CFE Fraud Risk Assessment 4 — Questions and Answers
Question 1: Which professional standard requires auditors to assess the risk of material misstatement due to fraud when planning an engagement?
- SAS No. 70
- AU-C Section 240
- PCAOB AS 1001
- SAS No. 99 / AU-C 240 (Correct answer)
Correct answer: SAS No. 99 / AU-C 240
SAS No. 99 (codified as AU-C Section 240) requires auditors to specifically consider fraud risk factors and adjust audit procedures accordingly when planning an engagement.
Question 2: What term describes the degree to which management and employees are committed to creating a culture of ethical behavior and fraud awareness?
- Control environment
- Tone at the top (Correct answer)
- Risk appetite
- Governance framework
Correct answer: Tone at the top
Tone at the top refers to the ethical climate set by senior leadership, which is a primary determinant of the organization's overall anti-fraud culture.
Question 3: Which of the following is the MOST common reason employees fail to report suspected fraud?
- Lack of awareness that fraud is occurring
- Fear of retaliation from management or colleagues (Correct answer)
- Uncertainty about how to contact law enforcement
- Belief that fraud only harms shareholders
Correct answer: Fear of retaliation from management or colleagues
Research consistently shows that fear of retaliation is the leading barrier to fraud reporting, underscoring the need for robust whistleblower protections.
Question 4: When assessing fraud risk at the account level, which of the following factors should receive the MOST weight?
- The size of the department that manages the account
- The susceptibility of the account to manipulation and the materiality of the balance (Correct answer)
- Whether the account was reviewed last quarter
- The education level of the employees who process the account
Correct answer: The susceptibility of the account to manipulation and the materiality of the balance
Accounts that are highly susceptible to manipulation (e.g., estimates, reserves) and material in size warrant the greatest fraud risk attention.
Question 5: Which component of the COSO Internal Control framework is most directly concerned with fraud risk assessment?
- Control Activities
- Information and Communication
- Risk Assessment (Correct answer)
- Monitoring Activities
Correct answer: Risk Assessment
The Risk Assessment component of COSO specifically includes identifying and analyzing risks, including fraud risks, that may prevent the organization from achieving its objectives.
Question 6: Which factor most significantly increases the fraud risk associated with journal entries?
- Entries made early in the month
- Top-side entries made by senior management near period-end (Correct answer)
- Entries that are rounded to the nearest dollar
- Recurring entries posted automatically by the system
Correct answer: Top-side entries made by senior management near period-end
Top-side journal entries made by management near period-end are a primary vehicle for financial statement fraud and represent a significant fraud risk indicator.
Question 7: Which of the following best describes a 'fraud risk appetite' statement?
- A list of all detected fraud incidents in the past year
- A formal declaration of the level of fraud risk an organization is willing to accept (Correct answer)
- An internal audit plan for testing fraud controls
- A policy requiring mandatory reporting of all suspicious activity
Correct answer: A formal declaration of the level of fraud risk an organization is willing to accept
A fraud risk appetite statement formally documents how much fraud risk the board and management are willing to tolerate, guiding control investment decisions.
Which professional standard requires auditors to assess the risk of material misstatement due to fraud when planning an engagement?