All questions
Question 1
A payroll authorization control requires written manager approval for all new hires before HR processes them in the system. Testing reveals that managers routinely approve new hires verbally without completing the required written form. Which conclusion is most appropriate?
- The control is both designed and operating effectively because approvals are occurring verbally
- The control is designed effectively but not operating effectively because verbal approvals do not satisfy the written documentation requirement
- The control is neither designed nor operating effectively
- The control has an operating effectiveness deficiency specifically because the written authorization is not consistently completed, leaving no auditable evidence that approvals occurred (correct answer)
Explanation: The control was properly designed - requiring written authorization before system processing is sound control design. However, it is not operating effectively because managers are not following the written documentation requirement. Without written approval, there is no auditable evidence that proper authorization occurred, creating a gap in the control's operating effectiveness. Option A incorrectly accepts verbal approvals as equivalent to the designed written control. Option B is directionally correct but understates the specific problem, which is both the absence of written evidence and the inability to audit the authorization trail. Option C incorrectly concludes the design is also flawed.
Question 2
An accounts payable control evaluation finds: purchase orders exist for 94% of transactions, receiving reports exist for 89% of transactions, and invoice approvals exist for 97% of transactions. The 11% of transactions missing receiving reports have an average amount of $8,500. Which assessment is most accurate?
- Controls are operating effectively because all compliance rates exceed 85%
- The missing receiving reports are a deficiency only if they resulted in an actual payment error
- Missing receiving reports represent a control gap - without confirmation of receipt, the company cannot verify that goods were delivered before payment is made (correct answer)
- Receiving reports are a secondary control compensated by the high invoice approval rate
Explanation: The receiving report is a critical control in the three-way match process because it confirms that goods were actually received before payment is authorized. An 11% gap means that for roughly one in nine transactions, the company has no documented confirmation of receipt. This creates a real risk of paying for undelivered goods or fictitious invoices. Option A applies an arbitrary threshold without considering the purpose of the control. Option B requires a realized loss to classify a deficiency, which is incorrect - risk potential determines deficiency status. Option D incorrectly treats the approval control as compensating for missing receipt confirmation; they serve different verification purposes.
Question 3
A company uses a three-tier control model with preventive, detective, and corrective controls. An evaluation finds the financial reporting process relies primarily on detective and corrective controls with minimal preventive controls. Which analytical concern does this raise?
- Detective controls are superior to preventive controls because they provide evidence of actual errors
- The balance is optimal because corrective controls can fix any error that detective controls identify
- Minimal preventive controls are acceptable as long as detective controls have a 100% detection rate
- Relying primarily on detective and corrective controls means errors must occur before they can be caught; preventive controls stop errors from entering the system, reducing the likelihood of undetected misstatements (correct answer)
Explanation: A well-designed control system uses preventive controls as the first line of defense because they stop errors and irregularities before they enter financial records. Detective and corrective controls are essential complements, but they cannot fully substitute for prevention because: detection always occurs after the fact, some errors may not be detected, and correction is more costly than prevention. Over-reliance on detective controls means the financial reporting process depends on finding and fixing errors rather than preventing them. Option A incorrectly ranks detective controls above preventive. Option B assumes 100% correction effectiveness, which is unrealistic. Option C's 100% detection rate assumption is not achievable in practice.
Question 4
A company's monitoring activities include: monthly management reviews of budget-to-actual variances, quarterly control self-assessments by department heads, and an annual internal audit of key processes. None of these activities are performed by individuals independent of the processes being monitored. Which concern does this raise?
- Self-monitoring is always sufficient as long as it is documented and reviewed by management
- Monthly budget reviews are sufficient monitoring for all financial reporting risks
- Control self-assessments by department heads are the strongest monitoring form because they have direct process knowledge
- When monitoring is performed exclusively by those responsible for the processes, objectivity is reduced, limiting the ability to detect control deficiencies that those individuals may have contributed to or have an interest in concealing (correct answer)
Explanation: Effective monitoring requires an appropriate degree of independence. When management reviews its own variances, department heads self-assess their own controls, and the internal audit function lacks independence, the monitoring system has a structural limitation: those doing the monitoring have a potential conflict of interest in identifying and reporting problems in their own areas. COSO emphasizes that the objectivity of the evaluator is critical to monitoring effectiveness. The degree of independence needed varies with the significance of the risk, but some level of independence is essential for credible monitoring. Options A and C incorrectly treat process proximity as an advantage that outweighs independence concerns. Option B understates the breadth of monitoring needed.
