What this quiz covers
This quiz focuses on Evaluate Internal Control Components, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Bar.
A payroll authorization control requires written manager approval for all new hires before HR processes them in the system. Testing reveals that managers routinely approve new hires verbally without completing the required written form. Which conclusion is most appropriate?
CPA Bar Quiz
Practice Evaluate Internal Control Components in CPA Bar with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
This quiz focuses on Evaluate Internal Control Components, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Bar.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
A payroll authorization control requires written manager approval for all new hires before HR processes them in the system. Testing reveals that managers routinely approve new hires verbally without completing the required written form. Which conclusion is most appropriate?
Explanation: The control was properly designed - requiring written authorization before system processing is sound control design. However, it is not operating effectively because managers are not following the written documentation requirement. Without written approval, there is no auditable evidence that proper authorization occurred, creating a gap in the control's operating effectiveness. Option A incorrectly accepts verbal approvals as equivalent to the designed written control. Option B is directionally correct but understates the specific problem, which is both the absence of written evidence and the inability to audit the authorization trail. Option C incorrectly concludes the design is also flawed.
An accounts payable control evaluation finds: purchase orders exist for 94% of transactions, receiving reports exist for 89% of transactions, and invoice approvals exist for 97% of transactions. The 11% of transactions missing receiving reports have an average amount of $8,500. Which assessment is most accurate?
Explanation: The receiving report is a critical control in the three-way match process because it confirms that goods were actually received before payment is authorized. An 11% gap means that for roughly one in nine transactions, the company has no documented confirmation of receipt. This creates a real risk of paying for undelivered goods or fictitious invoices. Option A applies an arbitrary threshold without considering the purpose of the control. Option B requires a realized loss to classify a deficiency, which is incorrect - risk potential determines deficiency status. Option D incorrectly treats the approval control as compensating for missing receipt confirmation; they serve different verification purposes.
A company uses a three-tier control model with preventive, detective, and corrective controls. An evaluation finds the financial reporting process relies primarily on detective and corrective controls with minimal preventive controls. Which analytical concern does this raise?
Explanation: A well-designed control system uses preventive controls as the first line of defense because they stop errors and irregularities before they enter financial records. Detective and corrective controls are essential complements, but they cannot fully substitute for prevention because: detection always occurs after the fact, some errors may not be detected, and correction is more costly than prevention. Over-reliance on detective controls means the financial reporting process depends on finding and fixing errors rather than preventing them. Option A incorrectly ranks detective controls above preventive. Option B assumes 100% correction effectiveness, which is unrealistic. Option C's 100% detection rate assumption is not achievable in practice.
A company's monitoring activities include: monthly management reviews of budget-to-actual variances, quarterly control self-assessments by department heads, and an annual internal audit of key processes. None of these activities are performed by individuals independent of the processes being monitored. Which concern does this raise?
Explanation: Effective monitoring requires an appropriate degree of independence. When management reviews its own variances, department heads self-assess their own controls, and the internal audit function lacks independence, the monitoring system has a structural limitation: those doing the monitoring have a potential conflict of interest in identifying and reporting problems in their own areas. COSO emphasizes that the objectivity of the evaluator is critical to monitoring effectiveness. The degree of independence needed varies with the significance of the risk, but some level of independence is essential for credible monitoring. Options A and C incorrectly treat process proximity as an advantage that outweighs independence concerns. Option B understates the breadth of monitoring needed.
A board of directors evaluates its internal control system by relying exclusively on management self-assessment reports that consistently show all controls as effective. No independent verification is performed. Which concern does this evaluation process raise?
Explanation: Effective board oversight requires independent verification of control effectiveness, not merely management's representation. When management is both responsible for implementing controls and the sole source of information about their effectiveness, there is an inherent conflict of interest. The board's oversight function requires it to obtain some independent assurance - through internal audit, external audit, or other means - to challenge and verify management's self-assessment. Option A confuses operational knowledge with independent objectivity. Option B is incorrect; SEC rules require rigorous internal control assessment and attestation, not unchallenged self-reporting. Option D understates the board's governance responsibility for internal control oversight.
A policy requires controller approval for all journal entries above $50,000. Testing of 40 such entries finds that 6 (15%) were posted without controller approval. How should this deficiency be assessed?
Explanation: A 15% exception rate for a journal entry authorization control is a meaningful operating effectiveness failure. Journal entries above $50,000 represent high-risk transactions; the authorization requirement exists specifically to prevent unauthorized or erroneous entries with significant financial impact. A 15% bypass rate means that one in six high-value journal entries circumvents the control. Options A and B apply subjective tolerance percentages that have no basis in control evaluation standards. Option C is incorrect; the issue is that the control activity itself is not being followed, not merely that a monitoring mechanism failed to catch exceptions.
