Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save75geek

IIA-CIA-Part1 Internal Audit Fundamentals Questions and Answers

Questions 4

In the COSO internal control framework, which of the following components serves as the foundation for the other components?

Options:

A.

Control activities.

B.

Control environment.

C.

Risk assessment.

D.

Monitoring

Buy Now
Questions 5

What is the primary purpose of The IIA ' s Code of Ethics?

Options:

A.

Communicate specific activities appropriate to the performance of internal auditing.

B.

Promote ethical culture within corporations and other business organizations.

C.

Establish mandatory standards of competence for the practice of internal auditing.

D.

Establish principles and expectations governing behavior of individuals and organizations in the conduct of internal auditing.

Buy Now
Questions 6

Which risk management activity would cause the internal auditor to assume a management responsibility?

Options:

A.

Assessing management ' s acceptance of risk.

B.

Reviewing a cybersecurity risk report issued by management.

C.

Developing a list of emerging risks for management.

D.

Prioritizing risks for management.

Buy Now
Questions 7

Which of the following skills is most important for an internal auditor who facilitates control self-assessment workshops to possess?

Options:

A.

Groupthink.

B.

Collaboration skills.

C.

Process analysis skills.

D.

Project management skills.

Buy Now
Questions 8

During a payroll audit, the internal auditor discovered that several individuals who have the same position classification as he are earning a significantly higher salary. The auditor noted the names and amounts of each, and he planned to prepare a request to the chief audit executive for a salary increase based on this information. Which of the following IIA Code of Ethics principles was violated in this scenario?

Options:

A.

Competency.

B.

Objectivity,

C.

Integrity.

D.

Confidentiality

Buy Now
Questions 9

An internal auditor is assessing how the organization processes financial transactions and whether written policies and procedures are followed. The auditor requested to meet with certain employees to understand their related roles and responsibilities. However the employees refuse to meet with the auditor claiming they are too busy. Which of the following responses would best demonstrate the auditor ' s conflict-resolution skills?

Options:

A.

The auditor considers the employees to be unresponsive and proceeds to document the actions and concerns as a scope limitation that can affect the engagement

B.

The auditor considers other options to determine whether the employees are processing financial transactions as required by the organization

C.

The auditor meets with senior management of the organization to discuss the employees ' behavior and possible resolutions that would satisfy all parties

D.

The auditor meets with the department supervisor and staff to discuss the employees ' actions in order to obtain an understands and potential resolution

Buy Now
Questions 10

A fraud investigation was completed by management, and a proven fraud was communicated to relevant authorities. According to IIA guidance, which of the following roles would be most appropriate for the internal audit activity to undertake after the investigation?

Options:

A.

Plan employee sessions and team building strategies for the organization to improve awareness of fraud among employees

B.

Review the investigation and implement any improvements to the process.

C.

Conduct lessons learned sessions to ascertain how the fraud occurred and which controls failed.

D.

Determine why the fraud was not detected earlier and design controls to strengthen early detection.

Buy Now
Questions 11

According to IIA guidance, which of the following statements is true regarding reporting the results of the quality assurance and improvement program?

Options:

A.

Results of internal assessments need to be reported to the board at least once every five years.

B.

The external assessor must present the findings from the external assessment to senior management and the board upon completion.

C.

Deficiencies within the internal audit activity must be reported to the board as soon as they are noted.

D.

Results of ongoing monitoring of the internal audit activity ' s performance must be reported to senior management and the board at least annually

Buy Now
Questions 12

Which of the following is an example of risk monitoring to ensure a system is performing as intended?

Options:

A.

Checking the progress of risk treatment plans

B.

Considering the consequence and likelihood of risks

C.

Documenting the risks and their areas of impact

D.

Communicating to management about risks

Buy Now
Questions 13

Which of the following activities would an internal auditor perform as a consulting engagement for an organization?

Options:

A.

Advising new internal auditors working for the organization on how to develop strategies on planning audits for the upcoming fiscal year

B.

Assessing whether the organization ' s corporate social responsibility program is meeting its yearly goals to reduce carbon emissions.

C.

Briefing the organization ' s department managers on how to implement risk management processes into their daily operations.

D.

Communicating with senior management to better understand how new purchasing controls will minimize payment processing time.

Buy Now
Questions 14

An IT contractor applied for an internal audit position at a bank. The contractor worked for the bank ' s IT security manager two years ago. If the audit manager interviewed the contractor and wants to extend a job offer, which of the following actions should the chief audit executive pursue?

Options:

A.

Allow the audit manager to hire the contractor and state that the individual is free to perform IT audits, including security.

B.

Not allow the audit manager to hire the contractor, as it would be a conflict of interest

C.

Allow the audit manager to hire the contractor, but state that the individual is not allowed to work on IT security audits for one year.

D.

Not allow the audit manager to hire the contractor and ask the individual to apply again in one year.

Buy Now
Questions 15

In which of the following audits would the internal auditors most likely contribute to the assessment of organizational governance?

Options:

A.

An assessment of compliance of individual data protection procedures with data protection regulations

B.

An assessment of profit and loss generated by financial assets and instruments in the past quarter

C.

An assessment of the effectiveness of back-up procedures and execution of business recovery plans

D.

An assessment of performance management practices and establishment of key performance indicators

Buy Now
Questions 16

Who is responsible for setting the risk appetite?

Options:

A.

External auditors.

B.

Chief risk officer.

C.

Operations management.

D.

Board of directors.

Buy Now
Questions 17

As part of a fraud investigation by regulators, a court order was issued to a bank. The court order requested the chief audit executive (CAE) to provide access to a number of audit reports and workpapers, some of which included customers ' confidential information such as transaction activity and other personal details. What is the appropriate response by the CAE?

Options:

A.

Reject the court order, citing a potential breach of customers ' confidentiality agreement

B.

Consult with legal counsel to determine what information to provide.

C.

Respond promptly and provide all that was requested by the court order.

D.

Seek permission from customers prior to sharing their information.

Buy Now
Questions 18

Which of the following statements is true regarding assurance and advisory services provided by an internal audit function?

Options:

A.

When internal auditors are performing an advisory engagement, they always focus on the organization as a whole.

B.

When internal auditors are performing advisory engagements, they focus only on areas not covered by assurance engagements.

C.

Advisory services are mainly applicable during the planning stages of projects to assess relevant risks.

D.

The type of information required depends on whether the engagement is assurance or advisory.

Buy Now
Questions 19

A sales manager was recently bypassed for a promotion. He feels entitled to a higher salary and is angry that management does not recognize his contributions. To make up for this perceived injustice, he begins to record false expenses on his travel expense reports. This scenario best illustrates which of the following fraud risk factors?

Options:

A.

Incentive.

B.

Rationalization.

C.

Pressure.

D.

Opportunity.

Buy Now
Questions 20

Which of the following is true regarding risk analysis?

Options:

A.

Impact and likelihood should be assessed together.

B.

Impact and likelihood should be given equal consideration by the internal auditor.

C.

Impact and likelihood should be measured using quantitative methods.

D.

Impact and likelihood should be used to determine risk response.

Buy Now
Questions 21

Which of the following best describes the approach the internal audit activity should take to assess and make appropriate recommendations to improve the organization?

Options:

A.

To evaluate an organization s governance processes for making strategic and operational decisions eternal auditors should review the organization s policies and processes related to staff compensation

B.

To determine how an organization provides oversight of its risk management and control activities internal auditors should review board meeting minutes and the board policy manual

C.

To assess how an organization promotes ethics and values both internally and among its external business partners, internal auditors should review the organization ' s related objectives programs and activities

D.

To evaluate how an organization ensures effective performance management and accountability internal auditors should review previously conducted risk assessments

Buy Now
Questions 22

In which of the following situations would the organizational independence of an internal audit activity be impaired?

Options:

A.

The chief audit executive reports administratively to the CEO.

B.

Scope limitations are imposed on internal audits.

C.

The internal audit activity provides assurance services for an activity for which the engagement supervisor had responsibility within the previous year.

D.

The compensation committee of the board approves the remuneration of the chief audit executive.

Buy Now
Questions 23

Who is held responsible for oversight of the organization ' s risk management framework?

Options:

A.

Operational management.

B.

Board of directors.

C.

Internal auditors.

D.

Head of risk management.

Buy Now
Questions 24

Which of the following best illustrates the principle of due professional care?

Options:

A.

The internal audit activity uses key performance indicators for all staff members after all audit engagements.

B.

The internal auditors provide assurance to third parties indicating that their work was properly supervised.

C.

The internal auditors demonstrate they have an understanding of engagement objectives and scope.

D.

The internal auditors are heavily involved in training and development to enhance their skills.

Buy Now
Questions 25

Which of the following should catch the internal auditor ' s attention as a potential red flag for fraud?

Options:

A.

The accounting unit keeps detailed records and preserves supporting documentation in excess of company requirements

B.

One of the subsidiaries has more bank accounts than any other comparable subsidiary

C.

The same external audit firm has been with the company for three years without rotation

D.

The arithmetic median tenure of employees working at production facilities is 15 years

Buy Now
Questions 26

Which of the following statements is true regarding the independent peer review process undertaken to fulfill the requirement for an external quality assessment?

Options:

A.

Two individuals in the same internal audit activity may perform an independent peer review as long as they do not report to the same audit manager

B.

Individuals from a separate but related organization such as an affiliate may perform peer reviews

C.

Individuals working in separate internal audit activities may be considered independent as long as do not report to the same chief audit executive

D.

Peer reviews are generally less cost-effective than hiring an external quality assessor

Buy Now
Questions 27

An internal auditor discovers that a production manager has been understating stock items produced in the factory and concealing it by accounting for it as abnormal waste.

Which of the following types of fraud does this exemplify?

Options:

A.

Skimming.

B.

Assets misappropriation.

C.

Financial statement fraud.

D.

Diversion.

Buy Now
Questions 28

A significant number of employees expressed concerns of a hostile work environment within a large manufacturing plant, which is in contrast to the organization ' s stated culture of tolerance and open communication. Which of the following approaches would be most effective for an internal auditor to assess whether the organization supports a culture of tolerance and open communication?

Options:

A.

Assess plant employees ' social media activity for specific messages related to tolerance and open communication

B.

Compare plant employees’ compensation and benefits with those at similar sized organizations that have a stated culture of tolerance and open communication.

C.

Evaluate organization policies and procedures for references related to encouraging tolerance and open communication.

D.

Conduct a meeting with all plant employees and management to discuss tolerance and open communication

Buy Now
Questions 29

An internal auditor is finding it difficult to get management to accept audit findings because of issues that management is having with how the information is presented. Management has expressed disagreement in the past about this auditor’s style in presenting complex findings and the general tone of the report.

Which of the following competencies or skills likely requires improvement on the auditor’s part?

Options:

A.

Communication.

B.

Critical thinking.

C.

Persuasion and negotiation.

D.

Business acumen.

Buy Now
Questions 30

An internal auditor observed that sales staff are able to modify or cancel an order in the system prior to shipping* She wonders whether they can also modify orders after shipping. Which of the following types of controls should she examine?

Options:

A.

Batch controls.

B.

Application controls.

C.

General IT controls.

D.

Logical access controls

Buy Now
Questions 31

The internal audit activity is responsible for conducting fraud investigations. A potential fraud instance was identified during an audit engagement. The chief audit executive appoints a lead investigator. Which of the following would most likely be the next step?

Options:

A.

Ask internal auditors to gather all relevant information and evidence.

B.

Identify and interview witnesses first and potential suspects later.

C.

Conduct a fraud risk assessment to identify the most vulnerable areas.

D.

Determine the competencies needed and assess whether team members have a conflict of Interest.

Buy Now
Questions 32

An internal audit activity includes in its audit reports the assertion that its work is performed in conformance with the International Standards for the Professional Practice of Internal Auditing ( Standards). A recent external quality assessment concluded that the internal audit activity had substantial deficiencies that impact its overall operations.

According to IIA guidance, which of the following is the most appropriate action for issuing future audit reports?

Options:

A.

Refrain from indicating that the internal audit activity operates in conformance with the Standards until the chief audit executive confirms that the internal audit activityhas addressed all areas of nonconformance and the audit committee has been notified.

B.

Refrain from indicating that the internal audit activity operates in conformance with the Standards until another external assessment confirms that the significant areas of nonconformance have been addressed.

C.

Indicate that the internal audit activity operates in partial conformance with the Standards t as the internal audit activity has a quality assurance and improvement program in place to address deficiencies and has met the requirement for conducting an external assessment.

D.

Update and reissue previous audit reports, removing the assertion that the internal audit activity operates in conformance with the Standards, and distribute them to ail parties who received the original reports.

Buy Now
Questions 33

The internal auditor obtained large volumes of transaction history data for accounts on which he suspected that some fraudulent transactions occurred. Which of the following actions best demonstrates due professional care by the internal auditor?

Options:

A.

The internal auditor carefully scrutinized the data by manually reviewing each transaction to ensure that all irregularities were identified.

B.

The internal auditor employed the use of data analytics tools to sort, analyze, and detect anomalies in the data

C.

The internal auditor started the data analysis process by selecting a random sample of transactions on which to perform further tests.

D.

The internal auditor requested that the branch supervisor assist in identifying fraudulent transactions, as he was most familiar with the accounts being audited.

Buy Now
Questions 34

An audit client who was unsatisfied with the audit report rating called the chief audit executive (CAE) and complained that the internal auditor who performed the audit was biased because his spouse, who worked in the area under review, was on a list of employees to be terminated. Which of the following measures would be most appropriate to prevent this situation from arising?

