Home

Tutoring

Subjects

Live Classes

Study Coach

Essay Review

On-Demand Courses

Colleges

Games


Sign up

Log in

Opening subject page...

Loading your content

Practice

  • All Subjects
  • Algebra Flashcards
  • SAT Math Practice Tests
  • Math Question of the Day
  • Live Classes
  • On-Demand Courses

Varsity Tutors

  • Find a Tutor
  • Test Prep
  • Online Classes
  • K-12 Learning
  • College Search
  • VarsityTutors.com

© 2026 Varsity Tutors. All rights reserved.

← Back to quizzes

CPA Isc Quiz

CPA Isc Quiz: Evaluate Design And Implementation Of Controls

Practice Evaluate Design And Implementation Of Controls in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

Question 1 / 20

0 of 20 answered

When evaluating the design of an internal control, an auditor is primarily assessing:

Select an answer to continue

What this quiz covers

This quiz focuses on Evaluate Design And Implementation Of Controls, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

When evaluating the design of an internal control, an auditor is primarily assessing:

  1. Whether the control was performed correctly every time during the audit period.
  2. Whether the control, if operating as intended, is capable of preventing or detecting a material misstatement or significant risk. (correct answer)
  3. Whether the control is documented in the organization's policy manual.
  4. Whether the control was implemented within the approved project budget.

Explanation: Design evaluation asks whether the control as designed would be effective if it operated as intended. Answer B is correct. Operating effectiveness (A) is a separate assessment. Documentation (C) supports but does not define design. Budget (D) is irrelevant.

Question 2

A control requiring manager approval of all journal entries above $10,000 before posting is designed to address which control objective?

  1. Authorization - ensuring significant entries receive appropriate approval before recording. (correct answer)
  2. Completeness - ensuring all entries are captured in the general ledger.
  3. Valuation - ensuring entries are recorded at correct amounts.
  4. Cutoff - ensuring entries are recorded in the correct period.

Explanation: A management approval requirement is an authorization control. Answer A is correct. Completeness (B) ensures all entries are captured. Valuation (C) relates to amounts. Cutoff (D) relates to timing.

Question 3

Which of the following best describes the difference between a preventive control and a detective control?

  1. Preventive controls are performed by management; detective controls are performed by auditors.
  2. Preventive controls operate after a transaction is recorded; detective controls operate before.
  3. Preventive controls stop errors or fraud before they occur; detective controls identify them after they have occurred. (correct answer)
  4. Preventive controls apply only to IT systems; detective controls apply to manual processes.

Explanation: The key distinction is timing: preventive controls stop undesired events; detective controls identify them after the fact. Answer C is correct. Answers A, B, and D mischaracterize the distinction.

Question 4

An automated three-way match control in accounts payable is best classified as:

  1. A detective control that identifies duplicate payments after processing.
  2. A corrective control that reverses unauthorized payments automatically.
  3. A compensating control used when segregation of duties cannot be achieved.
  4. A preventive control that stops payment of invoices not matched to an approved PO and goods receipt. (correct answer)

Explanation: Three-way match prevents payment unless a matching PO and receipt exist - stopping unauthorized payments before they occur. Answer D is correct. It prevents rather than detects (A), does not reverse payments (B), and is a primary control (C).

Question 5

An auditor evaluates RBAC controls and finds that role definitions have not been updated in five years despite significant organizational changes. This represents:

  1. A well-designed control that does not require updates once implemented.
  2. A minor issue since role definitions are technical configurations.
  3. A design and implementation gap - outdated roles may grant inappropriate access. (correct answer)
  4. An acceptable compensating control since the system was implemented years ago.

Explanation: RBAC is only effective when role definitions match current job functions. Outdated roles create inappropriate access. Answer C is correct. Controls require ongoing maintenance (A, B, D).

Question 6

Which of the following represents the strongest evidence that controls over financial reporting are well-designed?

  1. Controls are mapped to specific risks, cover all significant risks, operate at appropriate process points, and include both preventive and detective elements. (correct answer)
  2. Controls are documented in a policy manual approved by the CFO.
  3. The organization has more controls than industry peers.
  4. Controls were designed by an external consulting firm.

Explanation: Well-designed controls are risk-based, comprehensive, well-positioned, and layered. Answer A is correct. Documentation (B), quantity (C), and designer (D) do not demonstrate design adequacy.

