CPA Quiz: Evaluate Design And Implementation Of Controls
20 questions · exam conditions
0:00
Evaluate Design And Implementation Of ControlsQuestion 1 of 20

Which best illustrates a control that is well-designed but poorly implemented?

A control requiring manager approval for expenses over $1,000 that has never been documented in any policy.
A control requiring manager approval for expenses over $1,000 that is documented and trained, but managers routinely approve requests without reviewing supporting documentation.
A control requiring manager approval that is consistently followed and documented.
A control requiring manager approval with no defined dollar threshold.
← Back to quizzes

CPA Quiz

CPA Quiz: Evaluate Design And Implementation Of Controls

Practice Evaluate Design And Implementation Of Controls in CPA with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

What this quiz covers

This quiz focuses on Evaluate Design And Implementation Of Controls, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

Which best illustrates a control that is well-designed but poorly implemented?

  1. A control requiring manager approval for expenses over $1,000 that has never been documented in any policy.
  2. A control requiring manager approval for expenses over $1,000 that is documented and trained, but managers routinely approve requests without reviewing supporting documentation. (correct answer)
  3. A control requiring manager approval that is consistently followed and documented.
  4. A control requiring manager approval with no defined dollar threshold.
Explanation: A well-designed control (clear threshold, appropriate responsibility) not followed in practice (approvals without review) illustrates operating effectiveness failure with adequate design. Answer B is correct. Undocumented controls (A) have design gaps. Consistently followed (C) is effective. No threshold (D) is a design gap.

Question 2

The control operates as designed, yet errors persist. Evaluate first:

  1. Control implementation
  2. The control's design (correct answer)
  3. Control monitoring
  4. Control documentation
Explanation: When a control runs exactly as designed but errors continue, implementation isn't the problem; the built-in procedure itself is failing to address the risk. You should first evaluate the control's design to see whether its steps are capable of preventing or detecting the errors. Control monitoring is tempting, but monitoring checks ongoing operation, and operation already matches design.

Question 3

An automated match approves invoices within a 5% tolerance. Which design is deficient?

  1. Approval based on tolerance
  2. Overrides need no approval (correct answer)
  3. Tolerance applies consistently
  4. System logs all overrides
Explanation: An override bypasses the 5% tolerance, so letting it pass without approval defeats the control; overrides should require separate authorization. Approval based on tolerance is the rule itself, not deficient, and consistent application plus logging support it. The deficient design is the unapproved override.

Question 4

A new rule blocks terminated employee logins. Which evidence best confirms implementation?

  1. Config shows active rule
  2. Manager signed the rule change
  3. No overrides in exception log
  4. Direct test confirms block (correct answer)
Explanation: The strongest evidence that a control is truly implemented is a direct test proving the terminated login is blocked. Configuration may show the rule exists, but it doesn't prove enforcement in practice. A direct test verifies the actual outcome, so it best confirms implementation.

Question 5

A process has only a detective control. Which risk profile makes the design acceptable?

  1. Risk is low and infrequent (correct answer)
  2. Errors are prevented upstream
  3. Management reviews all output
  4. System runs fully automated
Explanation: With only a detective control, problems are found after they occur, not stopped. That design is acceptable only when the risk is low and infrequent, so any damage stays small and rare. The tempting wrong choice is 'errors are prevented upstream,' but that describes a preventive control, not a risk profile that justifies detective-only design.

Question 6

A bot posts entries using a human user's credentials. Best control design?

  1. Give bot limited system access
  2. Review bot entries each week
  3. Assign bot a service account (correct answer)
  4. Train users about bot policy
Explanation: A bot posting with a human account ties its actions to that person and bypasses the controls on that human account. A service account gives the bot its own identity, so you can grant least privilege, monitor it, and revoke it independently. Giving the bot limited system access is the tempting wrong answer because it still leaves the bot using the human credentials.

Question 7

Which of the following represents the strongest evidence that controls over financial reporting are well-designed?