Options:

A.

Initiating an internal investigation to clarify whether a biased judgment took place.

B.

Requiring the internal auditors to disclose any potential conflicts of interest.

C.

Requiring that the audit client disclose any potential conflicts of interest with the auditor.

D.

Requiring human resources manager to submit all future job applicants ' data in order to identify relatives of auditors.

Buy Now
Questions 35

An organization is considering purchasing a new banking software system and has asked the internal audit activity to evaluate the system. An internal auditor assigned to perform the engagement worked at the software company two years ago and is familiar with the system ' s design strengths and weaknesses. Which of the following is true regarding impairment to the auditor ' s objectivity?

Options:

A.

This situation does not necessitate any action related to the auditor ' s objectivity.

B.

The auditor should decline to perform the audit because personal conflicts of interest are likely.

C.

The auditor must disclose to the chief audit executive that this situation may impair her objectivity.

D.

The auditor can provide only consulting services, not assurance.

Buy Now
Questions 36

Senior management relies on the professional judgment of an internal auditor and uses outcomes of her audit work to make business decisions Which of the following personal qualities displayed by the internal auditor is most likely the foundation for this relationship?

Options:

A.

Integrity

B.

Negotiation skills.

C.

Business acumen

D.

Flexibility

Buy Now
Questions 37

An internal auditor assigned to a supplier management process engagement reviews the risk assessment with the process owner The auditor inquires about the risk response for potentially engaging unqualified third-party service providers The process owner responds that due diligence checks are undertaken to make sure that third parties possess requisite competencies before they are engaged Which of the following risk management techniques is the process owner using?

Options:

A.

Risk avoidance

B.

Risk reduction

C.

Risk sharing

D.

Risk acceptance

Buy Now
Questions 38

An audit engagement required that an internal auditor, using available tools, test a transaction population for a period The auditor decided to test a sample of transactions rather than the full population.

Results of the audit were reported as satisfactory to management. Subsequent to the audit report, fraud was discovered in the area audited and was found to include transactions that were in the relevant transaction population not tested by the auditor. The auditor later disclosed that he decided to test a sample because it was representative of the population and facilitated quicker testing. Which of the following skills below, if improved, would most likely have prevented this situation?

Options:

A.

Objectivity

B.

Critical thinking.

C.

Empathy.

D.

Communication

Buy Now
Questions 39

According to the 11A Code of Ethics, which of the following is required with regard to communicating results?

Options:

A.

The internal auditor should present material information to appropriate personnel within the organization without revealing confidential matters that could be detrimental to the organization.

B.

The internal auditor should disclose all material information obtained by the date of the final engagement communication.

C.

The internal auditor should obtain all material information within the established time and budget parameters.

D.

The internal auditor should reveal material facts that could potentially distort the reporting of activities under review.

Buy Now
Questions 40

An internal auditor for a construction organization suspects that fraud is occurring, as inventory replacement costs for hand tools and additional materials have been consistently exceeding the budget at two large job sites.

Based on this information, which type of fraud is most likely occurring at these job sites?

Options:

A.

Disbursement fraud.

B.

Skimming.

C.

Diversion.

D.

Misappropriation.

Buy Now
Questions 41

Upon completion of an external assessment as part of the quality assurance and improvement program (QAIP), the chief audit executive (CAE) reported the results to senior management and the board The CAE included the following elements in the report

- Qualifications and independence of me external assessment team

- Conclusions of assessors

- Corrective action plans

How should the CAE improve the aforementioned approach to reporting the resets of QAIP?

Options:

A.

Senior management should be excluded from the reporting as the QAiP results must be communicated to re board only

B.

The report can be streamlined by removing unnecessary information such as the qualifications and me independence of external assessors

C.

The results must be snared with the external a auditors as well, so they can determine the extent to which they can rely on me work of the internal audit activity

D.

The report should indicate that the external assessment must be performed at least once every five years

Buy Now
Questions 42

Which of the following is a greater consideration for internal auditors when they are performing a consulting engagement than when they are performing an assurance engagement ' ?

Options:

A.

The relative complexity of the engagement

B.

The cost of the engagement relative to its benefits

C.

The extent of work needed to achieve the engagement ' s objective

D.

The needs and expectations of the engagement client

Buy Now
Questions 43

What is the best course of action when the internal audit activity does not have the knowledge necessary to perform a planned audit of the organization ' s new IT data backup process?

Options:

A.

Postpone the audit engagement to a later date.

B.

Recruit and hire a full-time staff auditor who is proficient in data backup processes.

C.

Change the plan from an assurance engagement to a consulting engagement.

D.

Provide data backup training to the engagement supervisor.

Buy Now
Questions 44

Which of the following indicates that internal audit independence may be compromised?

Options:

A.

The internal auditor maintains a close personal relationship with operational management.

B.

Material observations were intentionally left out of the audit report.

C.

Internal auditors assigned to the audit engagement did not have the knowledge, skills, and competencies needed to perform their responsibilities.

D.

An internal auditor failed to apply professional skepticism while performing audit tests in an area overseen by an experienced, reputable manager

Buy Now
Questions 45

During a review of the procurement function, an internal auditor identified an existing control for adding new vendors into the vendor contract system. Which of the following would best help the auditor determine the adequacy of the control ' s design?

Options:

A.

Flowchart of the vendor addition process.

B.

Independent confirmations sent to vendors.

C.

Analysis of the control ' s costs and benefits.

D.

Interview with management of the procurement function.

Buy Now
Questions 46

Which of the following frauds is most likely to occur in the accounts payable function?

Options:

A.

Factitious vendors are entered into the system, possibly resulting in improper disbursements.

B.

Bad debt expense is intentionally omitted from the financial statements.

C.

Certain costs are capitalized, rather than expensed.

D.

A related party receives benefits not appropriate in an arm ' s-length transaction.

Buy Now
Questions 47

An organization’s senior management team is awarding substantial bonuses if employees meet financial targets. Which of the following motivators to potentially commit fraud would become most likely in this scenario?

Options:

A.

Opportunity

B.

Pressure

C.

Rationalization

D.

Justification

Buy Now
Questions 48

Which of the following would most likely be classified as a consulting engagement?

Options:

A.

Examining the internal control effectiveness of the marketing department

B.

Assessing the adequacy of the IT system ' s business process design

C.

Facilitating a self assessment of the organizations business risk and control identification

D.

Reviewing the application controls in the human resources system

Buy Now
Questions 49

Which of the following is true for consulting engagements ' ?

Options:

A.

The internal audit activity must ensure management actions have been effectively implemented or risk accepted

B.

A work program for the engagement is not required but may be developed

C.

The nature of consulting services does not have to be in the internal audit charter

D.

Risks identified from the engagement must be considered when evaluating the organization ' s risk management processes

Buy Now
Questions 50

Who is responsible for ensuring internal auditors’ continuing professional development?

Options:

A.

Individual internal auditors.

B.

Chief audit executive.

C.

The board.

D.

Engagement supervisors.

Buy Now
Questions 51

A newly hired internal auditor is performing an engagement that requires significant IT expertise that he does not possess. If the auditor does not alert the chief audit executive about his lack of expertise and decides to perform the engagement anyhow, which principle of the IIA ' s Code of Ethics would he violate?

Options:

A.

Due professional care.

B.

Competency.

C.

Effective communication

D.

Professionalism

Buy Now
Questions 52

Which of the following corporate social responsibility strategies is associated with responding to outside pressure by assuming additional responsibility?

Options:

A.

Accommodation.

B.

Reaction.

C.

Defense.

D.

Proaction.

Buy Now
Questions 53

Which of the following situations is most likely to prompt the internal audit activity to disclose its nonconformance with the Standards?

Options:

A.

One of the organization ' s senior internal auditors owns a side business, though to date, no sales have been made to this business.

B.

The annual internal audit plan includes performance audits of main business processes, but reviews of high-risk development projects were not considered.

C.

The internal audit activity committed to carrying out an audit of documentation on investment hedging, and a hedging expert was contracted to assist with the engagement.

D.

A periodic quality self-assessment of the internal audit activity identified a number of improvement areas with regard to key performance indicators.

Buy Now
Questions 54

An internal auditor is assessing fraud risks and creating a fraud risk matrix for a particular branch location. Which of the following is most likely to be included in the matrix?

Options:

A.

Risks and relevant mitigating controls.

B.

Business processes and relevant fraud risks.

C.

Fraud scenarios and relevant risks.

D.

Opportunity, rationalization, and pressure to commit fraud.

Buy Now
Questions 55

Which of the following is an example of a directive control?

Options:

A.

Segregation of duties.

B.

Exception reports.

C.

Training programs.

D.

Supervisory review.

Buy Now
Questions 56

An organization allows the same individual to physically access inventory and purchase new assets when supplies are depleted. Which of the following would best help the organization manage the risk of fraud?

Options:

A.

Accounting personnel should regularly perform a reconciliation between invoices and purchase orders.

B.

Accounting personnel should conduct a periodic inventory count and reconcile all inventory movements.

C.

Internal auditors should review the frequency and volume of purchased assets to detect trends in the inventory levels.

D.

Management should establish a policy requiring new inventory asset purchases to be made on serialized order forms with copies retained.

Buy Now
Questions 57

During the closing meeting of a procurement audit, the business manager disagrees with the observation presented by the engagement supervisor and accuses the team of not understanding the procurement objectives The engagement supervisor blames the manager for impeding the audit What skillset should the chief audit executive utilize to manage this situation?

Options:

A.

The ability to negotiate

B.

The ability to use analytical tools

C.

The ability to foresee issues

D.

The ability to manage conflict

Buy Now
Questions 58

Which of the following risk management techniques best describes the strategy of obtaining insurance to protect against losses due to bad weather conditions?

Options:

A.

Risk avoidance

B.

Risk reduction

C.

Risk acceptance

D.

Risk sharing

Buy Now
Questions 59

The results of an assessment of the adequacy of controls would be considered incomplete or misleading unless the internal auditor considers which of the following?

Options:

A.

Number of mitigating controls.

B.

Effectiveness of the control environment

C.

Use of computer-assisted auditing techniques.

D.

IT security controls

Buy Now
Questions 60

Which of the following can be used to integrate cultural risk factors into testing for an audit engagement?

Options:

A.

Results of employee surveys.

B.

Process maps.

C.

The organizational chart.

D.

The documented governance structure.

Buy Now
Questions 61

Which of the following best describes the role of internal control frameworks?

Options:

A.

They outline specific internal controls for an organization to implement to ensure business objectives will be achieved.

B.

They provide guidance related to internal control design and implementation to assist with the evaluation and benchmarking of business practices.

C.

They serve as a list of appropriate internal controls for auditors to ensure an organization is using best practices.

D.

They serve as a template for identifying standardized best practices in effective risk management across industries and countries.

Buy Now
Questions 62

Which of the following statements is true regarding the use of risk frameworks?

Options:

A.

They are only effective at the strategic level in managing key external and internal risks.

B.

They are jointly managed by the board and senior management to create a consensus for key risks.

C.

They are usually implemented as an automated methodology to identify and manage key risks at the process level.

D.

They are flexible in addressing and linking objectives and related risks across the organization.

Buy Now
Questions 63

Which documents would help a forensic auditor identify instances of collusion between an employee and vendor to defraud the organization?

Options:

A.

Email correspondence.

B.

Payment request forms.

C.

Vendor invoices.

D.

Bank statements.

Buy Now
Questions 64

Which of the following statements is true regarding organizational independence of the internal audit activity (IAA)?

Options:

A.

Reporting to a higher level within the organization reduces the potential scope of engagements that can be undertaken by the IAA.

B.

The benefit of the IAA ' s organizational independence is realized primarily via reduced costs for the external auditor.

C.

Independence is impaired when the scope of the IAA is subject to changes required by senior management.

D.

Inadequate organizational independence can result in the chief audit executive being able to fire staff without consulting the audit committee.

Buy Now
Questions 65

To meet the resource requirements of this year’s internal audit plan, the chief audit executive (CAE) has recruited additional staff auditors, including an employee who resigned as a senior supervisor from the accounts payable department two months ago. There is a scheduled accounts payable review that the CAE wants to start within the next five months. Which approach should the CAE take, knowing the expertise of his new recruit in the area intended to be audited?

Options:

A.

Have the new internal auditor’s previous boss be excused from the area during fieldwork.

B.

Have the new internal auditor be responsible for the planning of the audit as well as the review of the audit fieldwork.

C.

Have the new internal auditor assigned to other responsibilities and not work on the accounts payable audit engagement.

D.

Have the new internal auditor assist with conducting the fieldwork, but ensure that her work is reviewed by the CAE.

Buy Now
Questions 66

During the planning stage of an assurance engagement, the engagement supervisor initially reviews the control environment to identify and examine possible fraud risks.

Which finding should be considered a potential red flag?

Options:

A.

Senior management reinforces the code of ethics.

B.

Senior management sets unattainable business targets.

C.

Senior management reiterates the whistleblowing policy.

D.

Senior management does not have a succession plan.

Buy Now
Questions 67

In which of the following scenarios is the internal auditor in conformance with The IIA ' s Code of Ethics and the Standards?

Options:

A.

The auditor testifies in front of a jury about an organization ' s fraudulent financial practices after receiving a subpoena

B.

Management has agreed to remedy a significant control deficiency, so the auditor excludes the deficiency from the engagement report

C.

The chief audit executive declines an assurance engagement in IT because the internal audit activity is not proficient in IT

D.

