced expertise which most internal auditors are not expected to possess ' ?
Management of an area under review is aggressive, upset, and questioning the knowledge and experience of the organization ' s internal auditors, as the audit results highlight critical findings. The relationship between the internal audit activity and management has continued to degenerate. as previous audit reports also showed a large number of issues. What would be the best strategy for working through the current audit results while also attempting to repair the relationship with management?
In which of the following audits would the internal auditors most likely contribute to the assessment of organizational governance?
According to NA guidance, which of the following provides the best evidence of conformance with the Standards with respect to the proficiency required of the internal audit activity?
According to MA guidance, which of the following is the most accurate statement regarding the internal audit charter?
Which of the following situations best describes an internal auditor who may have violated the IIA Code of Ethics principle of confidentiality?
In the COSO internal control framework, which of the following components serves as the foundation for the other components?
Which of the following internal controls best mitigates the risk of corruption schemes between employees and vendors?
Which of the following is (he most effective way any organization can ensure proper governance over its internal controls?
Which of the following internal control attributes would an internal auditor test to understand whether organizational structure supports effective internal control?
Which of the following would be a preventive control for helping to manage fraud in an organization?
An internal audit activity is performing a governance engagement. Which of the following would provide the best evidence for an internal auditor when evaluating the organization’s culture?
Which of the following factors is most important for internal auditors to consider when prioritizing fraud risks?
Which of the following scenarios demonstrates an impairment to internal audit independence?
In an environment where employees are frequently penalized for mistakes and the organizational culture is one of fear and blame which of the following is an internal auditor most likely to find?
According to IIA guidance, which of the following statements regarding ethics is true?
During fieldwork, an internal auditor located a significant internal control issue. Without identifying the origins of the issue, the auditor concluded the engagement and included the issue in the final audit report. To enhance audit quality, which of the following skills should the internal auditor improve?
Which of the following statements best represents the due professional care that is required of internal auditors?
Which of the following is true regarding the stakeholder theory of corporate social responsibility?
When an organization purchases a derivative contract in the stock market to limit the potential loss in the value of a security, the organization is applying which of the following risk management techniques?
After being assigned to an audit of the accounts payable process, an internal auditor privately notifies the chief audit executive that she is a finalist for an open manager position within the accounts payable department. Which of the following is the IIA Code of Ethics principle that the auditor upheld?
According to IIA guidance, which of the following actions best demonstrates due professional care by an internal auditor when she discovers a number of fraud-related red flags during an audit engagement?
Which of the following tools would be most useful to an internal auditor performing an assessment of the effectiveness of the organization ' s risk responses?
What should the internal audit function promote to most effectively deter fraud?
Which of the following risk management techniques best describes the strategy of obtaining insurance to protect against losses due to bad weather conditions?
Which of the following describes the internal audit activity ' s most appropriate role in an organization ' s risk management process?
Which of the following would likely have the greatest influence on the long-term quality of an organization’s control environment?
Which of the following factors are commonly assessed to determine the magnitude of risk events?
During an assurance engagement an internal auditor discovered that risk limits risk limit were set for a new market expansion project Management of the area under review was eager to comply and submitted a potential risk limit value for the auditor ' s review and approval. Which of the following would be an appropriate course of action for the auditor to take?
What should an internal audit function do when performing an advisory engagement for an organization?
The accounting department asked the chief audit executive (CAE) to perform a review of suspicious transactions. The CAE was an accounting manager for the organization six months ago.
How should she respond to the request?
Which of the following best describes the Standards requirement for collective proficiency of the internal audit activity?
Which of the following situations undermines the independence of the internal audit activity?
According to IIA guidance, which of the following activities would typically be examined when using the maturity model approach for assessing an organization ' s risk management program?
A chief audit executive (CAE) has just joined an organization with an existing internal audit activity. Based on her review of the current organizational structure, the CAE determines that the internal audit activity lacks adequate independence. Which of the following actions is the CAE ' s best step to take next to move the internal audit activity toward organizational independence?
The largest risks facing an organization should be mitigated by which type of controls?
A business unit manager was impressed by the competence of the internal auditor who was conducting an assurance engagement in his area and the manager made the auditor an attractive job offer to begin after the audit was completed The auditor later told her auditor in charge that she was considering the offer. Which of the following IIA Code of Ethics principles was most likely violated?
Which of the following is the best example of an ongoing independent monitoring activity?
To achieve conformance with the Standards, the chief audit executive must include which of the following activities in the quality assurance and improvement program (QAIP)?
During a procurement process audit the internal audit activity undertakes a fraud risk assessment and considers a range of possible fraud scenarios within the process. Which of the following scenarios constitutes a pressure to commit fraud?