Question 5
A board of directors evaluates its internal control system by relying exclusively on management self-assessment reports that consistently show all controls as effective. No independent verification is performed. Which concern does this evaluation process raise?
- Management self-assessments are the most reliable source of control information because management has direct operational knowledge
- This approach is consistent with SEC regulations and no additional procedures are necessary
- Exclusive reliance on management self-assessments creates a conflict of interest; management evaluating its own controls lacks the objectivity required for effective board oversight (correct answer)
- The board is not responsible for internal control evaluation; this is solely the external auditor's role
Explanation: Effective board oversight requires independent verification of control effectiveness, not merely management's representation. When management is both responsible for implementing controls and the sole source of information about their effectiveness, there is an inherent conflict of interest. The board's oversight function requires it to obtain some independent assurance - through internal audit, external audit, or other means - to challenge and verify management's self-assessment. Option A confuses operational knowledge with independent objectivity. Option B is incorrect; SEC rules require rigorous internal control assessment and attestation, not unchallenged self-reporting. Option D understates the board's governance responsibility for internal control oversight.
Question 6
A policy requires controller approval for all journal entries above $50,000. Testing of 40 such entries finds that 6 (15%) were posted without controller approval. How should this deficiency be assessed?
- Not a deficiency - 15% exceptions are within normal tolerance for large organizations
- A minor deficiency - the 85% compliance rate indicates the control is generally functioning
- A monitoring deficiency only - the control design is sound but the exception was not caught in review
- A control operating effectiveness deficiency - a 15% exception rate for a key authorization control is a significant failure that elevates the risk of unauthorized entries reaching the financial statements (correct answer)
Explanation: A 15% exception rate for a journal entry authorization control is a meaningful operating effectiveness failure. Journal entries above $50,000 represent high-risk transactions; the authorization requirement exists specifically to prevent unauthorized or erroneous entries with significant financial impact. A 15% bypass rate means that one in six high-value journal entries circumvents the control. Options A and B apply subjective tolerance percentages that have no basis in control evaluation standards. Option C is incorrect; the issue is that the control activity itself is not being followed, not merely that a monitoring mechanism failed to catch exceptions.
Question 7
An IT application controls evaluation shows all 15 payroll control tests functioning correctly. However, the IT general controls review found that payroll application code can be modified by IT staff without an independent change management process. Which conclusion is most analytically sound?
- Application controls are effective and no further concern exists since testing passed
- The IT general control weakness is irrelevant because application controls passed all tests
- The IT general control weakness undermines reliance on application control test results - unauthorized program changes could alter how controls function after testing (correct answer)
- Expanding application testing to 30 samples would provide sufficient additional assurance
Explanation: IT general controls provide the environment in which application controls operate. If the change management process does not prevent unauthorized program modifications, then application controls may have functioned correctly at the time of testing but could be altered afterward without detection. This is a fundamental principle of IT audit: weak ITGCs reduce the reliability of application control testing results because the tested controls may not represent the controls actually operating in the system over the full period. Option A and B ignore this dependency relationship. Option D treats sample size as a substitute for addressing the ITGC weakness.
Question 8
An information and communication evaluation finds that financial reports are produced accurately but operational managers do not receive timely notification of control exceptions, and control failures are not escalated to the board. Which evaluation is most appropriate?