An IT application controls evaluation shows all 15 payroll control tests functioning correctly. However, the IT general controls review found that payroll application code can be modified by IT staff without an independent change management process. Which conclusion is most analytically sound?
Explanation: IT general controls provide the environment in which application controls operate. If the change management process does not prevent unauthorized program modifications, then application controls may have functioned correctly at the time of testing but could be altered afterward without detection. This is a fundamental principle of IT audit: weak ITGCs reduce the reliability of application control testing results because the tested controls may not represent the controls actually operating in the system over the full period. Option A and B ignore this dependency relationship. Option D treats sample size as a substitute for addressing the ITGC weakness.
An information and communication evaluation finds that financial reports are produced accurately but operational managers do not receive timely notification of control exceptions, and control failures are not escalated to the board. Which evaluation is most appropriate?
Explanation: The information and communication component of COSO requires that relevant information - including information about control deficiencies and failures - be communicated throughout the organization to those who need it to fulfill their control responsibilities. This includes upward communication to the board about significant control failures. Accurate financial reporting satisfies only the external reporting aspect of information and communication; the internal flow of control-relevant information is equally important. Option A narrowly focuses on one output of the information system. Option B incorrectly limits the audience for control information. Option C incorrectly separates exception reporting from information and communication, when both components are involved.
A company installs a whistleblower hotline to strengthen its control environment. After six months, zero reports have been received, and management concludes the control environment is strong. Which analytical challenge is most relevant?
Explanation: The effectiveness of a whistleblower hotline cannot be measured solely by the volume of reports received. Zero reports in the first six months may indicate: employees are unaware the hotline exists; employees fear retaliation despite stated protections; employees do not trust that reports are truly anonymous; or the hotline process is inaccessible. A genuinely effective hotline requires employee awareness, credible anonymity protections, and a demonstrated culture in which reports are taken seriously without retaliation. Management must assess these conditions rather than treating silence as evidence of a healthy control environment. Option A accepts an unsupported inference. Option C incorrectly limits hotline relevance to public companies. Option D is a valid timing concern but does not identify the most fundamental analytical issue.
A company's cash management function includes: a combination safe with access restricted to the treasurer; daily cash counts reconciled to the general ledger; dual custody required for transfers exceeding $25,000; and a mandatory vacation policy requiring two consecutive weeks. Which of these is best classified as a detective control?
Explanation: A detective control identifies errors or irregularities after they have occurred. Daily cash counts reconciled to the GL detect discrepancies by comparing physical cash to recorded amounts - a post-event check. The combination safe (Option B) prevents unauthorized access - a preventive control. Dual custody (Option C) prevents unauthorized transfers by requiring two parties - preventive. Mandatory vacation (Option D) reduces fraud opportunities by forcing rotation - preventive, as it deters and uncovers ongoing schemes through coverage by others.
Under the COSO framework, what is the primary distinction between ongoing monitoring activities and separate evaluations?
Explanation: COSO distinguishes between ongoing monitoring - which is built into normal operations (such as supervisory review of work, system-generated exception reports, and management dashboard reviews) - and separate evaluations, which are periodic assessments conducted specifically to evaluate control effectiveness (such as internal audits and control self-assessments). Both types contribute to the monitoring component. Option A introduces a financial vs. operational distinction that does not exist in the COSO framework. Option C is incorrect; management performs both types of monitoring. Option D incorrectly limits the scope of each.
An IT application control rejects invoice amounts exceeding $500,000 and requires supervisor override to proceed. During the year, 12 supervisor overrides were processed for invoices ranging from $520,000 to $2,100,000. The internal auditor finds no after-the-fact review of overrides was performed. What is the nature of this control gap?
Explanation: Override capabilities in application controls require compensating detective controls to remain effective. Without after-the-fact review of overrides, a supervisor could approve fraudulent or unauthorized invoices without any subsequent detection. The review of overrides serves as a detective control that preserves the overall effectiveness of the exception process. Option B addresses threshold calibration, which is a separate concern from the missing review. Option C incorrectly dismisses the value of post-override review. Option D is incorrect; frequency alone does not determine whether overrides constitute a material weakness - the absence of a review mechanism is the substantive issue.
A company's risk assessment identifies significant risk from management bias in fair value measurements of complex financial instruments. The control response is to have the same finance team that prepares the estimates also review them for reasonableness. Which control design concern does this reveal?
Explanation: A fundamental principle of control design is that review controls must be performed by individuals independent of the preparation process. When the finance team reviews its own fair value estimates, there is no independent challenge of the assumptions, inputs, or methodology. This self-review threat is particularly significant for complex estimates where subjectivity and management bias are identified risks. Effective control design would require review by an independent group - a valuation committee, internal audit, or external specialist. Option A confuses technical expertise with independence. Option C incorrectly dismisses the possibility of effective controls. Option D identifies accountability without addressing independence.
