All questions
Question 1
You are performing an audit of a government entity that administers a benefits program. A recent economic downturn has increased application volume by 40%, and management reassigned experienced reviewers to customer service to handle call volume. As a result, new staff are approving eligibility with limited supervision, and management has not updated its assessment of risks related to improper payments. What is the impact of this external factor on the internal control system?
- It primarily affects monitoring activities because increased volume eliminates the need for supervisory review.
- It primarily affects risk assessment because management should reassess risks arising from external changes and resource constraints that may increase improper payment risk. (correct answer)
- It primarily affects information and communication because the downturn requires changing the chart of accounts.
- It primarily affects control environment because external economic conditions determine employee competence.
Explanation: This question examines how external changes impact the risk assessment component of internal control. The critical facts are a 40% volume increase due to economic downturn, reassignment of experienced staff leaving new employees with limited supervision, and management's failure to update its risk assessment for improper payments. Risk assessment under COSO requires identifying and analyzing relevant risks to achieving objectives, including how external changes and internal capability constraints affect risk levels. Option A is incorrect because increased volume actually heightens, not eliminates, the need for supervisory review and monitoring. Option C is incorrect because the issue isn't about changing accounting structure but about reassessing operational risks. Option D is incorrect because while external conditions create challenges, employee competence is still a management responsibility within the control environment. The key principle is that organizations must continuously reassess risks when significant external or internal changes occur and adjust controls accordingly to maintain effectiveness.
Question 2
You are performing a financial statement audit of a not-for-profit that relies on volunteer coordinators at multiple sites. The organization has a code of conduct, but volunteer coordinators are not trained on it, and management cannot demonstrate that coordinators understand reporting channels for suspected misuse of restricted grants. Several coordinators state they "handle issues locally" rather than escalating them. Which internal control component needs strengthening?
- Information and communication, because expectations and reporting channels are not being clearly communicated across the organization. (correct answer)
- Control activities, because the code of conduct should be replaced with additional reconciliations.
- Monitoring activities, because training replaces the need for ongoing evaluations.
- Risk assessment, because communication failures are addressed only by changing the audit plan.
Explanation: This question tests the information and communication component of internal control in a decentralized not-for-profit environment. The critical issue is that volunteer coordinators lack training on the code of conduct and don't understand reporting channels for suspected grant misuse, leading to local handling rather than proper escalation. Information and communication under COSO involves obtaining and sharing relevant, quality information to support the functioning of internal control, including clear communication of responsibilities and reporting channels. Option B is incorrect because codes of conduct serve a different purpose than reconciliations and both are needed. Option C is incorrect because training supports but doesn't replace ongoing monitoring activities. Option D is incorrect because communication failures require strengthening the information and communication component, not just audit plan changes. The key principle is that effective internal control requires clear communication of expectations, responsibilities, and reporting mechanisms throughout all levels of the organization, including decentralized operations.
Question 3
You are auditing an issuer in an integrated audit. The company has a code of conduct and annual training, but you learn that sales leadership's bonuses are heavily tied to quarterly revenue targets, and there is a pattern of pressuring accounting to "find a way" to meet targets. The audit committee receives complaints through a hotline but does not track resolution trends. Which element of the COSO framework is most affected by this issue?
- Control environment, because incentive pressures and insufficient governance attention to ethical behavior affect tone at the top and expectations for integrity. (correct answer)
- Control activities, because compensation plans directly replace revenue recognition controls.
- Information and communication, because hotline complaints are only an IT issue.
- Risk assessment, because once targets are set, fraud risk is eliminated through planning.
Explanation: This question evaluates the control environment component of COSO in issuer integrated audits, focusing on incentives and governance. Bonus ties to targets, pressure on accounting, and untracked complaints indicate weak tone and integrity. Choice A is correct as COSO emphasizes environment's influence on behavior and fraud risks, per PCAOB AS 2110. Choice B is incorrect because control activities support transactions, not replacing environmental factors. Choice C is wrong as information and communication handle flows, not hotline trends; choice D errs as risk assessment identifies but does not eliminate fraud through planning. Auditors should scrutinize environmental indicators for fraud implications. A framework involves assessing incentives, enhancing oversight, and monitoring resolutions to foster integrity.
