Certified Internal Auditor Certified Internal Auditor 2 — Questions and Answers
Question 1: Which of the following best describes the concept of 'reasonable assurance' in internal auditing?
- Absolute certainty that all risks have been eliminated
- A high level of confidence that objectives are being met, though not a guarantee (Correct answer)
- Assurance provided only on financial controls
- Confirmation that no fraud exists within the organization
Correct answer: A high level of confidence that objectives are being met, though not a guarantee
Reasonable assurance is a high but not absolute level of confidence that controls are functioning and objectives are being achieved.
Question 2: An internal audit activity uses a risk-based audit plan. Which element is MOST critical when determining the audit universe?
- Number of available audit staff
- The organization's risk appetite and strategic objectives (Correct answer)
- Prior audit findings only
- External auditor recommendations
Correct answer: The organization's risk appetite and strategic objectives
A risk-based audit plan aligns the audit universe with the organization's risk appetite and strategic objectives to prioritize high-risk areas.
Question 3: When an internal auditor identifies a control deficiency that management chooses to accept rather than remediate, the auditor should:
- Remove the finding from the audit report
- Escalate the issue directly to external regulators
- Document management's risk acceptance decision in the audit report (Correct answer)
- Resign from the engagement
Correct answer: Document management's risk acceptance decision in the audit report
When management accepts risk without remediation, the auditor must document this decision in the final audit communication.
Question 4: The IIA's International Professional Practices Framework (IPPF) is BEST described as:
- A mandatory set of laws governing internal audit globally
- A conceptual framework including mandatory guidance and recommended guidance (Correct answer)
- A framework applicable only to publicly traded companies
- A collection of best practices from external auditing standards
Correct answer: A conceptual framework including mandatory guidance and recommended guidance
The IPPF consists of mandatory guidance (Core Principles, Standards, Code of Ethics) and recommended guidance (Implementation Guidance, Supplemental Guidance).
Question 5: An auditor is reviewing a company's segregation of duties in accounts payable. Which finding represents the GREATEST control risk?
- One person approves vendor invoices and reconciles the accounts payable ledger (Correct answer)
- The CFO reviews all payments over $50,000
- Vendor master file changes require dual approval
- Payments are processed through an automated ERP system
Correct answer: One person approves vendor invoices and reconciles the accounts payable ledger
Combining invoice approval and ledger reconciliation in one person eliminates a key detective control and creates significant fraud risk.
Question 6: Which type of audit engagement focuses on whether an organization's activities comply with applicable laws, regulations, and policies?
- Operational audit
- Financial audit
- Compliance audit (Correct answer)
- IT audit
Correct answer: Compliance audit
A compliance audit evaluates the extent to which the organization adheres to laws, regulations, and internal policies.
Question 7: According to IIA Standards, the chief audit executive (CAE) must communicate the internal audit activity's independence to whom?
- Only to senior management
- Only to the external auditors
- To senior management and the board (Correct answer)
- To regulators and shareholders only
Correct answer: To senior management and the board
The CAE must confirm to senior management and the board at least annually that the internal audit activity is independent.
Which of the following best describes the concept of 'reasonable assurance' in internal auditing?