Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium IIA IIA-CIA-Part1 Dumps Questions Answers

Internal Audit Fundamentals Questions and Answers

Question 1

An internal audit activity is performing a governance engagement. Which of the following would provide the best evidence for an internal auditor when evaluating the organization’s culture?

Options:

A.

Personnel and customer surveys, actual reports, and due diligence results regarding third-party governance practices.

B.

Details on mandatory reporting to third parties, disclosure committee charter and responsibilities, and the internal communication system.

C.

Succession plans, development programs, and job descriptions with responsibilities and authorities.

D.

Ethics and integrity policy; structured interviews with employees; and established and communicated values, mission, and vision.

Buy Now
Question 2

According to IIA guidance, which of the following statements regarding the internal audit charter is true?

Options:

A.

The nature of consulting services typically is not included in the charter.

B.

The chief audit executive must formally review the charter at least once a year

C.

The nature of assurances provided to parties outside of the organization typically is not included in the charter.

D.

The charter typically defines the internal audit activity ' s position within the organization.

Question 3

Which of the following statements is most accurate with respect to the required elements of the quality assurance and improvement program?

Options:

A.

Internal assessments provide sufficient objectivity to provide evidence to the board that the internal audit activity understands the organization’s control processes.

B.

Quality assessments focus on the internal audit activity ' s structure, relationships with stakeholders, compliance with the Standards, and internal audit staff proficiency.

C.

In order to comply with the Standards, the internal audit activity must obtain an objective assessment of its processes and function at least once a year.

D.

Internal auditors completing internal assessments must demonstrate certification to perform quality assessments.

Question 4

According to MA guidance, which of the following is true with regard to the internal audit charter?

1. It specifies the minimum resources needed for assurance engagements.

2. It requires final approval from senior management.

3. It defines the internal audit activity ' s authority and responsibilities.

4. It describes the expectations for communicating the results of a quality assurance and Improvement program.

Options:

A.

1 and 4 only.

B.

3 and 4 only.

C.

1.2. and 4.

D.

2. 3. and 4.

Question 5

The organization ' s internal audit charter was last updated six years ago. To update the charter, which of the following actions is most appropriate for the chief audit executive to take?

Options:

A.

Wait for the next external assessment and address all of the missing information in the charter based on the recommendations from the external assessment team.

B.

Perform a review of IIA guidance to become acquainted with the latest mandatory elements prior to updating the charter

C.

Use an internal audit charter template from another organization that operates within the same industry.

D.

Identify an individual within the internal audit activity who has in-depth knowledge of mandatory IIA guidance elements to address any gaps or areas of the current version of the charter that could be improved.

Question 6

An internal auditor was completely honest with operational management when delivering unfavorable audit results. Which of the following best describes the IIA Code of Ethics principle that the auditor demonstrated?

Options:

A.

Integrity

B.

Objectivity

C.

Competency

D.

Transparency

Question 7

At a construction company, supervisors are entitled to bonus payments if there are no safety rule violations on their teams. There are several channels available for workers to report accidents and violations, and all reported violations are investigated. Bonus payment calculations are approved by managers and the head of safety. Which of the controls best addresses the risk that supervisors will conceal accidents on their teams in order to receive the bonus?

Options:

A.

The investigation of all reported violations

B.

The authorization process for bonus calculations

C.

The variety of reporting channels

D.

The presence of safety rules

Question 8

A multinational organization has asked the internal audit activity to assist in setting up the organization’s risk management system. The chief audit executive (CAE) agrees to take on the engagement as a consultant. Which of the following tasks is appropriate for the CAE to undertake?

Options:

A.

Coordinate and facilitate risk workshops for management to attend.

B.

Establish the degree of risk appetite for management to accept.

C.

Set risk indicators and mitigation plans for management to implement

D.

Determine the number of significant risks for management to report to the board.

Question 9

Which of the following describes the most appropriate match between a potential temporary guest auditor candidate and an upcoming audit assignment?

Options:

A.

A purchasing manager with two years of prior audit experience in public practice to lead a contracts management audit

B.

A communications officer who worked in the marketing department during the last six months to conduct a customer loyalty program audit

C.

A manager of social responsibility who has a nursing background to participate m a health and safety audit for the corporate office and plant facilities

D.

An accounting manager who discovered and reported fraud committed by a payables clerk to conduct a performance audit of accounts payable

Question 10

Senior management asks the chief audit executive to review the organization ' s compliance with recently introduced legislation on international transfer pricing. The review requires an internal auditor who thoroughly understands the legislation and pricing methods. The internal audit activity does not have an auditor with those skills. Which of the following is the most appropriate course of action?

Options:

A.

Outsource the engagement to an external audit firm that has appropriate skills.

B.

Recruit a lawyer with knowledge of the legislation to the audit team and ask the new auditor to perform the engagement.

C.

Decline to perform the engagement, as the internal audit activity does not have the appropriate skill set.

D.

Carry out the engagement using existing internal audit staff to help them gain the appropriate experience.

Question 11

Which action by senior management indicates to the internal auditor that there may be fraudulent activities occurring within the organization?

Options:

A.

Setting unrealistic targets for staff to achieve

B.

Granting external audit firms access to staff and records.

C.

Automating some processes and allowing others to be performed manually

D.

Enforcing a zero-tolerance policy for misconduct

Question 12

Which of the following is most likely to result in the impairment of independence for the internal audit activity?

Options:

A.

The chief audit executive (CAE) has a dual reporting relationship within the organization.

B.

The CAE performs an audit of a functional area that is also under the CAE ' s oversight.

C.

The CAE has unrestricted access to information throughout the organization and to the board.

D.

The board is involved in decisions to hire or remove the CAE and in drafting and approving an internal audit charter.

Question 13

Which data analytics competency is critical for new internal auditors to possess in order to plan and perform internal audit engagements in conformance with the Standards?

Options:

A.

Describe data analytics and the application of data analytics methods in internal auditing.

B.

Apply data analytics methods in internal auditing.

C.

Evaluate the use of data analytics in an internal audit.

D.

Understand the definition of data analytics only.

Question 14

The same internal auditor has audited the regional purchasing department annually for the last three years. The audits have shown several significant control deficiencies that have not been corrected by management. New management is in charge of this regional purchasing department, and it is time to audit the department again. What concerns should be considered prior to assigning the audit to the same auditor?

Options:

A.

Intimidation threats may compromise the auditor ' s objectivity due to multiple negative audit reports completed by the auditor.

B.

The auditor has reviewed the department annually for the last three years, leading to familiarity, which can impact the internal audit activity ' s independence.

C.

A negative cognitive bias may be in place that affects the employee ' s objectivity due to the recent audits with uncorrected control deficiencies.

D.

The auditor may have formed a cultural bias, as the department under review is in the auditor ' s geographic area.

Question 15

Which of the following best describes a purpose for the internal audit charter?

Options:

A.

The internal audit charter authorizes the internal audit activity ' s reporting structure and clearly defines the roles of each internal auditor.

B.

The internal audit charter defines the roles and responsibilities of the chief audit executive, board of directors, and senior management.

C.

The internal audit charter authorizes access to records, personnel, and physical properties relevant to the performance of audit engagements.

D.

The internal audit charter defines the criteria by which the internal audit activity ' s performance will be evaluated

Question 16

Which of the following activities would breach the principles of The IIA ' s Code of Ethics?

Options:

A.

The internal auditor is keeping personal notes from an engagement conducted on the organization ' s information system security for future use.

