Home

Tutoring

Subjects

Live Classes

Study Coach

Essay Review

On-Demand Courses

Colleges

Games


Sign up

Log in

Opening subject page...

Loading your content

Practice

  • All Subjects
  • Algebra Flashcards
  • SAT Math Practice Tests
  • Math Question of the Day
  • Live Classes
  • On-Demand Courses

Varsity Tutors

  • Find a Tutor
  • Test Prep
  • Online Classes
  • K-12 Learning
  • College Search
  • VarsityTutors.com

© 2026 Varsity Tutors. All rights reserved.

← Back to quizzes

CPA Bar Quiz

CPA Bar Quiz: Assess Risks And Control Deficiencies

Practice Assess Risks And Control Deficiencies in CPA Bar with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

Question 1 / 20

0 of 20 answered

The COSO Internal Control - Integrated Framework organizes internal control into which set of components?

Select an answer to continue

What this quiz covers

This quiz focuses on Assess Risks And Control Deficiencies, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Bar.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

The COSO Internal Control - Integrated Framework organizes internal control into which set of components?

  1. Control environment, risk assessment, control activities, information and communication, and monitoring activities (correct answer)
  2. Preventive controls, detective controls, and corrective controls
  3. Risk identification, risk assessment, risk response, and risk monitoring
  4. Governance, strategy, performance, review, information and communication, and monitoring

Explanation: The COSO Internal Control - Integrated Framework comprises five components: (1) control environment, which sets the tone of the organization; (2) risk assessment, identifying and analyzing risks to objectives; (3) control activities, the policies and procedures that help ensure directives are carried out; (4) information and communication, supporting the identification, capture, and exchange of information; and (5) monitoring activities, evaluating whether each component functions as intended. Option B describes control types, not COSO components. Option C describes a generic risk management cycle. Option D describes elements of the COSO ERM framework, which has more components.

Question 2

A company's accounts payable clerk has authority to both approve vendor invoices and issue payment checks. Which internal control deficiency does this represent?

  1. Lack of physical safeguards over company assets
  2. Inadequate segregation of duties (correct answer)
  3. Insufficient documentation requirements for disbursements
  4. Absence of a transaction audit trail

Explanation: Segregation of duties requires that authorization, custody, and recordkeeping functions be assigned to different individuals. Allowing one person to both approve invoices (authorization) and issue payment checks (custody/execution) eliminates a key check and creates a risk of unauthorized or fraudulent payments. Option A describes a different control category related to physical access. Option C describes documentation controls, which are separate from the segregation issue. Option D addresses audit trail requirements, which are distinct from who performs each step.

Question 3

A company uses a three-way match process (purchase order, receiving report, and vendor invoice) for all disbursements. An auditor finds that 35 payments were processed without a corresponding purchase order. This represents which type of control deficiency?

  1. An IT general control weakness in the payment processing system
  2. A failure of a compensating control
  3. A failure in authorization and approval controls for disbursements (correct answer)
  4. A monitoring deficiency with no impact on financial statement risk

Explanation: The purchase order is an authorization control - it documents that an appropriately authorized person approved the transaction before goods or services were acquired. Processing payments without a purchase order bypasses this authorization step, allowing disbursements that may not have been properly approved. Option A is incorrect; this is a process control failure, not specifically an IT general control issue. Option B mischaracterizes the issue as a compensating control failure. Option D incorrectly minimizes the financial reporting impact, since unauthorized disbursements create a risk of improper expense recording.

Question 4

A company's IT department has unrestricted access to modify transaction records in the accounting system with no review, logging, or approval requirement. This represents which type of control risk?

  1. A segregation of duties violation in the purchasing function
  2. A physical access control deficiency over computer hardware
  3. An IT general control weakness that could allow unauthorized or undetected changes to financial data (correct answer)
  4. A user access review deficiency affecting only human resources records

Explanation: IT general controls (ITGCs) include logical access controls, change management, and computer operations controls. Unrestricted ability to modify transaction records without any logging or review is a fundamental logical access control failure. Because accounting systems process and store financial data, this weakness could allow unauthorized adjustments to the financial records, directly affecting financial reporting reliability. Option A misidentifies the function affected. Option B confuses logical access with physical access. Option D incorrectly narrows the impact to HR records.

