Certified Internal Auditor Governance & Organizational Structure 1 — Questions and Answers
Question 1: According to the IIA's definition, which of the following best describes organizational governance?
- The process of identifying and mitigating enterprise risks
- The combination of processes and structures implemented by the board to inform, direct, manage, and monitor activities (Correct answer)
- The audit committee's exclusive oversight of financial reporting
- Management's internal process for setting annual strategic objectives
Correct answer: The combination of processes and structures implemented by the board to inform, direct, manage, and monitor activities
The IIA defines governance as the combination of processes and structures implemented by the board to inform, direct, manage, and monitor activities toward achieving organizational objectives.
Question 2: Which internal control framework is most widely used for compliance evaluations under the Sarbanes-Oxley Act in the United States?
- COBIT 2019
- ISO 31000
- COSO Internal Control – Integrated Framework (Correct answer)
- Basel III Capital Framework
Correct answer: COSO Internal Control – Integrated Framework
The COSO Internal Control – Integrated Framework is the most widely adopted standard for internal control evaluation in the U.S. and is explicitly referenced in SEC/SOX guidance.
Question 3: The concept of 'tone at the top' in corporate governance primarily refers to:
- The volume and frequency of compliance communications issued by internal audit
- The ethical climate and values visibly modeled and enforced by senior leadership and the board (Correct answer)
- The number of board and committee meetings held each fiscal year
- The seniority threshold required before employees receive ethics training
Correct answer: The ethical climate and values visibly modeled and enforced by senior leadership and the board
'Tone at the top' refers to the ethical culture and values established and visibly demonstrated by senior leadership and the board, which permeates throughout the organization.
Question 4: Under IIA Standards, which of the following best describes internal audit's role in governance?
- Approving the organization's strategic plan before board adoption
- Evaluating and contributing to the improvement of governance, risk management, and control processes (Correct answer)
- Setting executive compensation benchmarks for the compensation committee
- Selecting and nominating candidates for board membership
Correct answer: Evaluating and contributing to the improvement of governance, risk management, and control processes
IIA Standards require internal audit to evaluate and contribute to the improvement of governance, risk management, and control processes using a systematic, disciplined approach.
Question 5: Which of the following is a primary responsibility of the audit committee within corporate governance?
- Day-to-day operational management of finance department activities
- Oversight of financial reporting integrity, internal controls, and external auditors (Correct answer)
- Setting product pricing strategies and revenue targets
- Directly managing the internal audit department's budget and staffing
Correct answer: Oversight of financial reporting integrity, internal controls, and external auditors
The audit committee's primary responsibility is overseeing financial reporting processes, the adequacy of internal controls, and the relationship with and work of external auditors.
Question 6: The internal control principle of 'separation of duties' is designed primarily to:
- Increase efficiency by assigning tasks to functional specialists
- Reduce the risk of fraud and undetected error by ensuring no single person controls all aspects of a critical transaction (Correct answer)
- Allow senior management to delegate all operational responsibilities to staff
- Simplify the external audit process by clearly defining ownership of tasks
Correct answer: Reduce the risk of fraud and undetected error by ensuring no single person controls all aspects of a critical transaction
Separation of duties is a preventive control designed to reduce fraud and error risk by ensuring that authorization, recording, and custody functions over critical transactions are assigned to different individuals.
Question 7: In the COSO Enterprise Risk Management framework, governance is best described as:
- A financial reporting process managed by the controller's office
- The structures, authorities, and responsibilities that enable an organization to establish ERM practices (Correct answer)
- The risk appetite statement issued annually by senior management
- The internal audit charter that defines audit scope and authority
Correct answer: The structures, authorities, and responsibilities that enable an organization to establish ERM practices
In COSO ERM, governance encompasses the structures, authorities, and responsibilities that enable an organization to manage its enterprise risks effectively and align ERM with strategy.
According to the IIA's definition, which of the following best describes organizational governance?