B.

The internal auditor is performing an engagement of the purchasing department where he used to work five years ago.

C.

The internal auditor is using information from a recent engagement to assist with a friend ' s business.

D.

The internal auditor is discussing relevant information involving questionable vendors with a government regulatory agency.

Question 17

Which of the following is true about a system of internal control?

Options:

A.

Internal control should be updated at least annually.

B.

Technology does not change the internal control landscape.

C.

Strategy should fit the system of internal control.

D.

Articulating measurable objectives is part of internal control.

Question 18

Which of the following is a responsibility of the internal audit activity as it relates to risk and risk management?

Options:

A.

Evaluating and suggesting improvements to the risk management process.

B.

Establishing the organization ' s risk appetite.

C.

Determining whether the risk attitude is aligned with shareholder interests.

D.

Ensuring an adequate risk management system is in place.

Question 19

According to IIA guidance which of the following statements is true regarding the internal audit charier?

Options:

A.

The charier should be revised and re-approved whenever a new chief audit executive (CAE) is appointed or at the request of the board

B.

The charier should be re-approved every five years, in conjunction with the external quality assessment

C.

The charier can be revised at the discretion of the CAE whenever 4 is determined that its content no longer supports the achievement of objectives

D.

The charier should be reviewed and resubmitted for board approval annually together with the audit plan

Question 20

An organization is implementing a new cybersecurity policy and has established a committee to ensure stakeholder alignment across the organization ' s infrastructure, network, and security teams. The head of the committee has asked the chief audit executive if the internal audit activity could play a role in these efforts. According to HA guidance, which of the following is the most appropriate response?

Options:

A.

It is not appropriate for the internal audit activity to play a role because its independence must be protected.

B.

The internal audit activity should not participate because there are no IT auditors on staff.

C.

The internal audit activity is knowledgeable about risk and therefore should prioritize the organization ' s responses and control activities for the committee.

D.

The internal audit activity may assist the committee and consult with management on the organization ' s responses and control activities.

Question 21

If an internal auditor suspects fraud during an engagement which of the following is expected of the auditor?

Options:

A.

Evaluate the suspected activities to determine whether a forma! investigation is warranted,

B.

Immediately inform senior management and the board of the suspected fraud.

C.

Ascertain the level of resources needed to formally investigate the fraud, and proceed with the investigation if resources permit,

D.

Include in the engagement documentation all possible effects and the potential impact of the fraud to the organization

Question 22

The chief audit executive (CAE) has hired a new internal auditor who was immediately assigned to a procurement function audit. Because the new auditor ' s name is similar to that of the procurement manager, some staff members think the two are related, although they are not. Which of the following actions is most appropriate for the CAE to take?

Options:

A.

Take no action, as there is no impairment to independence.

B.

Remove the new internal auditor from the engagement team.

C.

Discuss the matter with the appropriate personnel to alleviate concerns.

D.

Closely supervise the new auditor and carefully review his work.

Question 23

Which of the following is an example of the chief audit executive (CAE) demonstrating due professional care?

Options:

A.

The CAE relies on CAEs in other organizations to understand how due professional care should be executed in her internal audit activity

B.

The CAE meets with the board of directors on a quarterly basis to provide a status update.

C.

The CAE assesses the audit staff ' s knowledge and skills annually to determine whether additional resources are needed to fulfill the internal audit plan.

D.

The CAE provides absolute assurance to line management during each eternal audit engagement

Question 24

What is the primary reason for establishing a continuing professional development program within an organization ' s internal audit activity?

Options:

A.

To ensure all internal audit responsibilities can be met

B.

To ensure all audit staff members are capable of performing a quality self-assessment.

C.

To ensure that each auditor maintains responsibility for his own professional development.

D.

To attract the best and most talented candidates in the profession

Question 25

An internal auditor believes that the internal audit activity ' s independence is impaired. Which of the following actions should the internal auditor take first?

Options:

A.

Report the impairment to senior management

B.

Discuss the impairment with the audit manager

C.

Ascertain the best approach to disclose the impairment.

D.

Decide on the extent of impact of the impairment

Question 26

Which of the following best describes why a chief audit executive might obtain the services of a fraud specialist to assist in a major fraud investigation ' ?

Options:

A.

Fraud specialists are better at using computer-assisted audit techniques

B.

Fraud specialists are better equipped to act as an expert witness in court

C.

Fraud specialists are better able to properly apply due professional care

D.

Fraud specialists are better at using crime scene investigation techniques

Question 27

During a review of the procurement function, an internal auditor identified an existing control for adding new vendors into the vendor contract system. Which of the following would best help the auditor determine the adequacy of the control ' s design?

Options:

A.

Flowchart of the vendor addition process.

B.

Independent confirmations sent to vendors.

C.

Analysis of the control ' s costs and benefits.

D.

Interview with management of the procurement function.

Question 28

Due to toe increased operational responsibility of the CEO. The chief audit executive (CAE) of an organization currently reports to the chief financial officer (CFO). What is the likely imped of such a situation?

Options:

A.

There may be limitation m the scope of engagements that can be undertaken

B.

The CPO could provide expert advice when auditing areas under his purview

C.

The internal audit activity is adequately positioned when the CAE reports to a member of executive management

D.

The expense of finance staff can be catted upon during an audit of finance-related areas

Question 29

Which of the following actions should the audit committee take to promote organizational independence for the internal audit activity?

Options:

A.

Delegate final approval of the risk-based internal audit plan to the chief audit executive (CAE).

B.

Approve the annual budget and resource plan for the internal audit activity.

C.

Assist the CAE with hiring objective and competent internal audit staff.

D.

Encourage the CAE to communicate and coordinate with the external auditor.

Question 30

Which of the following should a general internal auditor be able to characterize as an IT-related risk?

Options:

A.

Computer servers are in a room that is accessible to all employees,

B.

An IT architect avoids taking vacations and sharing his workload with coworkers,

C.

Hours billed by IT developers exceed 24 hours daily.

D.

Audit logs are lacking in a system that processes personal data.

Question 31

Which of the following would be the most appropriate first step for the board to take when developing an effective system of governance?

Options:

A.

Determine the organization’s overall risk appetite.

B.

Establish a governance committee.

C.

Delegate authority to members of senior management.

D.

Identify key stakeholders and their expectations

Question 32

Which of the following is considered to be a threat to the internal auditor ' s objectivity?

Options:

A.

The auditor drafted the operational procedures of the area that she is currently auditing.

B.

The auditor received a bonus that was approved by the board of directors.

C.

The assigned auditor recommended operational procedures for the organization.

D.

The assigned auditor rotated out of the same business activity three years ago

Question 33

When an organization purchases a derivative contract in the stock market to limit the potential loss in the value of a security, the organization is applying which of the following risk management techniques?

Options:

A.

Avoiding the risk altogether.

B.

Transferring the risk.

C.

Introducing a control feature.

D.

Accepting the risk.

Question 34

Which of the following documents would promote objectivity within an organization ' s internal audit activity?

Options:

A.

Internal audit charter.

B.

Internal audit manual.

C.

Audit committee charter

D.

Human resources employee handbook.

Question 35

To meet the resource requirements of this year’s internal audit plan, the chief audit executive (CAE) has recruited additional staff auditors, including an employee who resigned as a senior supervisor from the accounts payable department two months ago. There is a scheduled accounts payable review that the CAE wants to start within the next five months. Which approach should the CAE take, knowing the expertise of his new recruit in the area intended to be audited?

