In the COSO internal control framework, which of the following components serves as the foundation for the other components?
Which risk management activity would cause the internal auditor to assume a management responsibility?
Which of the following skills is most important for an internal auditor who facilitates control self-assessment workshops to possess?
During a payroll audit, the internal auditor discovered that several individuals who have the same position classification as he are earning a significantly higher salary. The auditor noted the names and amounts of each, and he planned to prepare a request to the chief audit executive for a salary increase based on this information. Which of the following IIA Code of Ethics principles was violated in this scenario?
An internal auditor is assessing how the organization processes financial transactions and whether written policies and procedures are followed. The auditor requested to meet with certain employees to understand their related roles and responsibilities. However the employees refuse to meet with the auditor claiming they are too busy. Which of the following responses would best demonstrate the auditor ' s conflict-resolution skills?
A fraud investigation was completed by management, and a proven fraud was communicated to relevant authorities. According to IIA guidance, which of the following roles would be most appropriate for the internal audit activity to undertake after the investigation?
According to IIA guidance, which of the following statements is true regarding reporting the results of the quality assurance and improvement program?
Which of the following is an example of risk monitoring to ensure a system is performing as intended?
Which of the following activities would an internal auditor perform as a consulting engagement for an organization?
An IT contractor applied for an internal audit position at a bank. The contractor worked for the bank ' s IT security manager two years ago. If the audit manager interviewed the contractor and wants to extend a job offer, which of the following actions should the chief audit executive pursue?
In which of the following audits would the internal auditors most likely contribute to the assessment of organizational governance?
As part of a fraud investigation by regulators, a court order was issued to a bank. The court order requested the chief audit executive (CAE) to provide access to a number of audit reports and workpapers, some of which included customers ' confidential information such as transaction activity and other personal details. What is the appropriate response by the CAE?
Which of the following statements is true regarding assurance and advisory services provided by an internal audit function?
A sales manager was recently bypassed for a promotion. He feels entitled to a higher salary and is angry that management does not recognize his contributions. To make up for this perceived injustice, he begins to record false expenses on his travel expense reports. This scenario best illustrates which of the following fraud risk factors?
Which of the following best describes the approach the internal audit activity should take to assess and make appropriate recommendations to improve the organization?
In which of the following situations would the organizational independence of an internal audit activity be impaired?
Who is held responsible for oversight of the organization ' s risk management framework?
Which of the following best illustrates the principle of due professional care?
Which of the following should catch the internal auditor ' s attention as a potential red flag for fraud?
Which of the following statements is true regarding the independent peer review process undertaken to fulfill the requirement for an external quality assessment?
An internal auditor discovers that a production manager has been understating stock items produced in the factory and concealing it by accounting for it as abnormal waste.
Which of the following types of fraud does this exemplify?
A significant number of employees expressed concerns of a hostile work environment within a large manufacturing plant, which is in contrast to the organization ' s stated culture of tolerance and open communication. Which of the following approaches would be most effective for an internal auditor to assess whether the organization supports a culture of tolerance and open communication?
An internal auditor is finding it difficult to get management to accept audit findings because of issues that management is having with how the information is presented. Management has expressed disagreement in the past about this auditor’s style in presenting complex findings and the general tone of the report.
Which of the following competencies or skills likely requires improvement on the auditor’s part?
An internal auditor observed that sales staff are able to modify or cancel an order in the system prior to shipping* She wonders whether they can also modify orders after shipping. Which of the following types of controls should she examine?
The internal audit activity is responsible for conducting fraud investigations. A potential fraud instance was identified during an audit engagement. The chief audit executive appoints a lead investigator. Which of the following would most likely be the next step?
An internal audit activity includes in its audit reports the assertion that its work is performed in conformance with the International Standards for the Professional Practice of Internal Auditing ( Standards). A recent external quality assessment concluded that the internal audit activity had substantial deficiencies that impact its overall operations.
According to IIA guidance, which of the following is the most appropriate action for issuing future audit reports?
The internal auditor obtained large volumes of transaction history data for accounts on which he suspected that some fraudulent transactions occurred. Which of the following actions best demonstrates due professional care by the internal auditor?