Question 7

A reconciliation control is performed daily but variances are routinely noted and ignored without investigation. This indicates:

  1. The reconciliation is well-designed and operating effectively.
  2. The variance tolerance is too low, causing excessive false positives.
  3. The control should be redesigned as a preventive control.
  4. A design or implementation gap - without variance investigation, the reconciliation does not achieve its objective. (correct answer)

Explanation: A reconciliation that identifies variances but never resolves them fails its objective. Answer D is correct. Uninvestigated variances mean the control is ineffective (A, B, C).

Question 8

An auditor tests a dual-approval control for wire transfers over $50,000 and finds 3 of 25 sampled transfers had only one approver. The auditor should conclude:

  1. Operating effectiveness exceptions exist - the control did not operate as designed in 12% of transactions, requiring assessment of deficiency severity. (correct answer)
  2. The control is effective since 22 of 25 transactions were approved correctly.
  3. The control should be redesigned to require only one approver since compliance is difficult.
  4. The exceptions are acceptable since amounts may have been below $50,000.

Explanation: Three exceptions out of 25 is a meaningful deviation rate for a key authorization control. The auditor must assess deficiency severity. Answer A is correct. 88% compliance may be insufficient for key financial controls (B). Lowering the standard weakens the control (C). Assumptions require evidence (D).

Question 9

Compared to a manual approval control for purchase orders, an automated control that rejects POs with invalid vendor IDs is:

  1. Less reliable because automated systems are more prone to errors than humans.
  2. More reliable and consistent - automation applies the rule every time without human error or override. (correct answer)
  3. Equivalent in effectiveness to the manual control.
  4. Only effective if IT monitors the automated control daily.

Explanation: Automated controls apply rules consistently to every transaction, eliminating human inconsistency. Answer B is correct. Automation is generally more consistent than humans for repetitive rules (A, C). Daily monitoring is not always required (D).

Question 10

A payroll manager who enters payroll data and processes the payroll run also reviews and approves the payroll register. This represents:

  1. An effective control since the manager is most knowledgeable about payroll.
  2. An efficient process that reduces payroll processing time.
  3. A segregation of duties deficiency - the same person who prepares payroll should not also approve it. (correct answer)
  4. An acceptable arrangement in small organizations with limited staff.

Explanation: Having the same person prepare and approve payroll eliminates the independent check that approval provides. Answer C is correct. Knowledge (A) and efficiency (B) do not justify the gap. Small organization constraints require compensating controls, not acceptance (D).

Question 11

An IT audit identifies that a critical financial system has no user acceptance testing (UAT) before changes are deployed to production. This is a gap in which stage?

  1. Authorization - changes are deployed without management approval.
  2. Monitoring - there is no mechanism to track deployed change performance.
  3. Risk assessment - the organization has not identified risks of untested changes.
  4. Quality assurance in the implementation phase - without UAT, changes may introduce defects affecting financial data accuracy. (correct answer)

Explanation: UAT is a quality assurance control in the implementation process. Its absence means defects could reach production. Answer D is correct. Authorization (A), monitoring (B), and risk assessment (C) are distinct control activities.

Question 12

In COSO, 'risk assessment' as a component informs control design by:

  1. Providing financial estimates of control implementation costs.
  2. Replacing the need for control activities by monitoring risks directly.
  3. Identifying and analyzing risks so controls can be designed to specifically address them. (correct answer)
  4. Assigning risk ownership to external auditors.

Explanation: Risk assessment identifies what can go wrong, driving proportionate control design. Answer C is correct. Cost estimation (A) is a management decision. Risk assessment informs, not replaces, controls (B). Risk ownership belongs to management (D).

Question 13

A daily cash receipts reconciliation is performed but not reviewed or signed off by a supervisor. The most significant design gap is:

  1. The absence of independent supervisory review - without it, the reconciliation is a self-checking process with limited assurance. (correct answer)
  2. The reconciliation is performed too frequently; monthly would be sufficient.
  3. The reconciliation should be automated rather than manual.
  4. The preparer should also make the deposits to improve efficiency.

Explanation: A reconciliation without independent review provides limited assurance - the preparer cannot objectively verify their own work. Answer A is correct. Daily frequency is appropriate for cash (B). Automation preference (C) is a separate consideration. Combined roles worsen segregation (D).