Options:

A.

Have the new internal auditor’s previous boss be excused from the area during fieldwork.

B.

Have the new internal auditor be responsible for the planning of the audit as well as the review of the audit fieldwork.

C.

Have the new internal auditor assigned to other responsibilities and not work on the accounts payable audit engagement.

D.

Have the new internal auditor assist with conducting the fieldwork, but ensure that her work is reviewed by the CAE.

Question 36

An employee accepts cash payments from customers and does not record the sale. This is an example of which of the following types of fraud?

Options:

A.

Asset misappropriation.

B.

Skimming

C.

Corruption.

D.

Lapping.

Question 37

According to the IIA Code of Ethics, which of the following best describes the conduct of an internal auditor who demonstrates the principle of competency?

Options:

A.

The auditor is prudent in the use and protection of information acquired in the course of his work.

B.

The auditor does not accept anything that may impair or be presumed to impair his professional judgment.

C.

The auditor does not perform services in a particular area when he lacks skills in that area.

D.

The auditor performs work with honesty, diligence, and responsibility.

Question 38

Management is installing security cameras to identify unauthorized physical access to the organization ' s warehouse. This is an example of which of the following types of controls?

Options:

A.

Detective controls.

B.

Key controls.

C.

Primary controls.

D.

Preventive controls

Question 39

An investment advisory firm purchased professional liability insurance to offer protection from lawsuits brought by customers claiming they received poor or erroneous advice. Which of the following best describes this risk management technique?

Options:

A.

Mitigation.

B.

Acceptance

C.

Transfer.

D.

Avoidance

Question 40

An organization is considering purchasing a new banking software system and has asked the internal audit activity to evaluate the system. An internal auditor assigned to perform the engagement worked at the software company two years ago and is familiar with the system ' s design strengths and weaknesses. Which of the following is true regarding impairment to the auditor ' s objectivity?

Options:

A.

This situation does not necessitate any action related to the auditor ' s objectivity.

B.

The auditor should decline to perform the audit because personal conflicts of interest are likely.

C.

The auditor must disclose to the chief audit executive that this situation may impair her objectivity.

D.

The auditor can provide only consulting services, not assurance.

Question 41

Which of the following is the most appropriate way to ensure that a newly formed internal audit activity remains free from undue influence by management?

Options:

A.

Appoint the chief audit executive as a member of the board.

B.

Adopt written policies and procedures for the internal audit activity, approved by the board.

C.

Ensure the chief audit executive reports administratively to the audit committee.

D.

Establish the internal audit activity’s position within the organization in an audit charter.

Question 42

Which of the following best demonstrates conformance with the Standards relating to continuing professional development of internal auditors?

Options:

A.

Regulatory approval from an accrediting agency.

B.

Self-assessments against a competency framework.

C.

Approval and signoff from the board of directors.

D.

A review by external auditors on an annual basis

Question 43

According to HA guidance, which of the following is true regarding independence and objectivity for small internal audit activities?

Options:

A.

The chief audit executive (CAE) may consider including a disclaimer on independence in audit reports.

B.

The CAE may consider greater involvement of those with suitable knowledge of audit practice.

C.

Conformance with this Standard is not dependent upon the size of the internal audit activity.

D.

Due to the small size of the internal audit activity, having an external assessment once every seven years is acceptable.

Question 44

The internal audit activity was denied access to expenditure and budget reports because they were considered to be confidential. This situation would result in which of the following limitations of the internal audit activity?

Options:

A.

Independence

B.

Integrity

C.

objectivity

D.

Authority

Question 45

According to The IIA’s Code of Ethics, which of the following scenarios offers the best example of violating the principle of integrity?

Options:

A.

An internal audit manager collaborates with senior management to provide misleading information to government authorities.

B.

An internal audit manager provides sample audit reports and workpapers to a friend without obtaining prior approval

C.

An internal audit manager carries out a technical audit request without seeking expert opinion, despite a lack of the requisite skills.

D.

An internal audit manager assigned to audit a sales process failed to reveal that the process owner is a relative

Question 46

According to IIA guidance, the internal audit activity must be free from interference in which of the following areas in order to maintain organizational independence?

Options:

A.

Monitoring resources.

B.

Compensating the chief audit executive.

C.

Determining scope.

D.

Allocating internal costs.

Question 47

Which of the following actions would an internal auditor perform primarily during a consulting engagement of a debt collections process?

Options:

A.

Reviewing journal entries for accuracy and completeness.

B.

Comparing the policies and procedures to regulatory collections guidance.

C.

Advising management on streamlining the recording of accounts receivable.

D.

Performing a walk-through of the debt collections process to determine whether proper segregation of duties exists

Question 48

A newly appointed chief audit executive (CAE) is tasked with creating a new internal audit activity within the organization. Which of the following would the CAE need to include in the new internal audit charter?

Options:

A.

The requirement to provide an annual cost analysis that justifies having an internal audit activity

B.

The specific engagements that the internal audit activity will perform for the organization

C.

The board s oversight role and responsibilities pertaining to the internal audit activity

D.

The relevant regulations that will guide the internal audit activity ' s regulatory compliance assessments

Question 49

Which of the following risk management techniques best describes the strategy of obtaining insurance to protect against losses due to bad weather conditions?

Options:

A.

Risk avoidance

B.

Risk reduction

C.

Risk acceptance

D.

Risk sharing

Question 50

Senior management and the board have expressed concerns about the length of engagements and whether their outcome aligns with the organization ' s strategies and objectives. Which of the following actions, if taken by the chief audit executive, could address these concerns?

Options:

A.

Communicating to internal audit staff instructions for completing engagements within shorter time periods.

B.

Requesting additional funding from the board to train internal audit staff on time and resource management.

C.

Implementing the use of agile auditing during engagements to meet expectations.

D.

Encouraging internal audit staff to participate in workshops to further develop their understanding of the organization ' s strategies.

Question 51

In which of the following situations has the internal auditor violated the IIA ' s Code of Ethics?

Options:

A.

An employee confided in an internal auditor and told him about fradulent activities. Although the employee asked for confidentially, the auditor disclosed her identity later during police questioning.

B.

While auditing payroll controls, an auditor was granted temporary access to salary data. The auditor referred to the acquired information while negotiating her work conditions three months later.

C.

Management considers an auditor to be highly competent and asked the audit to participate in an upcoming acquisition project. The auditor declined the request, calming a lack of knowledge.

D.

An internal auditor failed to acquire the continuing education credits needed for the year and requested that. The IIA change his certification status to inactive until the completed the required education activities.

Question 52

Which of the following statements is true regarding internal controls?

Options:

A.

Strategic objectives are prerequisites to establishing internal controls.

B.

Internal controls eliminate process breakdowns caused by human errors.

C.

Well-established internal controls cannot be overridden.

D.

Robust internal controls ensure business success.

Question 53

According to IIA guidance, which of the following statements is true regarding proficiency?

Options:

A.

The globally accepted Certified Internal Auditor designation is mandatory at chief audit executive levels.

B.

Internal auditors are encouraged to obtain appropriate professional designations.

C.

Specialty designations are required for those who perform specialized audit and consulting work.

D.

Studies for professional designations are the preferred source of continuing professional education

Question 54

Which of the following would best assist the internal audit activity in assessing whether an organization ' s responses to risk are aligned with its risk appetite?

Options:

A.

Analyzing the results of successful testing of controls and monitoring procedures implemented by management

B.

