CAA Internal Controls & Risk Management 2 — Questions and Answers
Question 1: What is inherent risk in the context of audit and internal control?
- The risk that a material misstatement will not be detected by the auditor
- The risk of a material misstatement before considering any related controls (Correct answer)
- The risk that arises from weak internal controls
- The risk of management override of controls
Correct answer: The risk of a material misstatement before considering any related controls
Inherent risk is the susceptibility of an assertion to a material misstatement assuming no related internal controls exist.
Question 2: What is control risk as defined in auditing standards?
- The risk that the auditor will issue an incorrect opinion
- The risk that a material misstatement will not be prevented or detected by internal controls (Correct answer)
- The risk inherent to the nature of the business
- The risk of unauthorized access to computer systems
Correct answer: The risk that a material misstatement will not be prevented or detected by internal controls
Control risk is the risk that a material misstatement will occur and not be prevented or detected on a timely basis by the entity's internal controls.
Question 3: Under Sarbanes-Oxley Act Section 404, what are public company management teams required to do?
- File quarterly tax returns with the SEC
- Assess and report on the effectiveness of internal controls over financial reporting (Correct answer)
- Conduct annual employee background checks
- Submit internal audit plans to the board of directors
Correct answer: Assess and report on the effectiveness of internal controls over financial reporting
SOX Section 404 requires management to assess and report on the effectiveness of internal controls over financial reporting, and external auditors must attest to that assessment.
Question 4: How is a 'material weakness' in internal controls defined under PCAOB standards?
- A minor deficiency that does not affect financial statements
- A significant deficiency that has been remediated
- A deficiency where there is a reasonable possibility that a material misstatement will not be prevented or detected (Correct answer)
- Any control that fails more than once during the year
Correct answer: A deficiency where there is a reasonable possibility that a material misstatement will not be prevented or detected
A material weakness is a deficiency, or combination of deficiencies, in internal control such that there is a reasonable possibility that a material misstatement will not be prevented or detected and corrected on a timely basis.
Question 5: Which of the following best describes a detective control?
- A policy that prevents unauthorized transactions from being initiated
- A control that identifies errors or fraud after they have occurred (Correct answer)
- A procedure that corrects errors once detected
- A training program that educates employees on compliance
Correct answer: A control that identifies errors or fraud after they have occurred
Detective controls are designed to identify and expose undesirable events that have already occurred, such as reconciliations, audits, and exception reports.
Question 6: What is Enterprise Risk Management (ERM)?
- A framework for pricing insurance products
- A comprehensive approach to identifying, assessing, and managing risks across an entire organization (Correct answer)
- A method for calculating a company's tax exposure
- A process limited to managing financial statement fraud risk
Correct answer: A comprehensive approach to identifying, assessing, and managing risks across an entire organization
ERM is a holistic, organization-wide process for identifying, assessing, managing, and monitoring risks that could affect the achievement of the organization's objectives.
Question 7: Which of the following is the key distinction between internal auditors and external auditors?
- Internal auditors only review tax compliance; external auditors review all financial matters
- Internal auditors are employees of the organization; external auditors are independent third parties (Correct answer)
- External auditors report to the CFO; internal auditors report to shareholders
- Internal auditors issue publicly available opinions; external auditors do not
Correct answer: Internal auditors are employees of the organization; external auditors are independent third parties
Internal auditors are employed by the organization and focus on operational efficiency and risk management, while external auditors are independent third parties who attest to the fairness of financial statements.
What is inherent risk in the context of audit and internal control?