GRC Internal Controls and Auditing 3 — Questions and Answers
Question 1: Under the Sarbanes-Oxley Act Section 404, who is responsible for assessing the effectiveness of internal controls over financial reporting?
- External auditor only
- Internal auditor only
- Management and the external auditor (Correct answer)
- The audit committee only
Correct answer: Management and the external auditor
SOX 404 requires management to assess ICFR effectiveness, and the external auditor to attest to that assessment.
Question 2: A company's accounts payable clerk also approves invoices for payment. This represents a failure in:
- Physical access controls
- Segregation of duties (Correct answer)
- Change management controls
- IT general controls
Correct answer: Segregation of duties
When one individual both authorizes and processes payments, a key segregation of duties requirement is violated.
Question 3: What is a 'compensating control'?
- A control that replaces financial losses
- An alternative control that mitigates risk when the primary control is not feasible (Correct answer)
- A control that detects fraud after the fact
- A backup procedure for IT systems
Correct answer: An alternative control that mitigates risk when the primary control is not feasible
Compensating controls provide alternative risk mitigation when standard controls cannot be implemented due to cost or operational constraints.
Question 4: Which type of audit evidence is generally considered the MOST reliable?
- Verbal confirmation from management
- Internally generated documents
- Externally obtained documentary evidence (Correct answer)
- Inquiry from process owners
Correct answer: Externally obtained documentary evidence
Evidence obtained from independent third parties outside the entity is considered more reliable than internally produced records.
Question 5: An auditor discovers that a key control has not been operating for six months. How should this be classified?
- Control deficiency
- Significant deficiency or material weakness depending on severity (Correct answer)
- Immaterial finding
- Audit observation
Correct answer: Significant deficiency or material weakness depending on severity
The severity determines whether a control failure is a control deficiency, significant deficiency, or material weakness under PCAOB/COSO standards.
Question 6: What is the role of the 'three lines of defense' model in governance and internal control?
- Define cybersecurity perimeter zones
- Clarify responsibilities for risk management across operations, risk/compliance, and internal audit (Correct answer)
- Segregate IT duties across infrastructure teams
- Establish escalation paths for compliance violations
Correct answer: Clarify responsibilities for risk management across operations, risk/compliance, and internal audit
The three lines model assigns risk ownership to operational management (1st), oversight functions (2nd), and independent assurance (3rd).
Question 7: Which audit procedure involves tracing a transaction from initiation through completion to understand the entire process flow?
- Confirmation
- Observation
- Walkthrough (Correct answer)
- Recalculation
Correct answer: Walkthrough
A walkthrough traces a single transaction end-to-end to verify the auditor's understanding of the process and identify control points.
Under the Sarbanes-Oxley Act Section 404, who is responsible for assessing the effectiveness of internal controls over financial reporting?