Determining that there are no gaps between the internal auditors ' risk assessment and the risk assessment performed by the organization

C.

Obtaining evidence that employees throughout the organization are aware of the organization s risk appetite

D.

Verifying that previously identified organizational risks were documented in board meeting minutes

Question 55

Which level of corporate social responsibility does whistleblowing in companies primarily support?

Options:

A.

Ethical responsibility.

B.

Economic responsibility.

C.

Legal responsibility.

D.

Discretionary responsibility.

Question 56

According to IIA guidance, which of the following statements is true of assurance services provided by the internal audit activity?

Options:

A.

Internal auditors cannot assess an operation for which they were responsible within the previous year.

B.

Management of the area under review must agree with the engagement objectives, scope, and techniques.

C.

The engagement results will vary in form and content depending upon the needs and wishes of the engagement client.

D.

The only parties involved in the engagement are the internal auditor and management of the area under review.

Question 57

According to IIA guidance, which of the following is accurate regarding the chief audit executive ' s (CAE ' s) requirement to report the results of quality assessments?

1. The CAE must report the results of external assessments at least annually.

2. The CAE must report the results of ongoing monitoring at least annually.

3. The CAE must report the results of quality assessments to senior management.

4. The CAE must report the results of quality assessments to the board.

Options:

A.

1 and 3 only.

B.

2 and 4 only.

C.

1,2. and 3.

D.

2,3, and 4.

Question 58

During a monthly internal audit staff meeting, the chief audit executive (CAE) decided to reinforce the importance of internal audit staff being objective in their work. Which of the following examples would be most appropriate for the CAE to include as part of the meeting presentation?

Options:

A.

Statistical sampling techniques should always be used to pull unbiased sampling for testing.

B.

Fieldwork completed by internal auditors should be appropriately reviewed.

C.

Internal auditors should avoid using the lunch room simultaneously with audit clients.

D.

During the audit review period, there should be no nonaudit dialogues with the audit client.

Question 59

Which of the following statements best represents the duo professional care that is required of internal auditor’s?

Options:

A.

Internal auditors should perform assurance procedures to ensure that all significant risks are identified.

B.

Internal auditor should not perform consulting engagements for operations for which they had previous responsibilities.

C.

Internal auditors should consider the cost of assurance in relation to the potential benefits.

D.

Internal auditors should device internal audit programs to confirm that the results are accurate.

Question 60

Which of the following is true regarding internal audit role ' s in The IIA ' s Three Lines Model?

Options:

A.

As internal control is part of risk management, the internal audit role in risk management implies reduced emphasis on internal control.

B.

Internal audit can blur the distinction between the second and the third lines as long as value is added.

C.

Internal audit cannot rely on other assurance providers when opining on the effectiveness of risk management.

D.

Internal audit should be aligned with first- and second-line functions through effective communication, cooperation, and collaboration.

Question 61

Which of the following threatens internal audit objectivity ' ?

Options:

A.

Internal auditors are expected by senior management to identify a minimum of five major control weaknesses in each area audited

B.

Internal auditors are prevented from accessing information necessary to undertake their audit engagements

C.

The chief audit executive reports directly to the chief financial officer who previously led the internal audit activity

D.

The CEO requests the internal audit activity develop a charter that clearly delineates its purpose and responsibilities within the organization

Question 62

A newly hired chief audit executive is reviewing available documentation to provide evidence of conformance with the standard for continuing professional development. Which of the following documents is the most reliable source for this purpose?

Options:

A.

The organization ' s training policy.

B.

A list of auditors who requested to attend the next audit conference.

C.

Self-assessments against an internally developed audit benchmark

D.

In house training manual

Question 63

Regarding the chief audit executive (CAE). which ot the following is considered an impairment to the independence of the internal audit activity?

Options:

A.

The CAE reports administratively to the CEO.

B.

The CAE is asked to submit the liquidation of her travel allowances to human resources for approval.

C.

The CAE ' s supervisor is responsible for the risk management function.

D.

The CAE is asked to review new procedures before implementation.

Question 64

Which of the following resources would be most effective for an organization that would like to improve how it informs stakeholders of its social responsibility performance?

Options:

A.

ISO 26000.

B.

Global Reporting Initiative.

C.

Open Compliance and Ethics Group.

D.

COSO’s enterprise risk management framework

Question 65

Anew internal auditor suspects fraud is taking place. Which action should the new auditor take?

Options:

A.

Collect relevant audit evidence and begin working with management of the area to investigate the fraud.

B.

Inform the chief audit executive and meet with the suspect to determine whether the person committed fraud.

C.

Document supporting information and recommend an investigation to the appropriate audit management.

D.

Evaluate existing controls and implement new procedures to mitigate the opportunity for fraud.

Question 66

Which of the following Code of Ethics principles specifically requires internal auditors to disclose all material facts known to them that, if not disclosed, may distort the reporting of activities under review?

Options:

A.

Confidentiality.

B.

Transparency.

C.

Integrity.

D.

Objectivity.

Question 67

Which of the following policies promotes internal audit objectivity?

Options:

A.

The chief audit executive (CAE) reports functionally to the CEO

B.

The CAE s compensation is approved by the chief financial officer

C.

The CAF ' s appointment is determined by the CEO

D.

The CAE reports administratively to the chief operating officer

Question 68

An internal auditor believes that a weakness exists in the control environment relating to the delegation of authority and responsibility within the management structure. Which of the following actions should the internal auditor first consider in this matter?

Options:

A.

Recommend a control change and obtain management support

B.

Evaluate the potential impact on related controls

C.

Address the risk with senior management and the board

D.

Develop and communicate the scope and evaluation criteria to be used by management

Question 69

Which of the following would be an important aspect of an internal auditor ' s role in fraud management?

Options:

A.

Utilizing analytical techniques to actively discover instances of potential fraud

B.

Conducting fraud based audits to ensure that fraud will be detected during engagements

C.

Implementing fraud prevention controls to minimize and mitigate the risk of fraud

D.

Reporting instances of fraud discovered during engagements to regulatory bodies

Question 70

The management at a national consumer goods organization implements a fair work and pay practice as well as a policy to treat employees equitably and consistently.

Which common characteristics of fraud will the practice and policy most likely reduce?

Options:

A.

Pressure or incentive.

B.

Opportunity.

C.

Rationalization.

D.

Commitment.

Question 71

According to The IIA’s Code of Ethics, which of the following best describes the principle of integrity?

Options:

A.

Auditors shall observe the law and make disclosures expected by the law and the profession

B.

Auditors shall disclose all material facts known to them that if not disclosed may distort the reporting of activities under review

C.

Auditors shall engage only in those services for which they have the necessary knowledge skills and experience

D.

Auditors shall be prudent in the use and protection of information acquired in the course of their duties

Question 72

According to IIA guidance, which of the following is the strongest indicator of deficiencies in the risk management process?

Options:

A.

The periodic evaluation of risk ratings is primarily dependent on subjective assessments.

B.

Separate evaluations of the risk management process were conducted, but the results were never integrated.

C.

Management ' s primary objective is minimizing changes to the structure and operation of the risk management process.

D.

Many aspects of the related enterprise risk management program are informal and undocumented.

Question 73

The chief audit executive (CAE) planned an in-person group training to help internal auditors perform onsite inspections of an automobile manufacturing facility. The training would have allowed the auditors to better understand the production of the organization ' s automobiles. However, a global health crisis has impacted the training by prohibiting in-person contact at the facility. Which of the following could the CAE use to provide auditors with a better understanding of the organization s production process?