Question 5

Under the COSO ERM framework, risk appetite is best described as which of the following?

  1. The amount and type of risk an organization is willing to accept in pursuit of its value and objectives (correct answer)
  2. The maximum financial loss the organization can sustain before becoming insolvent
  3. The level of risk remaining after all available risk responses have been applied
  4. The probability that a specific risk event will occur within a defined time period

Explanation: Risk appetite is the broad-based amount and type of risk a company is willing to accept in pursuit of its mission and objectives. It reflects management's philosophy and operating style and guides decisions about which risks to take and which to avoid. Option B describes solvency risk tolerance, not risk appetite as defined in ERM. Option C describes residual risk, which is what remains after risk responses are applied. Option D describes likelihood, which is one component of risk assessment.

Question 6

A company's risk assessment identifies a high-likelihood, low-impact risk and a low-likelihood, high-impact risk. Limited resources are available for mitigation. Which analytical framework best guides resource allocation?

  1. Always address the high-likelihood risk first because frequent occurrences generate more cumulative cost
  2. Consider the expected value (likelihood x impact) and strategic significance of each risk before allocating resources, since the high-impact risk may warrant priority despite its lower probability (correct answer)
  3. Always address the low-likelihood, high-impact risk first because severe consequences are never acceptable
  4. Accept both risks since resource constraints make mitigation economically unfeasible

Explanation: Risk prioritization requires evaluating both dimensions - likelihood and impact - and potentially their product (expected value or expected loss). A low-likelihood, high-impact event may represent existential risk to the organization and warrant priority mitigation even if it occurs rarely. Conversely, a high-frequency, low-impact risk may be efficiently managed through acceptance if expected losses are tolerable. Strategic significance (could the high-impact risk threaten core objectives?) adds another dimension beyond expected value. Options A and C apply rigid priority rules that ignore the opposing dimension. Option D abandons risk management rather than optimizing it.

Question 7

An auditor identifies that the controller has sole authority to post journal entries, approve those entries, and prepare the financial statements, with no independent review by any other party. How should this deficiency be classified?

  1. A control deficiency only, because no actual misstatement has been identified
  2. A significant deficiency, because it involves a high-level employee with broad authority
  3. Likely a material weakness, because the combination of incompatible functions with no compensating review creates a reasonable possibility of undetected material misstatement (correct answer)
  4. Not a deficiency, because controllers routinely maintain broad access to financial systems as part of their role

Explanation: When a single individual performs mutually incompatible financial reporting functions - posting, approving, and preparing financial statements - with no compensating review, the risk of undetected misstatement is significant. This combination eliminates multiple layers of oversight and is the type of scenario that meets the definition of a material weakness: a reasonable possibility that a material misstatement would not be prevented or detected. Option A is incorrect; severity is assessed on risk potential, not whether a misstatement has occurred. Option B understates the severity. Option D incorrectly normalizes this concentration of incompatible functions.

Question 8

A company's ESG reporting processes have no internal controls, no verification procedures, and no review mechanisms, while its financial reporting is subject to rigorous controls. Which risk does this asymmetry create?

  1. ESG reporting is entirely voluntary and therefore not subject to any control or accuracy requirements
  2. Inaccurate or unverified ESG disclosures expose the company to reputational, regulatory, and investor relations risks as ESG scrutiny by stakeholders and regulators increases (correct answer)
  3. ESG risks are inherently immaterial relative to financial reporting risks and require no controls
  4. The company should eliminate ESG disclosures entirely to eliminate the associated risk

Explanation: ESG disclosure is an increasingly regulated area, with the SEC and other regulators expanding requirements around climate-related and sustainability disclosures. Even where disclosure remains voluntary, institutional investors and proxy advisory firms scrutinize ESG data. Inaccurate or unverified ESG disclosures can result in regulatory action, reputational damage, loss of investor confidence, and potential securities liability. Option A is incorrect; even voluntary disclosures carry liability risk if materially false or misleading. Option C is incorrect; ESG risks can be material, particularly for companies in carbon-intensive or resource-dependent industries. Option D is a disproportionate response that would likely increase scrutiny.