An audit client who was unsatisfied with the audit report rating called the chief audit executive (CAE) and complained that the internal auditor who performed the audit was biased because his spouse, who worked in the area under review, was on a list of employees to be terminated. Which of the following measures would be most appropriate to prevent this situation from arising?
An organization is considering purchasing a new banking software system and has asked the internal audit activity to evaluate the system. An internal auditor assigned to perform the engagement worked at the software company two years ago and is familiar with the system ' s design strengths and weaknesses. Which of the following is true regarding impairment to the auditor ' s objectivity?
Senior management relies on the professional judgment of an internal auditor and uses outcomes of her audit work to make business decisions Which of the following personal qualities displayed by the internal auditor is most likely the foundation for this relationship?
An internal auditor assigned to a supplier management process engagement reviews the risk assessment with the process owner The auditor inquires about the risk response for potentially engaging unqualified third-party service providers The process owner responds that due diligence checks are undertaken to make sure that third parties possess requisite competencies before they are engaged Which of the following risk management techniques is the process owner using?
An audit engagement required that an internal auditor, using available tools, test a transaction population for a period The auditor decided to test a sample of transactions rather than the full population.
Results of the audit were reported as satisfactory to management. Subsequent to the audit report, fraud was discovered in the area audited and was found to include transactions that were in the relevant transaction population not tested by the auditor. The auditor later disclosed that he decided to test a sample because it was representative of the population and facilitated quicker testing. Which of the following skills below, if improved, would most likely have prevented this situation?
According to the 11A Code of Ethics, which of the following is required with regard to communicating results?
An internal auditor for a construction organization suspects that fraud is occurring, as inventory replacement costs for hand tools and additional materials have been consistently exceeding the budget at two large job sites.
Based on this information, which type of fraud is most likely occurring at these job sites?
Upon completion of an external assessment as part of the quality assurance and improvement program (QAIP), the chief audit executive (CAE) reported the results to senior management and the board The CAE included the following elements in the report
- Qualifications and independence of me external assessment team
- Conclusions of assessors
- Corrective action plans
How should the CAE improve the aforementioned approach to reporting the resets of QAIP?
Which of the following is a greater consideration for internal auditors when they are performing a consulting engagement than when they are performing an assurance engagement ' ?
What is the best course of action when the internal audit activity does not have the knowledge necessary to perform a planned audit of the organization ' s new IT data backup process?
Which of the following indicates that internal audit independence may be compromised?
During a review of the procurement function, an internal auditor identified an existing control for adding new vendors into the vendor contract system. Which of the following would best help the auditor determine the adequacy of the control ' s design?
Which of the following frauds is most likely to occur in the accounts payable function?
An organization’s senior management team is awarding substantial bonuses if employees meet financial targets. Which of the following motivators to potentially commit fraud would become most likely in this scenario?
Which of the following would most likely be classified as a consulting engagement?
Who is responsible for ensuring internal auditors’ continuing professional development?
A newly hired internal auditor is performing an engagement that requires significant IT expertise that he does not possess. If the auditor does not alert the chief audit executive about his lack of expertise and decides to perform the engagement anyhow, which principle of the IIA ' s Code of Ethics would he violate?
Which of the following corporate social responsibility strategies is associated with responding to outside pressure by assuming additional responsibility?
Which of the following situations is most likely to prompt the internal audit activity to disclose its nonconformance with the Standards?
An internal auditor is assessing fraud risks and creating a fraud risk matrix for a particular branch location. Which of the following is most likely to be included in the matrix?
An organization allows the same individual to physically access inventory and purchase new assets when supplies are depleted. Which of the following would best help the organization manage the risk of fraud?
During the closing meeting of a procurement audit, the business manager disagrees with the observation presented by the engagement supervisor and accuses the team of not understanding the procurement objectives The engagement supervisor blames the manager for impeding the audit What skillset should the chief audit executive utilize to manage this situation?
Which of the following risk management techniques best describes the strategy of obtaining insurance to protect against losses due to bad weather conditions?
The results of an assessment of the adequacy of controls would be considered incomplete or misleading unless the internal auditor considers which of the following?
Which of the following can be used to integrate cultural risk factors into testing for an audit engagement?
Which of the following statements is true regarding the use of risk frameworks?
Which documents would help a forensic auditor identify instances of collusion between an employee and vendor to defraud the organization?
Which of the following statements is true regarding organizational independence of the internal audit activity (IAA)?