Options:

A.

A general web-based training on auditing manufacturing processes.

B.

Self-study courses on the industry ' s production practices

C.

Industry publications that discuss production methods

D.

A virtual meeting with management that explains the production of automobiles

Question 74

Which of the following statements is true regarding reporting results of the quality assurance and improvement program to senior management and the board?

Options:

A.

Internal assessments must be reported to the board at least every five years

B.

If supported by assessment results, reporting provides assurance that internal auditors demonstrate conformance with the Code of Ethics

C.

Following the reporting the board must give the internal audit activity five years to correct any deviations

D.

A report, including the results of both internal and external assessments must be provided to the board annually

Question 75

Which of the following activities aligns with The IIA ' s Core Principles for the Professional Practice of Internal Auditing?

Options:

A.

The chief audit executive reports to senior management for compensation decisions and communications of audit results to the board

B.

Final reports from consulting engagements show the summary of findings, and the internal auditor’s advice is clearly distinct and separate from management ' s decisions

C.

Internal auditors rotate through operations and management positions then perform audit engagements on these areas to ensure timely application of their knowledge

D.

Due to limited resources, internal auditors prioritize assurance on internal controls and risk management and exclude evaluating governance processes, which are deemed outside of their core responsibilities

Question 76

An internal audit activity is using the auditing-by-element approach to audit the organization ' s controls around corporate social responsibility. Which of the following would be an element for the internal audit activity to consider?

Options:

A.

Working conditions.

B.

Employees ' families.

C.

Marketplace competition.

D.

Shareholders and investors

Question 77

Evidence discovered during the course of an engagement suggests that multiple incidents of fraud have occurred. There do not appear to be sufficient controls in place to prevent reoccurrence. Which of the following is the internal auditor ' s most appropriate next step?

Options:

A.

Immediately notify management of the area under review and the other internal auditors involved in the engagement.

B.

Discuss the situation with the engagement supervisor to determine whether fraud investigation experts are required to investigate the matter properly.

C.

Fully document in the workpapers the evidence that has been discovered and recommend appropriate controls to address the fraud.

D.

Provide the evidence that was discovered to local law enforcement for possible prosecution of the suspected fraud.

Question 78

Which of the following is most likely to impair the organizational independence of the internal audit activity?

Options:

A.

The chief audit executive (CAE) reports administratively to the chief financial officer.

B.

The CAE oversees the effectiveness of the organization’s risk management function.

C.

The CAE reports functionally to the CEO.

D.

The CAE managed the finance department for the past five years.

Question 79

During a payroll audit, the internal auditor discovered that several individuals who have the same position classification as he are earning a significantly higher salary. The auditor noted the names and amounts of each, and he planned to prepare a request to the chief audit executive for a salary increase based on this information. Which of the following IIA Code of Ethics principles was violated in this scenario?

Options:

A.

Competency.

B.

Objectivity,

C.

Integrity.

D.

Confidentiality

Question 80

An internal auditor notes that inventory counts are conducted on Mondays only and that all documentation is on paper as there are no computers in the underground warehouses. Also she notices that the person responsible for receiving the goods is the same one who distributes materials and spare parts Finally, she sees that spare parts are written off and taken by the heads of mining units to different underground locations to wait for their turn to be installed. Which of the described findings requires more consideration from a fraud risk perspective?

Options:

A.

The job responsibilities of the warehouse employee compromise segregation of duties

B.

Spare parts are written off before their actual usage and installation

C.

Warehouse management is conducted on paper and requires further investigation

D.

The inventory counts take place on specific days of the week for no apparent reason

Question 81

According to NA guidance, which of the following practices by the chief audit executive (CAE) best enhances the organizational independence of the internal audit activity?

Options:

A.

CAE reviews and approves the annual audit plan,

B.

CAE meets privately with the CEO at least annually.

C.

CAE meets privately with the board at least annually,

D.

CAE reports to the board regarding audit staff performance evaluation and compensation.

Question 82

Which of the following is a typical characteristic of an organization ' s risk management framework?

Options:

A.

Risk tolerance may or may not align with risk appetite depending on whether the assessment is quantitative or qualitative

B.

Risk is assessed on both an inherent and a residual basis

C.

The framework addresses four organizational objective categories strategic, historical, operational, and investment

D.

External risks and internal opportunities are omitted from the risk assessment scope

Question 83

What is expected of internal auditors in regards to due professional care?

Options:

A.

Auditors perform assurance services without regard to cost

B.

Auditors perform assurance services effectively to identify all risks

C.

Auditors perform assurance services needed to achieve the engagement ' s objectives

D.

Auditors perform assurance services to guarantee all significant risks will be addressed

Question 84

An internal auditor wants to compare her organization’s governance processes to those of a well-known governance model. Which of the following approaches would the auditor take for this purpose?

Options:

A.

Perform a gap analysis to assess me differences between the approaches

B.

Assess the governance processes using computerized modeling techniques

C.

identify any differences between the processes using a variance analysis

D.

Benchmark the governance processes using a capability maturity modal

Question 85

According to IIA guidance, which of the following statements is true regarding due professional care?

Options:

A.

Internal auditors must exercise due professional care to Insure that all significant risks will be identified,

B.

Internal auditors must apply the care and skill expected of a reasonably prudent and competent internal auditor

C.

Due professional care requires the internal auditor to conduct extensive examinations and verifications to ensure fraud does not exist,

D.

Due professional care is displayed during a consulting engagement when the internal auditor focuses on potential benefits of the engagement rather than the cost.

Question 86

An electric company hires several independent contractors to trim trees that are in close proximity to electricity lines. Which of the following would be the most effective control to mitigate the risk of contractors submitting fraudulent invoices regarding work completed?

Options:

A.

Require contractors to submit completed and signed work acceptance sheets

B.

Utilize unmanned drones to conduct regular flights and photo shoots over the areas where work is performed

C.

Reconcile invoices and work acceptance sheets submitted by contractors

D.

Compare actual payments to contractors with budgeted values and analyze discrepancies

Question 87

Which of the following is the internal audit activity expected to do with respect to the organization ' s governance processes?

Options:

A.

Formally audit all governance activities.

B.

Provide strategic guidance on the organizational processes to senior management.

C.

Achieve agreement with the board regarding the range of activities, depth of review, and time period to include in the assessment.

D.

Audit against the governance structures and practices widely used in the industry.

Question 88

Senior management has requested that the internal audit activity review and amend policies where necessary when auditing the purchasing department. To which of the following would the chief audit executive most likely give primary consideration when responding to this request?

Options:

A.

Auditor competency.

B.

Internal audit independence.

C.

Auditor objectivity.

D.

Engagement scope.

Question 89

A third-party provider ' s questionable labor practices have exposed the organization to reputational risks and regulatory risks. Which of the organization ' s risk management practices was most likely ineffective?

Options:

A.

The organization ensured that the third-party vendor provided the best pricing for the requested services.

B.

The organization conducted quality control reviews of provided services to ensure industry standards were met.

C.

The organization performed a due diligence review of all vendors during the bid review process.

D.

The organization planned to issue a resolution concerning the third-party provider ' s labor practices.

Question 90

The internal audit activity is responsible for conducting fraud investigations. A potential fraud instance was identified during an audit engagement. The chief audit executive appoints a lead investigator. Which of the following would most likely be the next step?

Options:

A.

Ask internal auditors to gather all relevant information and evidence.

B.

