โ† All Certified Internal Auditor Flashcard Decks

Case Studies & Practical Application Flashcards

7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Case Studies & Practical Application flashcards as text
  1. An internal audit team is conducting a follow-up on prior audit recommendations. They find that management implemented a compensating control instead of the originally recommended primary control. What should the auditor conclude?

    Answer: Assess whether the compensating control adequately mitigates the identified risk

    The auditor's goal is risk mitigation; a compensating control can close a recommendation if it adequately addresses the underlying risk.

  2. During a contract management audit, an auditor finds that a vendor's performance metrics consistently fall below SLA thresholds but no penalties have been assessed. The contract owner says the vendor 'always makes it up.' What risk does this represent?

    Answer: Financial loss, contractual rights waiver, and potential favoritism or conflict of interest

    Failure to enforce SLA penalties risks financial loss, may legally waive contractual rights, and can indicate undisclosed conflicts of interest.

  3. An auditor reviewing capital project management finds that a $5M construction project has no change order log, and the final cost was $7.2M. What is the primary audit finding?

    Answer: Lack of change order controls, preventing proper authorization and tracking of scope/cost changes

    The absence of a change order log is a control deficiency that prevented proper oversight of the $2.2M cost increase.

  4. An auditor is assessing a company's business continuity plan (BCP). They find that the plan was last tested 18 months ago and key personnel listed have since left the company. What is the most critical risk?

    Answer: Critical recovery roles may be unfilled during an actual disruption, rendering the plan ineffective

    An untested, outdated BCP with departed key personnel creates a high risk that recovery procedures will fail when actually needed.

  5. An auditor reviewing a bank's loan approval process finds that the same officer who approves loans also performs the annual credit reviews. What control deficiency does this represent?

    Answer: Lack of segregation of duties, creating a self-review threat

    Allowing the originating officer to also conduct credit reviews eliminates an independent check on the quality of lending decisions.

  6. During an environmental compliance audit, an auditor discovers that hazardous waste disposal records for one facility are missing for a six-month period. Management believes the records were lost in a system migration. What should the auditor recommend?

    Answer: Assess regulatory notification obligations and implement controls to prevent future record loss during migrations

    Missing compliance records may trigger mandatory regulatory notification obligations, and the auditor should address both the current exposure and prevent recurrence.

  7. An auditor finds that a company's travel and entertainment policy allows business class travel for flights over four hours but that 60% of business class tickets sampled were for shorter flights. What type of test would most efficiently identify the scope of this issue?

    Answer: Data analytics on the full travel expense population to flag all flights under four hours booked as business class

    Data analytics applied to the full population allows the auditor to quantify the complete scope of the policy violation efficiently.