The auditor communicates an audit opinion on fraud risk during an audit engagement’s preliminary fraud risk assessment

Buy Now
Questions 68

A whistleblower reveals to the chief audit executive (CAE) detailed allegations of potential fraud at the senior management level. Although the CAE has some experience in the area, she chooses to retain an external fraud expert to conduct the investigation. When asked by the director of finance to defend the expenditure, which of the following statements represents the CAE ' s best response?

Options:

A.

The CAE refers to the Standards and explains that to protect her independence, she needs to remain isolated from the investigation.

B.

The CAE refers to the Standards and explains that the internal audit activity must obtain competent assistance if needed.

C.

The CAE refers to the Standards and explains that to protect her objectivity, she needs to remain isolated from the investigation.

D.

The CAE describes the specifics of the allegation to underscore the importance of the situation and the need for expert investigation

Buy Now
Questions 69

According to IIA guidance, which of the following activities would typically be examined when using the maturity model approach for assessing an organization ' s risk management program?

Options:

A.

Monitor and review

B.

Performance measurement.

C.

Setting the context.

D.

Communication.

Buy Now
Questions 70

According to IIA guidance, which of the following is the primary reason the chief audit executive discusses the internal audit charter with senior management and the board?

Options:

A.

To provide guidance and solicit feedback on managing the internal audit activity as expected by various stakeholders.

B.

To provide an understanding of the Mission of Internal Audit and The IIA ' s mandatory guidance elements.

C.

To provide an update on the internal audit activity ' s quality of engagement supervision.

D.

To provide information on existing internal audit planning, changes to the internal audit plan, and the rationale for the changes

Buy Now
Questions 71

As a result of a high-profile processing error, respective business unit managers are implementing new controls. The internal audit team was asked for their advice regarding the controls. The objective of this consulting engagement would be determined by which of the following?

Options:

A.

The organization ' s board of directors.

B.

The chief audit executive.

C.

The business unit manager and the engagement supervisor.

D.

The compliance manager and the business unit manager.

Buy Now
Questions 72

An organization sells products through distributors. The organization ' s chief audit executive insists that the organization ' s code of conduct be applicable to their distributors as well. Which of the following risks would this mitigate?

Options:

A.

Business continuity

B.

Market manipulation

C.

intellectual property leakage

D.

Reputational damage

Buy Now
Questions 73

Which of the following processes does the board manage to ensure adequate governance?

Options:

A.

Establish and measure performance objectives for the internal audit activity.

B.

Select board members with necessary knowledge and skills.

C.

Develop, approve, and execute the strategic plan of the organization.

D.

Develop strategies to mitigate the risks to achieving the organization’s objectives

Buy Now
Questions 74

Which of the following is an advantage of using nongovernmental organization (NGO) members on an assurance team when auditing corporate social responsibility?

Options:

A.

Typically less time is needed to train the NGO members on the audit process.

B.

NGO members are often more unbiased and objective

C.

A report with a positive statement from an NGO member is deemed to be more credible. As opposed to auditors.

D.

NGO members are licensed to audit corporate social responsibility.

Buy Now
Questions 75

To encourage internal audit objectivity, which of the following is an appropriate policy the chief audit executive should establish?

Options:

A.

Internal auditors should report their audit findings directly to the audit committee.

B.

To receive an outstanding performance rating, internal auditors are required to generate audit findings.

C.

Prior to hiring a new internal auditor, the chief audit executive must determine whether the auditor owns stock in the organization.

D.

Internal auditors are permitted to audit an entity managed by a close friend or relative, as long as they notify the chief audit executive.

Buy Now
Questions 76

An organization’s board of directors has decided that the internal audit activity must have greater access to different pans of the organization in order to perform their assurance work effectively Which of !he following areas is the board seeking to improve by making this change?

Options:

A.

Internal audit authority.

B.

Internal audit reporting structure.

C.

Internal audit independence and objectivity.

D.

Internal audit interaction with the board

Buy Now
Questions 77

Which of the following is the most appropriate way to ensure that a newly formed internal audit activity remains free from undue influence by management?

Options:

A.

Appoint the chief audit executive as a member of the board.

B.

Adopt written policies and procedures for the internal audit activity, approved by the board.

C.

Ensure the chief audit executive reports administratively to the audit committee.

D.

Establish the internal audit activity’s position within the organization in an audit charter.

Buy Now
Questions 78

The internal audit activity was denied access to expenditure and budget reports because they were considered to be confidential. This situation would result in which of the following limitations of the internal audit activity?

Options:

A.

Independence

B.

Integrity

C.

objectivity

D.

Authority

Buy Now
Questions 79

An engagement supervisor obtains facilities maintenance reports from a contractor during an audit of third-party services. Which of the following is the source of authority for the engagement supervisor to make such contact outside the organization?

Options:

A.

The policies and procedures of the internal audit activity.

B.

The provisions of the internal audit charter.

C.

The authority of the CEO.

D.

The IIA ' s Code of Ethics.

Buy Now
Questions 80

Senior management requested that the internal audit function conduct an advisory engagement to evaluate the design and implementation of the project for setting up a new accounting system.

Which approach should the auditors perform that relates only to an advisory engagement?

Options:

A.

Collaborate with senior management to define the objective and scope of the engagement rather than completing a risk assessment.

B.

Identify the criteria to be used to evaluate the aspects of the activity under review defined in the engagement objectives.

C.

Include in the engagement conclusions the auditors’ judgment regarding the effectiveness of governance, risk management, and control processes.

D.

Identify the types and quantity of resources necessary to achieve the engagement objectives.

Buy Now
Questions 81

Which of the following should be part of the internal audit activity ' s duties?

Options:

A.

Actively reporting to the governing body.

B.

Providing risk management frameworks.

C.

Assisting management in developing processes and controls to manage risks and issues.

D.

Identifying and mitigating significant risks to the organization.

Buy Now
Questions 82

According to IIA guidance, which of the following is the strongest indicator of deficiencies in the risk management process?

Options:

A.

The periodic evaluation of risk ratings is primarily dependent on subjective assessments.

B.

Separate evaluations of the risk management process were conducted, but the results were never integrated.

C.

Management ' s primary objective is minimizing changes to the structure and operation of the risk management process.

D.

Many aspects of the related enterprise risk management program are informal and undocumented.

Buy Now
Questions 83

Which of the following procedures will best help an internal auditor assess operating effectiveness of fraud prevention and detection controls?

Options:

A.

Benchmarking best practices

B.

Testing,

C.

Mapping,

D.

Interviewing

Buy Now
Questions 84

Which of the following is considered to be a threat to the internal auditor ' s objectivity?

Options:

A.

The auditor drafted the operational procedures of the area that she is currently auditing.

B.

The auditor received a bonus that was approved by the board of directors.

C.

The assigned auditor recommended operational procedures for the organization.

D.

The assigned auditor rotated out of the same business activity three years ago

Buy Now
Questions 85

Which of the following is the primary benefit of establishing a formal training program for the internal audit activity?

Options:

A.

It is useful to reinforce the independence of the internal audit activity.

B.

It is useful to guide internal auditors as they perform specific engagements.

C.

It is useful to maintain the skills and competencies of internal audit staff.

D.

It is useful to measure the effectiveness and maturity of the internal audit activity.

Buy Now
Questions 86

During a payroll audit, a staff internal auditor suspects that signatures on some of the documents being sampled for examination are not authentic. Which of the following actions should the auditor take before proceeding with the examination?

Options:

A.

Suggest to the payroll manager that the suspicious documents should be sent to the organization ' s security department for forensic review.

B.

Keep the suspicious documents in the workpaper file until the end of the engagement, and then discuss the suspicions with the payroll manager.

C.

Discuss the suspicious documents with payroll staff to seek their views on the authenticity of the signatures.

D.

Review the suspicious documents with the chief audit executive and seek advice concerning further examination.

Buy Now
Questions 87

Which of the followIng would permit an internal audit activity to use the statement " conducted m conformance with the International Standards for the Professional Practice of Internal Auditing m audit reports?

Options:

A.

The result of a quality assurance and improvement program confirm there are no material issues.

B.

Engagement workpapers are retained by the internet audit activity according to the retention and deletion policy.

C.

The internal audit activity receives positive feedback from the managers of the areas that were under review.

D.

internal auditors demonstrate proficiency by maintaining professional internal audit certifications

Buy Now
Questions 88

Which of the following is an example of impairment to internal auditor independence or objectivity ' ?

Options:

A.

Assurance engagements for functions over which the chief audit executive (CAE) has responsibility are overseen by a party outside the internal audit activity

B.

Internal auditors provide consulting services relating to operations for which they had previous responsibilities

C.

Internal auditors provide consulting services relating to operations for which they have current responsibilities

D.

Consulting engagements for functions over which the CAE has responsibility are overseen by a party outside the internal audit activity

Buy Now
Questions 89

Which of the following is most likely to result in the impairment of independence for the internal audit activity?

Options:

A.

The chief audit executive (CAE) has a dual reporting relationship within the organization.

B.

The CAE performs an audit of a functional area that is also under the CAE ' s oversight.

C.

The CAE has unrestricted access to information throughout the organization and to the board.

D.

The board is involved in decisions to hire or remove the CAE and in drafting and approving an internal audit charter.

Buy Now
Questions 90

Which of the following documents would promote objectivity within an organization ' s internal audit activity?

Options:

A.

Internal audit charter.

B.

Internal audit manual.

C.

Audit committee charter

D.

Human resources employee handbook.

Buy Now
Questions 91

In its five years of existence, an internal audit activity conducted a single internal assessment of its quality assurance and improvement program (QAIP). The results of that assessment showed that the internal audit activity did not conform with the Standards. Prior to this, an external assessment of the internal audit activity ' s QAIP was conducted, which reported that the internal audit activity was in conformance with the Standards. Considering the two assessments, what would be the internal audit activity ' s current state of conformance with the Standards?

Options:

A.

Conformance with the Standards.

B.

Nonconformance with the Standards

C.

Unable to determine conformance with the Standards.

D.

Partial conformance with the Standards

Buy Now
Questions 92

Which of the following would be considered an indicator that an organization ' s ethics program is not yet well developed?

Options:

A.

Disciplinary actions for ethics compliance violations are reviewed by the internal audit activity for consistency.

B.

Communication of ethics compliance expectations is the responsibility of employees ' direct managers.

C.

The organization ' s code of ethics and related compliance policy are reviewed annually for potential updates.

D.

The board of directors reviews ethics oversight metrics for violations and compliance.

Buy Now
Questions 93

According to IIA guidance, which of the following best describes the chief audit executive s responsibility for confirming to the board the organizational independence of the internal audit activity ' ?

Options:

A.

The CAE must do this at least annually

B.

The CAE must do this at least once every five years

C.

The CAE must do this upon completion of each external quality assessment

D.

The CAE should do this periodically in conjunction with a review of the internal audit charter

Buy Now
Questions 94

An internal auditor interviews for a position within the organization’s IT department while simultaneously conducting an audit of the area’s ability to manage the organization’s user network accounts.

This presents a conflict of which of the following principles?

Options:

A.

Confidentiality.

B.

Objectivity.

C.

Competency.

D.

Integrity.

Buy Now
Questions 95

Which of the following most accurately describes the role of the board when it comes to organizational governance?

Options:

A.

Responsibility for outcome of the process.

B.

Responsibility to be involved in management of the organization.

C.

Responsibility to determine who is accountable for outcomes.

D.

Responsibility to identify risks in the organization’s business environment

Buy Now
Questions 96

An engagement supervisor noticed that a newly hired internal auditor struggles with large data samples because he appears reluctant to apply available spreadsheet statistical functions and tends to perform testing of transactions manually In which of the following areas does the internal auditor most likely need training?

Options:

A.

Critical thinking.

B.

International Professional Practices Framework

C.

Professional ethics

D.

Business acumen

Buy Now
Questions 97

Which of the following would be a red flag for potential issues in the control environment?

Options:

A.

Segregation of duties during preparation of the financial statements

B.

Compensation structures that are based on commissions

C.

A low rate of turnover in key financial positions

D.

The presence of a whistleblower policy and fraud hotlinea

Buy Now
Questions 98

Which of the following should be considered in developing a risk and control model for use in an engagement?

Options:

A.

The risk and control model should be globally accepted by the profession.

B.

The risk and control model should be strictly adhered to in performing the engagement.

C.

The risk and control model should be tailored to the organization that will be the subject of the engagement.

D.

The risk and control model should be developed individually by the auditor for use on individual audit projects within the planned engagement.

Buy Now
Questions 99

Which of the following types of policies best helps promote objectivity in the interna! audit activity ' s work?

Options:

A.

Policies that are distributed to all members of the internal audit activity and require a signed acknowledgment,

B.

Policies that match internal auditors ' performance with feedback from management of the area under review.

C.

Policies that keep internal auditors in areas where they have vast audit expertise.

D.

Policies that provide examples of inappropriate business relationships.

Buy Now
Questions 100

The management team of an agricultural organization has prioritized corporate social responsibility (CSR) initiatives. Which of the following would be considered a CSR activity?

Options:

A.

Offering a one-off donation to an environmental charity for its expansion efforts

B.

Organizing organization volunteers to provide periodic plantation skill sharing to farmers

C.

Providing special year-end monetary bonuses to the organization ' s employees at all levels

D.