Which of the following statements best represents the duo professional care that is required of internal auditor’s?
Which of the following is an appropriate roe fa the internal audit activity?
Which of the following is a true statement regarding controls such as ethical values, tone at the top and operational style?
During his quarterly meeting with the chief audit executive (CAE), it was recommended to an experienced staff internal auditor that he complete a communication and leadership training. The training was also included in the auditor’ yearly professional development plan. The auditor is confused, as he believes he should attend trainings on technical areas rather than spend time on communication and leadership.
According to IIA guidance, which of the following statements regarding this scenario is true?
A global manufacturing company has three regional offices. The chief audit executive (CAE) is concerned about the cost of an upcoming external quality assessment of the internal audit activity. The last external assessment was performed six years ago. Recently, the internal audit staff at one of the regional offices performed an internal assessment. To ensure conformance with the Standards, what is the most appropriate action for the CAE to take?
An organization ' s board has approved an expansion plan into a new market. The board acknowledged that if the expansion is not successful, the organization would encounter large monetary losses consisting of legal fees, research and development costs, rent expenses, and labor fees. Which of the following has the board approved?
The management team of an agricultural organization has prioritized corporate social responsibility (CSR) initiatives. Which of the following would be considered a CSR activity?
An internal auditor has suspicions that some fictitious vendors have been created in the organization ' s computer system. Which of the following would be the best technique to detect this fraud?
In which of the following situations may the internal audit activity report conformance with the Standards?
During a monthly internal audit staff meeting, the chief audit executive (CAE) decided to reinforce the importance of internal audit staff being objective in their work. Which of the following examples would be most appropriate for the CAE to include as part of the meeting presentation?
Which of the following represents a breach to the principle of maintaining objectivity?
The chief audit executive (CAE) has decided to outsource an audit of the organization ' s cloud governance in the annual audit plan. Why would the CAE outsource this audit?
Which of the following offers the feast evidence that the internal audit activity has achieved organizational independence?
An organization is considering purchasing a new banking software system and has asked the internal audit activity to evaluate the system. An internal auditor assigned to perform the engagement worked at the software company two years ago and is familiar with the system ' s design strengths and weaknesses. Which of the following is true regarding impairment to the auditor ' s objectivity?
Which of the following would be the most effective in helping to detect fraud?
While auditing an organization ' s credit approval process, an internal auditor learns that the organization has made a large loan to another auditor ' s relative. Which course of action should the auditor take?
Which of the following is the primary engagement responsibility of an entry-level internal auditor?
An internal auditor for a construction organization suspects that fraud is occurring, as inventory replacement costs for hand tools and additional materials have been consistently exceeding the budget at two large job sites.
Based on this information, which type of fraud is most likely occurring at these job sites?
The chief audit executive (CAE) has hired a new internal auditor who was immediately assigned to a procurement function audit. Because the new auditor ' s name is similar to that of the procurement manager, some staff members think the two are related, although they are not. Which of the following actions is most appropriate for the CAE to take?
An internal auditor argued that the organization’s insurance coverage is inadequate and recommended a particular insurance agency that could evaluate and provide alternative insurance products. The owner of the insurance agency is a close friend of the auditor.
Which statement is true regarding this recommendation?
Which of the following can be used to minimize employees’ resentment of controls?
Which of the following would be most helpful to measure whether an internal audit activity successfully provides risk-based assurance?
Which of the following characteristics is typical of the internal audit activity?
An internal audit team received the following feedback from operational management via a post-engagement survey " Management agrees with all audit findings However, the audit team did not consider our input on the best way to resolve the issues”
This feedback is an indication that the internal audit activity may need to improve which of the following interpersonal skills?
The chief audit executive (CAE) of a large organization has been asked by the board to assume responsibility for risk management and compliance operations, both of which are distinct departments within the organization and are subject to periodic audits by the internal audit activity In regards to future audits of these functions which of the following approaches would be most appropriate?
An internal audit team analyzed the organization ' s value-at-risk model during an assurance engagement and suggested several useful improvements. Management was impressed by the internal audit team’s work and requested additional actions. Which of the following requested actions would impact internal audit independence most severely if fulfilled?
According to IIA guidance, which of the following best describes expense reimbursement fraud?
According to IIA guidance, which of the following best describes the chief audit executive s responsibility for confirming to the board the organizational independence of the internal audit activity ' ?
An internal auditor was completely honest with operational management when delivering unfavorable audit results. Which of the following best describes the IIA Code of Ethics principle that the auditor demonstrated?
An internal audit of an organization ' s disbursement department revealed that multiple payments were made to legitimate vendors bearing fraudulent banking information belonging lo employees in the department. These vendors were initially set up with accurate banking information but were subsequently modified by disbursement officers with access to the vendor management system. Which of the following controls would have likely prevented the fraudulent modification of vendors ' banking information?