Question 9

An IT general controls review finds that application change management requires developer sign-off before deployment but does not require independent testing by a separate QA team. Which risk does this create?

  1. The control is adequate because developer sign-off meets standard industry practice
  2. This weakness affects only the IT department and has no impact on financial reporting accuracy
  3. Without independent testing, developers can introduce unauthorized changes or undetected errors into production systems that process financial data, potentially compromising data integrity (correct answer)
  4. The company should eliminate its change management process and rely exclusively on detective controls

Explanation: Independent testing by a QA team separate from the developers who wrote the code is a critical control in application change management. Without it, developers could introduce intentional or unintentional errors into production applications. Because accounting applications process transactions that feed into financial statements, application integrity directly affects financial reporting reliability. This is an IT general control weakness that elevates the risk of material misstatement. Option A is incorrect; developer-only sign-off is widely recognized as insufficient segregation. Option B is incorrect; IT application weaknesses directly affect financial reporting. Option D eliminates a preventive control framework in favor of detective-only controls, which is not a sound approach.

Question 10

According to the COSO Enterprise Risk Management framework, which statement best describes the scope of the risk management process?

  1. It is organized around five components: governance and culture, strategy and objective-setting, performance, review and revision, and information, communication, and reporting (correct answer)
  2. It covers only the five components of the COSO Internal Control - Integrated Framework
  3. It focuses on governance, strategy, performance, review, information and communication, and monitoring
  4. It is limited to risk identification, quantification, prioritization, and reporting

Explanation: The 2017 COSO ERM - Integrating with Strategy and Performance framework organizes enterprise risk management into five components: governance and culture (sets tone and oversight structures), strategy and objective-setting (aligns risk appetite with strategic direction), performance (identifies and assesses risks that affect achievement of objectives), review and revision (evaluates how well the ERM framework is performing over time), and information, communication, and reporting (supports risk-informed decision making across the entity). Option B confuses the ERM framework with the COSO Internal Control - Integrated Framework, which has five different components. Option C is a near-miss: it omits culture from the first component and substitutes 'monitoring' for the distinct review and revision and reporting functions defined in the 2017 framework. Option D is an incomplete and overly narrow description that omits the governance, strategy, and performance dimensions central to the ERM framework.

Question 11

A company has three compensating controls in place to address a segregation of duties weakness in the cash receipts cycle. Management asserts the compensating controls fully eliminate the deficiency. Which evaluation is most accurate?

  1. The assertion is correct because three compensating controls always offset a segregation of duties deficiency
  2. Compensating controls may reduce the risk associated with the deficiency but generally do not fully eliminate it; the underlying segregation issue should still be disclosed and addressed when feasible (correct answer)
  3. Compensating controls are not permitted under COSO and must be replaced with preventive controls
  4. Cash receipts is a low-risk cycle and compensating controls are unnecessary

Explanation: Compensating controls can reduce the likelihood that a deficiency results in a misstatement, but they do not remove the root cause - the incompatibility of the combined functions. An auditor or regulator evaluating the control environment would still note the segregation deficiency and assess whether the compensating controls are sufficiently strong to reduce severity from a material weakness to a significant deficiency or control deficiency. Option A incorrectly treats the number of compensating controls as determinative. Option C is incorrect; COSO does not prohibit compensating controls. Option D understates cash receipts risk, which is a common focus of misappropriation schemes.

Question 12

A company's board receives quarterly risk reports from management. An internal auditor notes that risk scores have been unchanged for three consecutive years despite significant business changes including two acquisitions and a new product launch. Which concern is most significant?

  1. Consistent risk scores reflect a well-managed risk program with stable exposures
  2. Quarterly reporting is insufficient and the board should receive monthly risk updates
  3. Internal auditors should not review risk management activities as this creates an independence conflict
  4. Unchanged risk scores despite material business changes may indicate the risk assessment process is not functioning effectively or that management is not providing objective risk information to the board (correct answer)

Explanation: Risk scores should change as the business environment evolves. Two acquisitions and a new product launch introduce new operational, regulatory, integration, and market risks that should be reflected in updated risk assessments. Scores that remain static across three years of significant change suggest either that risk assessments are not being performed with genuine rigor, or that management is suppressing unfavorable risk information to avoid board scrutiny. Both possibilities represent a failure in the risk governance process. Option A reaches the opposite, unsupported conclusion. Option B addresses reporting frequency without addressing the quality concern. Option C is incorrect; internal audit oversight of risk management processes is a standard and expected function.