Arranging a free-of-charge picnic for all of the organization ' s employees and their family members

Buy Now
Questions 101

During an audit of the purchasing department, an internal auditor identifies significant issues that could affect the organization ' s financial reporting. Management disagrees with the audit results. Which of the following responses best demonstrates the internal auditor has the necessary competencies related to professional Judgment and conflict management?

Options:

A.

The auditor maintains his convictions and continues to proceed with the review process despite management ' s concerns related to the results.

B.

The auditor bypasses management, discusses the results with the board, and seeks the board ' s input on how best to address the recommendations.

C.

The auditor consults with other members of the audit team, and together they develop alternative recommendations that management may be more likely to accept.

D.

The auditor meets with management to discuss the results and obtain a better understanding of the specific concerns.

Buy Now
Questions 102

According to NA guidance, which of the following conditions would enhance the independence of the internal audit activity?

Options:

A.

The organizational culture rewards critical and objective thinking.

B.

The quality of work performed by the internal audit activity is periodically reviewed,

C.

The organization establishes effective governing body oversight,

D.

Audit assignments are rotated among internal audit staff

Buy Now
Questions 103

Which of the following is an example of a risk avoidance strategy?

Options:

A.

Outsourcing the payroll function

B.

Installing cameras in the mailroom

C.

Exiting a product line

D.

Insuring all fixed assets

Buy Now
Questions 104

According to IIA guidance, which of the following statements is true regarding the internal audit activity’s responsibilities in providing consulting services?

Options:

A.

The chief audit executive is responsible for deciding the priority of consulting services in the internal audit plan

B.

The scope of consulting services is determined primarily by the internal auditor with input from management of the area under review

C.

The board defines the internal audit activity’s responsibilities over consulting activities

D.

Adding value to an organization requires the internal audit activity to initiate a consulting engagement

Buy Now
Questions 105

Which of the following internal control attributes would an internal auditor test to understand whether organizational structure supports effective internal control?

Options:

A.

Incentives and compensation practices.

B.

Tone at the top.

C.

Risk management oversight.

D.

Internal reporting responsibilities.

Buy Now
Questions 106

Anew internal auditor suspects fraud is taking place. Which action should the new auditor take?

Options:

A.

Collect relevant audit evidence and begin working with management of the area to investigate the fraud.

B.

Inform the chief audit executive and meet with the suspect to determine whether the person committed fraud.

C.

Document supporting information and recommend an investigation to the appropriate audit management.

D.

Evaluate existing controls and implement new procedures to mitigate the opportunity for fraud.

Buy Now
Questions 107

Management assessed the organization’s risk of expanding operations into a new, but volatile, region and began looking for a compatible local partner to manage sales and distribution. Which of the following best describes this risk management technique?

Options:

A.

Avoidance.

B.

Acceptance.

C.

Reduction.

D.

Sharing

Buy Now
Questions 108

During an assurance engagement, an internal auditor uses benchmarking research to support preparation of a report to stakeholders that contains significant findings about control deficiencies. Which of the following skills did the auditor demonstrate?

Options:

A.

Internal audit management.

B.

Conflict negotiation.

C.

Critical thinking.

D.

Persuasion and collaboration.

Buy Now
Questions 109

Which of the following activities should the chief audit executive perform to ensure compliance with an organization ' s code of conduct?

Options:

A.

Act as an advisor to the committee responsible for reviewing violations of the code.

B.

Review and adjudicate all violations of the code of conduct.

C.

Lead the committee responsible for the oversight of the code.

D.

Implement a system of procedures to inform all employees of the code.

Buy Now
Questions 110

Which of the following primarily sets the foundation for effective corruption risk mitigation?

Options:

A.

A strong ethical culture.

B.

A competent internal audit function.

C.

A formal code of ethics.

D.

An appropriate risk management framework.

Buy Now
Questions 111

An internal auditor is updating the risk register for risks identified during a recent organizational risk assessment. According to the Standards, which of the following would the auditor include in the risk register?

Options:

A.

Management’s acceptance of inadequate controls for cybersecurity risk.

B.

Discussions with senior management relating to a new revenue stream.

C.

Mitigating controls implemented by the engagement supervisor

D.

Project manager planned hours versus time spent for all prior year projects

Buy Now
Questions 112

Which of the following is a primary responsibility of senior management with respect to ethical violations?

Options:

A.

Senior management provides oversight for the organization ' s ethical climate.

B.

Senior management promotes an ethical culture in the organization.

C.

Senior management assesses the effectiveness of the organization’s ethical programs.

D.

Senior management reviews major ethical policies in the organization for compliance

Buy Now
Questions 113

Which of the following is the best reason why the engagement supervisor should take care in explaining to local management the criteria that will be used to measure the effectiveness of the control environment?

Options:

A.

The assessment will cover soft controls and company values.

B.

The assessment will focus on the policy for a particular process.

C.

The assessment will lack a defined scope

D.

The assessment will probably uncover fraud risks.

Buy Now
Questions 114

At what point in time can an organization conclude that the established organizational governance framework was correctly implemented?

Options:

A.

When the internal auditor conducts observations and fieldwork.

B.

When management completes the risk assessment.

C.

When the internal auditor evaluation shows its soundness.

D.

When the organization ' s goals and objectives are met.

Buy Now
Questions 115

Which of the following actions should the audit committee take to promote organizational independence for the internal audit activity?

Options:

A.

Delegate final approval of the risk-based internal audit plan to the chief audit executive (CAE).

B.

Approve the annual budget and resource plan for the internal audit activity.

C.

Assist the CAE with hiring objective and competent internal audit staff.

D.

Encourage the CAE to communicate and coordinate with the external auditor.

Buy Now
Questions 116

When performing an audit of the risk management process an auditor makes the observations listed below. Which poses the greatest risk to the organization?

Options:

A.

The identified risks have not undergone a detailed review to ensure completeness in the past two years.

B.

The controls in place to mitigate the risks are not tested on an annual basis to confirm operating effectiveness.

C.

The process in place to identify and evaluate new risks to the organization is informal and poorly documented.

D.

The identified risks have not been ranked to establish their importance and risk management priority.

Buy Now
Questions 117

During a monthly internal audit staff meeting, the chief audit executive (CAE) decided to reinforce the importance of internal audit staff being objective in their work. Which of the following examples would be most appropriate for the CAE to include as part of the meeting presentation?

Options:

A.

Statistical sampling techniques should always be used to pull unbiased sampling for testing.

B.

Fieldwork completed by internal auditors should be appropriately reviewed.

C.

Internal auditors should avoid using the lunch room simultaneously with audit clients.

D.

During the audit review period, there should be no nonaudit dialogues with the audit client.

Buy Now
Questions 118

An internal auditor has suspicions that some fictitious vendors have been created in the organization ' s computer system. Which of the following would be the best technique to detect this fraud?

Options:

A.

Review for duplicate invoice numbers, duplicate dates, and duplicate amounts

B.

Run checks to find matches between vendor and employee addresses

C.

Check for recurring requests for refunds where invoices are paid twice

D.

Review for unexplained increases in inventory

Buy Now
Questions 119

Which of the following statements is the most appropriate for a chief audit executive to include in the internal audit policy manual in order to promote objectivity?

Options:

A.

Internal auditors may conduct a financial effectiveness engagement in a business unit at any point after being transferred from that area.

B.

Internal auditors may conclude that a business unit ' s current control environment is adequate and effective if the review of the prior year ' s workpapers and audit report supports that conclusion.

C.

Internal auditors may conduct an engagement in a business unit at any point after providing a training workshop in that area.

D.

Internal auditors should limit the scope of an engagement if they become aware of a potential impairment of their objectivity in order to reduce the potential impact of the impairment on the engagement results.

Buy Now
Questions 120

Which of the following are some of the requirements of the quality assurance and improvement program (QAIP)?

Options:

A.

The OAIP should be conducted at least once every three years, and must be performed by an external assessor.

B.

The OAIP should be conducted on an ongoing basis, and can be completed as a self-assessment,

C.

he QAIP should include both internal assessments performed by staff and external assessments performed by independent, objective individuals

D.

The OAIP should be performed with scoping limitations established by the board.

Buy Now
Questions 121

Which of the following would likely have the greatest influence on the long-term quality of an organization’s control environment?

Options:

A.

Regulatory compliance.

B.

Business performance.

C.

Financial reconciliations.

D.

Accountability structure.

Buy Now
Questions 122

Nine months ago, an employee who was responsible for collections in the accounts receivables department joined the internal audit team. There is an accounts receivables assurance audit scheduled as part of this year ' s approved audit plan, which will include a review of the collections unit. With the knowledge and experience of this individual in the area, which of the following is the best approach for the chief audit executive (CAE) to take?

Options:

A.

Have the auditor formerly with the collections unit assist with planning and documenting the audit field work.

B.

Have the auditor formerly with the collections unit not participate on the audit team.

C.

Have the auditor formerly with the collections unit conduct the fieldwork and ensure it is reviewed by the CAE.

D.

Have the auditor formerly with the collections unit review all fieldwork done to ensure that there was adequate coverage.

Buy Now
Questions 123

Which of the following statements is true regarding organizational culture and an audit of the control environment?

Options:

A.

For multinational organizations it is important to ensure that the organizational culture is consistent at all locations

B.

Because the chief audit executive (CAE) is part of the organizational culture, external auditors should be engaged to evaluate the control environment

C.

If there are unresolved scope restrictions, the CAE should consider whether to pursue the audit and note the scope restrictions in the audit report

D.

Because it will create a conflict of interest relating to the control environment, senior management should not be consulted during the audit

Buy Now
Questions 124

Which of the following functions does an internal audit charter serve?

Options:

A.

It provides a formal, written agreement with management and the board regarding the organization’s internal audit function.

B.

It provides all internal auditors with unlimited access to records, personnel, and physical property.

C.

It provides senior management with formal criteria for periodic assessments of the adequacy of the internal audit function’s purpose, authority, and responsibility.

D.

It provides the internal audit function with the authority to perform any fraud investigation engagement that can enhance or protect the value of the organization.

Buy Now
Questions 125

The internal audit activity is responsible for which of the following actions related to an organization’s internal controls?

Options:

A.

Mitigating risks affecting achievement of organizational objectives.

B.

Enabling opportunities affecting achievement of organizational objectives.

C.

Analyzing and advising regarding costs versus benefits of control activities,

D.

Attesting to fairness of financial statements.

Buy Now
Questions 126

Which of the following statements is true regarding the role of the internal audit activity in the organization ' s risk management process?

Options:

A.

The internal audit activity should not be responsible for developing the organization ' s risk management framework, even with appropriate safeguards.

B.

The internal audit activity is typically responsible for alerting operational management to emerging risks and changes in regulatory scenarios

C.

The internal audit activity may coach management on risk response scenarios if safeguards have been implemented.

D.

The internal audit activity should avoid giving assurance regarding the accuracy of risk evaluations if safeguards have not been implemented.

Buy Now
Questions 127

Which of the following situations would best indicate to the chief audit executive that one of the audit team members is struggling with application of due professional care?

Options:

A.

The engagement supervisor requests that an auditor carry out improvements to workpapers to address numerous problems: evidence is missing, references are incorrect, and conclusions are superfluous

B.

Audit work was completed m accordance with the established goals; however, a material misstatement was later uncovered in the audited area by another assurance provider.

C.

According to the audit report, several control failures occurred due to irresponsible behavior of local management, who was consequently deprived of bonuses and wrote a negative feedback to the auditor

D.

The delivery of audit results was several weeks late because the internal auditor had to spend additional time trying to understand the nature of certain transactions with derivation.

Buy Now
Questions 128

Which of the following actions should the organization ' s governing body perform to provide the most effective governance over the organization ' s culture?

Options:

A.

Coordinate control activities.

B.

Provide direction.

C.

Design key controls.

D.

Deliver assurance.

Buy Now
Questions 129

Which of the following specifications in an internal audit charter is the most important factor in the internal audit activity’s independence?

Options:

A.

Description of internal audit activity ' s responsibilities

B.

Definition of internal auditing

C.

Statement of internal audit activity ' s authority

D.

Description of internal audit activity ' s reporting structure

Buy Now
Questions 130

Which of the following would best illustrate to the chief audit executive that due professional care was exercised by internal auditors during an engagement?

Options:

A.

Internal auditors gave assurance that no irregularities existed.

B.

Internal auditors had the knowledge and skills needed.

C.

Internal auditors assigned were sufficient and appropriate.

D.

Internal auditors considered the use of data analysis techniques.

Buy Now
Questions 131

An internal auditor was offered expensive tickets to a sporting event by the manager of an area that she was currently auditing. The auditor politely declined. Which of the following fundamental principles of the MA Code of Ethics did she display?

Options:

A.

Confidentiality.

B.

Independence.

C.

Competency.

D.

Objectivity

Buy Now
Questions 132

In a small organization, management is unable to achieve adequate segregation of duties for its cash-handling procedures Therefore hidden surveillance cameras were installed to monitor cash-handling activities Which of the following best describes this type of control?

Options:

A.

Corrective control

B.

Process-level control

C.

Compensating control

D.

Preventive control

Buy Now
Questions 133

A new CEO authorizes a vendor’s access to the organization’s vendor payment and contracting database as part of a review to identify wasteful spending. An employee in the contracting department raised concerns to the internal audit function about potential fraud involving the vendor’s access to the database’s sensitive information, including that of the vendor’s competitors.

Which is a potential fraud risk that requires special consideration during an internal audit engagement?

Options:

A.

The new CEO hired the vendor to perform work that the internal audit function could have performed.

B.

Vendor employees may not have been properly screened for database security clearance.

C.