Which of the following best demonstrates organizational independence of the internal audit activity?
When performing an audit of the risk management process an auditor makes the observations listed below. Which poses the greatest risk to the organization?
Which finding indicates a potential deficiency in an organization’s internal control framework?
During an assurance engagement internal auditors interview operational management to gather and evaluate information. Which approach is most important for internal auditors to be able to listen effectively to interviewees in the given situation?
Which of the following actions taken during an audit engagement is the best demonstration of an internal auditor ' s due professional care?
According to HA guidance, if an internal auditor suspects fraud during an assurance engagement, what should the auditor do first?
Which of the following is a typical characteristic of an organization ' s risk management framework?
During a brainstorming session, employees stated that dishonest vendors could submit fictitious invoices to the organization, and such an invoice may be authorized for payment because the employees responsible might be clicking approval boxes without going into the details.
Given this information, which of the following controls should be tested during the audit engagement?
Considering the concepts of organization wide risk management and the system of internal controls, the internal audit activity as a whole can be considered which of the following types of control?
Which of the following would be considered an impairment to an internal auditor ' s objectivity when performing a review of the organization ' s procurement function ' ?
According to IIA guidance, which of the following is necessary for internal auditors to comply with the requirements for proficiency?
1. Sufficient consideration of current activities, trends, and emerging issues to effectively carry out their professional responsibilities.
2. Ability to provide relevant advice and recommendations to management and the board.
3. Understanding of key IT risks and controls and the ability to identify fraud using technology-based audit techniques.
4. Knowledge, skills, and other competencies necessary to perform individual responsibilities during the engagement.
Which of the following is an example of a detective control?
Which situation demonstrates an internal auditor’s due professional care?
An organization recently hired a manager for a newly established operations department. The manager requests the internal audit function to establish appropriate internal controls and processes for the management of operations.
How should the chief audit executive respond?
Which of the following best demonstrates the board of directors ' governance over internal control?
Which of the following statements is true regarding consulting and assurance engagements performed by the internal audit activity ' ?
Which of the following is an appropriate role for the internal audit activity?
A chief audit executive assigned an internal auditor to perform an assurance engagement. The auditor concluded with a major audit finding based on hearsay evidence Which of the following competencies did the auditor appear to be lacking?
Which of the following statements about internal audit consulting engagements is true?
With regard to governance, which of the following is a board-level responsibility rather than a management responsibility?
Which of the following situations would best indicate to the chief audit executive that one of the audit team members is struggling with application of due professional care?
According to IIA guidance, which of the following activities would typically be examined when using the maturity model approach for assessing an organization ' s risk management program?
Which of the following should be part of the internal audit activity ' s duties?
Which of the following written documents typically offers the best evidence that internal auditors exercise due professional care in conformance with the Standards?
The internal audit activity completed its analysis of sample transactions to determine occurrences of double billings According to If A guidance, which of the following best demonstrates that internal auditors exercised due professional care during the review?
According to IIA guidance, which of the following is an appropriate role for the internal audit activity?
Senior management has requested that the internal audit activity review and amend policies where necessary when auditing the purchasing department. To which of the following would the chief audit executive most likely give primary consideration when responding to this request?
A newly appointed chief audit executive (CAE) started analyzing the organization ' s policies in an attempt to customize them to address internal audit specifics. Which of the following organizationwide practices is most likely to be acceptable to the CAE?
Which of the following best demonstrates that the internal audit activity is using due professional care?
Which of the following is a primary benefit of implementing a governance, risk management, and compliance framework within an organization?
The chief risk officer (CRO) requested the internal audit function’s assistance during the implementation of the organization’s risk management process. The board wants the CRO and chief audit executive to define what the internal audit function’s role will be before it approves or denies the request.
Which of the following internal audit roles would be the most appropriate in this scenario?
Which of the following is an example of a risk reduction strategy?
In which of the following scenarios is the internal auditor in conformance with The IIA ' s Code of Ethics and the Standards?
In an internal audit charter, which of the following statements regarding the chief audit executive (CAE) would be most directly related to describing the responsibilities of the internal audit activity*?
Which of the following statements is true regarding organization wide risk management?
In a small company with a small budget, the board and senior management asked the chief audit executive (CAE) to develop specific controls prompted by a new regulatory requirement affecting a specific process. The CAE was also directed to report functionally to senior management. An audit engagement on this process was already set in the internal audit plan. Which of the following represents an impairment to the internal audit activity ' s independence?
An organization is testing a new IT system for digital data storage and security. The internal audit activity has been asked to evaluate the system in a consulting engagement. Although several internal auditors on staff are qualified to perform basic assessments of IT systems, none are familiar with the new system. Which of the following is a legitimate response to the prospective client?