Question 13

A company performs an annual risk assessment but has not updated its risk register since completing a major acquisition 18 months ago. The acquired entity operates in a different industry with distinct regulatory requirements. Which concern is most analytically relevant?

  1. Annual risk assessments are standard practice and the 18-month gap is within acceptable norms
  2. Risk registers should be updated only when auditors identify new risks during their annual engagement
  3. The acquisition introduced new operational, regulatory, and integration risks that should have been incorporated into the risk register promptly; an outdated register may leave material risks unidentified and unaddressed (correct answer)
  4. The risk register is an optional governance document with no direct bearing on internal control effectiveness

Explanation: Risk assessments and risk registers should be updated whenever a significant business change occurs - and a major acquisition that adds a new industry and regulatory environment clearly qualifies. An 18-month gap following an acquisition means the company may be operating with unidentified compliance, integration, and operational risks. The COSO framework requires that risk assessment be an ongoing process responsive to changes in the business environment. Option A accepts a timing gap that significantly exceeds what is appropriate given the magnitude of change. Option B cedes a management responsibility to the auditors. Option D is incorrect; the risk register is a fundamental tool of ERM.

Question 14

A company requires dual signatures on checks exceeding 10,000.Asinglecheckfor10,000. A single check for 10,000.Asinglecheckfor9,800 is written to a fictitious vendor and passes without triggering the dual-signature requirement. This scenario illustrates which control concept?

  1. A material weakness because an actual fraud was not prevented
  2. A detective control that failed to identify the fictitious vendor
  3. An IT access control deficiency in the payment system
  4. A control threshold that was deliberately exploited by structuring the transaction to fall just below the approval level (correct answer)

Explanation: This is a classic example of structuring - intentionally keeping transactions below a control threshold to avoid triggering the associated oversight requirement. The dual-signature control worked exactly as designed for transactions over $10,000, but the fraudster circumvented it by structuring the payment just below the limit. This is a known fraud technique that highlights the limitation of threshold-based controls. Option A incorrectly labels this as a material weakness based solely on the fraud outcome. Option B describes a detective control, but the dual-signature requirement is a preventive control. Option C is not supported by the facts presented.

Question 15

A company operates in multiple foreign jurisdictions but its ERM framework was designed for its home country and has not been adapted for foreign operations. Which risk category is most directly affected?

  1. Strategic risk only, because regulatory differences affect long-term planning
  2. Operational risk only, because foreign regulations primarily affect production processes
  3. Reputational risk only, because non-compliance affects public perception
  4. Compliance risk across all foreign jurisdictions, since the unadapted ERM framework may fail to identify, assess, or respond to jurisdiction-specific legal and regulatory requirements (correct answer)

Explanation: An ERM framework that has not been tailored to foreign regulatory environments creates compliance risk - the risk of failing to adhere to laws, regulations, and codes applicable in each jurisdiction. Unadapted frameworks may miss local tax requirements, labor laws, environmental regulations, anti-bribery statutes, or data privacy rules. While strategic, operational, and reputational risks may also be affected, compliance risk is the most direct and immediate category because it relates to legal obligations in each operating jurisdiction. Options A, B, and C each identify valid secondary risk categories but miss the primary compliance risk exposure.

Question 16

In the COSO ERM framework, which risk response strategy involves transferring risk exposure to another party through mechanisms such as insurance or a joint venture arrangement?

  1. Risk avoidance
  2. Risk reduction
  3. Risk acceptance
  4. Risk sharing (correct answer)

Explanation: Risk sharing (also called risk transfer) involves shifting some or all of the risk to another party. Insurance transfers the financial consequences of a loss to an insurer; joint ventures share both the upside and downside with a partner. Option A (avoidance) exits the activity that gives rise to the risk entirely. Option B (reduction) takes action to decrease the likelihood or impact of a risk event. Option C (acceptance) acknowledges the risk and takes no specific action to mitigate it, typically when the cost of mitigation exceeds the expected benefit.