The vendor has read-only access to all of the organization’s payments and contracting database.

D.

The vendor uses information from the database to gain information about services provided.

Buy Now
Questions 134

According to HA guidance, which of the following is true regarding independence and objectivity for small internal audit activities?

Options:

A.

The chief audit executive (CAE) may consider including a disclaimer on independence in audit reports.

B.

The CAE may consider greater involvement of those with suitable knowledge of audit practice.

C.

Conformance with this Standard is not dependent upon the size of the internal audit activity.

D.

Due to the small size of the internal audit activity, having an external assessment once every seven years is acceptable.

Buy Now
Questions 135

What controls could be implemented as a preventive measure against malicious insider threats, such as an unauthorized employee obtaining electronic customer sales information and later selling them to a competitor?

Options:

A.

Role-based access controls.

B.

Visitor management system controls.

C.

Network firewall prevention controls.

D.

Information classification controls.

Buy Now
Questions 136

Which of the following would be the most appropriate first step for the board to take when developing an effective system of governance?

Options:

A.

Determine the organization’s overall risk appetite.

B.

Establish a governance committee.

C.

Delegate authority to members of senior management.

D.

Identify key stakeholders and their expectations

Buy Now
Questions 137

Which of the following statements represents the most appropriate correlation between an organization ' s risk maturity and the internal audit activity’s consulting role in risk management processes?

Options:

A.

When an organization has a high level of risk maturity the internal audit activity is less likely to provide consulting services related to risk management

B.

When an organization has a low level of risk maturity, the internal audit activity is less likely to provide consulting services related to risk management

C.

When an organization has a high level of risk maturity the internal audit activity is more likely to provide consulting services related to risk management

D.

There is typically no correlation between an organization’s risk maturity and the extent to which the internal audit activity’s consulting role in risk management processes

Buy Now
Questions 138

To comply with the proficiency standard which of the following would the chief audit executive likely consider as the primary hiring criterion when choosing a new internal auditor?

Options:

A.

The length and consistency of the auditor ' s work experience

B.

The auditor ' s demonstrated problem-solving skills

C.

The auditor ' s skills compared to those already possessed by other audit staff

D.

The auditor ' s ability to be self motivated and a good team player

Buy Now
Questions 139

During an audit of a foreign subsidiary an internal audit team discovered that products were sold to a prohibited country due to sanctions. What is the best course of action for the internal audit team?

Options:

A.

Include the facts m the engagement communications

B.

Inform me external auditors of the violation.

C.

Report the violation to the government regulators

D.

Consult with the legal department

Buy Now
Questions 140

It is important for the chief audit executive to consider the level of competence of the internal audit staff because their competence influences which of the following?

Options:

A.

The cost-benefit relationship of planned audits.

B.

Proficiency needed to carry out engagements.

C.

Achievement of the objectives of internal control.

D.

Quantity of the audits performed.

Buy Now
Questions 141

When would on-the-job training be more effective?

Options:

A.

When participants already have a certain degree of experience and knowledge.

B.

When it makes up the largest part of the training budget.

C.

When it includes ongoing feedback and coaching from experienced team members.

D.

When it is standardized for the whole entire staff.

Buy Now
Questions 142

According to IIA guidance, which of the following actions best demonstrates that due professional care has been considered by the internal audit activity when conducting a review of an organization ' s assets?

Options:

A.

Determining whether any opportunity exists for senior executives to misappropriate property or funds

B.

Planning and executing fieldwork In a complete and timely manner to identify all significant risks

C.

Verifying whether the board of directors has implemented effective internal controls

D.

Having senior management determine whether the degree of work planned is sufficient to meet engagement objectives

Buy Now
Questions 143

Nearing the completion of fieldwork, an internal auditor shared the draft report findings with management prior to the closing meeting. During the closing meeting, management expressed dissatisfaction in that they were not familiar with some of the findings. Management also noted that some aspects of the report seemed confusing. Which of the following competencies appears to have been lacking in this scenario?

Options:

A.

Communication.

B.

Business acumen.

C.

Persuasion.

D.

Critical thinking.

Buy Now
Questions 144

The chief audit executive (CAE) has hired a new internal auditor who was immediately assigned to a procurement function audit. Because the new auditor ' s name is similar to that of the procurement manager, some staff members think the two are related, although they are not. Which of the following actions is most appropriate for the CAE to take?

Options:

A.

Take no action, as there is no impairment to independence.

B.

Remove the new internal auditor from the engagement team.

C.

Discuss the matter with the appropriate personnel to alleviate concerns.

D.

Closely supervise the new auditor and carefully review his work.

Buy Now
Questions 145

Which of the following should the internal audit activity establish to ensure auditors develop the appropriate skills for conducting audits?

Options:

A.

An audit charter that includes the internal audit activity mission and vision

B.

A policy encouraging audit staff to earn certifications

C.

A quality assurance and improvement program to address audit risk areas

D.

An internal audit plan that links engagements to strategic objectives

Buy Now
Questions 146

According to IIA guidance, which of the following is accurate regarding the chief audit executive ' s (CAE ' s) requirement to report the results of quality assessments?

1. The CAE must report the results of external assessments at least annually.

2. The CAE must report the results of ongoing monitoring at least annually.

3. The CAE must report the results of quality assessments to senior management.

4. The CAE must report the results of quality assessments to the board.

Options:

A.

1 and 3 only.

B.

2 and 4 only.

C.

1,2. and 3.

D.

2,3, and 4.

Buy Now
Questions 147

An internal auditor is finalizing an audit report on the effectiveness of the organization ' s overall system of internal control. Several audit tests were performed, and the only issue identified was that the CEO frequently asks employees to make exceptions or bypass the organization ' s standard written policies and procedures. Which of the following conclusions is most appropriate for the auditor to report?

Options:

A.

The auditor should indicate that the system of internal control is not effective.

B.

The auditor should indicate that the system of internal control is generally effective, except for the minor issue identified.

C.

The auditor should indicate that the system of internal control is effective.

D.

The auditor cannot express a conclusive opinion in the audit report.

Buy Now
Questions 148

Which of the following is a way to demonstrate an individual internal auditor ' s competency through continuing professional development?

Options:

A.

Create different training budgets for each of the internal auditors

B.

Define average training hours per auditor as a team performance measure

C.

Analyze internal audit client survey feedback following audits

D.

Review training records for all internal auditors

Buy Now
Questions 149

According to IIA guidance, which of the following is a required aspect of an internal audit charter?

Options:

A.

Management approval

B.

Independent review

C.

Reporting relationships

D.

Quarterly assessment

Buy Now
Questions 150

While conducting an engagement in the procurement department, the internal auditor noticed that the department head’s travel reports showed minor travel expenses, and there were no charges for hotels, meals, or transportation. However, the auditor knew that the department head frequently traveled worldwide to meet with suppliers and visit their production sites. Which of the following would be the most appropriate next step for the auditor?

Options:

A.

The auditor should make a note of the issue for follow-up when employee travel expenses are audited.

B.

The auditor should analyze trends and changes among the organization’s suppliers over the past few years.

C.

The auditor should investigate whether there are any special arrangements regarding senior management travel.

D.

The auditor should analyze the list of destinations the department head visited to estimate typical costs.

Buy Now
Questions 151

Which of the following would provide the best support for internal auditors to meet their continuing professional development requirements?

Options:

A.

Access to online internal audit and business skills courses.

B.

Records of self-assessment reports completed by the internal audit staff.

C.

Cosourcing arrangements with external providers on specific engagements.

D.

Performance reviews comparing internal auditors ' achievements against specified goals.

Buy Now
Questions 152

An internal auditor was completely honest with operational management when delivering unfavorable audit results. Which of the following best describes the IIA Code of Ethics principle that the auditor demonstrated?

Options:

A.

Integrity

B.

Objectivity

C.

Competency

D.

Transparency

Buy Now
Questions 153

According to HA guidance, if an internal auditor suspects fraud during an assurance engagement, what should the auditor do first?

Options:

A.

Recommend parties involved to be sanctioned in accordance with the organization ' s policy.

B.

Determine whether any additional audit work needs to be performed.

C.

Launch an investigation to obtain details of the fraud and parties involved.

D.

Request that the responsible process owner remediate the issue immediately.

Buy Now
Questions 154

According to NA guidance, which of the following describes the primary reason to implement environmental and social safeguards within an organization?

Options:

A.

To enable Triple Bottom Line reporting capability.

B.

To facilitate the conduct of risk assessment.

C.

To achieve and maintain sustainable development.

D.

To fulfill regulatory and compliance requirements.

Buy Now
Questions 155

Which of the following statements is true regarding the disclosure of results of the quality assurance and improvement program?

Options:

A.

If the results of both internal and external assessments support conformance with the Standards, the internal audit activity must communicate this to the board and senior management in writing.

B.

If it has been in existence fewer than five years and has no documented external assessment, the internal audit activity may not indicate that it is operating in conformance with the Standards.

C.

If nonconformance affects its ability to fulfill its professional responsibilities or stakeholder expectations, the internal audit activity should disclose nonconformance as well as its impact.

D.

If an external assessment reflects an overall conclusion of nonconformance, the internal audit activity may continue to communicate that it conforms with theStandards if it discloses a remediation plan, including timeline with subsequent validation.

Buy Now
Questions 156

Which of the following is true regarding internal audit role ' s in The IIA ' s Three Lines Model?

Options:

A.

As internal control is part of risk management, the internal audit role in risk management implies reduced emphasis on internal control.

B.

Internal audit can blur the distinction between the second and the third lines as long as value is added.

C.

Internal audit cannot rely on other assurance providers when opining on the effectiveness of risk management.

D.

Internal audit should be aligned with first- and second-line functions through effective communication, cooperation, and collaboration.

Buy Now
Questions 157

A new internal auditor was recently recruited to the internal audit activity from the organization ' s finance department. What is likely to be the chief audit executive’s greatest concern regarding assigning the new auditor to upcoming audits in the finance department?

Options:

A.

The time it may take the new auditor to complete the assignment and report the findings to management.

B.

The qualifications of the new auditor and whether the auditor ' s business knowledge is relevant to the assignment.

C.

The potential for a conflict of interest to exist or appear to exist if the new auditor undertakes these assignments.

D.

The knowledge the new auditor may have of control weaknesses in the finance department.

Buy Now
Questions 158

An electric company hires several independent contractors to trim trees that are in close proximity to electricity lines. Which of the following would be the most effective control to mitigate the risk of contractors submitting fraudulent invoices regarding work completed?

Options:

A.

Require contractors to submit completed and signed work acceptance sheets

B.

Utilize unmanned drones to conduct regular flights and photo shoots over the areas where work is performed

C.

Reconcile invoices and work acceptance sheets submitted by contractors

D.

Compare actual payments to contractors with budgeted values and analyze discrepancies

Buy Now
Questions 159

Which of the following actions by the chief audit executive (CAE) best describes a potential impairment to the internal audit function’s independence?

Options:

A.

Providing comparative remuneration data to the board during the CAE’s salary negotiations.

B.

Accepting management’s request to reschedule an audit engagement due to key staff absences.

C.

Reducing the scope of several engagements in response to a 15 percent budget cut imposed by senior management.

D.

Deferring consultation engagements to ensure key assurance audits are delivered on time.

Buy Now
Questions 160

Which of the following is included in the risk identification process?

Options:

A.

Screening for the impact and likelihood or whether the risk is controllable.

B.

Weighing the likelihood that an event or condition will happen.

C.

Disclosing all plausible events or conditions that could occur.

D.

Determining controllability of an event or condition.

Buy Now
Questions 161

An internal auditor was assigned to work in the procurement department for six months to gam m-depth knowledge about the procurement process. Which of the following personnel development practices was applied in this situation?

Options:

A.

Cosourcing

B.

Inbound rotation

C.

Guest auditor

D.

Outbound rotation

Buy Now
Questions 162

After being assigned to an audit of the accounts payable process, an internal auditor privately notifies the chief audit executive that she is a finalist for an open manager position within the accounts payable department. Which of the following is the IIA Code of Ethics principle that the auditor upheld?

Options:

A.

Independence.

B.

Confidentiality.

C.

Objectivity.

D.

Competency

Buy Now
Questions 163

Evidence discovered during the course of an engagement suggests that multiple incidents of fraud have occurred. There do not appear to be sufficient controls in place to prevent reoccurrence. Which of the following is the internal auditor ' s most appropriate next step?

Options:

A.

Immediately notify management of the area under review and the other internal auditors involved in the engagement.

B.

Discuss the situation with the engagement supervisor to determine whether fraud investigation experts are required to investigate the matter properly.

C.

Fully document in the workpapers the evidence that has been discovered and recommend appropriate controls to address the fraud.

D.

Provide the evidence that was discovered to local law enforcement for possible prosecution of the suspected fraud.

Buy Now
Questions 164

Which of the following scenarios would most significantly restrict the areas where internal audit could perform assurance services?

Options:

A.

Regulators mandate specific audit engagements to be included in the audit plan.

B.

The internal audit activity reports functionally to the chief financial officer

C.

The internal audit activity reports administratively to the CEO and functionally to the audit committee.

D.

The internal audit activity reports administratively to the chief financial officer.

Buy Now
Questions 165

Recently an organization’s internal audit activity discovered ghost employees who receive payments Senior management decides to strengthen the internal control measures to address this Which of the following is considered an effective control to mitigate payments to ghost employees?

Options:

A.

Staff transfers are reviewed by the recruiting manager and approved by the head of human resources

B.