Question 4
You are performing an audit of a not-for-profit organization that receives most donations through an online platform. During planning, you learn that a new state privacy law will require stricter handling of donor data and may restrict certain third-party marketing integrations used by the organization. Management has not performed a formal assessment of how the law affects processes and related controls over donor data and revenue recognition. What is the impact of this external factor on the internal control system?
- It primarily affects the risk assessment component because management should identify and analyze external changes that impact objectives and related controls. (correct answer)
- It primarily affects control activities because the law automatically creates segregation of duties between IT and development.
- It primarily affects monitoring activities because external laws eliminate the need for internal evaluations of control performance.
- It primarily affects the control environment because external laws replace management's ethical tone and governance responsibilities.
Explanation: This question tests understanding of how external factors impact the risk assessment component of COSO's internal control framework. The critical fact is that a new privacy law affecting donor data handling has been enacted, but management has not performed a formal assessment of its impact on processes and controls. Risk assessment under COSO requires management to identify and analyze risks arising from external changes, including new regulations, that could affect achievement of objectives. Option B is incorrect because external laws do not automatically create segregation of duties; management must still design and implement appropriate control activities. Option C is incorrect because external laws do not eliminate the need for monitoring activities; rather, they may increase monitoring requirements. Option D is incorrect because external laws do not replace management's responsibility for establishing tone at the top and governance structures. The transferable principle is that organizations must continuously assess how external changes, particularly regulatory requirements, affect their risk profile and adjust their internal control system accordingly to maintain effective control over financial reporting.
Question 5
You are the auditor of an issuer performing an integrated audit. In testing IT general controls over financial reporting, you find that developers have the ability to migrate code changes into production without independent approval, and there is no evidence of review of emergency changes. Management notes that application reports are reconciled monthly by accounting and believes that reduces the risk. Which internal control component needs strengthening?
- Control activities, because change management approvals and segregation of duties are key policies and procedures supporting reliable processing. (correct answer)
- Risk assessment, because change management is primarily an external risk outside management's control.
- Monitoring activities, because monthly reconciliations replace the need for IT general controls testing.
- Information and communication, because the primary issue is the format of system-generated reports rather than access to production.
Explanation: This question tests understanding of IT general controls within the control activities component for an integrated audit. The critical deficiency is that developers can migrate code to production without independent approval and emergency changes lack evidence of review, creating risks of unauthorized or erroneous changes affecting financial reporting. Control activities include IT general controls such as program change controls and segregation of duties between development and production environments. Option B is incorrect because change management is an internal control matter, not an external risk. Option C is incorrect because monthly reconciliations of application reports cannot compensate for weak IT general controls that could allow unauthorized changes. Option D is incorrect because the issue is unauthorized system access and change management, not report formatting. The professional principle is that effective IT general controls, including proper segregation of duties and change management procedures, are foundational to relying on IT-dependent controls and system-generated reports.
Question 6
You are conducting a financial statement audit of a government entity that processes a high volume of vendor payments. The entity's internal audit function performs periodic reviews of disbursements, but the reviews are informal, results are not documented, and identified issues are not tracked to remediation. Management asserts that "internal audit is monitoring," but cannot demonstrate follow-up. Which internal control component needs strengthening?
- Information and communication, because the entity should eliminate exception reporting to avoid confusion.
- Monitoring activities, because the entity lacks documented evaluations and follow-up on identified control issues. (correct answer)
- Control environment, because monitoring replaces the need for governance oversight.
- Risk assessment, because vendor master file changes should be approved by the procurement manager.