Identify and interview witnesses first and potential suspects later.

C.

Conduct a fraud risk assessment to identify the most vulnerable areas.

D.

Determine the competencies needed and assess whether team members have a conflict of Interest.

Question 91

During an assurance engagement, an internal auditor uses benchmarking research to support preparation of a report to stakeholders that contains significant findings about control deficiencies. Which of the following skills did the auditor demonstrate?

Options:

A.

Internal audit management.

B.

Conflict negotiation.

C.

Critical thinking.

D.

Persuasion and collaboration.

Question 92

Which of the following is an example of a directive control?

Options:

A.

Segregation of duties.

B.

Exception reports.

C.

Training programs.

D.

Supervisory review.

Question 93

Regarding assurance and consulting services provided by the internal audit activity which of the following statements is correct?

Options:

A.

The nature and scope of a consulting engagement are determined by the internal audit activity based on its risk assessment

B.

The nature and scope of an assurance engagement are subject to agreement with management of the area under review

C.

Both assurance services and consulting services can be focused on controls or performance or both

D.

The assurance engagement process ends with reporting

Question 94

An internal audit team received the following feedback from operational management via a post-engagement survey " Management agrees with all audit findings However, the audit team did not consider our input on the best way to resolve the issues”

This feedback is an indication that the internal audit activity may need to improve which of the following interpersonal skills?

Options:

A.

Leadership

B.

Conflict management

C.

Communication

D.

Influence

Question 95

Which of the following is a key determinant used by external auditors to decide whether they can rely on work performed by the internal audit activity?

Options:

A.

The auditors ' independence.

B.

The auditors ' objectivity.

C.

The auditors ' integrity.

D.

The auditors ' confidentiality.

Question 96

Which of the following is a greater consideration for internal auditors when they are performing a consulting engagement than when they are performing an assurance engagement ' ?

Options:

A.

The relative complexity of the engagement

B.

The cost of the engagement relative to its benefits

C.

The extent of work needed to achieve the engagement ' s objective

D.

The needs and expectations of the engagement client

Question 97

Which of the following requests, if accepted by the internal audit activity, would impair its independence?

Options:

A.

A request to develop workshops on corporate governance for management.

B.

A request to act as liaison with external auditors.

C.

A request to determine appropriate risk management responses for management.

D.

A request to provide counseling services on ethical matters.

Question 98

Prior to commencing a financial compliance engagement, the engagement supervisor reads the business plan for the finance department and meets informally with the director to learn more about any key issues. Which of the following competencies is the engagement supervisor demonstrating?

Options:

A.

The ability to inspire trust

B.

The ability to communicate effectively

C.

The ability to display courage

D.

The ability to understand the needs of stakeholders

Question 99

Which of the following approaches will internal audit utilize when developing a set of performance standards to measure an organization’s risk management process against?

Options:

A.

Key principles approach

B.

Process elements approach

C.

Holistic approach

D.

Maturity model approach

Question 100

An internal auditor is assessing the effectiveness of the organization ' s risk management practices She checks to see whether risk management is an intégrai part of decision making and whether risk management is transparent, responsive to change and addresses uncertainty. According to HA guidance on risk management frameworks, which of the following approaches is the auditor most likely using?

Options:

A.

Maturity model approach

B.

Process element approach

C.

Key principles approach

D.

Key performance indicators approach.

Question 101

Which of the following statements best describes how the internal audit activity obtains reasonable assurance that significant risks in the organization are identified and assessed?

Options:

A.

The internal auditors review the organization ' s strategic plan, business plan, and policies, and have discussions with the board and senior management.

B.

The internal auditors evaluate the adequacy and timeliness of management ' s reporting of risk management results.

C.

The internal auditors interview staff at various levels and determine whether the organization ' s objectives, significant risks, and risk appetite are articulated sufficiently.

D.

The internal auditors review recently completed risk assessments and related reports issued by senior management, external auditors, and other sources.

Question 102

A significant number of employees expressed concerns of a hostile work environment within a large manufacturing plant, which is in contrast to the organization ' s stated culture of tolerance and open communication. Which of the following approaches would be most effective for an internal auditor to assess whether the organization supports a culture of tolerance and open communication?

Options:

A.

Assess plant employees ' social media activity for specific messages related to tolerance and open communication

B.

Compare plant employees’ compensation and benefits with those at similar sized organizations that have a stated culture of tolerance and open communication.

C.

Evaluate organization policies and procedures for references related to encouraging tolerance and open communication.

D.

Conduct a meeting with all plant employees and management to discuss tolerance and open communication

Question 103

An engagement supervisor notes that an internal auditor usually documents and submits draft audit reports for review without giving the process owners the opportunity to state their position on the issues raised. How should the engagement supervisor respond?

Options:

A.

Encourage the auditor to continue this practice, as it demonstrates objectivity.

B.

Encourage the auditor to improve communication skills.

C.

Encourage the auditor to conduct post-engagement surveys to obtain the audit client ' s position on the issues raised.

D.

Encourage the auditor to sign the draft reports before submitting them.

Question 104

The chief audit executive (CAE) decided to conduct a self-assessment with independent validation. Which of the following is the most likely reason the CAE selected this course of action?

Options:

A.

The audit committee requested the self assessment for quality assurance purposes

B.

The staff auditors have the necessary knowledge and experience to conduct the review

C.

The internal audit activity is relatively small in size and is due for an external assessment

D.

The internal audit activity is due for a self-assessment which is specifically required at least once every five years

Question 105

The organization ' s chief audit executive (CAE) is planning an immediate assurance engagement following several product recalls. However, the internal audit staff does not have the required Knowledge and experience to adequately assess all the relevant processes and procedures. According to 11A guidance, which of the following actions should the CAE take under these circumstances?

Options:

A.

Use the current available resources to conduct the review and exclude those procedures that can ' t currently be performed.

B.

Implement an accelerated training plan to provide the audit staff with the necessary skills and knowledge to conduct the engagement.

C.

Encourage management to accept the assessed risk until the internal audit activity is able to adequately review the area.

D.

Obtain assistance for the audit team from other internal assurance providers who possess the requisite expertise in the area.

Question 106

Which risk management activity would cause the internal auditor to assume a management responsibility?

Options:

A.

Assessing management ' s acceptance of risk.

B.

Reviewing a cybersecurity risk report issued by management.

C.

Developing a list of emerging risks for management.

D.

Prioritizing risks for management.

Question 107

To encourage internal audit objectivity, which of the following is an appropriate policy the chief audit executive should establish?

Options:

A.

Internal auditors should report their audit findings directly to the audit committee.

B.

To receive an outstanding performance rating, internal auditors are required to generate audit findings.

C.

Prior to hiring a new internal auditor, the chief audit executive must determine whether the auditor owns stock in the organization.

D.

Internal auditors are permitted to audit an entity managed by a close friend or relative, as long as they notify the chief audit executive.

Question 108

A whistleblower reveals to the chief audit executive (CAE) detailed allegations of potential fraud at the senior management level. Although the CAE has some experience in the area, she chooses to retain an external fraud expert to conduct the investigation. When asked by the director of finance to defend the expenditure, which of the following statements represents the CAE ' s best response?

Options:

A.

The CAE refers to the Standards and explains that to protect her independence, she needs to remain isolated from the investigation.

B.

The CAE refers to the Standards and explains that the internal audit activity must obtain competent assistance if needed.

C.

The CAE refers to the Standards and explains that to protect her objectivity, she needs to remain isolated from the investigation.