To meet the resource requirements of this year’s internal audit plan, the chief audit executive (CAE) has recruited additional staff auditors, including an employee who resigned as a senior supervisor from the accounts payable department two months ago. There is a scheduled accounts payable review that the CAE wants to start within the next five months. Which approach should the CAE take, knowing the expertise of his new recruit in the area intended to be audited?
During the planning stage of an assurance engagement, the engagement supervisor initially reviews the control environment to identify and examine possible fraud risks.
Which finding should be considered a potential red flag?
In which of the following scenarios is the internal auditor in conformance with The IIA ' s Code of Ethics and the Standards?
A whistleblower reveals to the chief audit executive (CAE) detailed allegations of potential fraud at the senior management level. Although the CAE has some experience in the area, she chooses to retain an external fraud expert to conduct the investigation. When asked by the director of finance to defend the expenditure, which of the following statements represents the CAE ' s best response?
According to IIA guidance, which of the following activities would typically be examined when using the maturity model approach for assessing an organization ' s risk management program?
According to IIA guidance, which of the following is the primary reason the chief audit executive discusses the internal audit charter with senior management and the board?
As a result of a high-profile processing error, respective business unit managers are implementing new controls. The internal audit team was asked for their advice regarding the controls. The objective of this consulting engagement would be determined by which of the following?
An organization sells products through distributors. The organization ' s chief audit executive insists that the organization ' s code of conduct be applicable to their distributors as well. Which of the following risks would this mitigate?
Which of the following processes does the board manage to ensure adequate governance?
Which of the following is an advantage of using nongovernmental organization (NGO) members on an assurance team when auditing corporate social responsibility?
To encourage internal audit objectivity, which of the following is an appropriate policy the chief audit executive should establish?
An organization’s board of directors has decided that the internal audit activity must have greater access to different pans of the organization in order to perform their assurance work effectively Which of !he following areas is the board seeking to improve by making this change?
Which of the following is the most appropriate way to ensure that a newly formed internal audit activity remains free from undue influence by management?
The internal audit activity was denied access to expenditure and budget reports because they were considered to be confidential. This situation would result in which of the following limitations of the internal audit activity?
An engagement supervisor obtains facilities maintenance reports from a contractor during an audit of third-party services. Which of the following is the source of authority for the engagement supervisor to make such contact outside the organization?
Senior management requested that the internal audit function conduct an advisory engagement to evaluate the design and implementation of the project for setting up a new accounting system.
Which approach should the auditors perform that relates only to an advisory engagement?
Which of the following should be part of the internal audit activity ' s duties?
According to IIA guidance, which of the following is the strongest indicator of deficiencies in the risk management process?
Which of the following procedures will best help an internal auditor assess operating effectiveness of fraud prevention and detection controls?
Which of the following is considered to be a threat to the internal auditor ' s objectivity?
Which of the following is the primary benefit of establishing a formal training program for the internal audit activity?
During a payroll audit, a staff internal auditor suspects that signatures on some of the documents being sampled for examination are not authentic. Which of the following actions should the auditor take before proceeding with the examination?
Which of the followIng would permit an internal audit activity to use the statement " conducted m conformance with the International Standards for the Professional Practice of Internal Auditing m audit reports?
Which of the following is an example of impairment to internal auditor independence or objectivity ' ?
Which of the following is most likely to result in the impairment of independence for the internal audit activity?
Which of the following documents would promote objectivity within an organization ' s internal audit activity?
In its five years of existence, an internal audit activity conducted a single internal assessment of its quality assurance and improvement program (QAIP). The results of that assessment showed that the internal audit activity did not conform with the Standards. Prior to this, an external assessment of the internal audit activity ' s QAIP was conducted, which reported that the internal audit activity was in conformance with the Standards. Considering the two assessments, what would be the internal audit activity ' s current state of conformance with the Standards?
Which of the following would be considered an indicator that an organization ' s ethics program is not yet well developed?
According to IIA guidance, which of the following best describes the chief audit executive s responsibility for confirming to the board the organizational independence of the internal audit activity ' ?
An internal auditor interviews for a position within the organization’s IT department while simultaneously conducting an audit of the area’s ability to manage the organization’s user network accounts.
This presents a conflict of which of the following principles?