- The information and communication component is effective because financial report accuracy is confirmed
- Operational managers are not responsible for receiving internal control information
- Control exception reporting is part of monitoring activities and is outside the scope of information and communication
- Effective information and communication requires that control failure information be communicated to those with oversight responsibility; accuracy of external financial reports alone does not satisfy this COSO component (correct answer)
Explanation: The information and communication component of COSO requires that relevant information - including information about control deficiencies and failures - be communicated throughout the organization to those who need it to fulfill their control responsibilities. This includes upward communication to the board about significant control failures. Accurate financial reporting satisfies only the external reporting aspect of information and communication; the internal flow of control-relevant information is equally important. Option A narrowly focuses on one output of the information system. Option B incorrectly limits the audience for control information. Option C incorrectly separates exception reporting from information and communication, when both components are involved.
Question 9
A company installs a whistleblower hotline to strengthen its control environment. After six months, zero reports have been received, and management concludes the control environment is strong. Which analytical challenge is most relevant?
- Zero reports confirm a positive control environment and management's conclusion is well-supported
- An absence of hotline reports does not confirm the absence of control issues; it may reflect employee unawareness, fear of retaliation, or lack of trust in the anonymity process (correct answer)
- Whistleblower hotlines are only required for public companies and are not relevant to control environment assessment
- Six months is too short to evaluate a hotline's effectiveness and management should wait longer before drawing conclusions
Explanation: The effectiveness of a whistleblower hotline cannot be measured solely by the volume of reports received. Zero reports in the first six months may indicate: employees are unaware the hotline exists; employees fear retaliation despite stated protections; employees do not trust that reports are truly anonymous; or the hotline process is inaccessible. A genuinely effective hotline requires employee awareness, credible anonymity protections, and a demonstrated culture in which reports are taken seriously without retaliation. Management must assess these conditions rather than treating silence as evidence of a healthy control environment. Option A accepts an unsupported inference. Option C incorrectly limits hotline relevance to public companies. Option D is a valid timing concern but does not identify the most fundamental analytical issue.
Question 10
A company's cash management function includes: a combination safe with access restricted to the treasurer; daily cash counts reconciled to the general ledger; dual custody required for transfers exceeding $25,000; and a mandatory vacation policy requiring two consecutive weeks. Which of these is best classified as a detective control?
- Daily cash counts reconciled to the general ledger, identifying discrepancies after transactions are recorded (correct answer)
- The combination safe with access restricted to the treasurer
- Dual custody required for all cash transfers exceeding $25,000
- The mandatory vacation policy requiring two consecutive weeks away
Explanation: A detective control identifies errors or irregularities after they have occurred. Daily cash counts reconciled to the GL detect discrepancies by comparing physical cash to recorded amounts - a post-event check. The combination safe (Option B) prevents unauthorized access - a preventive control. Dual custody (Option C) prevents unauthorized transfers by requiring two parties - preventive. Mandatory vacation (Option D) reduces fraud opportunities by forcing rotation - preventive, as it deters and uncovers ongoing schemes through coverage by others.
Question 11
Under the COSO framework, what is the primary distinction between ongoing monitoring activities and separate evaluations?
- Ongoing monitoring focuses on financial controls while separate evaluations address operational controls
- Ongoing monitoring is embedded in routine business operations and occurs continuously, while separate evaluations are periodic assessments conducted apart from day-to-day processes (correct answer)
- Separate evaluations are performed exclusively by external auditors while ongoing monitoring is management's responsibility
- Ongoing monitoring applies only to IT controls and separate evaluations address all other control areas
Explanation: COSO distinguishes between ongoing monitoring - which is built into normal operations (such as supervisory review of work, system-generated exception reports, and management dashboard reviews) - and separate evaluations, which are periodic assessments conducted specifically to evaluate control effectiveness (such as internal audits and control self-assessments). Both types contribute to the monitoring component. Option A introduces a financial vs. operational distinction that does not exist in the COSO framework. Option C is incorrect; management performs both types of monitoring. Option D incorrectly limits the scope of each.
Question 12
An IT application control rejects invoice amounts exceeding 500,000andrequiressupervisoroverridetoproceed.Duringtheyear,12supervisoroverrideswereprocessedforinvoicesrangingfrom520,000 to $2,100,000. The internal auditor finds no after-the-fact review of overrides was performed. What is the nature of this control gap?