Question 17

A company's control environment assessment reveals: no formal code of ethics, frequent management override of approval limits, an audit committee that has not convened in 12 months, and a CFO with sole authority over financial reporting. Which COSO component is most fundamentally compromised, and what is the broader implication?

  1. Monitoring is most compromised because the audit committee has not met; other components remain sound
  2. Information and communication is most compromised because the CFO controls all reporting outputs
  3. Control activities are most compromised because approval limits are routinely overridden
  4. The control environment is most fundamentally compromised; as the foundation of the entire COSO framework, weaknesses here undermine the effectiveness of all other components regardless of how well they are individually designed (correct answer)

Explanation: The control environment is the first and foundational component of COSO - it sets the tone, values, and accountability structures that make all other controls meaningful. An absent code of ethics, management override culture, inactive audit committee, and concentrated financial reporting authority all represent failures at the control environment level. When the control environment is weak, the other four COSO components are compromised because their effectiveness depends on the human behaviors and governance structures that the control environment establishes. Options A, B, and C each identify real control concerns but characterize them as component-specific failures rather than recognizing them as manifestations of a fundamentally weak control environment.

Question 18

A company's assessment shows strong entity-level controls (ethical tone at the top, effective audit committee, formal code of conduct) but weak transaction-level controls in the purchasing cycle (missing authorizations, incomplete supporting documentation). Which COSO-based conclusion is most appropriate?

  1. Strong entity-level controls do not compensate for specific transaction-level control deficiencies; both levels must function effectively (correct answer)
  2. A strong tone at the top eliminates the risk from transaction-level weaknesses because ethical management will self-correct errors
  3. The audit committee's involvement is sufficient to compensate for purchasing cycle weaknesses
  4. Transaction-level controls are inherently less important than entity-level controls and address lower-risk activities

Explanation: COSO views internal control as a multi-layered system in which all five components must be present and functioning. Entity-level controls set the right environment and reduce the overall likelihood of misconduct, but they do not replace transaction-level controls that prevent specific errors from entering the financial records. Unauthorized disbursements can occur even in ethical organizations if transactional authorization is absent. Options B and C overstate the compensating power of general tone and oversight. Option D is incorrect; COSO does not establish a hierarchy of importance between entity and transaction-level controls.

Question 19

Which of the following is an example of a preventive control rather than a detective control?

  1. Reconciling bank statements monthly to identify unauthorized transactions
  2. Reviewing exception reports to identify unusual transactions after they have been posted
  3. Requiring management authorization before a purchase order can be issued (correct answer)
  4. Conducting physical inventory counts to verify that recorded balances match physical quantities

Explanation: A preventive control is designed to stop an error or irregularity from occurring in the first place. Requiring authorization before a purchase order is issued prevents an unauthorized transaction from entering the system. Options A, B, and D are all detective controls - they identify errors or irregularities after they have already occurred by comparing records, reviewing reports, or counting physical assets. Detective controls are valuable for identifying issues but do not prevent them.

Question 20

A $2,000,000 inventory fraud was carried out by a warehouse manager who controlled all inventory transactions and reconciliations without oversight. After discovery, management concludes the segregation of duties policy was adequate and the fraud was an isolated incident. Which concern does this assessment raise?

  1. The conclusion is flawed; the occurrence of a successful fraud demonstrates that either the control design was inadequate or the control did not operate effectively, and the root cause must be corrected (correct answer)
  2. The conclusion is appropriate because a single incident does not by itself indicate a systemic control failure
  3. The assessment is sufficient as long as the responsible employee is terminated
  4. Control assessments after fraud should be conducted by the same team that originally designed the controls

Explanation: A realized fraud of $2,000,000 resulting from inadequate segregation of duties is direct evidence that the control framework failed - either the policy was not properly designed or it was not being followed. Concluding the policy was 'adequate' contradicts the empirical evidence of the fraud itself. Root cause analysis must determine whether the design was flawed (policy inadequate) or the operation was deficient (policy not enforced) before the exposure can be remediated. Options B and C minimize the control implications without investigating root cause. Option D creates a conflict of interest in the assessment.