Governance & Organizational Structure Flashcards
7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Governance & Organizational Structure flashcards as text
According to the IIA's definition, which of the following best describes organizational governance?
Answer: The combination of processes and structures implemented by the board to inform, direct, manage, and monitor activities
The IIA defines governance as the combination of processes and structures implemented by the board to inform, direct, manage, and monitor activities toward achieving organizational objectives.
Which internal control framework is most widely used for compliance evaluations under the Sarbanes-Oxley Act in the United States?
Answer: COSO Internal Control – Integrated Framework
The COSO Internal Control – Integrated Framework is the most widely adopted standard for internal control evaluation in the U.S. and is explicitly referenced in SEC/SOX guidance.
The concept of 'tone at the top' in corporate governance primarily refers to:
Answer: The ethical climate and values visibly modeled and enforced by senior leadership and the board
'Tone at the top' refers to the ethical culture and values established and visibly demonstrated by senior leadership and the board, which permeates throughout the organization.
Under IIA Standards, which of the following best describes internal audit's role in governance?
Answer: Evaluating and contributing to the improvement of governance, risk management, and control processes
IIA Standards require internal audit to evaluate and contribute to the improvement of governance, risk management, and control processes using a systematic, disciplined approach.
Which of the following is a primary responsibility of the audit committee within corporate governance?
Answer: Oversight of financial reporting integrity, internal controls, and external auditors
The audit committee's primary responsibility is overseeing financial reporting processes, the adequacy of internal controls, and the relationship with and work of external auditors.
The internal control principle of 'separation of duties' is designed primarily to:
Answer: Reduce the risk of fraud and undetected error by ensuring no single person controls all aspects of a critical transaction
Separation of duties is a preventive control designed to reduce fraud and error risk by ensuring that authorization, recording, and custody functions over critical transactions are assigned to different individuals.
In the COSO Enterprise Risk Management framework, governance is best described as:
Answer: The structures, authorities, and responsibilities that enable an organization to establish ERM practices
In COSO ERM, governance encompasses the structures, authorities, and responsibilities that enable an organization to manage its enterprise risks effectively and align ERM with strategy.