CPA Isc Quiz: Evaluate Design And Implementation Of Controls
20 questions · exam conditions
0:00
Evaluate Design And Implementation Of ControlsQuestion 1 of 20

Which best illustrates a control that is well-designed but poorly implemented?

A control requiring manager approval for expenses over $1,000 that has never been documented in any policy.
A control requiring manager approval for expenses over $1,000 that is documented and trained, but managers routinely approve requests without reviewing supporting documentation.
A control requiring manager approval that is consistently followed and documented.
A control requiring manager approval with no defined dollar threshold.
← Back to quizzes

CPA Isc Quiz

CPA Isc Quiz: Evaluate Design And Implementation Of Controls

Practice Evaluate Design And Implementation Of Controls in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

What this quiz covers

This quiz focuses on Evaluate Design And Implementation Of Controls, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

Which best illustrates a control that is well-designed but poorly implemented?

  1. A control requiring manager approval for expenses over $1,000 that has never been documented in any policy.
  2. A control requiring manager approval for expenses over $1,000 that is documented and trained, but managers routinely approve requests without reviewing supporting documentation. (correct answer)
  3. A control requiring manager approval that is consistently followed and documented.
  4. A control requiring manager approval with no defined dollar threshold.

Explanation: A well-designed control (clear threshold, appropriate responsibility) not followed in practice (approvals without review) illustrates operating effectiveness failure with adequate design. Answer B is correct. Undocumented controls (A) have design gaps. Consistently followed (C) is effective. No threshold (D) is a design gap.

Question 2

Which of the following represents the strongest evidence that controls over financial reporting are well-designed?

  1. Controls are mapped to specific risks, cover all significant risks, operate at appropriate process points, and include both preventive and detective elements. (correct answer)
  2. Controls are documented in a policy manual approved by the CFO.
  3. The organization has more controls than industry peers.
  4. Controls were designed by an external consulting firm.

Explanation: Well-designed controls are risk-based, comprehensive, well-positioned, and layered. Answer A is correct. Documentation (B), quantity (C), and designer (D) do not demonstrate design adequacy.

Question 3

In COSO, 'risk assessment' as a component informs control design by:

  1. Providing financial estimates of control implementation costs.
  2. Replacing the need for control activities by monitoring risks directly.
  3. Identifying and analyzing risks so controls can be designed to specifically address them. (correct answer)
  4. Assigning risk ownership to external auditors.

Explanation: Risk assessment identifies what can go wrong, driving proportionate control design. Answer C is correct. Cost estimation (A) is a management decision. Risk assessment informs, not replaces, controls (B). Risk ownership belongs to management (D).

Question 4

In the COSO Internal Control framework, the 'control environment' refers to:

  1. The collection of automated IT controls that enforce organizational policies.
  2. The set of reconciliation and monitoring controls performed by the accounting team.
  3. The physical and logical access controls protecting organizational assets.
  4. The foundation of the control framework - leadership tone, organizational structure, responsibilities, and ethical standards that influence how controls operate. (correct answer)

Explanation: The control environment is the organizational foundation on which all other controls rest. Answer D is correct. Automated IT controls (A), reconciliations (B), and access controls (C) are specific control types within the framework.

Question 5

An auditor finds a control requiring manager review of a 500-page monthly report to identify exceptions. The most significant design concern is:

  1. The report is printed rather than available electronically.
  2. A 500-page manual review is impractical and unlikely to reliably identify exceptions. (correct answer)
  3. The control should be performed weekly rather than monthly.
  4. The control should be performed by an independent auditor rather than a manager.

Explanation: A control that is theoretically sound but practically unperformable due to volume is a design weakness - reliability of detection is low. Answer B is correct. Format (A), frequency (C), and evaluator (D) are secondary issues.

Question 6

Which principle helps ensure controls remain relevant as the organization and its risks evolve?

  1. Controls should be periodically reviewed and updated to address current risks, technologies, and business processes. (correct answer)
  2. Controls should be designed as permanent structures that do not change to ensure consistency.
  3. Controls should be designed to address all possible future risks at implementation.
  4. Controls should be outsourced to ensure objectivity and longevity.