Explanation: This question tests understanding of the monitoring activities component within COSO's framework. The critical deficiency is that while internal audit performs reviews, they are informal, undocumented, and lack follow-up on identified issues - failing to meet the requirements for effective monitoring activities. Monitoring activities under COSO include ongoing evaluations and separate evaluations that assess whether controls are present and functioning, with deficiencies communicated and corrected timely. Option A is incorrect because exception reporting is a valuable information tool and should not be eliminated. Option C is incorrect because monitoring activities complement, not replace, governance oversight through the control environment. Option D is incorrect because the vendor master file approval issue relates to control activities, not the broader monitoring deficiency described. The key principle for professional judgment is that monitoring must be systematic, documented, and include mechanisms for tracking remediation of identified deficiencies to be effective.
Question 7
You are the auditor of a nonissuer construction contractor performing a financial statement audit. The company uses percentage-of-completion accounting and has a policy requiring project managers to review and approve monthly cost-to-complete estimates, but testing shows approvals are often missing and some estimates are updated only at quarter-end. Management argues that the chief executive officer reviews overall gross margin trends monthly, but there is no evidence of review at the project level. What action should the auditor take to address the control deficiency?
- Conclude the deficiency is inconsequential because overall margin trend review is a substitute for project-level approvals.
- Increase control risk to maximum and discontinue all audit procedures related to contract revenue.
- Communicate the deficiency to management and those charged with governance as appropriate and modify the nature, timing, or extent of substantive procedures over estimates. (correct answer)
- Require management to restate interim financial statements before the auditor may continue testing controls.
Explanation: This question addresses the auditor's response to control deficiencies in accounting estimates for a construction contractor. The key deficiency is inconsistent application of the control requiring project manager approval of cost-to-complete estimates, with some approvals missing and updates only at quarter-end rather than monthly. When control deficiencies are identified, auditing standards require communication to management and those charged with governance as appropriate, and modification of substantive procedures to address the increased risk. Option A is incorrect because overall margin trend review at the CEO level cannot substitute for detailed project-level controls over complex estimates. Option B is incorrect because the appropriate response is to increase substantive testing, not discontinue procedures entirely. Option D is incorrect because auditors cannot require restatement of interim statements based solely on control deficiencies without evidence of material misstatement. The professional framework emphasizes that deficiencies in controls over significant estimates require enhanced substantive procedures focused on the specific risks identified.
Question 8
You are engaged to perform an attestation engagement for a nonissuer service organization on management's description of its system and the suitability of design of controls. During inquiry, you learn management has not identified risks related to a new subcontractor that will handle after-hours customer support and will have access to customer account data. There is no formal vendor risk assessment, and contract terms do not address security responsibilities. Which element of the COSO framework is most affected by this issue?
- Risk assessment, because management has not identified and analyzed risks arising from changes in the business model and third-party relationships. (correct answer)
- Control environment, because vendor contracts replace governance oversight.
- Monitoring activities, because subcontractor onboarding is only evaluated after a security incident occurs.
- Information and communication, because the primary issue is failure to distribute monthly performance dashboards to employees.
Explanation: This question examines risk assessment in the context of third-party relationships in a service organization. The critical issue is management's failure to identify and assess risks related to a new subcontractor with access to customer data, lacking formal vendor risk assessment and appropriate contractual security provisions. Risk assessment under COSO requires identifying and analyzing risks relevant to achieving objectives, including those arising from significant changes like new vendor relationships that could impact the organization's ability to safeguard customer data. Option B is incorrect because vendor contracts supplement but don't replace governance oversight responsibilities. Option C is incorrect because vendor risks should be assessed proactively, not only after incidents occur. Option D is incorrect because the issue is risk identification and assessment, not performance reporting distribution. The key principle for service organizations is that management must assess risks associated with all aspects of service delivery, including subcontracted services, to maintain effective internal control over the entire system.
Question 9
You are the auditor of a nonissuer manufacturing company performing a financial statement audit. During walkthroughs of the revenue cycle, you note that customer credit limits are maintained in the system, but sales orders can be released for shipment even when the system flags the customer as over the limit, and there is no documented supervisory override approval. Management states that the controller "keeps an eye on it" through periodic review of aging but cannot show evidence of timely intervention. What action should the auditor take to address the control deficiency?