Which of the following most accurately describes the role of the board when it comes to organizational governance?
An engagement supervisor noticed that a newly hired internal auditor struggles with large data samples because he appears reluctant to apply available spreadsheet statistical functions and tends to perform testing of transactions manually In which of the following areas does the internal auditor most likely need training?
Which of the following would be a red flag for potential issues in the control environment?
Which of the following should be considered in developing a risk and control model for use in an engagement?
Which of the following types of policies best helps promote objectivity in the interna! audit activity ' s work?
The management team of an agricultural organization has prioritized corporate social responsibility (CSR) initiatives. Which of the following would be considered a CSR activity?
During an audit of the purchasing department, an internal auditor identifies significant issues that could affect the organization ' s financial reporting. Management disagrees with the audit results. Which of the following responses best demonstrates the internal auditor has the necessary competencies related to professional Judgment and conflict management?
According to NA guidance, which of the following conditions would enhance the independence of the internal audit activity?
According to IIA guidance, which of the following statements is true regarding the internal audit activity’s responsibilities in providing consulting services?
Which of the following internal control attributes would an internal auditor test to understand whether organizational structure supports effective internal control?
Anew internal auditor suspects fraud is taking place. Which action should the new auditor take?
Management assessed the organization’s risk of expanding operations into a new, but volatile, region and began looking for a compatible local partner to manage sales and distribution. Which of the following best describes this risk management technique?
During an assurance engagement, an internal auditor uses benchmarking research to support preparation of a report to stakeholders that contains significant findings about control deficiencies. Which of the following skills did the auditor demonstrate?
Which of the following activities should the chief audit executive perform to ensure compliance with an organization ' s code of conduct?
Which of the following primarily sets the foundation for effective corruption risk mitigation?
An internal auditor is updating the risk register for risks identified during a recent organizational risk assessment. According to the Standards, which of the following would the auditor include in the risk register?
Which of the following is a primary responsibility of senior management with respect to ethical violations?
Which of the following is the best reason why the engagement supervisor should take care in explaining to local management the criteria that will be used to measure the effectiveness of the control environment?
At what point in time can an organization conclude that the established organizational governance framework was correctly implemented?
Which of the following actions should the audit committee take to promote organizational independence for the internal audit activity?
When performing an audit of the risk management process an auditor makes the observations listed below. Which poses the greatest risk to the organization?
During a monthly internal audit staff meeting, the chief audit executive (CAE) decided to reinforce the importance of internal audit staff being objective in their work. Which of the following examples would be most appropriate for the CAE to include as part of the meeting presentation?
An internal auditor has suspicions that some fictitious vendors have been created in the organization ' s computer system. Which of the following would be the best technique to detect this fraud?
Which of the following statements is the most appropriate for a chief audit executive to include in the internal audit policy manual in order to promote objectivity?
Which of the following are some of the requirements of the quality assurance and improvement program (QAIP)?
Which of the following would likely have the greatest influence on the long-term quality of an organization’s control environment?
Nine months ago, an employee who was responsible for collections in the accounts receivables department joined the internal audit team. There is an accounts receivables assurance audit scheduled as part of this year ' s approved audit plan, which will include a review of the collections unit. With the knowledge and experience of this individual in the area, which of the following is the best approach for the chief audit executive (CAE) to take?
Which of the following statements is true regarding organizational culture and an audit of the control environment?
The internal audit activity is responsible for which of the following actions related to an organization’s internal controls?
Which of the following statements is true regarding the role of the internal audit activity in the organization ' s risk management process?
Which of the following situations would best indicate to the chief audit executive that one of the audit team members is struggling with application of due professional care?
Which of the following actions should the organization ' s governing body perform to provide the most effective governance over the organization ' s culture?
Which of the following specifications in an internal audit charter is the most important factor in the internal audit activity’s independence?
Which of the following would best illustrate to the chief audit executive that due professional care was exercised by internal auditors during an engagement?
An internal auditor was offered expensive tickets to a sporting event by the manager of an area that she was currently auditing. The auditor politely declined. Which of the following fundamental principles of the MA Code of Ethics did she display?
In a small organization, management is unable to achieve adequate segregation of duties for its cash-handling procedures Therefore hidden surveillance cameras were installed to monitor cash-handling activities Which of the following best describes this type of control?