Explanation: The control environment must evolve with the organization. Answer A is correct. Permanent unchanging controls (B) become outdated. Predicting all future risks (C) is not feasible. Outsourcing (D) does not ensure relevance.

Question 7

Which of the following best describes the difference between a preventive control and a detective control?

  1. Preventive controls are performed by management; detective controls are performed by auditors.
  2. Preventive controls operate after a transaction is recorded; detective controls operate before.
  3. Preventive controls stop errors or fraud before they occur; detective controls identify them after they have occurred. (correct answer)
  4. Preventive controls apply only to IT systems; detective controls apply to manual processes.

Explanation: The key distinction is timing: preventive controls stop undesired events; detective controls identify them after the fact. Answer C is correct. Answers A, B, and D mischaracterize the distinction.

Question 8

An automated three-way match control in accounts payable is best classified as:

  1. A detective control that identifies duplicate payments after processing.
  2. A corrective control that reverses unauthorized payments automatically.
  3. A compensating control used when segregation of duties cannot be achieved.
  4. A preventive control that stops payment of invoices not matched to an approved PO and goods receipt. (correct answer)

Explanation: Three-way match prevents payment unless a matching PO and receipt exist - stopping unauthorized payments before they occur. Answer D is correct. It prevents rather than detects (A), does not reverse payments (B), and is a primary control (C).

Question 9

An auditor evaluates RBAC controls and finds that role definitions have not been updated in five years despite significant organizational changes. This represents:

  1. A well-designed control that does not require updates once implemented.
  2. A minor issue since role definitions are technical configurations.
  3. A design and implementation gap - outdated roles may grant inappropriate access. (correct answer)
  4. An acceptable compensating control since the system was implemented years ago.

Explanation: RBAC is only effective when role definitions match current job functions. Outdated roles create inappropriate access. Answer C is correct. Controls require ongoing maintenance (A, B, D).

Question 10

A reconciliation control is performed daily but variances are routinely noted and ignored without investigation. This indicates:

  1. The reconciliation is well-designed and operating effectively.
  2. The variance tolerance is too low, causing excessive false positives.
  3. The control should be redesigned as a preventive control.
  4. A design or implementation gap - without variance investigation, the reconciliation does not achieve its objective. (correct answer)

Explanation: A reconciliation that identifies variances but never resolves them fails its objective. Answer D is correct. Uninvestigated variances mean the control is ineffective (A, B, C).

Question 11

An auditor tests a dual-approval control for wire transfers over $50,000 and finds 3 of 25 sampled transfers had only one approver. The auditor should conclude:

  1. Operating effectiveness exceptions exist - the control did not operate as designed in 12% of transactions, requiring assessment of deficiency severity. (correct answer)
  2. The control is effective since 22 of 25 transactions were approved correctly.
  3. The control should be redesigned to require only one approver since compliance is difficult.
  4. The exceptions are acceptable since amounts may have been below $50,000.

Explanation: Three exceptions out of 25 is a meaningful deviation rate for a key authorization control. The auditor must assess deficiency severity. Answer A is correct. 88% compliance may be insufficient for key financial controls (B). Lowering the standard weakens the control (C). Assumptions require evidence (D).

Question 12

Compared to a manual approval control for purchase orders, an automated control that rejects POs with invalid vendor IDs is:

  1. Less reliable because automated systems are more prone to errors than humans.
  2. More reliable and consistent - automation applies the rule every time without human error or override. (correct answer)
  3. Equivalent in effectiveness to the manual control.
  4. Only effective if IT monitors the automated control daily.

Explanation: Automated controls apply rules consistently to every transaction, eliminating human inconsistency. Answer B is correct. Automation is generally more consistent than humans for repetitive rules (A, C). Daily monitoring is not always required (D).

Question 13

A payroll manager who enters payroll data and processes the payroll run also reviews and approves the payroll register. This represents:

  1. An effective control since the manager is most knowledgeable about payroll.
  2. An efficient process that reduces payroll processing time.
  3. A segregation of duties deficiency - the same person who prepares payroll should not also approve it. (correct answer)
  4. An acceptable arrangement in small organizations with limited staff.

Explanation: Having the same person prepare and approve payroll eliminates the independent check that approval provides. Answer C is correct. Knowledge (A) and efficiency (B) do not justify the gap. Small organization constraints require compensating controls, not acceptance (D).