  1. Controls are mapped to specific risks, cover all significant risks, operate at appropriate process points, and include both preventive and detective elements. (correct answer)
  2. Controls are documented in a policy manual approved by the CFO.
  3. The organization has more controls than industry peers.
  4. Controls were designed by an external consulting firm.
Explanation: Well-designed controls are risk-based, comprehensive, well-positioned, and layered. Answer A is correct. Documentation (B), quantity (C), and designer (D) do not demonstrate design adequacy.

Question 8

In COSO, 'risk assessment' as a component informs control design by:

  1. Providing financial estimates of control implementation costs.
  2. Replacing the need for control activities by monitoring risks directly.
  3. Identifying and analyzing risks so controls can be designed to specifically address them. (correct answer)
  4. Assigning risk ownership to external auditors.
Explanation: Risk assessment identifies what can go wrong, driving proportionate control design. Answer C is correct. Cost estimation (A) is a management decision. Risk assessment informs, not replaces, controls (B). Risk ownership belongs to management (D).

Question 9

In the COSO Internal Control framework, the 'control environment' refers to:

  1. The collection of automated IT controls that enforce organizational policies.
  2. The set of reconciliation and monitoring controls performed by the accounting team.
  3. The physical and logical access controls protecting organizational assets.
  4. The foundation of the control framework - leadership tone, organizational structure, responsibilities, and ethical standards that influence how controls operate. (correct answer)
Explanation: The control environment is the organizational foundation on which all other controls rest. Answer D is correct. Automated IT controls (A), reconciliations (B), and access controls (C) are specific control types within the framework.

Question 10

An auditor finds a control requiring manager review of a 500-page monthly report to identify exceptions. The most significant design concern is:

  1. The report is printed rather than available electronically.
  2. A 500-page manual review is impractical and unlikely to reliably identify exceptions. (correct answer)
  3. The control should be performed weekly rather than monthly.
  4. The control should be performed by an independent auditor rather than a manager.
Explanation: A control that is theoretically sound but practically unperformable due to volume is a design weakness - reliability of detection is low. Answer B is correct. Format (A), frequency (C), and evaluator (D) are secondary issues.

Question 11

Which principle helps ensure controls remain relevant as the organization and its risks evolve?

  1. Controls should be periodically reviewed and updated to address current risks, technologies, and business processes. (correct answer)
  2. Controls should be designed as permanent structures that do not change to ensure consistency.
  3. Controls should be designed to address all possible future risks at implementation.
  4. Controls should be outsourced to ensure objectivity and longevity.
Explanation: The control environment must evolve with the organization. Answer A is correct. Permanent unchanging controls (B) become outdated. Predicting all future risks (C) is not feasible. Outsourcing (D) does not ensure relevance.

Question 12

Which of the following best describes the difference between a preventive control and a detective control?

  1. Preventive controls are performed by management; detective controls are performed by auditors.
  2. Preventive controls operate after a transaction is recorded; detective controls operate before.
  3. Preventive controls stop errors or fraud before they occur; detective controls identify them after they have occurred. (correct answer)
  4. Preventive controls apply only to IT systems; detective controls apply to manual processes.
Explanation: The key distinction is timing: preventive controls stop undesired events; detective controls identify them after the fact. Answer C is correct. Answers A, B, and D mischaracterize the distinction.

Question 13

An automated three-way match control in accounts payable is best classified as:

  1. A detective control that identifies duplicate payments after processing.
  2. A corrective control that reverses unauthorized payments automatically.
  3. A compensating control used when segregation of duties cannot be achieved.
  4. A preventive control that stops payment of invoices not matched to an approved PO and goods receipt. (correct answer)
Explanation: Three-way match prevents payment unless a matching PO and receipt exist - stopping unauthorized payments before they occur. Answer D is correct. It prevents rather than detects (A), does not reverse payments (B), and is a primary control (C).