- The override process lacks a compensating detective control; post-override review is needed to ensure supervisors are not approving unauthorized transactions (correct answer)
- The $500,000 threshold is too low and should be raised to reduce the volume of overrides
- Application validation controls are sufficient and post-override review provides no additional assurance
- The 12 overrides during the year automatically constitute a material weakness regardless of amounts
Explanation: Override capabilities in application controls require compensating detective controls to remain effective. Without after-the-fact review of overrides, a supervisor could approve fraudulent or unauthorized invoices without any subsequent detection. The review of overrides serves as a detective control that preserves the overall effectiveness of the exception process. Option B addresses threshold calibration, which is a separate concern from the missing review. Option C incorrectly dismisses the value of post-override review. Option D is incorrect; frequency alone does not determine whether overrides constitute a material weakness - the absence of a review mechanism is the substantive issue.
Question 13
An authorization control test of 60 purchase orders finds 4 approved by employees not on the authorized approver list at the time of approval. Which conclusion is most appropriate?
- The result is acceptable - 93% compliance is strong for authorization controls
- The 4 exceptions are immaterial because they represent a small dollar amount
- The control is operating effectively because the large majority were properly authorized
- The 4 unauthorized approvals represent an authorization control failure - approvals from individuals outside the authorization list bypass a fundamental control regardless of the dollar amounts involved (correct answer)
Explanation: Authorization controls exist to ensure only designated individuals approve transactions. When individuals outside the authorized approver list process approvals, the control has not simply produced an exception - it has been circumvented. Dollar amount is not the primary criterion for evaluating authorization control failures; the integrity of the authorization process itself is the concern. Options A and C apply percentage-based thresholds that have no formal basis in authorization control standards. Option B incorrectly subordinates the authorization failure to dollar materiality.
Question 14
A company's risk assessment identifies significant risk from management bias in fair value measurements of complex financial instruments. The control response is to have the same finance team that prepares the estimates also review them for reasonableness. Which control design concern does this reveal?
- The control is well-designed because the finance team has the necessary technical expertise to evaluate their own work
- Having preparers review their own work creates a self-review threat that fails to provide independent challenge of the assumptions and methods used (correct answer)
- Fair value measurement is inherently subjective and no controls can effectively address this risk
- The control is adequate because management is ultimately accountable for the accuracy of its estimates
Explanation: A fundamental principle of control design is that review controls must be performed by individuals independent of the preparation process. When the finance team reviews its own fair value estimates, there is no independent challenge of the assumptions, inputs, or methodology. This self-review threat is particularly significant for complex estimates where subjectivity and management bias are identified risks. Effective control design would require review by an independent group - a valuation committee, internal audit, or external specialist. Option A confuses technical expertise with independence. Option C incorrectly dismisses the possibility of effective controls. Option D identifies accountability without addressing independence.
Question 15
An IT general controls review finds that the IT department can create user accounts, assign any access privilege level, and delete accounts - all without HR or management approval. Which risk does this create?
- Physical access risk to server hardware
- Data backup and recovery risk
- Logical access control risk - IT can provision unauthorized system access that allows individuals to execute transactions beyond their authorization (correct answer)
- Change management risk related to application program updates
Explanation: Unilateral IT authority over user provisioning is a logical access control weakness. Without HR or management approval, IT staff could create fictitious accounts, grant excessive privileges to existing users, or retain access for terminated employees. This creates the ability for unauthorized transactions to be executed in financial and operational systems, directly affecting data integrity and financial reporting. Option A addresses physical server security. Option B addresses availability and recovery. Option D addresses application change management, a separate IT general control domain.
Question 16
A company implements a new ERP system, automating many previously manual accounts payable controls. Without retesting controls in Year 2 following the ERP implementation, management concludes that control effectiveness from Year 1 testing is maintained. Which concern does this raise?