Question 14

An IT audit identifies that a critical financial system has no user acceptance testing (UAT) before changes are deployed to production. This is a gap in which stage?

  1. Authorization - changes are deployed without management approval.
  2. Monitoring - there is no mechanism to track deployed change performance.
  3. Risk assessment - the organization has not identified risks of untested changes.
  4. Quality assurance in the implementation phase - without UAT, changes may introduce defects affecting financial data accuracy. (correct answer)

Explanation: UAT is a quality assurance control in the implementation process. Its absence means defects could reach production. Answer D is correct. Authorization (A), monitoring (B), and risk assessment (C) are distinct control activities.

Question 15

A daily cash receipts reconciliation is performed but not reviewed or signed off by a supervisor. The most significant design gap is:

  1. The absence of independent supervisory review - without it, the reconciliation is a self-checking process with limited assurance. (correct answer)
  2. The reconciliation is performed too frequently; monthly would be sufficient.
  3. The reconciliation should be automated rather than manual.
  4. The preparer should also make the deposits to improve efficiency.

Explanation: A reconciliation without independent review provides limited assurance - the preparer cannot objectively verify their own work. Answer A is correct. Daily frequency is appropriate for cash (B). Automation preference (C) is a separate consideration. Combined roles worsen segregation (D).

Question 16

'Control rationalization' in control design refers to:

  1. Eliminating all controls not tested by internal audit.
  2. Having external auditors approve all control designs.
  3. Increasing controls to reduce residual risk to zero.
  4. Evaluating and streamlining the control portfolio to ensure each control addresses a specific risk, removing redundant or ineffective controls while maintaining adequate coverage. (correct answer)

Explanation: Control rationalization improves efficiency by ensuring every control serves a clear purpose. Answer D is correct. Eliminating untested controls (A), external approval of all designs (B), and zero residual risk (C) are all incorrect.

Question 17

When assessing whether a control is appropriately designed for a high-risk process, which factor is most important?

  1. The control was implemented before the current fiscal year began.
  2. The control is performed by the most experienced employee.
  3. The control directly addresses the specific risk, operates at the right point in the process, and is proportionate to risk significance. (correct answer)
  4. The control was recommended by external auditors.

Explanation: Effective control design requires direct risk linkage, appropriate process positioning, and proportionate response. Answer C is correct. Timing (A), preparer experience (B), and auditor recommendation (D) do not determine design adequacy.

Question 18

What is the primary risk of over-reliance on manual controls?

  1. Manual controls are subject to human error, inconsistency, override, and may not scale as transaction volumes increase. (correct answer)
  2. Manual controls are more expensive to implement than automated controls.
  3. Manual controls cannot satisfy external audit requirements.
  4. Manual controls are ineffective at preventing fraud.

Explanation: Manual controls are less reliable than automated ones for high-volume processes - susceptible to fatigue, distraction, and inconsistency. Answer A is correct. Cost (B) varies. External auditors accept manual controls (C). Manual controls can prevent some fraud (D).

Question 19

Which approach most effectively evaluates overall design adequacy of an organization's internal control framework?

  1. Confirming all controls are documented in a single policy document.
  2. Verifying management has approved the framework annually.
  3. Counting the total number of controls implemented.
  4. Mapping identified risks to controls, identifying coverage gaps, and assessing whether each control is properly designed to address its target risk. (correct answer)

Explanation: A risk-control mapping exercise reveals whether all significant risks are covered and whether each control is designed to address its target risk. Answer D is correct. Documentation (A), approval (B), and counts (C) provide administrative evidence but not design adequacy.

Question 20

Which of the following best describes a 'compensating control'?

  1. A control that automatically corrects errors when detected by the system.
  2. A control that mitigates a risk when the ideal primary control cannot be implemented, providing an alternative means of achieving the same objective. (correct answer)
  3. A control that compensates employees for performing control activities.
  4. A control performed at year-end to compensate for controls not performed during the year.

Explanation: Compensating controls provide alternative risk mitigation when the preferred control is not feasible. Answer B is correct. Automatic correction (A) is corrective. Employee compensation (C) and year-end catch-up (D) are unrelated.