An organization discovers that the same customer exists in its CRM, billing, and shipping systems under three different names with three different addresses. This is best described as a:
Opening subject page...
Loading your content
CPA Isc Quiz
Practice Master Data And Data Controls in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
Question 1 / 20
0 of 20 answered
An organization discovers that the same customer exists in its CRM, billing, and shipping systems under three different names with three different addresses. This is best described as a:
This quiz focuses on Master Data And Data Controls, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
An organization discovers that the same customer exists in its CRM, billing, and shipping systems under three different names with three different addresses. This is best described as a:
Explanation: Duplicate customer records with inconsistent data across systems is a master data quality problem - the classic symptom of inadequate MDM governance. Answer A is correct. API failures (B), access controls (C), and encryption (D) are unrelated to the described data consistency issue.
Which of the following controls most directly prevents unauthorized additions to the vendor master file in an accounts payable system?
Explanation: An authorization control requiring independent management approval for new vendor additions directly prevents unauthorized vendor creation - a key preventive control against fictitious vendor fraud. Answer C is correct. Encryption (A) protects confidentiality. Monthly reports (B) are detective controls. Confidentiality agreements (D) are legal controls, not data entry controls.
A company finds that its customer master file contains records for 800 customers who have had no transactions in the past three years. The most appropriate action is:
Explanation: Inactive master data should be managed through a formal review process - some records may need to be retained for regulatory or legal purposes while others can be archived or inactivated. Answer D is correct. Immediate deletion (A) may violate retention requirements. Encryption (B) doesn't address inactivity. Unauthorized database access (C) is not a data management control.
Which of the following is the most effective control for detecting unauthorized changes to the vendor master file?
Explanation: Comparing master file changes to approved change requests is a detective control that identifies unauthorized modifications - directly linking changes to authorization evidence. Answer A is correct. Encryption (B) prevents reading, not modification by authorized users. Vendor confirmation (C) is a separate reconciliation process. Read-only access (D) prevents all changes including legitimate ones.
A company's employee master data record is updated when an employee changes departments. Controls require the HR system to automatically update the payroll and access management systems. An auditor finds that access management was not updated in 12 of 50 sampled department changes. This finding indicates:
Explanation: A 24% failure rate in automated access updates represents a significant interface control failure - employees who changed departments may have retained inappropriate access to their former systems. Answer C is correct. Capacity issues (A) would affect all updates. System support (B) would produce 100% failures, not 24%. The financial and security implications are not minor (D).
A company's chart of accounts (COA) is a type of master data. Which of the following controls most directly ensures the accuracy and completeness of the COA for financial reporting purposes?
Explanation: A formal change control process for the COA ensures changes are authorized and appropriate - preventing unauthorized account creation or modification that could misrepresent or obscure financial activity. Answer A is correct. Encryption (B) protects confidentiality. Employee verification (C) is not a standard COA control. Industry benchmarks (D) are strategic planning tools, not COA controls.
An organization implements a data stewardship program for its customer master data. A data steward's primary responsibility for master data is to:
Explanation: A data steward is the operational accountability role for master data quality - monitoring quality metrics, resolving issues, enforcing standards, and ensuring the data remains accurate and fit for use. Answer C is correct. Encryption (A), backup (B), and access restriction (D) are IT operations and security functions, not data stewardship roles.
An organization's payroll system maintains an employee master file with salary and bank account information. An auditor reviews controls over this file and finds that payroll staff can modify bank account numbers without any secondary approval. The primary fraud risk is:
Explanation: Unrestricted bank account modification in payroll is a direct fraud risk - payroll staff can redirect employee pay to accounts they control. This is one of the most common payroll fraud schemes. Answer D is correct. Legitimate reasons (A) do not eliminate the fraud risk. Processing speed (B) and payment receipt (C) are operational concerns, not the primary fraud risk.
A company's price master data contains approved pricing for 50,000 products. An auditor finds that 127 products have negative prices in the master file. This represents:
Explanation: Negative prices in a product master file are a significant data quality error - they could result in credit invoices being generated instead of sales invoices, directly affecting revenue. Answer A is correct. Price promotions use discount structures, not negative prices (B). Negative prices are not normal (C). Financial impact of 127 products could be material (D).
Which of the following represents the primary risk of maintaining outdated or inaccurate customer master data?
Explanation: Inaccurate customer master data cascades through all downstream processes - billing, shipping, AR, tax calculations - because transactions reference master data at the time of processing. Answer C is correct. Storage capacity (A) and navigation difficulty (B) are operational concerns. Marketing effectiveness (D) is a business concern but not the primary data integrity risk.