An IT general controls review finds that the IT department can create user accounts, assign any access privilege level, and delete accounts - all without HR or management approval. Which risk does this create?
Explanation: Unilateral IT authority over user provisioning is a logical access control weakness. Without HR or management approval, IT staff could create fictitious accounts, grant excessive privileges to existing users, or retain access for terminated employees. This creates the ability for unauthorized transactions to be executed in financial and operational systems, directly affecting data integrity and financial reporting. Option A addresses physical server security. Option B addresses availability and recovery. Option D addresses application change management, a separate IT general control domain.
A company implements a new ERP system, automating many previously manual accounts payable controls. Without retesting controls in Year 2 following the ERP implementation, management concludes that control effectiveness from Year 1 testing is maintained. Which concern does this raise?
Explanation: When an organization transitions to a new system, the specific controls change even if the objectives remain the same. Manual authorization processes and automated system validation rules are different in nature, design, and failure modes. A new ERP system may have configuration gaps, interface errors, or missing controls that only become apparent through testing. Prior-year results cannot be extrapolated to a new system environment because the system being tested is fundamentally different. Option A makes an unsupported assumption about ERP improvements. Option C correctly identifies that objectives are consistent but incorrectly uses this as a justification for skipping testing. Option D is incorrect; prior-year results do not extend to changed system environments.
A review of revenue recognition controls finds that the system automatically records revenue when a sales order is marked 'shipped' in the order management system, with no independent verification that physical shipment occurred or that title transferred. Which control gap does this identify?
Explanation: Revenue under ASC 606 should be recognized when performance obligations are satisfied - typically upon delivery and transfer of control/title. If revenue is automatically triggered by a system status change without independent verification that the physical event occurred, the control does not confirm the underlying economic event. An employee could mark an order as shipped without actually shipping it, prematurely triggering revenue recognition. Option A narrowly frames this as a technology issue. Option C ignores that consistent application of a flawed rule still produces misstatements. Option D proposes a detective response to what is fundamentally a preventive control design gap.
A company has a strong internal audit function, effective audit committee oversight, and sophisticated monitoring systems. An external auditor determines the control environment is weak due to the CEO's history of circumventing controls. Which COSO-based conclusion applies?
Explanation: COSO explicitly identifies the control environment as the foundation upon which all other components rest. A CEO who circumvents controls represents the most serious type of control environment failure - management override - because it undermines the reliability of all other controls. Monitoring activities can detect some issues, but they cannot prevent a determined executive from overriding controls in the moment. Additionally, internal audit and monitoring effectiveness depends on management's willingness to act on findings, which is compromised when the top executive circumvents rather than supports the control system. Options A and B overstate the compensating power of monitoring and oversight against a culture of executive override.
A company identifies a new risk: significant judgment is required in estimating warranty reserves, which could affect earnings by up to $4,000,000. Management responds by documenting the estimation methodology and requiring CFO approval for all reserve changes. Which COSO components does this response primarily address?
Explanation: Identifying and analyzing a new risk (warranty estimation uncertainty) is part of risk assessment. Designing a response - documenting methodology and requiring CFO approval - represents control activities. Together, these two COSO components address the identification of the risk and the establishment of controls to manage it. Option A (control environment) relates to the broader organizational culture and governance structure. Option B relates to how information flows within the organization. Option D involves evaluating whether controls are functioning as intended over time.
An internal auditor evaluates the severity of a deficiency: the AR aging and bad debt estimation are prepared by one employee with no supervisory review. A second employee independently reconciles AR to the GL monthly, detecting approximately 80% of errors in testing. Which classification most likely applies?
Explanation: The compensating reconciliation control reduces, but does not eliminate, the risk. An 80% detection rate means 20% of errors may not be caught. For a significant accounting estimate like bad debt reserves, a 20% undetected error rate may still be sufficient to create more than a remote possibility of material misstatement - which would support a material weakness. However, the reconciliation provides meaningful mitigation. This nuanced scenario is most consistent with a significant deficiency - more severe than a simple control deficiency but with a compensating control that reduces the risk below the material weakness threshold. Option B overstates severity without considering the compensating control. Option C overstates the reconciliation's effectiveness given the 80% detection rate. Option D understates severity.
A control environment assessment finds strong written policies, a published code of ethics, and documented control procedures. However, employee interviews reveal management routinely overrides policies and employees feel pressure to meet targets at the expense of compliance. Which evaluation is most accurate?
Explanation: The COSO framework recognizes that the control environment reflects the actual behavior of the organization, not just its written policies. When management's actions contradict documented standards - overriding controls, creating pressure to compromise compliance - the effective control environment is weak despite the paper documentation. This disconnect between formal documentation and actual behavior is a critical finding. Option B confuses documentation quality with actual environment effectiveness. Option C incorrectly reclassifies a behavioral control environment failure as a monitoring problem. Option D dismisses compelling evidence of real control environment weakness.