- ERP systems always improve control effectiveness and documentation of the system selection process is sufficient
- System implementations require reassessment of controls because automated controls in the new system may function differently from the manual controls they replaced, and continuity cannot be assumed without evidence (correct answer)
- Since the underlying control objectives are unchanged, testing is not required after a system change
- Year 1 testing results can be carried forward if no exceptions were identified in Year 1
Explanation: When an organization transitions to a new system, the specific controls change even if the objectives remain the same. Manual authorization processes and automated system validation rules are different in nature, design, and failure modes. A new ERP system may have configuration gaps, interface errors, or missing controls that only become apparent through testing. Prior-year results cannot be extrapolated to a new system environment because the system being tested is fundamentally different. Option A makes an unsupported assumption about ERP improvements. Option C correctly identifies that objectives are consistent but incorrectly uses this as a justification for skipping testing. Option D is incorrect; prior-year results do not extend to changed system environments.
Question 17
A review of revenue recognition controls finds that the system automatically records revenue when a sales order is marked 'shipped' in the order management system, with no independent verification that physical shipment occurred or that title transferred. Which control gap does this identify?
- A technology implementation deficiency only, correctable through system configuration
- A control design gap - automated revenue recognition lacks a control to verify that the triggering event actually occurred before recording revenue (correct answer)
- No gap exists because automated controls apply rules consistently without human error
- A monitoring deficiency correctable by reviewing exception reports after posting
Explanation: Revenue under ASC 606 should be recognized when performance obligations are satisfied - typically upon delivery and transfer of control/title. If revenue is automatically triggered by a system status change without independent verification that the physical event occurred, the control does not confirm the underlying economic event. An employee could mark an order as shipped without actually shipping it, prematurely triggering revenue recognition. Option A narrowly frames this as a technology issue. Option C ignores that consistent application of a flawed rule still produces misstatements. Option D proposes a detective response to what is fundamentally a preventive control design gap.
Question 18
A company has a strong internal audit function, effective audit committee oversight, and sophisticated monitoring systems. An external auditor determines the control environment is weak due to the CEO's history of circumventing controls. Which COSO-based conclusion applies?
- Strong monitoring activities compensate for a weak control environment and the overall system is effective
- The audit committee's oversight is the most critical element and fully offsets the CEO's behavior
- The control environment is the foundation; even robust monitoring cannot fully compensate for a CEO who circumvents controls, because management override undermines the integrity of the entire system (correct answer)
- Only the external auditor's findings are relevant; internal audit effectiveness does not affect the assessment
Explanation: COSO explicitly identifies the control environment as the foundation upon which all other components rest. A CEO who circumvents controls represents the most serious type of control environment failure - management override - because it undermines the reliability of all other controls. Monitoring activities can detect some issues, but they cannot prevent a determined executive from overriding controls in the moment. Additionally, internal audit and monitoring effectiveness depends on management's willingness to act on findings, which is compromised when the top executive circumvents rather than supports the control system. Options A and B overstate the compensating power of monitoring and oversight against a culture of executive override.
Question 19
A company identifies a new risk: significant judgment is required in estimating warranty reserves, which could affect earnings by up to $4,000,000. Management responds by documenting the estimation methodology and requiring CFO approval for all reserve changes. Which COSO components does this response primarily address?
- Control environment
- Information and communication
- Risk assessment and control activities (correct answer)
- Monitoring activities
Explanation: Identifying and analyzing a new risk (warranty estimation uncertainty) is part of risk assessment. Designing a response - documenting methodology and requiring CFO approval - represents control activities. Together, these two COSO components address the identification of the risk and the establishment of controls to manage it. Option A (control environment) relates to the broader organizational culture and governance structure. Option B relates to how information flows within the organization. Option D involves evaluating whether controls are functioning as intended over time.
Question 20
The COSO Internal Control - Integrated Framework defines internal control as a process designed to provide reasonable assurance regarding the achievement of which three categories of objectives?
- Operations, reporting, and compliance (correct answer)
- Revenue, cost control, and profitability
- Prevention, detection, and correction
- Financial, operational, and strategic objectives
Explanation: The COSO framework organizes objectives into three categories: operations objectives (effectiveness and efficiency of operations), reporting objectives (reliability of financial and non-financial reporting), and compliance objectives (adherence to laws and regulations). Option B describes financial performance goals, not the COSO objective categories. Option C describes control types by function. Option D is close but the COSO framework specifically uses 'operations,' 'reporting,' and 'compliance' rather than 'strategic.'