CCO Internal Controls and Audit 1 — Questions and Answers
Question 1: What is the COSO Internal Control Framework?
- A financial reporting standard issued by the SEC
- A widely used framework defining internal control components: control environment, risk assessment, control activities, information/communication, and monitoring (Correct answer)
- A mandatory auditing standard for public companies
- A risk management framework specific to banking
Correct answer: A widely used framework defining internal control components: control environment, risk assessment, control activities, information/communication, and monitoring
The COSO framework provides the structure used by most organizations to design and evaluate internal controls across five integrated components.
Question 2: What is a 'key control' in an internal control system?
- A password or access credential
- A control that, if absent or ineffective, would result in a material misstatement or significant compliance violation going undetected (Correct answer)
- The most expensive control in a control framework
- Any control approved by the CFO
Correct answer: A control that, if absent or ineffective, would result in a material misstatement or significant compliance violation going undetected
Key controls are the most critical controls that directly prevent or detect the most significant risks — their failure has material consequences.
Question 3: What is segregation of duties and why is it important?
- Dividing the compliance function across multiple departments
- Requiring that no single employee controls all critical steps in a financial or operational process, reducing the risk of fraud or error (Correct answer)
- Separating legal and compliance functions
- Organizing employees into specialized teams
Correct answer: Requiring that no single employee controls all critical steps in a financial or operational process, reducing the risk of fraud or error
Segregation of duties prevents a single individual from both executing and recording transactions, reducing the risk of undetected fraud or error.
Question 4: What is a control deficiency and how does it differ from a material weakness?
- They are identical terms used interchangeably
- A control deficiency is any shortfall; a material weakness is one that creates a reasonable possibility of a material misstatement going undetected (Correct answer)
- A control deficiency is discovered by external auditors; a material weakness is found internally
- Material weaknesses apply only to cybersecurity controls
Correct answer: A control deficiency is any shortfall; a material weakness is one that creates a reasonable possibility of a material misstatement going undetected
Control deficiencies exist on a spectrum — a material weakness is the most severe, representing a significant risk that financial statements could be materially misstated.
Question 5: What is the purpose of a walkthrough in an internal audit?
- A physical inspection of company facilities
- A procedure where the auditor follows a transaction from initiation to completion to verify that controls exist and operate as described (Correct answer)
- An introductory tour for new compliance staff
- A regulatory examination process
Correct answer: A procedure where the auditor follows a transaction from initiation to completion to verify that controls exist and operate as described
Walkthroughs trace individual transactions through the entire process to confirm that documented controls are actually in place and functioning in practice.
Question 6: What is the three-way match in procurement controls?
- Matching three regulatory requirements to a single policy
- Comparing the purchase order, receiving report, and vendor invoice to verify all three agree before payment is approved (Correct answer)
- A three-signature approval requirement
- Matching three bids for every purchase
Correct answer: Comparing the purchase order, receiving report, and vendor invoice to verify all three agree before payment is approved
Three-way matching is a preventive control that ensures payment is only made when the ordered, received, and invoiced quantities and amounts all agree.
What is the COSO Internal Control Framework?