A new CEO authorizes a vendor’s access to the organization’s vendor payment and contracting database as part of a review to identify wasteful spending. An employee in the contracting department raised concerns to the internal audit function about potential fraud involving the vendor’s access to the database’s sensitive information, including that of the vendor’s competitors.
Which is a potential fraud risk that requires special consideration during an internal audit engagement?
According to HA guidance, which of the following is true regarding independence and objectivity for small internal audit activities?
What controls could be implemented as a preventive measure against malicious insider threats, such as an unauthorized employee obtaining electronic customer sales information and later selling them to a competitor?
Which of the following would be the most appropriate first step for the board to take when developing an effective system of governance?
Which of the following statements represents the most appropriate correlation between an organization ' s risk maturity and the internal audit activity’s consulting role in risk management processes?
To comply with the proficiency standard which of the following would the chief audit executive likely consider as the primary hiring criterion when choosing a new internal auditor?
During an audit of a foreign subsidiary an internal audit team discovered that products were sold to a prohibited country due to sanctions. What is the best course of action for the internal audit team?
It is important for the chief audit executive to consider the level of competence of the internal audit staff because their competence influences which of the following?
According to IIA guidance, which of the following actions best demonstrates that due professional care has been considered by the internal audit activity when conducting a review of an organization ' s assets?
Nearing the completion of fieldwork, an internal auditor shared the draft report findings with management prior to the closing meeting. During the closing meeting, management expressed dissatisfaction in that they were not familiar with some of the findings. Management also noted that some aspects of the report seemed confusing. Which of the following competencies appears to have been lacking in this scenario?
The chief audit executive (CAE) has hired a new internal auditor who was immediately assigned to a procurement function audit. Because the new auditor ' s name is similar to that of the procurement manager, some staff members think the two are related, although they are not. Which of the following actions is most appropriate for the CAE to take?
Which of the following should the internal audit activity establish to ensure auditors develop the appropriate skills for conducting audits?
According to IIA guidance, which of the following is accurate regarding the chief audit executive ' s (CAE ' s) requirement to report the results of quality assessments?
1. The CAE must report the results of external assessments at least annually.
2. The CAE must report the results of ongoing monitoring at least annually.
3. The CAE must report the results of quality assessments to senior management.
4. The CAE must report the results of quality assessments to the board.
An internal auditor is finalizing an audit report on the effectiveness of the organization ' s overall system of internal control. Several audit tests were performed, and the only issue identified was that the CEO frequently asks employees to make exceptions or bypass the organization ' s standard written policies and procedures. Which of the following conclusions is most appropriate for the auditor to report?
Which of the following is a way to demonstrate an individual internal auditor ' s competency through continuing professional development?
According to IIA guidance, which of the following is a required aspect of an internal audit charter?
While conducting an engagement in the procurement department, the internal auditor noticed that the department head’s travel reports showed minor travel expenses, and there were no charges for hotels, meals, or transportation. However, the auditor knew that the department head frequently traveled worldwide to meet with suppliers and visit their production sites. Which of the following would be the most appropriate next step for the auditor?
Which of the following would provide the best support for internal auditors to meet their continuing professional development requirements?
An internal auditor was completely honest with operational management when delivering unfavorable audit results. Which of the following best describes the IIA Code of Ethics principle that the auditor demonstrated?
According to HA guidance, if an internal auditor suspects fraud during an assurance engagement, what should the auditor do first?
According to NA guidance, which of the following describes the primary reason to implement environmental and social safeguards within an organization?
Which of the following statements is true regarding the disclosure of results of the quality assurance and improvement program?
Which of the following is true regarding internal audit role ' s in The IIA ' s Three Lines Model?
A new internal auditor was recently recruited to the internal audit activity from the organization ' s finance department. What is likely to be the chief audit executive’s greatest concern regarding assigning the new auditor to upcoming audits in the finance department?
An electric company hires several independent contractors to trim trees that are in close proximity to electricity lines. Which of the following would be the most effective control to mitigate the risk of contractors submitting fraudulent invoices regarding work completed?
Which of the following actions by the chief audit executive (CAE) best describes a potential impairment to the internal audit function’s independence?
An internal auditor was assigned to work in the procurement department for six months to gam m-depth knowledge about the procurement process. Which of the following personnel development practices was applied in this situation?