D.

The CAE describes the specifics of the allegation to underscore the importance of the situation and the need for expert investigation

Question 109

Which of the following is an example of impairment to internal auditor independence or objectivity ' ?

Options:

A.

Assurance engagements for functions over which the chief audit executive (CAE) has responsibility are overseen by a party outside the internal audit activity

B.

Internal auditors provide consulting services relating to operations for which they had previous responsibilities

C.

Internal auditors provide consulting services relating to operations for which they have current responsibilities

D.

Consulting engagements for functions over which the CAE has responsibility are overseen by a party outside the internal audit activity

Question 110

An internal auditor in a busy internal audit activity reviews her continuing professional development records toward the end of the year and is concerned to find she has undertaken limited training and formal professional development. Which of the following actions is the most appropriate for her to take?

Options:

A.

Remind the chief audit executive (CAE) that he is responsible for her continuing professional development and needs to address the issue

B.

Contact her professional organization and explain that she does not need formal professional development, as she is being developed sufficiently through undertaking audit engagements.

C.

Accept that she is unlikely to meet continuing professional development requirements but look to attend training courses at the next available time.

D.

Accept that she is responsible for her own continuing professional development, develop a professional plan, and discuss it with the CAE.

Question 111

Which of the following statements is true regarding the importance of risk management?

Options:

A.

Risk management ensures the ability to eliminate potential hazards to the organization.

B.

Risk management includes consideration of potential opportunities for the organization.

C.

Risk management aids with the establishment of appropriate key performance indicators.

D.

Risk management increases employees ' commitment and belief in strategic goals.

Question 112

When the chief audit executive Is responsible for risk management in an organization, which of the following parties is responsible for overseeing the internal audit activity ' s assurance over risk management?

Options:

A.

The chief audit executive.

B.

A member of the compliance function.

C.

A party outside of the internal audit activity.

D.

A member of the risk management function.

Question 113

According to IIA guidance, which of the following is an appropriate role for the internal audit activity?

Options:

A.

Coaching management in responding to risks.

B.

Implementing risk responses on management ' s behalf.

C.

Imposing risk management processes.

D.

Setting the risk appetite.

Question 114

Which of the following is the best way for an internal auditor to demonstrate due professional care?

Options:

A.

Conduct an audit to the same extent that another prudent auditor would under similar circumstances

B.

Seek feedback from the engagement supervisor during the engagement

C.

Execute internal audit work in such a manner as to provide absolute assurance of compliance

D.

Request and receive client feedback surveys during the engagement

Question 115

Operational management in the IT department has developed key performance indicator reports, which are reviewed in detail during monthly staff meetings. This activity is designed to prevent which of the following conditions?

Options:

A.

Knowledge/skills gap,

B.

Monitoring gap.

C.

Accountability/reward failure,

D.

Communication failure.

Question 116

During an audit of company expenses, the internal auditor performed a test using data analytics and identified a violation of the company ' s expenses policy. The auditor who discovered the issue considered it a potential fraudulent transaction and informed the chief financial officer (CFO). The CFO dismissed the concern because he did not understand the data analytics test that was performed and the transaction was of a low value. Given this situation, which skills or competencies should this internal auditor seek to improve?

Options:

A.

Skills in evaluating the risk of fraud.

B.

Knowledge of key IT risks and controls

C.

Soft skills such as communication and negotiation.

D.

Knowledge and understanding of the company ' s expenses policy

Question 117

An internal auditor is finalizing an audit report on the effectiveness of the organization ' s overall system of internal control. Several audit tests were performed, and the only issue identified was that the CEO frequently asks employees to make exceptions or bypass the organization ' s standard written policies and procedures. Which of the following conclusions is most appropriate for the auditor to report?

Options:

A.

The auditor should indicate that the system of internal control is not effective.

B.

The auditor should indicate that the system of internal control is generally effective, except for the minor issue identified.

C.

The auditor should indicate that the system of internal control is effective.

D.

The auditor cannot express a conclusive opinion in the audit report.

Question 118

Which of the following concepts is emphasized in the Mission of Internal Audit?

Options:

A.

Support of good governance and controls.

B.

Enhancement of organizational value.

C.

Protection of tangible and intangible assets.

D.

Provision of professional advisory and assurance services.

Question 119

Which of the following could increase risks to the organization’s control environment?

Options:

A.

Strong board of directors oversight.

B.

Incentive-based compensation structures.

C.

Lower than average employee turnover.

D.

Implementation of a fraud hotline.

Question 120

Which of the following scenarios provides the most concerning red flag or indicator of possible fraud?

Options:

A.

An employee receives a bonus for perfect attendance

B.

During the past 18 months three chief financial officers have left the organization after having been promoted to the position

C.

The organization does not perform any due diligence research on third party service providers

D.

Three competitors are highly profitable but a fourth equal in size is approaching bankruptcy limits

Question 121

Which of the following best demonstrates the authority of the internal audit activity?

Options:

A.

Suggesting alternatives to decision makers.

B.

Improving the integrity of information.

C.

Determining the scope of internal audit services

D.

Achieving engagement objectives.

Question 122

Which of the following most accurately describes the role of the board when it comes to organizational governance?

Options:

A.

Responsibility for outcome of the process.

B.

Responsibility to be involved in management of the organization.

C.

Responsibility to determine who is accountable for outcomes.

D.

Responsibility to identify risks in the organization’s business environment

Question 123

Which of the following are considered root causes of fraud?

Options:

A.

Rationalization and corruption

B.

Corruption and opportunity

C.

Opportunity and perceived need

D.

Perceived need and weak internal controls

Question 124

Which of the following accurately describes the concept of inherent risk?

Options:

A.

Risk factors that exist when controls are in place and operating effectively

B.

Internal risk factors assuming no controls are in place

C.

Risk factors that cannot be mitigated because they are innate to a process

D.

Combination of internal and external risk factors in their pure state assuming no controls are in place

Question 125

Which of the following actions should an organization take to detect an emerging risk of potential fraud?

Options:

A.

Adopt reward and recognition programs that promote good behaviors

B.

Undertake background checks for new employees as part of the hiring process

C.

Establish an anonymous platform for reporting suspected unethical behaviors

D.

Institute periodic educational training on expected ethical behaviors

Question 126

During a complex financial compliance engagement, a senior internal auditor determines that current audit procedures are not sufficient for adequate testing She consults with a colleague and learns that a spreadsheet application contains a helpful tool She proceeds to use the tool to properly complete the evaluation Which of the following best describes the core competency displayed by the senior auditor?

Options:

A.

Business acumen

B.

Persuasion and collaboration

C.

Critical thinking

D.

Communication

Question 127

Which of the following scenarios is a characterize of an organization with a highly effective ethical culture?

Options:

A.

An organization implements and communicates to staff a formal and comprehensive code of conduct, which is clear and understandable.

B.

An organization waives reference and background checks when hiring for certain sensitive positions in order to not violate potential employees ' rights to privacy.

C.

An organization punishes senior management more harshly for ethics violations than it would for lower-level staff to send a message throughout the organization.

D.

An organization conducts surveys of employees, suppliers, and customers once every five years to determine the slate of the ethical climate in the organization.

Question 128

Which of the following should play a leading role in overseeing the ethical atmosphere of an organization?

Options:

A.

Internal audit activity

B.

Operating management

C.

Senior management

D.

Board of directors

Question 129

Which of the following scenarios would most likely impair the independence of an internal audit activity?

