Risk Assessment & Internal Controls Flashcards
7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Internal Controls flashcards as text
Segregation of duties is LEAST effective when which condition exists?
Answer: Multiple employees share access to the same system
Shared system access alone does not eliminate segregation of duties; the critical failure is when one person controls conflicting functions such as authorization and recording.
A financial institution uses stress testing to model the impact of a sudden 300 basis point interest rate spike. This activity primarily supports which risk management objective?
Answer: Scenario-based risk quantification
Stress testing applies hypothetical adverse scenarios to quantify potential losses, which is a form of scenario-based risk quantification.
Which internal control principle requires that audit trails and transaction records be preserved and accessible for review?
Answer: Documentation and record retention
Documentation and record retention ensures that all transactions are recorded and evidence is available for subsequent review or audit.
A compliance team rates a vendor relationship as high-risk due to geographic location in a high-corruption jurisdiction. This rating is an output of which process?
Answer: Third-party due diligence screening
Third-party due diligence screening evaluates external parties based on factors including jurisdiction, ownership, and corruption indices to assign risk ratings.
Which statement BEST describes a Key Risk Indicator (KRI)?
Answer: A forward-looking metric that signals increasing risk exposure before a loss occurs
KRIs are leading indicators designed to provide early warning of rising risk levels, allowing management to act before incidents occur.
An organization discovers that a preventive control failed to stop a policy violation but an exception report flagged the transaction. Which control type caught the issue?
Answer: Detective control
Detective controls, such as exception reports and reconciliations, identify issues that have already occurred after the preventive layer has failed.
Control risk in the context of an internal audit engagement refers to:
Answer: The risk that internal controls will fail to prevent or detect a material error
Control risk is the risk that an entity's internal controls will not prevent or detect a material misstatement on a timely basis.