After being assigned to an audit of the accounts payable process, an internal auditor privately notifies the chief audit executive that she is a finalist for an open manager position within the accounts payable department. Which of the following is the IIA Code of Ethics principle that the auditor upheld?
Evidence discovered during the course of an engagement suggests that multiple incidents of fraud have occurred. There do not appear to be sufficient controls in place to prevent reoccurrence. Which of the following is the internal auditor ' s most appropriate next step?
Which of the following scenarios would most significantly restrict the areas where internal audit could perform assurance services?
Recently an organization’s internal audit activity discovered ghost employees who receive payments Senior management decides to strengthen the internal control measures to address this Which of the following is considered an effective control to mitigate payments to ghost employees?
During an assurance engagement internal auditors interview operational management to gather and evaluate information. Which approach is most important for internal auditors to be able to listen effectively to interviewees in the given situation?
Applying ISO 31000, which of the following is part of the external context for risk management?
In which of the following situations may the internal audit activity report conformance with the Standards?
During a brainstorming session, employees stated that dishonest vendors could submit fictitious invoices to the organization, and such an invoice may be authorized for payment because the employees responsible might be clicking approval boxes without going into the details.
Given this information, which of the following controls should be tested during the audit engagement?
During an audit engagement of a large retail store, internal auditors noted significant discrepancies between available inventory and sales and suspect an abuse of cash register refunds and voids. Which of the following would be the most effective preventative control to reduce these losses?
Which of the following situations best describes an internal auditor who may have violated the IIA Code of Ethics principle of confidentiality?
Which of the following best describes the risk contained in an initial public offering for a new stock?
Which of the following scenarios represents a top-down flow of information regarding corporate governance?
Which type of engagement requires that the client agrees with the techniques used by the internal audit activity?
Which of the following statements best describes the difference between risk appetite and risk tolerance?
Upon completion of an external quality assessment, which of the following would the chief audit executive be required to report to the board?
The chief audit executive reports functionally to the board and administratively to the CEO and has been in operation for many years. Internal auditors often find that management of areas under review are reluctant to provide requested documents during audits. This has often resulted in limitations of the scope of work performed by the internal audit function.
Which element of the internal audit charter needs enforcement to prevent such limitations?
According to NA guidance, which of the following provides the best evidence of conformance with the Standards with respect to the proficiency required of the internal audit activity?
In which of the following scenarios would the internal auditor’s objectivity be best protected?
Which of the following would best describe a control implemented to detect cash register disbursement fraud in a large retail store?
According to IIA guidance, which of the following corporate social responsibility {CSR) evaluation activities may be performed by the internal audit activity?
1. Consult on CSR program design and implementation
2. Serve as an advisor on CSR governance and risk management.
3. Review third parties for contractual compliance with CSR terms.
4. Identify and mitigate risks to help meet the CSR program objectives.
The organization s procurement manager asks the internal auditor to deliver training to the procurement team on the organization’s third-party risk management process. Which of the following is the most appropriate response?
According to MA guidance, which of the following statements is true regarding an effective governance process?
The organization ' s internal audit charter was last updated six years ago. To update the charter, which of the following actions is most appropriate for the chief audit executive to take?
According to IIA guidance, which of the following conditions would enhance the independence of the internal audit activity?
According to IIA guidance, which of the following best describes expense reimbursement fraud?
An internal auditor performed a risk assessment and concluded that the controls over access privileges to a bank account were appropriate. Later, the auditor learned that a contractor was using a shared password provided by an authorized user of the account. Which of the following statements best describes the auditor ' s application of due professional care?
Wi ch of the following circumstances would most likely be considered a potential red flag for fraud by the internal audit activity?
After the draft engagement report is issued, the manager of the area that was reviewed is informally interviewed by the engagement supervisor regarding the audit experience. Which of the following is most likely the purpose for this interview?
Which of the following qualifies as an acceptable consulting service provided by the internal audit activity?
Which of the following actions by the internal audit activity requires disclosure to the board of nonconformance with the Standards?
An organization uses hedging to address foreign currency risk.
Which of the following best describes this risk strategy?
An internal audit activity is performing a governance engagement. Which of the following would provide the best evidence for an internal auditor when evaluating the organization’s culture?