An organization's ERP system is configured to prevent the same bank account number from being assigned to more than one vendor. This system control is best described as:
Explanation: A uniqueness constraint on bank account numbers in the vendor master file is a preventive input control - blocking at the data entry stage the creation of multiple vendor records pointing to the same bank account. Answer D is correct. Processing controls (A) and output controls (B) operate after entry. Access controls (C) restrict users, not data values.
A company's item master data includes the unit of measure (UOM) for each inventory item. A UOM error causes 100 units of a high-value component to be recorded as 100 individual items instead of 100 boxes of 12. The primary financial reporting impact is:
Explanation: A UOM error directly causes financial misstatement - recording 100 boxes of 12 as 100 individual units understates inventory count by 1,100 units, which could be material depending on the item value. Answer B is correct. Location display (A) and physical location (C) are operational concerns. Future ordering (D) is a downstream operational impact.
Which of the following is the most important control over changes to the employee pay rate master data in a payroll system?
Explanation: Pay rate changes require segregation of duties: HR initiates based on approved changes, management approves, and an independent reviewer verifies payroll processed correctly - preventing unauthorized rate increases. Answer A is correct. Encryption (B) protects confidentiality. Employee self-service (C) is not an authorization control. Archiving (D) supports retention but not change authorization.
An organization maintains a chart of accounts with 2,400 active GL accounts. During an audit, the auditor finds 340 accounts that have never been used in the 5 years since the ERP system was implemented. The most appropriate recommendation is:
Explanation: Unused GL accounts should be reviewed and inactivated if no longer needed - they represent unnecessary complexity and potential avenues for posting unauthorized transactions. Answer C is correct. Immediate deletion (A) requires review first. Unused accounts can create fraud risk (B). Reclassification (D) doesn't address the control issue.
Which of the following data controls addresses the risk that a vendor's banking information is fraudulently changed to divert future payments?
Explanation: Verifying bank account changes using independently confirmed contact information (original contract phone numbers) prevents fraudulent bank account redirections - a common social engineering attack. Answer D is correct. Encryption (A) protects stored data but not change authorization. Vendor access restriction (B) addresses vendor-side access. Payment confirmations (C) detect fraud after it occurs.
An auditor reviews vendor master file change activity and finds that 3 new vendors were added, all within the same week, by the same AP clerk, with addresses in the same city, and all have received payments within 30 days of being added. This pattern is most consistent with:
Explanation: The combination of rapid creation by a single individual, geographic clustering, and quick payments is a high-risk pattern for fictitious vendor fraud - the clerk may have created vendors they control to divert company payments. Answer C is correct. The pattern is too specific to be coincidental normal activity (A) or automated (B). Duplicates don't explain rapid new payments (D).
A company's master data management policy requires that all master data changes be logged in an immutable audit trail. The primary purpose of this requirement is to:
Explanation: An immutable audit trail for master data changes ensures accountability and provides evidence for investigations, audits, and regulatory examinations - it cannot be altered or deleted by the individuals who made changes. Answer D is correct. Performance optimization (A) and backup completeness (B) are secondary benefits. Automatic rollback (C) requires additional tooling beyond logging.
Which of the following represents the most significant data control weakness in an accounts payable master data environment?
Explanation: The ability for one person to create vendors, approve invoices, and release payments represents the most dangerous combination of incompatible duties in AP - enabling the complete fraud cycle without any compensating check. Answer B is correct. Inactive records (A), unverified contacts (C), and missing tax fields (D) are data quality issues but far less severe than the segregation of duties failure.
A company's product master data includes standard cost information used for inventory valuation. An unauthorized change increases the standard cost of a component by 35%. What is the primary financial reporting risk?
Explanation: Standard costs directly drive inventory valuation and COGS calculations - a 35% unauthorized change in standard cost produces material misstatement of both balance sheet inventory and income statement COGS. Answer B is correct. Location codes (A) are operational. Future purchasing (C) is a procurement concern. Variance alerts (D) may be a detective control but the primary risk is financial misstatement.
Which of the following best describes the purpose of data ownership in a master data governance framework?
Explanation: Data ownership establishes accountability - the data owner (business leader) is responsible for the master data domain's quality, standards, and governance. Answer A is correct. Modification tracking (B) is audit logging. Access restriction (C) relates to access controls. Unique identifiers (D) are a technical data integrity measure.