New staff requisition forms are authorized by operational management and acknowledged by the head of human resources

C.

Staff salary payments and accounting records are approved by the head of accounting and acknowledged by the head of human resources

D.

The staff salary payment list is reviewed by the head of payroll and endorsed by the head of human resources

Buy Now
Questions 166

During an assurance engagement internal auditors interview operational management to gather and evaluate information. Which approach is most important for internal auditors to be able to listen effectively to interviewees in the given situation?

Options:

A.

Make an audio recording of the interview

B.

Interrupt with questions during unclear statements

C.

Express interest by asking follow-up questions

D.

Avoid periods of silence

Buy Now
Questions 167

Applying ISO 31000, which of the following is part of the external context for risk management?

Options:

A.

Risk treatment method based on risk evaluation.

B.

Organizational culture, objectives, and processes.

C.

The regulatory and competitive environment

D.

The method of determining the risk level.

Buy Now
Questions 168

In which of the following situations may the internal audit activity report conformance with the Standards?

Options:

A.

An internal audit activity has been in existence at least five years and has not completed an external assessment,

B.

An internal auditor was assigned to an audit engagement but did not meet individual objectivity requirements.

C.

The internal audit activity prepared an internal audit plan that was not risk-based.

D.

The internal audit activity has been in existence fewer than five years, but periodic self-assessments were conducted.

Buy Now
Questions 169

During a brainstorming session, employees stated that dishonest vendors could submit fictitious invoices to the organization, and such an invoice may be authorized for payment because the employees responsible might be clicking approval boxes without going into the details.

Given this information, which of the following controls should be tested during the audit engagement?

Options:

A.

Confirmation of receipt of goods or services.

B.

Automatic processing of approved payments to the bank.

C.

Segregation of duties in accounts payable.

D.

Detection of preferential treatment of vendors.

Buy Now
Questions 170

During an audit engagement of a large retail store, internal auditors noted significant discrepancies between available inventory and sales and suspect an abuse of cash register refunds and voids. Which of the following would be the most effective preventative control to reduce these losses?

Options:

A.

Ensure that returned merchandise is restocked to shelves or sent to the manufacturer by an independent employee.

B.

Call a sample of customers who returned merchandise to test the legitimacy of the returns and check refund amounts.

C.

Require that a manager use a reserved register code to approve voids or refunds.

D.

Analyze voids and refunds by employee, credit card number, and amount for unusual numbers, amounts, or patterns.

Buy Now
Questions 171

Which of the following situations best describes an internal auditor who may have violated the IIA Code of Ethics principle of confidentiality?

Options:

A.

The auditor intentionally omitted from his resume that he was fired from his previous job for fraud allegations,

B.

The auditor decided not to notify her supervisor that her brother-in-law was responsible for the project the auditor was expected to evaluate.

C.

The auditor asked the audit client to copy requested files to her personal unencrypted memory stick because it was faster and more convenient.

D.

The auditor was assigned to analyze the organization ' s incentive program and spent long hours reviewing other employees’ bonuses,

Buy Now
Questions 172

Which of the following best describes the risk contained in an initial public offering for a new stock?

Options:

A.

Residual risk.

B.

Net risk.

C.

Inherent risk.

D.

Underlying risk.

Buy Now
Questions 173

Which of the following would be addressed in the internal audit charter?

Options:

A.

Expertise requirements for internal auditors

B.

Functional and administrative reporting lines for the chief audit executive

C.

Audit engagements to be completed in the next fiscal year

D.

Budget requirements for each engagement

Buy Now
Questions 174

Which of the following scenarios represents a top-down flow of information regarding corporate governance?

Options:

A.

The chief audit executive receives supply chain audit reports from an internal audit manager.

B.

The chief administrative officer reviews the payroll calendar prepared by the payroll manager.

C.

The chief information officer receives cybersecurity reports from the IT manager.

D.

The board approves the new annual budget prepared by the CEO.

Buy Now
Questions 175

Which type of engagement requires that the client agrees with the techniques used by the internal audit activity?

Options:

A.

A performance audit.

B.

A sensitive fraud investigation.

C.

A compliance audit

D.

A consulting service.

Buy Now
Questions 176

Which of the following statements best describes the difference between risk appetite and risk tolerance?

Options:

A.

Risk appetite applies to specific objectives, while risk tolerance refers to an organization ' s general attitude toward risk,

B.

Risk appetite refers to the degree of risk acceptance for a particular objective, while risk tolerance is one approach to risk management.

C.

Risk appetite refers to an organization ' s general level of acceptance, while risk tolerance is a more specific and subordinate concept.

D.

There is no significant difference between the two terms.

Buy Now
Questions 177

Upon completion of an external quality assessment, which of the following would the chief audit executive be required to report to the board?

Options:

A.

The total time spent to accomplish the external assessment

B.

The detailed evaluation results of the external assessment

C.

The competency and independence of the external assessment team

D.

The timetable and schedule of the next external assessment

Buy Now
Questions 178

The chief audit executive reports functionally to the board and administratively to the CEO and has been in operation for many years. Internal auditors often find that management of areas under review are reluctant to provide requested documents during audits. This has often resulted in limitations of the scope of work performed by the internal audit function.

Which element of the internal audit charter needs enforcement to prevent such limitations?

Options:

A.

Authority.

B.

Organization and reporting structure.

C.

Independence and objectivity.

D.

Responsibilities.

Buy Now
Questions 179

According to NA guidance, which of the following provides the best evidence of conformance with the Standards with respect to the proficiency required of the internal audit activity?

Options:

A.

Discussions with the chief audit executive.

B.

A listing of employee profiles and certifications.

C.

Inquiry of external auditors.

D.

Validation by human resources.

Buy Now
Questions 180

In which of the following scenarios would the internal auditor’s objectivity be best protected?

Options:

A.

A former human resources manager conducts an effectiveness review of the appointment and termination process six months after transferring to the internal audit activity.

B.

An accounts payable clerk assists the internal auditors during an effectiveness review of the physical access controls to the server room.

C.

An internal auditor writes the system manual for a newly acquired payroll software application prior to conducting an effectiveness review of the system.

D.

An internal auditor conducts an effectiveness review of an organization ' s business continuity plan in which his son is a minority stockholder.

Buy Now
Questions 181

Which of the following would best describe a control implemented to detect cash register disbursement fraud in a large retail store?

Options:

A.

Separate the duties of processing and authorizing refunds on merchandise

B.

Post signs in the register area prompting customers to ask for and examine their sales receipts

C.

Periodically count the cash in the register and compare it to the expected amount

D.

Use cash registers with internal tapes that are tamper proof and that require a manager to process voids or refunds

Buy Now
Questions 182

According to IIA guidance, which of the following corporate social responsibility {CSR) evaluation activities may be performed by the internal audit activity?

1. Consult on CSR program design and implementation

2. Serve as an advisor on CSR governance and risk management.

3. Review third parties for contractual compliance with CSR terms.

4. Identify and mitigate risks to help meet the CSR program objectives.

Options:

A.

1,2, and 3.

B.

1,2, and 4.

C.

1, 3, and 4.

D.

2, 3, and 4

Buy Now
Questions 183

The organization s procurement manager asks the internal auditor to deliver training to the procurement team on the organization’s third-party risk management process. Which of the following is the most appropriate response?

Options:

A.

The internal auditor should reject the request it she previously worked in the procurement area to maintain objectivity

B.

The internal auditor should reject the request if the internal audit team does not have the requisite expertise.

C.

The internal auditor should accept the request and in fact she may assume some management responsibilities temporarily if the result is a relevant training benefit

D.

The internal auditor may accept the request only if she defines the scope to ensure conformance with the Code of Ethics

Buy Now
Questions 184

Which of the following is a detective control strategy against fraud?

Options:

A.

Requiring employees to attend ethics training.

B.

Performing background checks on employees.

C.

Implementing a control self-assessment.

D.

Performing a surprise audit

Buy Now
Questions 185

According to MA guidance, which of the following statements is true regarding an effective governance process?

Options:

A.

It stipulates that risk needs to be considered when making strategic decisions.

B.

It encourages strict segregation of the risk management and internal control processes.

C.

It relies on effective risk management when establishing the organization ' s risk appetite.

D.

It relies on the board to devise ways to communicate the effectiveness of internal controls.

Buy Now
Questions 186

The organization ' s internal audit charter was last updated six years ago. To update the charter, which of the following actions is most appropriate for the chief audit executive to take?

Options:

A.

Wait for the next external assessment and address all of the missing information in the charter based on the recommendations from the external assessment team.

B.

Perform a review of IIA guidance to become acquainted with the latest mandatory elements prior to updating the charter

C.

Use an internal audit charter template from another organization that operates within the same industry.

D.

Identify an individual within the internal audit activity who has in-depth knowledge of mandatory IIA guidance elements to address any gaps or areas of the current version of the charter that could be improved.

Buy Now
Questions 187

According to IIA guidance, which of the following conditions would enhance the independence of the internal audit activity?

Options:

A.

The organizational culture rewards critical and objective thinking.

B.

The quality of work performed by the internal audit activity is periodically reviewed.

C.

The organization establishes effective governing body oversight.

D.

Audit assignments are rotated among internal audit staff.

Buy Now
Questions 188

Which of the following is an example of a risk reduction strategy?

Options:

A.

Outsourcing the payroll function.

B.

Absorbing the cost of losses.

C.

Insuring fixed assets.

D.

Installing cameras around the plant

Buy Now
Questions 189

According to IIA guidance, which of the following best describes expense reimbursement fraud?

Options:

A.

Theft of cash after it is recorded in the books

B.

Theft of cash before it is recorded in the books

C.

Theft of assets through fictitious or inflated invoices

D.

Theft of assets through false mileage travel logs and meal charges

Buy Now
Questions 190

An internal auditor performed a risk assessment and concluded that the controls over access privileges to a bank account were appropriate. Later, the auditor learned that a contractor was using a shared password provided by an authorized user of the account. Which of the following statements best describes the auditor ' s application of due professional care?

Options:

A.

Due professional care was exercised, despite the auditor’s failure to identify the significant risk.

B.

Due professional care was not exercised because the auditor failed to identify all the significant risks during the risk assessment.

C.

Due professional care was not exercised because the residual risk from the possibility of authorized users sharing their passwords was not considered.

D.

Due professional care was not exercised because the auditor failed to conduct interviews to obtain testimonial evidence of possible password sharing

Buy Now
Questions 191

Wi ch of the following circumstances would most likely be considered a potential red flag for fraud by the internal audit activity?

Options:

A.

The monthly payroll reports are not vetted to ensure terminated employees have been removed from the payroll system

B.

The volume of nonroutine journal entries has steadily increased over time.

C.

The database of approved suppliers has not been reviewed the last year

D.

The recent employee survey indicates that some employees remain unaware of the organization’s whistieblower hotline.

Buy Now
Questions 192

After the draft engagement report is issued, the manager of the area that was reviewed is informally interviewed by the engagement supervisor regarding the audit experience. Which of the following is most likely the purpose for this interview?

Options:

A.

Such an interview is performed when there is a need to dismiss an internal auditor

B.

Feedback from the manager will contribute to the audit team ' s professional development

C.

The manager ' s opinion will be used to form the final audit assessment and report rating.

D.

The manager will provide insights into the audited industry ' s trends

Buy Now
Questions 193

Which of the following qualifies as an acceptable consulting service provided by the internal audit activity?

Options:

A.

Develop training and system rollout plans in response to the results of the change readiness assessment of a new sales distribution model

B.

Lead a risk self assessment session for laboratory managers to help identify inherent risks and provide recommendations on how to evaluate the risks

C.

Audit a third party cloud service provider to review the effectiveness of governance and management controls in providing secure services to its customers

D.

Conduct a post-implementation assessment of the enterprise resource planning system to determine whether project objectives were met and to identify opportunities to maximize potential benefits

Buy Now
Questions 194

Which of the following actions by the internal audit activity requires disclosure to the board of nonconformance with the Standards?

Options:

A.

The internal audit activity did not complete an external assessment within the last seven years

B.

The internal audit activity performed an engagement with limited scope due to lack of knowledge

C.

The internal audit activity failed to consider risk when conducting a review of a department

D.

An internal auditor was assigned to an engagement m an area where she previously worked more than 10 years ago

Buy Now
Questions 195

An organization uses hedging to address foreign currency risk.

Which of the following best describes this risk strategy?

Options:

A.

Avoidance.

B.

Acceptance.

C.

Reduction.

D.

Sharing.

Buy Now
Questions 196

An internal audit activity is performing a governance engagement. Which of the following would provide the best evidence for an internal auditor when evaluating the organization’s culture?

Options:

A.

Personnel and customer surveys, actual reports, and due diligence results regarding third-party governance practices.

B.

Details on mandatory reporting to third parties, disclosure committee charter and responsibilities, and the internal communication system.

C.

Succession plans, development programs, and job descriptions with responsibilities and authorities.

D.

Ethics and integrity policy; structured interviews with employees; and established and communicated values, mission, and vision.

Buy Now
Questions 197

Which of the following most accurately describes corporate social responsibility at an organization?

Options:

A.

An organizational locus on improving the overall environment, even it is to the detriment of the local community.

B.

A philosophy driven by employees that flows up to senior management and the board of directors.

C.

An overall commitment of the organization to improve the quality of life for not only the employees but the community at large.

D.

A policy of ensuring that the organization is socially responsible, even if it leads to unprofitability due to increased costs.

Buy Now
Questions 198

Which of the following is an acceptable supplement to promote professional development within the internal audit function?