Which of the following most accurately describes corporate social responsibility at an organization?
Which of the following is an acceptable supplement to promote professional development within the internal audit function?
An internal auditor is assessing the effectiveness of the organization ' s risk management practices. She checks to see whether risk management is an integral part of decision making and whether risk management is transparent, responsive to change, and addresses uncertainty. According to IIA guidance on risk management frameworks, which of the following approaches is the auditor most likely using?
According to IIA guidance, which of the following is true of the internal audit activity’s quality assurance and improvement program?
1 Monitoring the internal audit activity’s performance must be ongoing
2 All aspects of the internal audit activity should be evaluated
3 The requirement for external assessments can be satisfied through self-assessments that are validated by an independent external party
4 The review of assurance services should be the primary focus
The internal audit activity completed its analysis of sample transactions to determine occurrences of double billings According to If A guidance, which of the following best demonstrates that internal auditors exercised due professional care during the review?
Which of the following practices is generally most effective to protect internal audit objectivity?
During a quality assessment of the internal audit activity an auditor is assessing whether the independence of the internal audit activity is at risk of being compromised. According to IIA guidance, which of the following would provide the best source of evidence for such an assessment?
Considering the concepts of organization wide risk management and the system of internal controls, the internal audit activity as a whole can be considered which of the following types of control?
Which of the following is (he most effective way any organization can ensure proper governance over its internal controls?
An experienced internal auditor is planning an assurance engagement of the organization ' s sales activities. During process walkthroughs and interviews, many sales representatives expressed concerns about management ' s escalating demands to meet the organization ' s sales goals. According to the MA guidance, which of the following is the best application of due professional care in planning the engagement?
Which of the following situations presents the lowest risk of impairing an internal audit activity ' s independence?
The manager of the payroll department requested a review of the payroll process, but only wants the engagement to include processes related to approval of time worked. What type of activity is this?
During an audit of company expenses, the internal auditor performed a test using data analytics and identified a violation of the company ' s expenses policy. The auditor who discovered the issue considered it a potential fraudulent transaction and informed the chief financial officer (CFO). The CFO dismissed the concern because he did not understand the data analytics test that was performed and the transaction was of a low value. Given this situation, which skills or competencies should this internal auditor seek to improve?
An internal auditor is reviewing the organization’s procurement processes. The procurement manager states that suppliers’ bank details are verified by phone call directly with the supplier before being updated in the procurement system. The organization has around 3,000 suppliers. The auditor is skeptical that a phone call is made for each supplier when bank details are changed.
The auditor decides to verify the manager’s statement by analyzing the change to one supplier’s bank details.
Which piece of evidence would convince the auditor that the control described by the procurement manager is effective?
An organization opened its warehouse to sell written-off surplus and outdated office furniture to the general public. Prices were negotiable, and customers could pay by cash, check, or credit card. Receipts were available upon request, and were issued by the inventory manager upon collection of payment. At the end of the day, the manager forwarded all of the funds he had collected to the finance department for deposit. Which of the following types of fraud is most likely to occur under these circumstances?
Management decided to post the organization ' s newly established code of conduct on its website. This decision is primarily intended to mitigate which of the following risks?
Which of the following is a threat to the internal audit function’s organizational independence?
Which of the following statements is true regarding management ' s use of judgement to design, implement, and conduct internal control?
An organization grants its internal auditors authority to access sensitive confidential information so the auditors may analyze data and conduct effective assurance engagements.
This effectively demonstrates support for which of the following fundamental principles of internal auditing?
A chief audit executive has decided to use the process element approach to evaluate the organization’s risk management process.
According to IIA guidance, which of the following provides evidence that the risk evaluation element is in place?
An internal auditor is trying to evaluate what could go wrong after determining that a risk management technique is operating effectively. What type of risk is the auditor assessing?
An internal auditor has completed an assurance engagement Which of the following is most likely true regarding the engagement?
According to IIA guidance, which of the following actions is a chief audit executive required to take with regard to reporting the results of the quality assurance and improvement program?
Which of the following best describes a proactive role for the internal audit activity with regard to the organization ' s ethics program?
The board of a newly established organization was discussing the contents of the draft internal audit charter One board member suggested adding to the charter an obligation for the internal audit activity to develop controls in business procedures. The board member explained that the new organization needs professional-level developers, internal auditors have the necessary skills and competencies, and the internal audit activity is well positioned to assume this responsibility. Which of the following would be a potential concern if the board member’s suggestion is adopted?