- Rely on the controller's periodic review as a compensating control and reduce substantive testing of revenue.
- Communicate the deficiency in writing to those charged with governance and design and perform additional substantive procedures responsive to the increased risk. (correct answer)
- Delay evaluation of the deficiency until the completion stage and communicate only if a misstatement is identified.
- Request management to implement a new credit approval workflow and test operating effectiveness for the entire year before issuing the auditor's report.
Explanation: This question tests the auditor's response to control deficiencies in the revenue cycle, specifically regarding credit limit override controls. The key fact is that while credit limits exist in the system, sales can be processed without documented supervisory approval when limits are exceeded, and the controller's periodic review lacks evidence of timely intervention. According to auditing standards, when a control deficiency is identified, the auditor must communicate it to those charged with governance and design substantive procedures responsive to the increased risk of material misstatement. Option A is incorrect because an undocumented, informal review cannot serve as a compensating control and would not justify reducing substantive testing. Option C is incorrect because control deficiencies must be evaluated and communicated timely, not deferred until completion. Option D is incorrect because the auditor cannot delay the audit report while waiting for management to implement and operate new controls for an entire year. The professional judgment framework requires auditors to assess control deficiencies based on their potential impact on financial reporting and respond with appropriate substantive procedures to address the heightened risk.
Question 10
You are auditing a nonissuer professional services firm in a financial statement audit. The firm has a formal client acceptance policy requiring conflict checks and approval by a risk partner, but you find multiple new clients onboarded without documented conflict checks, and engagement teams state the policy is "optional" when business is slow. Which element of the COSO framework is most affected by this issue?
- Control environment, because management's enforcement of policies and commitment to competence and accountability set expectations for adherence to controls. (correct answer)
- Information and communication, because conflict checks are primarily a data processing issue.
- Monitoring activities, because client acceptance is not part of the control environment under COSO.
- Control activities, because tone at the top and policy enforcement are unrelated to whether controls operate.
Explanation: This question examines the COSO control environment component, which establishes the tone at the top and influences the control consciousness of the organization. The driving facts are the firm's formal client acceptance policy requiring conflict checks and risk partner approval, yet multiple clients were onboarded without documentation, and staff viewed the policy as 'optional' during slow business periods, revealing weak enforcement. Choice A is correct as it aligns with COSO principles emphasizing management's commitment to integrity, accountability, and policy enforcement to set expectations for control adherence, as outlined in COSO's foundational elements. Choice B is incorrect because information and communication pertain to generating and using relevant information, not primarily to conflict checks as a data issue, while choice C is wrong as client acceptance policies can relate to the control environment through tone-setting, contrary to the distractor's claim. Choice D is incorrect because tone at the top and policy enforcement are integral to the control environment and directly impact whether control activities operate effectively under COSO. Professionals should exercise judgment by evaluating indicators of control environment strength, such as policy compliance rates and staff perceptions, to identify risks early. A useful framework is to map observed behaviors to COSO's five components, prioritizing control environment assessments as they underpin the entire internal control system.
Question 11
You are auditing a government entity in a financial statement audit. The finance director instructs staff to post year-end accruals without support to "use up the budget," and staff indicate they fear retaliation if they object. The entity has written policies, but they are not enforced. Based on the entity's control environment, what is the most appropriate response?
- Treat the issue as a documentation oversight only and request the finance director to sign the accrual entries as evidence.
- Reassess fraud risks and management override, expand substantive procedures over year-end accruals, and consider implications for governance communications. (correct answer)
- Rely on written policies as sufficient evidence of an effective control environment and reduce testing.
- Defer evaluation until the next audit period because control environment issues do not affect current-year assertions.
Explanation: This question examines the control environment component of COSO in government audits, highlighting override and enforcement issues. Instructions to post unsupported accruals and fear of retaliation indicate weak integrity and tone. Choice B aligns with AU-C Section 240 for reassessing fraud risks and AU-C Section 265 for governance communications. Choice A is incorrect as documentation oversights require substantive responses. Choice C is wrong because policies need enforcement for effectiveness; choice D fails as environment affects current assertions per standards. Auditors should heighten skepticism for override indicators. A framework involves enforcing policies, assessing cultural impacts, and designing procedures to detect manipulations.