Options:

A.

Incorporate an expert from the area under review to help scope the engagement.

B.

Increase the frequency of engagements in specific areas to help internal auditors learn about them.

C.

Gather and incorporate knowledge from subject matter experts within the organization.

D.

Spend time learning how management establishes risk tolerance levels.

Buy Now
Questions 199

Which statement is correct about effective internal auditing?

Options:

A.

It requires that senior management and the board establish reporting responsibilities for the chief audit executive (CAE).

B.

It aligns with the Global Internal Audit Standards as the exclusive authoritative guide when performing engagements.

C.

It involves communication with the board and senior management on a continuous basis to ensure engagements are relevant.

D.

It allows the CAE to plan engagements that meet the organization’s strategies and objectives.

Buy Now
Questions 200

An internal auditor is assessing the effectiveness of the organization ' s risk management practices. She checks to see whether risk management is an integral part of decision making and whether risk management is transparent, responsive to change, and addresses uncertainty. According to IIA guidance on risk management frameworks, which of the following approaches is the auditor most likely using?

Options:

A.

Maturity model approach.

B.

Process element approach.

C.

Key principles approach.

D.

Key performance indicators approach.

Buy Now
Questions 201

According to IIA guidance, which of the following is true of the internal audit activity’s quality assurance and improvement program?

1 Monitoring the internal audit activity’s performance must be ongoing

2 All aspects of the internal audit activity should be evaluated

3 The requirement for external assessments can be satisfied through self-assessments that are validated by an independent external party

4 The review of assurance services should be the primary focus

Options:

A.

1 and 2 only

B.

2 and 3 only

C.

1, 2 and 3

D.

1 3 and 4

Buy Now
Questions 202

The internal audit activity completed its analysis of sample transactions to determine occurrences of double billings According to If A guidance, which of the following best demonstrates that internal auditors exercised due professional care during the review?

Options:

A.

Internal auditors found no instances of double billing and concluded there were no significant risks in this area.

B.

Internal auditors documented the scope and methodology of the data testing.

C.

Internal auditors discussed with management how data is safeguarded.

D.

Internal auditors received formal performance feedback from the engagement supervisor.

Buy Now
Questions 203

Which of the following practices is generally most effective to protect internal audit objectivity?

Options:

A.

Ensuring regular documentation of auditor skills and experience in the workpapers.

B.

Basing performance evaluations heavily on customer satisfaction surveys.

C.

Prohibiting auditors from accepting gifts from audit clients or potential clients.

D.

Ensuring that auditors have a balance of both operational and internal audit responsibilities.

Buy Now
Questions 204

Which of the following statements is true regarding control activities ' ?

Options:

A.

Control activities are defined by management through risk mitigation strategies

B.

Control activities should be defined for all business processes

C.

If two organizations have identical objectives and structures their control activities would be the same

D.

Organizations that are less regulated generally have more complex control activities than highly regulated organizations

Buy Now
Questions 205

During a quality assessment of the internal audit activity an auditor is assessing whether the independence of the internal audit activity is at risk of being compromised. According to IIA guidance, which of the following would provide the best source of evidence for such an assessment?

Options:

A.

An organizational chart showing the reporting line of the chief audit executive to the CEO

B.

The internal audit charter as endorsed by the organization’s governing body

C.

A review of the audit opinions issued from a sample of recent audit engagements

D.

An assessment of the scope of the audit work performed by the internal au < M activity

Buy Now
Questions 206

Considering the concepts of organization wide risk management and the system of internal controls, the internal audit activity as a whole can be considered which of the following types of control?

Options:

A.

Transaction-level control.

B.

Management-oversight control.

C.

Governance control.

D.

Process-level control.

Buy Now
Questions 207

Which of the following is (he most effective way any organization can ensure proper governance over its internal controls?

Options:

A.

By adopting the best practices of similar organizations in the industry.

B.

By adjusting their internal control framework as business practices evolve.

C.

By introducing the universally accepted COSO internal control framework.

D.

By encouraging the internal audit activity to provide training on internal controls.

Buy Now
Questions 208

An experienced internal auditor is planning an assurance engagement of the organization ' s sales activities. During process walkthroughs and interviews, many sales representatives expressed concerns about management ' s escalating demands to meet the organization ' s sales goals. According to the MA guidance, which of the following is the best application of due professional care in planning the engagement?

Options:

A.

Disregard the complaints because the information isn ' t reliable and isn ' t sufficient to support engagement conclusions and results.

B.

Consider the significance of the risks related to the complaints and develop appropriate assurance procedures in work programs.

C.

Disregard the complaints because using them would violate the confidentiality principle.

D.

Discuss management ' s needs and expectations related to including the complaints in the audit scope.

Buy Now
Questions 209

Which of the following situations presents the lowest risk of impairing an internal audit activity ' s independence?

Options:

A.

Senior management has the authority to terminate the chief audit executive

B.

Senior management has control over the internal audit activity ' s budget

C.

Senior management provides feedback on the scope of the internal audit plan.

D.

Senior management limits the internal audit activity ' s access to the board

Buy Now
Questions 210

The manager of the payroll department requested a review of the payroll process, but only wants the engagement to include processes related to approval of time worked. What type of activity is this?

Options:

A.

Financial assurance engagement.

B.

Operational consulting engagement.

C.

Compliance assurance engagement.

D.

Risk management consulting engagement.

Buy Now
Questions 211

During an audit of company expenses, the internal auditor performed a test using data analytics and identified a violation of the company ' s expenses policy. The auditor who discovered the issue considered it a potential fraudulent transaction and informed the chief financial officer (CFO). The CFO dismissed the concern because he did not understand the data analytics test that was performed and the transaction was of a low value. Given this situation, which skills or competencies should this internal auditor seek to improve?

Options:

A.

Skills in evaluating the risk of fraud.

B.

Knowledge of key IT risks and controls

C.

Soft skills such as communication and negotiation.

D.

Knowledge and understanding of the company ' s expenses policy

Buy Now
Questions 212

An internal auditor is reviewing the organization’s procurement processes. The procurement manager states that suppliers’ bank details are verified by phone call directly with the supplier before being updated in the procurement system. The organization has around 3,000 suppliers. The auditor is skeptical that a phone call is made for each supplier when bank details are changed.

The auditor decides to verify the manager’s statement by analyzing the change to one supplier’s bank details.

Which piece of evidence would convince the auditor that the control described by the procurement manager is effective?

Options:

A.

A commercial registration document of the supplier to verify its existence.

B.

Details of the last bank payment made to the selected supplier and verification against the bank account invoice.

C.

An annual confirmation email from each member of the procurement team to the procurement manager stating that bank details were confirmed.

D.

Documentation of the call made with the supplier that includes the details of both parties and the information to be verified.

Buy Now
Questions 213

Which of the following statements is true regarding occupational fraud?

Options:

A.

An employee who diverts the organization ' s purchases for personal use is demonstrating asset misappropriation

B.

An employee who intentionally omits negative information in the financial statement disclosures is demonstrating an example of corruption

C.

An employee who made an error in estimating losses may have committed fraud even if the error was not intentional

D.

An employee who creates a denial of service in the organization’s computer systems is committing asset misappropriation

Buy Now
Questions 214

An organization opened its warehouse to sell written-off surplus and outdated office furniture to the general public. Prices were negotiable, and customers could pay by cash, check, or credit card. Receipts were available upon request, and were issued by the inventory manager upon collection of payment. At the end of the day, the manager forwarded all of the funds he had collected to the finance department for deposit. Which of the following types of fraud is most likely to occur under these circumstances?

Options:

A.

Asset misappropriation.

B.

Bribery.

C.

Falsifying records.

D.

Skimming

Buy Now
Questions 215

Management decided to post the organization ' s newly established code of conduct on its website. This decision is primarily intended to mitigate which of the following risks?

Options:

A.

Accountability risk.

B.

Communication risk.

C.

Knowledge risk.

D.

Cultural risk.

Buy Now
Questions 216

Which of the following is a threat to the internal audit function’s organizational independence?

Options:

A.

Unconscious or unintentional cognitive bias in interpreting information during internal audit engagements.

B.

Familiarity arising from a long-term working relationship with an engagement client.

C.

Auditing the implementation of a system after providing advisory services and recommendations for the implementation process.

D.

Restrictions on access to information throughout the organization.

Buy Now
Questions 217

Which of the following statements is true regarding management ' s use of judgement to design, implement, and conduct internal control?

Options:

A.

The use of judgment enhances management ' s ability to make better decisions about internal control, but cannot guarantee perfect outcomes.

B.

Introducing judgment generally diminishes management ' s ability to make good decisions about internal control.

C.

It is inappropriate for management to exercise judgement in areas such as specifying and using suitable accounting principles.

D.

It is inappropriate for management to exercise judgement in assessing whether components are present, functioning, and operating together

Buy Now
Questions 218

An organization grants its internal auditors authority to access sensitive confidential information so the auditors may analyze data and conduct effective assurance engagements.

This effectively demonstrates support for which of the following fundamental principles of internal auditing?

Options:

A.

Independence.

B.

Integrity.

C.

Confidentiality.

D.

Proficiency and due professional care.

Buy Now
Questions 219

A chief audit executive has decided to use the process element approach to evaluate the organization’s risk management process.

According to IIA guidance, which of the following provides evidence that the risk evaluation element is in place?

Options:

A.

The organization has made a decision with regard to risk avoidance, risk sharing, and application of controls to manage risk.

B.

The organization has developed a mechanism to rank the relative importance of each risk in order to establish a risk treatment priority.

C.

The organization has developed a formal technique that considers the consequences and likelihood of each risk.

D.

The organization has established a formal process that considers the source of risk, areas of impact, and potential events.

Buy Now
Questions 220

Which of the following statements relating to risk management is true?

Options:

A.

The high-level risk assessment performed during engagement planning is a detailed step-by-step analytical process

B.

External auditors must be engaged to evaluate the potential for fraud and how the organization manages fraud risk

C.

A lack of controls is acceptable if the risk is reduced to an acceptable level in some other way

D.

Internal auditors are responsible for managing the risks of the organization

Buy Now
Questions 221

An internal auditor is trying to evaluate what could go wrong after determining that a risk management technique is operating effectively. What type of risk is the auditor assessing?

Options:

A.

Inherent risk.

B.

Residual risk.

C.

Impact risk.

D.

Detection risk.

Buy Now
Questions 222

An internal auditor has completed an assurance engagement Which of the following is most likely true regarding the engagement?

Options:

A.

During audit planning, the auditor provided the client with the scope of the engagement for their agreement

B.

The results of the engagement were included in a written report that was issued to the client who requested the engagement

C.

During audit planning, the auditor determined that the engagement scope would include a review of the security and privacy of payroll records

D.

The client requested the review of a new payroll system in order to improve the security of the system

Buy Now
Questions 223

According to IIA guidance, which of the following actions is a chief audit executive required to take with regard to reporting the results of the quality assurance and improvement program?

Options:

A.

Report external assessments upon completion of such assessments

B.

Report external assessments at least annually

C.

Report ongoing monitoring quarterly

D.

Report post-engagement reviews at least once every five years

Buy Now
Questions 224

Which of the following best describes a proactive role for the internal audit activity with regard to the organization ' s ethics program?

Options:

A.

Becoming a voting member of the organization ' s internal ethics council.

B.

Performing an annual organizationwide employee survey.

C.

Reviewing all departmental ethics-related policies.

D.

Conducting annual ethics training for all employees.

Buy Now
Questions 225

Which of the following would be the most effective fraud prevention control?

Options:

A.

Email alert sent to management for checks issued over $100,000.

B.

Installation of a video surveillance system in a warehouse prone to inventory loss.

C.

New hire training to explain fraud and employee misconduct.

D.

Daily report that identifies unsuccessful system log-in attempts

Buy Now
Questions 226

The board of a newly established organization was discussing the contents of the draft internal audit charter One board member suggested adding to the charter an obligation for the internal audit activity to develop controls in business procedures. The board member explained that the new organization needs professional-level developers, internal auditors have the necessary skills and competencies, and the internal audit activity is well positioned to assume this responsibility. Which of the following would be a potential concern if the board member’s suggestion is adopted?

Options:

A.

Due professional care.

B.

Internal audit objectivity.

C.

Risk management assurance.

D.

Professional development.

Buy Now
Questions 227

Guidelines need to be set for various levels of suspected fraud within an organization and when it would be reported to the audit committee. Which of the following would be

reported at the next meeting?

Options:

A.

Minor theft of less than $10,000, not involving senior management.

B.

Theft using collusion for more than $10,000. but not involving senior management.

C.

Denial of access to requested employees during an audit.

D.

Discussion of replacement of the chief audit executive.

Buy Now
Questions 228

Which of the following situations is most likely to threaten the independence of the internal audit activity?

Options:

A.

The chief audit executive reports functionally to the board and administratively to the CEO.

B.

The annual budget for the internal audit activity is approved by the chief financial officer.

C.

The internal audit activity is completely outsourced to an external service provider.

D.

The internal audit manager provides consulting services to the procurement department, where she worked during the prior year.

Buy Now
Questions 229

According to MA guidance, which of the following best describes how often the chief audit executive should review the quality assurance and improvement program of the internal audit activity?

Options:

A.

Whenever the business objectives of the organization change

B.

Just prior to an external assessment of the internal audit activity

C.

At the completion of each engagement.

D.

Progressively on a day-to-day basis

Buy Now
Questions 230

An internal auditor of a real estate organization wants to stay informed of current regulations on real estate investments.