1. Decline the engagement.
2. Proceed with the engagement, performing only those parts of the engagement that the internal auditors are qualified to perform.
3. Accept the engagement and develop the additional competencies in-house prior to the engagement ' s starting date.
4. Make arrangements to obtain assistance from a competent IT auditing expert.
Which control feature should an internal auditor review if critical computer hardware is missing from the IT department?
What must a chief audit executive do if significant changes to regulations may affect the nature of internal audit services?
Which of the following statements is true regarding management ' s use of judgement to design, implement, and conduct internal control?
An IT contractor applied for an internal audit position at a bank. The contractor worked for the bank ' s IT security manager two years ago. If the audit manager interviewed the contractor and wants to extend a job offer, which of the following actions should the chief audit executive pursue?
The internal audit activity is performing an assessment of an organization ' s ethics program, and the engagement scope specifies a focus on the training program ' s design. According to IIA guidance, which of the following questions would be the most relevant?
1. Does the training include situations that require an ethical decision?
2. What percentage of employees have taken the training?
3. What are the results of the employee assessment of the organization ' s ethical climate?
4. Does the instructor provide feedback on the thought process to reach an ethical resolution?
Which of the following internal control components has COSO identified as the most important?
The internal audit activity is asked to provide consulting services regarding the risks related to implementing a proposed new Inventory management system. Which of the following would be a key consideration of the internal audit activity in accepting this engagement?
An internal auditor is preparing for an overseas engagement. As part of the engagement, the auditor will conduct interviews with managers from various regional offices around the world.
Which of the following is the most important for the auditor to consider in establishing good relationships with regional managers?
Which of the following would the chief audit executive be required to disclose in the communication of quality assessment results to senior management and the board?
Which of the following best illustrates the principle of due professional care?
An internal auditor is assessing the effectiveness of the organization ' s risk management practices. She checks to see whether risk management is an integral part of decision making and whether risk management is transparent, responsive to change, and addresses uncertainty. According to IIA guidance on risk management frameworks, which of the following approaches is the auditor most likely using?
An internal auditor assigned to a supplier management process engagement reviews the risk assessment with the process owner The auditor inquires about the risk response for potentially engaging unqualified third-party service providers The process owner responds that due diligence checks are undertaken to make sure that third parties possess requisite competencies before they are engaged Which of the following risk management techniques is the process owner using?
Which of the following would best assist the internal audit activity in assessing whether an organization ' s responses to risk are aligned with its risk appetite?
An organization grants its internal auditors authority to access sensitive confidential information so the auditors may analyze data and conduct effective assurance engagements.
This effectively demonstrates support for which of the following fundamental principles of internal auditing?
An internal audit activity maintains a quality assurance and improvement program that includes annual self-assessments. The internal audit activity includes in each engagement report a clause that the engagement is conducted in conformance with the International! Standards for the Professional Practice of Internal Auditing (Standards). Which of the following justifies inclusion of this clause in the reports?
Which of the following scenarios demonstrates nonconformance with the Standards?
Which of the following represents an example of an ethical issue that the organization should address ' ?
For a high-risk observation, which is the best approach to follow when management takes an aggressive, uncompromising position in opposition to the internal audit activity?
As a result of a high-profile processing error, respective business unit managers are implementing new controls. The internal audit team was asked for their advice regarding the controls. The objective of this consulting engagement would be determined by which of the following?
Which of the following best describes the differences between internal auditors and external auditors?
An organization has limited resources to spend on corporate social responsibility initiatives. Which is the most suitable approach to determine how these resources should be used?
What is the main difference between a consulting engagement versus an assurance engagement?
When beginning an engagement to assess the effectiveness of the organization ' s newly revamped risk management processes, which of the following should internal auditors review first?
Which of the following are considered root causes of fraud?
According to MA guidance, which of the following best describes how often the chief audit executive should review the quality assurance and improvement program of the internal audit activity?
An internal auditor of a small manufacturing organization helps with a fraud investigation of accounts payable. The auditor notes that the accounts payable manager is very friendly and trusting with accounts payable staff, so the manager rarely checks the staff’s work.
Which component of the fraud triangle is most relevant in this scenario?
Which of the following statements is true regarding the use of risk frameworks?
An external assessment of an organization ' s internal audit activity was last completed four years ago Which of the following options would be acceptable this year if the internal audit activity is to fulfill the requirements of the Standards?
Anew internal auditor suspects fraud is taking place. Which action should the new auditor take?
Which of the following scenarios would most significantly restrict the areas where internal audit could perform assurance services?
Which of the following statements is true regarding an organization ' s code of ethics?