Question 12
You are auditing a nonissuer e-commerce company in a financial statement audit. The company rapidly expanded into new countries with different tax rules, but management did not update controls over sales tax/VAT calculation and continues to use domestic tax rates in the checkout system for certain jurisdictions. What is the impact of this external factor on the internal control system?
- It primarily affects risk assessment because entering new jurisdictions changes external regulatory factors that should be identified and analyzed for financial reporting impact. (correct answer)
- It primarily affects control environment because international expansion automatically indicates unethical management behavior.
- It primarily affects monitoring activities because tax rules are monitored by governments, so entity controls are unnecessary.
- It primarily affects information and communication because tax rates are corrected by better internal memos without system changes.
Explanation: This question evaluates the risk assessment component of COSO regarding external expansion in nonissuer audits. Unupdated tax controls for new jurisdictions show failure to analyze regulatory changes. Choice A aligns with COSO's requirement to assess external factors for reporting risks, per AU-C Section 315. Choice B is incorrect as control environment is internal, not implying unethical behavior from expansion. Choice C is wrong because monitoring is internal, not governmental; choice D errs as communication aids but requires system updates. Professionals must reassess risks from expansions promptly. A decision-making framework involves identifying jurisdictional differences, updating processes, and testing for compliance accuracy.
Question 13
You are auditing an issuer in an integrated audit. The company performs quarterly control self-assessments, but results are compiled by the same process owners being evaluated, and negative findings are frequently removed before reporting to management. There is no independent validation by internal audit. Which internal control component needs strengthening?
- Monitoring activities, because evaluations are not sufficiently objective and deficiencies are not being communicated to enable remediation. (correct answer)
- Information and communication, because the existence of self-assessments proves communication is effective.
- Control activities, because self-assessments are preventive controls over transaction processing.
- Risk assessment, because removing findings is the same as prioritizing risks appropriately.
Explanation: This question evaluates the monitoring activities component of COSO in issuer integrated audits. Biased self-assessments without validation compromise objective evaluations and remediation. Choice A is correct as COSO requires independent monitoring for timely deficiency communication, per PCAOB AS 2201. Choice B is incorrect because information and communication need effective flows, not proven by biased assessments. Choice C is wrong as control activities are transaction-level, not evaluations; choice D errs as risk assessment prioritizes but does not equate to removing findings. Professionals must ensure monitoring independence. A decision-making framework involves validating self-assessments, communicating findings, and remediating to enhance control effectiveness.
Question 14
An auditor is evaluating a client's control environment. Which of the following would provide the strongest evidence of management's commitment to integrity and ethical values, a key principle of the COSO framework's Control Environment component?
- The existence of a formal, written code of conduct.
- Management's consistent actions to enforce the code of conduct and discipline violators. (correct answer)
- Regular communication of the code of conduct to all employees during onboarding.
- The board of directors' annual review and approval of the code of conduct.
Explanation: The correct answer is B. While having a code of conduct (A), communicating it (C), and having board oversight (D) are all important, the strongest evidence of commitment is management's consistent action to enforce the code and hold individuals accountable. This demonstrates that the ethical values are not just documented but are actively practiced and integrated into the entity's culture ('tone at the top'). This aligns with the COSO principle of demonstrating a commitment to integrity and ethical values.
Question 15
During the planning phase of an audit for a manufacturing company, the auditor notes that the company recently implemented a complex new ERP system. The company did not, however, update its process for identifying and analyzing how this change could significantly impact its system of internal control.
This situation indicates a weakness in which component of the COSO internal control framework?
