Certified Internal Auditor Risk Assessment & Management — Questions and Answers
Question 1: What is the COSO Internal Control Framework?
- A framework defining five components of internal control: control environment, risk assessment, control activities, information/communication, and monitoring (Correct answer)
- A computer operating system for audit software
- A cost accounting methodology
- A customer service optimization system
Correct answer: A framework defining five components of internal control: control environment, risk assessment, control activities, information/communication, and monitoring
The COSO framework provides a comprehensive model for internal controls with five interrelated components that help organizations achieve objectives related to operations, reporting, and compliance.
Question 2: What is inherent risk versus residual risk?
- Inherent risk exists before controls; residual risk remains after controls are applied (Correct answer)
- They are the same measurement at different time points
- Residual risk is always higher than inherent risk
- Inherent risk only applies to financial audits
Correct answer: Inherent risk exists before controls; residual risk remains after controls are applied
Inherent risk is the level of risk present before any controls are implemented, while residual risk is the risk remaining after management applies controls and mitigation measures.
Question 3: What is a risk-based audit plan?
- An audit plan prioritized by the organization's most significant risks rather than auditing everything equally (Correct answer)
- A plan to audit only financial risks
- An audit plan created randomly without consideration of risk
- A plan that eliminates all organizational risks
Correct answer: An audit plan prioritized by the organization's most significant risks rather than auditing everything equally
A risk-based audit plan allocates audit resources to areas of highest risk, ensuring the most significant threats to organizational objectives receive audit attention first.
Question 4: What is the three lines of defense model in risk management?
- First line: operational management; Second line: risk/compliance functions; Third line: internal audit (Correct answer)
- Three layers of physical security in a building
- Three levels of insurance coverage
- Three rounds of financial statement review
Correct answer: First line: operational management; Second line: risk/compliance functions; Third line: internal audit
The three lines model assigns risk management roles: operational management owns and manages risk (1st), risk and compliance functions provide oversight (2nd), and internal audit provides independent assurance (3rd).
Question 5: How should internal auditors assess fraud risk?
- By evaluating the fraud triangle elements: opportunity, pressure/incentive, and rationalization (Correct answer)
- By only checking for missing cash
- By interviewing only senior management
- Fraud risk assessment is not an internal audit responsibility
Correct answer: By evaluating the fraud triangle elements: opportunity, pressure/incentive, and rationalization
Internal auditors assess fraud risk by evaluating the three elements of the fraud triangle — opportunity (weak controls), pressure (financial or personal), and rationalization (justification) — during all engagements.
Question 6: What is a risk appetite statement?
- A board-level declaration of the amount of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- A menu for the audit department's lunch meetings
- A list of risks the organization wants to take on
- A financial report showing risk-related expenses
Correct answer: A board-level declaration of the amount of risk an organization is willing to accept in pursuit of its objectives
A risk appetite statement, set by the board, defines the types and levels of risk the organization is willing to accept, providing guidance for management decision-making.
What is the COSO Internal Control Framework?