← All GRC Flashcard Decks

Internal Controls and Auditing Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Internal Controls and Auditing flashcards as text
  1. Under the Sarbanes-Oxley Act Section 404, who is responsible for assessing the effectiveness of internal controls over financial reporting?

    Answer: Management and the external auditor

    SOX 404 requires management to assess ICFR effectiveness, and the external auditor to attest to that assessment.

  2. A company's accounts payable clerk also approves invoices for payment. This represents a failure in:

    Answer: Segregation of duties

    When one individual both authorizes and processes payments, a key segregation of duties requirement is violated.

  3. What is a 'compensating control'?

    Answer: An alternative control that mitigates risk when the primary control is not feasible

    Compensating controls provide alternative risk mitigation when standard controls cannot be implemented due to cost or operational constraints.

  4. Which type of audit evidence is generally considered the MOST reliable?

    Answer: Externally obtained documentary evidence

    Evidence obtained from independent third parties outside the entity is considered more reliable than internally produced records.

  5. An auditor discovers that a key control has not been operating for six months. How should this be classified?

    Answer: Significant deficiency or material weakness depending on severity

    The severity determines whether a control failure is a control deficiency, significant deficiency, or material weakness under PCAOB/COSO standards.

  6. What is the role of the 'three lines of defense' model in governance and internal control?

    Answer: Clarify responsibilities for risk management across operations, risk/compliance, and internal audit

    The three lines model assigns risk ownership to operational management (1st), oversight functions (2nd), and independent assurance (3rd).

  7. Which audit procedure involves tracing a transaction from initiation through completion to understand the entire process flow?

    Answer: Walkthrough

    A walkthrough traces a single transaction end-to-end to verify the auditor's understanding of the process and identify control points.