- Control Activities
- Monitoring Activities
- Risk Assessment (correct answer)
- Information and Communication
Explanation: The correct answer is C. The Risk Assessment component of the COSO framework includes the principle that management should identify and assess changes that could significantly impact the system of internal control. The implementation of a new ERP system is a significant change, and the failure to analyze its impact on internal control is a direct deficiency in the client's risk assessment process. A weakness in control activities would relate to specific actions, a monitoring weakness would relate to evaluating control performance, and an information and communication weakness would relate to the flow of relevant information.
Question 16
Within the COSO framework, the Information and Communication component is critical for the functioning of the other four components. Which of the following describes a primary requirement of the information aspect of this component?
- The organization communicates internal control deficiencies in a timely manner to parties responsible for taking corrective action.
- The organization obtains or generates and uses relevant, quality information to support the functioning of internal control. (correct answer)
- The organization internally communicates information necessary to support the functioning of internal control, including objectives and responsibilities.
- The organization communicates with external parties regarding matters affecting the functioning of internal control.
Explanation: The correct answer is B. This is one of the three principles of the Information and Communication component, specifically addressing the 'information' part. For controls to function effectively, they must be based on relevant and high-quality information. Choices A, C, and D are also principles of this component, but they relate to the 'communication' aspect—communicating deficiencies, internal communication, and external communication, respectively.
Question 17
An auditor learns that a company's management team is dominated by a single, long-serving CEO who often overrides established control procedures. This situation represents a significant weakness primarily within which COSO component?
- Risk Assessment
- Control Activities
- Control Environment (correct answer)
- Monitoring Activities
Explanation: The correct answer is C. The Control Environment sets the tone of an organization, influencing the control consciousness of its people. A management team dominated by a single individual who overrides controls indicates a poor 'tone at the top' and a flawed management philosophy regarding internal controls. This undermines the entire system and is a fundamental weakness in the Control Environment. While it may lead to failures in Control Activities (B), the root cause lies within the Control Environment.
Question 18
A technology company has a well-designed set of controls over its revenue recognition process. However, the company provides inadequate training to new sales staff on complex contract terms, leading to frequent errors in how revenue is initially recorded.
This scenario points to a deficiency in which principle of the COSO framework's Control Environment component?
- The board of directors demonstrates independence from management.
- Management establishes appropriate structures and reporting lines.
- The organization demonstrates a commitment to attract, develop, and retain competent individuals. (correct answer)
- The organization holds individuals accountable for their internal control responsibilities.
Explanation: The correct answer is C. The failure to provide adequate training to ensure staff can perform their duties effectively is a weakness in the company's commitment to competence. This principle within the Control Environment emphasizes the need for the organization to ensure that those performing tasks related to internal control have the necessary skills and knowledge. The controls may be well-designed, but without competent personnel to execute them, they will not be effective.
Question 19
The COSO framework emphasizes that internal control is a process. The inherent limitations of internal control mean that it can provide only reasonable assurance, not absolute assurance, of achieving entity objectives. Which of the following is an inherent limitation of internal control?
- Faulty human judgment in decision-making. (correct answer)
- Lack of an independent internal audit function.
- Failure to perform regular risk assessments.
- Inadequate segregation of duties in a key process.
Explanation: The correct answer is A. Inherent limitations are those that exist even in a well-designed system of internal control. These include faulty human judgment, the possibility of management override, collusion among employees, and the fact that controls must be designed with a cost-benefit consideration. B, C, and D are examples of specific control deficiencies or weaknesses, not inherent limitations that would exist in any system.
Question 20
When evaluating an entity's internal control system, the auditor must understand how the five components of the COSO framework are present and functioning. What does 'present and functioning' mean in this context?
- Present means the components exist in design; functioning means they operate as designed. (correct answer)
- Present means the controls have been documented; functioning means they have been communicated.
- Present means management has formally approved the controls; functioning means employees are aware of them.
- Present means the controls are automated; functioning means the automation is error-free.
Explanation: The correct answer is A. For an effective system of internal control, the five components and relevant principles must be both present and functioning. 'Present' refers to the determination that the components and relevant principles exist in the design and implementation of the system of internal control. 'Functioning' refers to the determination that the components and relevant principles continue to operate as designed to achieve the entity's objectives.