Question 14

'Control rationalization' in control design refers to:

  1. Eliminating all controls not tested by internal audit.
  2. Having external auditors approve all control designs.
  3. Increasing controls to reduce residual risk to zero.
  4. Evaluating and streamlining the control portfolio to ensure each control addresses a specific risk, removing redundant or ineffective controls while maintaining adequate coverage. (correct answer)

Explanation: Control rationalization improves efficiency by ensuring every control serves a clear purpose. Answer D is correct. Eliminating untested controls (A), external approval of all designs (B), and zero residual risk (C) are all incorrect.

Question 15

When assessing whether a control is appropriately designed for a high-risk process, which factor is most important?

  1. The control was implemented before the current fiscal year began.
  2. The control is performed by the most experienced employee.
  3. The control directly addresses the specific risk, operates at the right point in the process, and is proportionate to risk significance. (correct answer)
  4. The control was recommended by external auditors.

Explanation: Effective control design requires direct risk linkage, appropriate process positioning, and proportionate response. Answer C is correct. Timing (A), preparer experience (B), and auditor recommendation (D) do not determine design adequacy.

Question 16

What is the primary risk of over-reliance on manual controls?

  1. Manual controls are subject to human error, inconsistency, override, and may not scale as transaction volumes increase. (correct answer)
  2. Manual controls are more expensive to implement than automated controls.
  3. Manual controls cannot satisfy external audit requirements.
  4. Manual controls are ineffective at preventing fraud.

Explanation: Manual controls are less reliable than automated ones for high-volume processes - susceptible to fatigue, distraction, and inconsistency. Answer A is correct. Cost (B) varies. External auditors accept manual controls (C). Manual controls can prevent some fraud (D).

Question 17

Which approach most effectively evaluates overall design adequacy of an organization's internal control framework?

  1. Confirming all controls are documented in a single policy document.
  2. Verifying management has approved the framework annually.
  3. Counting the total number of controls implemented.
  4. Mapping identified risks to controls, identifying coverage gaps, and assessing whether each control is properly designed to address its target risk. (correct answer)

Explanation: A risk-control mapping exercise reveals whether all significant risks are covered and whether each control is designed to address its target risk. Answer D is correct. Documentation (A), approval (B), and counts (C) provide administrative evidence but not design adequacy.

Question 18

In the COSO Internal Control framework, the 'control environment' refers to:

  1. The collection of automated IT controls that enforce organizational policies.
  2. The set of reconciliation and monitoring controls performed by the accounting team.
  3. The physical and logical access controls protecting organizational assets.
  4. The foundation of the control framework - leadership tone, organizational structure, responsibilities, and ethical standards that influence how controls operate. (correct answer)

Explanation: The control environment is the organizational foundation on which all other controls rest. Answer D is correct. Automated IT controls (A), reconciliations (B), and access controls (C) are specific control types within the framework.

Question 19

An auditor finds a control requiring manager review of a 500-page monthly report to identify exceptions. The most significant design concern is:

  1. The report is printed rather than available electronically.
  2. A 500-page manual review is impractical and unlikely to reliably identify exceptions. (correct answer)
  3. The control should be performed weekly rather than monthly.
  4. The control should be performed by an independent auditor rather than a manager.

Explanation: A control that is theoretically sound but practically unperformable due to volume is a design weakness - reliability of detection is low. Answer B is correct. Format (A), frequency (C), and evaluator (D) are secondary issues.

Question 20

A company's internal audit team evaluates whether controls over a new cloud-based financial system are adequate. Which of the following should the auditors assess as part of the design evaluation?

  1. Whether the cloud provider has been in business for at least 10 years.
  2. Whether the system's built-in controls (e.g., automated approvals, access restrictions, audit logs) are appropriately configured to address the organization's specific financial reporting risks. (correct answer)
  3. Whether all employees have received cloud security training.
  4. Whether the system was implemented on time and within budget.

Explanation: Control design evaluation for a cloud-based system requires assessing whether the system's configurable controls are set up to address the organization's specific risks - authorization settings, access restrictions, logging configurations. Answer B is correct. Vendor longevity (A), training (C), and project delivery (D) do not assess control design adequacy.