Certified Internal Auditor Certified Internal Auditor MCQ 2 — Questions and Answers
Question 1: According to the IIA Standards, which of the following best describes the purpose of the internal audit activity's quality assurance and improvement program (QAIP)?
- To ensure compliance with regulatory requirements imposed by external bodies
- To enable an evaluation of the internal audit activity's conformance with the Standards and assess whether auditors apply ethical principles (Correct answer)
- To measure the efficiency of audit report distribution to the board
- To replace the need for external quality assessments every five years
Correct answer: To enable an evaluation of the internal audit activity's conformance with the Standards and assess whether auditors apply ethical principles
The QAIP is designed to evaluate conformance with the Standards and the Code of Ethics and to assess whether internal auditors apply ethical principles.
Question 2: A chief audit executive (CAE) discovers that management has restricted the scope of an audit in a way that limits the internal audit activity's ability to fulfill its responsibilities. What is the CAE's most appropriate course of action?
- Accept the restriction and complete the audit with available information
- Cancel the audit and move on to the next scheduled engagement
- Communicate the impact of the scope limitation to senior management and the board (Correct answer)
- Report the restriction directly to the external auditors
Correct answer: Communicate the impact of the scope limitation to senior management and the board
The CAE must communicate scope limitations and their impact to senior management and the board to preserve organizational oversight.
Question 3: Which control framework is most commonly referenced in the IIA Standards for evaluating the effectiveness of an organization's internal control system?
- ISO 31000
- COSO Internal Control – Integrated Framework (Correct answer)
- COBIT 2019
- NIST Cybersecurity Framework
Correct answer: COSO Internal Control – Integrated Framework
The COSO Internal Control – Integrated Framework is the primary framework referenced for assessing the effectiveness of internal controls.
Question 4: During a risk assessment, an internal auditor determines that a control exists but has not been tested. How should this control be classified in the risk assessment?
- As an effective control that reduces inherent risk
- As a compensating control with full credit
- As an unverified control that should not reduce the assessed risk until tested (Correct answer)
- As an ineffective control requiring immediate remediation
Correct answer: As an unverified control that should not reduce the assessed risk until tested
Untested controls cannot be credited for risk reduction because their operating effectiveness has not been confirmed.
Question 5: An internal auditor is evaluating a company's accounts payable process and finds that the same employee approves purchase orders, receives goods, and processes vendor invoices. What type of control weakness does this represent?
- Inadequate detective control
- Failure of segregation of duties (Correct answer)
- Deficiency in IT general controls
- Lack of corrective controls
Correct answer: Failure of segregation of duties
Having one employee perform all three functions (authorization, custody, and recording) violates the segregation of duties principle.
Question 6: Which of the following sampling methods gives every item in the population an equal and known chance of being selected?
- Judgmental sampling
- Stratified sampling
- Simple random sampling (Correct answer)
- Cluster sampling
Correct answer: Simple random sampling
Simple random sampling ensures each population item has an equal and known probability of selection, making it statistically valid.
Question 7: According to IIA guidance, when should internal auditors use a control self-assessment (CSA) approach?
- Only when external auditors request it as a supplementary procedure
- To shift primary responsibility for controls from management to the audit team
- To facilitate and supplement risk and control assessments by involving process owners (Correct answer)
- As a replacement for all traditional audit fieldwork
Correct answer: To facilitate and supplement risk and control assessments by involving process owners
CSA is used to supplement traditional auditing by engaging process owners in evaluating risks and controls within their own operations.
According to the IIA Standards, which of the following best describes the purpose of the internal audit activity's quality assurance and improvement program (QAIP)?