Certified Internal Auditor Flashcards
7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certified Internal Auditor flashcards as text
An internal auditor discovers during fieldwork that the scope of the engagement must be expanded due to newly identified risks. The auditor should:
Answer: Discuss the scope expansion with the CAE and communicate changes to management
Scope changes require discussion with the CAE and communication to management to ensure appropriate resources and approvals are obtained.
Which of the following BEST describes a 'key risk indicator' (KRI)?
Answer: A forward-looking metric that provides early warning of increasing risk exposure
KRIs are forward-looking metrics used to signal rising risk levels before they materialize into losses or control failures.
Under the IIA Standards, internal auditors must disclose all material facts known to them that, if not disclosed, would distort the report. This is an element of which attribute?
Answer: Objectivity
Objectivity requires internal auditors to disclose all material facts to prevent reports from being misleading or incomplete.
An auditor testing IT controls discovers that application access logs are not reviewed regularly. This finding BEST relates to which type of IT control weakness?
Answer: Monitoring control
Failure to regularly review access logs is a weakness in monitoring controls, which are designed to detect inappropriate or unauthorized activity.
Which engagement planning step requires the auditor to obtain background information about the processes and risks of the area under review?
Answer: Preliminary survey
A preliminary survey gathers background information about the auditable unit to help the auditor understand risks and focus the engagement.
An audit report is MOST effective when findings are communicated using which structure?
Answer: Condition, criteria, cause, effect, and recommendation
The condition-criteria-cause-effect-recommendation structure provides a complete, logical presentation of audit findings.
When assessing enterprise risk management (ERM), internal auditors should PRIMARILY evaluate:
Answer: Whether the ERM process aligns with the organization's risk appetite and objectives
The key ERM assessment is whether the process is designed and operating to manage risks within the organization's stated risk appetite and support its objectives.