Guidelines need to be set for various levels of suspected fraud within an organization and when it would be reported to the audit committee. Which of the following would be
reported at the next meeting?
Which of the following situations is most likely to threaten the independence of the internal audit activity?
According to MA guidance, which of the following best describes how often the chief audit executive should review the quality assurance and improvement program of the internal audit activity?
An internal auditor of a real estate organization wants to stay informed of current regulations on real estate investments.
Which of the following is likely the best option?
The chief audit executive (CAE) annually develops a budget and resource plan and submits it to the board for approval. This action best fulfills which of the following responsibilities of the CAE?
A business unit manager was impressed by the competence of the internal auditor who was conducting an assurance engagement in his area and the manager made the auditor an attractive job offer to begin after the audit was completed The auditor later told her auditor in charge that she was considering the offer. Which of the following IIA Code of Ethics principles was most likely violated?
Which of the following parties would be responsible for ongoing monitoring of the organization ' s corporate social responsibility activities to reduce its carbon footprint?
With regard to IT governance, which of the following is the most effective and appropriate role for the internal audit activity?
While auditing an organization ' s credit approval process, an internal auditor learns that the organization has made a large loan to another auditor ' s relative. Which course of action should the auditor take?
An external assessment of an organization ' s internal audit activity was last completed four years ago Which of the following options would be acceptable this year if the internal audit activity is to fulfill the requirements of the Standards?
The same internal auditor has audited the regional purchasing department annually for the last three years. The audits have shown several significant control deficiencies that have not been corrected by management. New management is in charge of this regional purchasing department, and it is time to audit the department again. What concerns should be considered prior to assigning the audit to the same auditor?
An organization established 20 years ago has had its internal audit activity in place for the last three years. Which of the following would allow the internal audit activity to accurately state that it is in conformance with the Standards ' ?
Which of the following best describes why a chief audit executive might obtain the services of a fraud specialist to assist in a major fraud investigation ' ?
According to IIA guidance, which of the following statements is true regarding ISO 31000?
Which step should an internal auditor complete during fieldwork to detect fraudulent activities during an audit?
Senior management has decided to adopt the key principles approach of the ISO 31000 risk management framework. According to IIA guidance, which of the following principles is most appropriate when implementing the risk management process in a dynamic agency?
An internal auditor extended the scope of testing for a disbursements engagement following a fraud risk assessment Despite the investment of additional audit resources no significant issues were found Unfortunately a major payment fraud was discovered several
months later According to IIA guidance which of the following statements is true regarding the internal auditor ' s application of due professional care?
Which of the following scenarios best illustrates the concept of due professional care?
A manufacturer of power tools is experiencing regular fluctuations in the price of electrical power which is having a serious impact on the bottom line. Which of the following would be the most effective risk strategy to reduce the impact of these fluctuations?
What must a chief audit executive do if significant changes to regulations may affect the nature of internal audit services?
An internal auditor of a small manufacturing organization helps with a fraud investigation of accounts payable. The auditor notes that the accounts payable manager is very friendly and trusting with accounts payable staff, so the manager rarely checks the staff’s work.
Which component of the fraud triangle is most relevant in this scenario?
Which of the following is the internal audit activity expected to do with respect to the organization ' s governance processes?
Which of the following situations undermines the independence of the internal audit activity?
Which of the following is an indicator that the organization s risk management process is effective?
Which of the following circumstances would most likely be considered a potential red flag for fraud by the internal audit activity?
A chief audit executive (CAE) has just joined an organization with an existing internal audit activity. Based on her review of the current organizational structure, the CAE determines that the internal audit activity lacks adequate independence. Which of the following actions is the CAE ' s best step to take next to move the internal audit activity toward organizational independence?
An internal audit team was assigned to review the organization’s information security protocol After fieldwork was completed an internal auditor identified an error in the review of security access The error could affect the overall results of the engagement Which of the following is the most appropriate course of action for the internal auditor?
The organization discusses the need to change its accounting software.
In which of the following stages would an internal auditor’s advisory review most benefit the organization?
Which should the internal auditor first consider when assessing fraud risks during an engagement?