Question 14

An auditor evaluates RBAC controls and finds that role definitions have not been updated in five years despite significant organizational changes. This represents:

  1. A well-designed control that does not require updates once implemented.
  2. A minor issue since role definitions are technical configurations.
  3. A design and implementation gap - outdated roles may grant inappropriate access. (correct answer)
  4. An acceptable compensating control since the system was implemented years ago.
Explanation: RBAC is only effective when role definitions match current job functions. Outdated roles create inappropriate access. Answer C is correct. Controls require ongoing maintenance (A, B, D).

Question 15

A reconciliation control is performed daily but variances are routinely noted and ignored without investigation. This indicates:

  1. The reconciliation is well-designed and operating effectively.
  2. The variance tolerance is too low, causing excessive false positives.
  3. The control should be redesigned as a preventive control.
  4. A design or implementation gap - without variance investigation, the reconciliation does not achieve its objective. (correct answer)
Explanation: A reconciliation that identifies variances but never resolves them fails its objective. Answer D is correct. Uninvestigated variances mean the control is ineffective (A, B, C).

Question 16

An auditor tests a dual-approval control for wire transfers over $50,000 and finds 3 of 25 sampled transfers had only one approver. The auditor should conclude:

  1. Operating effectiveness exceptions exist - the control did not operate as designed in 12% of transactions, requiring assessment of deficiency severity. (correct answer)
  2. The control is effective since 22 of 25 transactions were approved correctly.
  3. The control should be redesigned to require only one approver since compliance is difficult.
  4. The exceptions are acceptable since amounts may have been below $50,000.
Explanation: Three exceptions out of 25 is a meaningful deviation rate for a key authorization control. The auditor must assess deficiency severity. Answer A is correct. 88% compliance may be insufficient for key financial controls (B). Lowering the standard weakens the control (C). Assumptions require evidence (D).

Question 17

Compared to a manual approval control for purchase orders, an automated control that rejects POs with invalid vendor IDs is:

  1. Less reliable because automated systems are more prone to errors than humans.
  2. More reliable and consistent - automation applies the rule every time without human error or override. (correct answer)
  3. Equivalent in effectiveness to the manual control.
  4. Only effective if IT monitors the automated control daily.
Explanation: Automated controls apply rules consistently to every transaction, eliminating human inconsistency. Answer B is correct. Automation is generally more consistent than humans for repetitive rules (A, C). Daily monitoring is not always required (D).

Question 18

A payroll manager who enters payroll data and processes the payroll run also reviews and approves the payroll register. This represents:

  1. An effective control since the manager is most knowledgeable about payroll.
  2. An efficient process that reduces payroll processing time.
  3. A segregation of duties deficiency - the same person who prepares payroll should not also approve it. (correct answer)
  4. An acceptable arrangement in small organizations with limited staff.
Explanation: Having the same person prepare and approve payroll eliminates the independent check that approval provides. Answer C is correct. Knowledge (A) and efficiency (B) do not justify the gap. Small organization constraints require compensating controls, not acceptance (D).

Question 19

An IT audit identifies that a critical financial system has no user acceptance testing (UAT) before changes are deployed to production. This is a gap in which stage?

  1. Authorization - changes are deployed without management approval.
  2. Monitoring - there is no mechanism to track deployed change performance.
  3. Risk assessment - the organization has not identified risks of untested changes.
  4. Quality assurance in the implementation phase - without UAT, changes may introduce defects affecting financial data accuracy. (correct answer)
Explanation: UAT is a quality assurance control in the implementation process. Its absence means defects could reach production. Answer D is correct. Authorization (A), monitoring (B), and risk assessment (C) are distinct control activities.

Question 20

A daily cash receipts reconciliation is performed but not reviewed or signed off by a supervisor. The most significant design gap is:

  1. The absence of independent supervisory review - without it, the reconciliation is a self-checking process with limited assurance. (correct answer)
  2. The reconciliation is performed too frequently; monthly would be sufficient.
  3. The reconciliation should be automated rather than manual.
  4. The preparer should also make the deposits to improve efficiency.
Explanation: A reconciliation without independent review provides limited assurance - the preparer cannot objectively verify their own work. Answer A is correct. Daily frequency is appropriate for cash (B). Automation preference (C) is a separate consideration. Combined roles worsen segregation (D).