Which of the following is likely the best option?

Options:

A.

Participate in an annual conference titled “Housing and Commercial Investments: Updated Government Amendments.”

B.

Review a professional organization’s report of the prior year titled “Real Estate and Latest Business Requirements.”

C.

Read a doctoral thesis published two years ago on the topic of real estate investments, governance, and business risks.

D.

Review policies and procedures contained in last year’s audit.

Buy Now
Questions 231

The chief audit executive (CAE) annually develops a budget and resource plan and submits it to the board for approval. This action best fulfills which of the following responsibilities of the CAE?

Options:

A.

The responsibility to maintain organizational independence.

B.

The responsibility to perform engagements with due professional care.

C.

The responsibility to communicate corrective action plans to the board.

D.

The responsibility to define the purpose of the internal audit activity.

Buy Now
Questions 232

A business unit manager was impressed by the competence of the internal auditor who was conducting an assurance engagement in his area and the manager made the auditor an attractive job offer to begin after the audit was completed The auditor later told her auditor in charge that she was considering the offer. Which of the following IIA Code of Ethics principles was most likely violated?

Options:

A.

Integrity

B.

Confidentiality

C.

Objectivity

D.

No violation was committed

Buy Now
Questions 233

Which of the following parties would be responsible for ongoing monitoring of the organization ' s corporate social responsibility activities to reduce its carbon footprint?

Options:

A.

Chief audit executive

B.

Facility operation manager

C.

Public relations manager

D.

Regulatory agency

Buy Now
Questions 234

With regard to IT governance, which of the following is the most effective and appropriate role for the internal audit activity?

Options:

A.

Independently evaluate the skills and experience of potential chief information officer candidates to assess the best fit based on the organization ' s risk appetite.

B.

Evaluate the organization’s governance standards and assess IT-related activities to identify gaps and develop policies, ensuring alignment with the organization’s risk appetite.

C.

Assist management in interpreting complex IT-related privacy and security risk exposures and evaluating potential mitigation strategies.

D.

Assess whether governance activities are aligned with the organization ' s risk appetite and take into consideration emerging risks

Buy Now
Questions 235

While auditing an organization ' s credit approval process, an internal auditor learns that the organization has made a large loan to another auditor ' s relative. Which course of action should the auditor take?

Options:

A.

Proceed with the audit engagement, but do not include the relative ' s information.

B.

Have the chief audit executive and management determine whether the auditor should continue with the audit engagement.

C.

Disclose in the engagement final communication that the relative is a customer.

D.

Immediately withdraw from the audit engagement.

Buy Now
Questions 236

Which of the following describes an advisory service?

Options:

A.

Engagement results include conclusions, recommendations, and independent opinion based on an objective assessment of evidence.

B.

Internal auditors determine engagement objectives, scope, and the assessment techniques to be used.

C.

Internal auditors provided the assessment services requested by the engagement client.

D.

The parties involved in the engagement process are the internal auditor, the owner of the assessed activity, and the user of the engagement results.

Buy Now
Questions 237

An external assessment of an organization ' s internal audit activity was last completed four years ago Which of the following options would be acceptable this year if the internal audit activity is to fulfill the requirements of the Standards?

Options:

A.

The internal audit activity conducts a self-assessment that is validated by a qualified and experienced internal auditor and then schedules a qualified, independent external assessor

B.

The board nominates an independent individual from senior management in the organization to conduct an assessment of the internal audit activity

C.

An external auditor conducts an audit of the organization which includes information about the internal audit activity

D.

The chief audit executive schedules a self-assessment and the board approves the results

Buy Now
Questions 238

The same internal auditor has audited the regional purchasing department annually for the last three years. The audits have shown several significant control deficiencies that have not been corrected by management. New management is in charge of this regional purchasing department, and it is time to audit the department again. What concerns should be considered prior to assigning the audit to the same auditor?

Options:

A.

Intimidation threats may compromise the auditor ' s objectivity due to multiple negative audit reports completed by the auditor.

B.

The auditor has reviewed the department annually for the last three years, leading to familiarity, which can impact the internal audit activity ' s independence.

C.

A negative cognitive bias may be in place that affects the employee ' s objectivity due to the recent audits with uncorrected control deficiencies.

D.

The auditor may have formed a cultural bias, as the department under review is in the auditor ' s geographic area.

Buy Now
Questions 239

An organization established 20 years ago has had its internal audit activity in place for the last three years. Which of the following would allow the internal audit activity to accurately state that it is in conformance with the Standards ' ?

Options:

A.

Documented assessment was performed by the audit committee and confirmed conformance.

B.

Internal and external assessments are performed annually, and nonconformance results are reported to the board.

C.

The independent and objective judgement of the chief audit executive confirmed conformance with the Standards.

D.

Documented internal assessments are performed periodically and confirm conformance.

Buy Now
Questions 240

Which of the following best describes why a chief audit executive might obtain the services of a fraud specialist to assist in a major fraud investigation ' ?

Options:

A.

Fraud specialists are better at using computer-assisted audit techniques

B.

Fraud specialists are better equipped to act as an expert witness in court

C.

Fraud specialists are better able to properly apply due professional care

D.

Fraud specialists are better at using crime scene investigation techniques

Buy Now
Questions 241

According to IIA guidance, which of the following statements is true regarding ISO 31000?

Options:

A.

The key principles approach checks whether each element of the risk management process is in place.

B.

The framework is effective in addressing the organization ' s structure, size, and risk profile but not its culture objectives.

C.

The end point for improving an organization s approach to risk management should be a gap analysis that evaluates any changes.

D.

A combination of the three primary approaches to the framework generally yields the most information despite the complexity

Buy Now
Questions 242

Which step should an internal auditor complete during fieldwork to detect fraudulent activities during an audit?

Options:

A.

Check outlier cash payments for inconsistencies and discrepancies.

B.

Brainstorm possible cash payment schemes.

C.

Develop procedures to identify the employee who processed the fraudulent cash payment.

D.

Recommend procedures to segregate cash receipt and disbursement duties.

Buy Now
Questions 243

Senior management has decided to adopt the key principles approach of the ISO 31000 risk management framework. According to IIA guidance, which of the following principles is most appropriate when implementing the risk management process in a dynamic agency?

Options:

A.

Everyone in the agency has a primary responsibility for identifying and managing risks as part of the risk management process.

B.

The risk management process, while evaluating risk, should develop a mechanism to rank the relative importance of each risk.

C.

The risk management process should be regularly reviewed and respond to changes in the environment, to remain relevant.

D.

The risk management process should use a formal technique to consider the consequence and likelihood of each risk.

Buy Now
Questions 244

An internal auditor extended the scope of testing for a disbursements engagement following a fraud risk assessment Despite the investment of additional audit resources no significant issues were found Unfortunately a major payment fraud was discovered several

months later According to IIA guidance which of the following statements is true regarding the internal auditor ' s application of due professional care?

Options:

A.

Due professional care was not applied because no additional work should have been performed unless there was actual evidence of fraud

B.

Due professional care was not applied because the extended scope resulted in no issues being identified, while fraud actually existed

C.

Due professional care was applied as the internal auditor modified the scope based on reasonable judgment, despite the additional cost of resources

D.

Due professional care was applied as the cost of audit resources should not be a determining factor in the degree of testing undertaken

Buy Now
Questions 245

Which of the following best describes organizational governance processes?

Options:

A.

Processes employed by internal and external assurance providers to authorize, direct, and provide oversight to management to better enable the meeting of organizational objectives

B.

Processes employed by the board of directors to authorize and provide guidance and oversight to management to promote the achievement of organizational objectives.

C.

Processes employed by the board of directors and senior management to mitigate risks to acceptable levels.

D.

Processes employed by risk owners to mitigate risks to acceptable levels within the organization ' s risk appetite

Buy Now
Questions 246

Which of the following scenarios best illustrates the concept of due professional care?

Options:

A.

After establishing engagement objectives and reviewing a process, the internal auditor assured process owners that all significant risk events were identified and tested using a systematic, disciplined approach.

B.

After conducting an audit based upon a predefined scope and objective, the internal auditor guaranteed management that the system of internal controls in an audited area operates effectively.

C.

As head of the internal audit activity, the chief audit executive reported functionally to the organization ' s board and administratively to senior management.

D.

As head of the internal audit activity, the chief audit executive ensures that engagement supervisors conduct post-engagement staff meetings.

Buy Now
Questions 247

A manufacturer of power tools is experiencing regular fluctuations in the price of electrical power which is having a serious impact on the bottom line. Which of the following would be the most effective risk strategy to reduce the impact of these fluctuations?

Options:

A.

Use an average cost for power to smooth the bottom line.

B.

Analyze the amount of power used to produce each power tool.

C.

Review the current process to identify opportunities to reduce power usage.

D.

Use a forward contract for bulk power purchases

Buy Now
Questions 248

What must a chief audit executive do if significant changes to regulations may affect the nature of internal audit services?

Options:

A.

Discuss the changes with the external auditors.

B.

Discuss the changes with the CEO, who is responsible for escalating to the board.

C.

Discuss the changes with the board and senior management.

D.

No action is needed because the changes are unlikely to affect the work of internal auditors.

Buy Now
Questions 249

An internal auditor of a small manufacturing organization helps with a fraud investigation of accounts payable. The auditor notes that the accounts payable manager is very friendly and trusting with accounts payable staff, so the manager rarely checks the staff’s work.

Which component of the fraud triangle is most relevant in this scenario?

Options:

A.

Pressure.

B.

Opportunity.

C.

Rationalization.

D.

Objectives.

Buy Now
Questions 250

Which of the following is the internal audit activity expected to do with respect to the organization ' s governance processes?

Options:

A.

Formally audit all governance activities.

B.

Provide strategic guidance on the organizational processes to senior management.

C.

Achieve agreement with the board regarding the range of activities, depth of review, and time period to include in the assessment.

D.

Audit against the governance structures and practices widely used in the industry.

Buy Now
Questions 251

Which of the following situations undermines the independence of the internal audit activity?

Options:

A.

The internal audit activity is responsible for the company ' s risk management function, and its head manager reports to the chief audit executive.

B.

A senior member of the internal audit activity once worked in the corporate finance department.

C.

The organization’s CEO reviews the internal audit activity’s annual budget per the organization’s policies and procedures.

D.

The internal audit activity often uses management ' s risk profile to build its own risk profile for annual planning.

Buy Now
Questions 252

Which of the following is an indicator that the organization s risk management process is effective?

Options:

A.

The organization s risk appetite mission, and objectives are dearly outlined.

B.

The organization s risk management practices are assessed as mature.

C.

The organization has adopted risk management frameworks and global models.

D.

The organization s significant risks are identified and adequately assessed

Buy Now
Questions 253

Which of the following circumstances would most likely be considered a potential red flag for fraud by the internal audit activity?

Options:

A.

The monthly payroll reports are not vetted to ensure terminated employees have been removed from the payroll system.

B.

The volume of nonroutine journal entries has steadily increased over time.

C.

The database of approved suppliers has not been reviewed in the last year.

D.

The recent employee survey indicates that some employees remain unaware of the organization’s whistleblower hotline.

Buy Now
Questions 254

A chief audit executive (CAE) has just joined an organization with an existing internal audit activity. Based on her review of the current organizational structure, the CAE determines that the internal audit activity lacks adequate independence. Which of the following actions is the CAE ' s best step to take next to move the internal audit activity toward organizational independence?

Options:

A.

Ensure the limitations are disclosed through communication with the board and senior management, so that the internal audit activity can continue operating under the same organizational structure.

B.

Request that the board restructure the reporting line of the internal audit activity to ensure the CAE has unrestricted access to the board.

C.

Rotate internal audit assignments among members of the internal audit activity to minimize the effects of the current structure.

D.

Train internal auditors about organizational independence and have them sign an acknowledgment of understanding.

Buy Now
Questions 255

An internal audit team was assigned to review the organization’s information security protocol After fieldwork was completed an internal auditor identified an error in the review of security access The error could affect the overall results of the engagement Which of the following is the most appropriate course of action for the internal auditor?

Options:

A.

Proceed with addressing the error and report any corrections to the engagement supervisor during the scheduled exit meeting

B.

Issue the audit report to senior management on schedule but include a disclaimer about the error

C.

Proceed with the scheduled closing of the engagement without consideration of the identified error

D.

Inform the engagement supervisor of the error and allow the supervisor to determine the appropriate action to take

Buy Now
Questions 256

The organization discusses the need to change its accounting software.

In which of the following stages would an internal auditor’s advisory review most benefit the organization?

Options:

A.

Pre-release stage.

B.

Implementation stage.

C.

Post-release stage.

D.

Conceptual stage.

Buy Now
Questions 257

Which should the internal auditor first consider when assessing fraud risks during an engagement?

Options:

A.

Compare the organizations fraud strategies with the industry ' s strategies.

B.

Review any related prior fraud investigations.

C.

Investigate any related fraud allegations.

D.

Communicate any suspicious fraud activities to management.

Buy Now
Exam Code: IIA-CIA-Part1
Exam Name: Internal Audit Fundamentals
Last Update: Oct 4, 2026
Questions: 858
IIA-CIA-Part1 pdf

IIA-CIA-Part1 PDF

$21.25  $84.99
IIA-CIA-Part1 Engine

IIA-CIA-Part1 Testing Engine

$25  $99.99
IIA-CIA-Part1 PDF + Engine

IIA-CIA-Part1 PDF + Testing Engine

$33.75  $134.99