Options:

A.

A relative of an internal audit team member works m a department being reviewed

B.

The internal audit budget is reduced by management requiring the removal of all lT-related engagements from the audit plan

C.

An audit manager removes a finding from the draft report due to disagreements with the chief financial officer

D.

The operating effectiveness of a control is reported as ' satisfactory. " because no concerns were identified during planning

Question 130

The chief audit executive of a large national retailer is reviewing the purpose and objectives of the organization ' s internal audit activity

Which of the following objectives is best aligned with The IIA ' s Mission of Internal Audit?

Options:

A.

To implement a quality assurance and improvement program

B.

To assess the effectiveness of internal controls over organizational assets

C.

To ensure internal auditors possess the competencies needed to perform their responsibilities

D.

To operate within the budget established by the board of directors

Question 131

Which of the following activities should the chief audit executive perform to ensure compliance with an organization ' s code of conduct?

Options:

A.

Act as an advisor to the committee responsible for reviewing violations of the code.

B.

Review and adjudicate all violations of the code of conduct.

C.

Lead the committee responsible for the oversight of the code.

D.

Implement a system of procedures to inform all employees of the code.

Question 132

Which of the following is a true statement regarding controls such as ethical values, tone at the top and operational style?

Options:

A.

Transaction testing, mapping and flowcharting is applicable while testing such controls

B.

Breakdowns in the these types of controls have historically led to fraudulent financial reporting

C.

Such controls can be defined as inherently ob)ective and tangible elements of control

D.

From an audit perspective it is significantly easier to assess ethical values than segregation of duties

Question 133

Six months after an employee was transferred to the internal audit activity his former operating manager requested that he return to assist a project team with the evaluation of a new pricing module for the organization’s online ordering system According to IIA guidance which of the following statements is true?

Options:

A.

The auditor cannot be assigned to this project, as it has been fewer than 12 months since he was transferred from that department.

B.

Another internal auditor should be appointed to the engagement to preserve the independence of the internal audit activity

C.

The auditor cannot participate in the assignment, as providing an opinion would impair his objectivity

D.

The auditor may participate on the project, as the nature of the assignment is consulting

Question 134

An accounts payable clerk has recently transferred Into the internal audit activity and has been assigned to an engagement related to accounts payable processes for which he was previously responsible Which of the following is the best action for the new internal auditor to take?

Options:

A.

If it is an assurance engagement accept the assignment because direct knowledge of the existing accounts payable processes will provide depth and add more value

B.

If it is a consulting engagement decline the assignment and ask to be reassigned, because in a consulting engagement the auditor must not assess operations for areas in which they were previously responsible

C.

If it is a consulting engagement accept the assignment because direct knowledge of the existing accounts payable processes will provide depth and add more value

D.

If it is an assurance engagement accept the assignment becausethe chief audit executive had knowledge of the internal auditor ' s previous role when this engagement was assigned

Question 135

According to HA guidance, if an internal auditor suspects fraud during an assurance engagement, what should the auditor do first?

Options:

A.

Recommend parties involved to be sanctioned in accordance with the organization ' s policy.

B.

Determine whether any additional audit work needs to be performed.

C.

Launch an investigation to obtain details of the fraud and parties involved.

D.

Request that the responsible process owner remediate the issue immediately.

Question 136

What is the ultimate goal of establishing a robust risk management framework in an organization?

Options:

A.

To support the organization ' s risk culture, involving employees at all levels.

B.

To ensure that the organization attains a better financial position.

C.

To assist the organization in identifying and mitigating key risks.

D.

To facilitate the organization ' s achievement of business goals and objectives.

Question 137

Which of the following relates to the concept of due professional care?

Options:

A.

An auditor attempts to obtain information needed to complete an assurance engagement but is denied access.

B.

The appointment of the chief audit executive is ratified by the board.

C.

An auditor demonstrates a good understanding of the steps involved in carrying out a consulting engagement.

D.

The internal audit resource plan is only approved by the chief financial officer.

Question 138

An organization has limited resources to spend on corporate social responsibility initiatives. Which is the most suitable approach to determine how these resources should be used?

Options:

A.

Support a mix of environmental economic and social initiatives to ensure a balanced approach is taken

B.

Survey employees and external stakeholders to see which causes are best suited to the organization.

C.

Select corporate social responsibility initiatives that support the overall strategic goals of the organization

D.

Conduct a financial analysis to determine where the most impact can be made with the budget available

Question 139

How do assurance services and consulting services differ?

Options:

A.

There is less variety of consulting services that an internal audit activity might provide compared to assurance services

B.

Assurance services are limited to financial events or actions, and consulting services are not limited in this way

C.

Consulting services do not have to be included in the internal audit charter

D.

Other employees in an organization can provide consulting services but only an internal audit activity can provide assurance services

Question 140

A chief audit executive (CAE) has been asked by the board to evaluate the effectiveness of ethical programs created by management. Which of the following would be the most appropriate action for the CAE to take?

Options:

A.

Compare the design of the organization ' s ethical programs with best practices.

B.

Verify that a code of conduct and related policies exist and are communicated.

C.

Use employee surveys to assess whether ethical programs are achieving desired outcomes.

D.

Compare the cost of the ethical programs with the achieved outcomes.

Question 141

An internal audit activity is taking steps to promote professional development among the staff, and is in the process of implementing a mentorship program. According to HA guidance, which of the following is important for a successful mentorship program?

Options:

A.

It is best if the mentor is the chief audit executive.

B.

Mentor meeting documentation should be retained in personnel files.

C.

It should target both new hires and highly experienced staff.

D.

Meetings with mentors should be formal and scheduled.

Question 142

An internal auditor creates a professional development plan to obtain more experience in the organization ' s environmental, social, and corporate governance initiatives. Which of the following would the auditor include in the plan to support these objectives?

Options:

A.

A plan to study for and obtain a certification in nonprofit management.

B.

A deadline within the individual development plan to meet the overall engagement objectives.

C.

A plan to perform a variety of engagements to develop general skills that could be used to assess environmental, social, and governance initiatives.

D.

A request to attend the organization ' s committee meeting that is focused on strategic community awareness.

Question 143

Which of the following practices is generally most effective to protect internal audit objectivity?

Options:

A.

Ensuring regular documentation of auditor skills and experience in the workpapers.

B.

Basing performance evaluations heavily on customer satisfaction surveys.

C.

Prohibiting auditors from accepting gifts from audit clients or potential clients.

D.

Ensuring that auditors have a balance of both operational and internal audit responsibilities.

Question 144

Which of the following best describes the type of risk that an adequately designed and effectively operating system of internal controls should mitigate?

Options:

A.

Net.

B.

Controllable.

C.

inherent,

D.

Residual.

Question 145

Which of the following types of policies best helps promote objectivity in the interna! audit activity ' s work?

Options:

A.

Policies that are distributed to all members of the internal audit activity and require a signed acknowledgment,

B.

Policies that match internal auditors ' performance with feedback from management of the area under review.

C.

Policies that keep internal auditors in areas where they have vast audit expertise.

D.

Policies that provide examples of inappropriate business relationships.

Question 146

What is the primary reason a chief audit executive should dedicate time and resources to support continuing professional development of internal audit staff?

Options:

A.

To ensure that internal audit staff maintains high overall job satisfaction.

B.

To ensure that internal audit staff acquired continuing professional education credits timely.

C.

To ensure that top risks are mitigated to an acceptance level.

D.

To ensure that internal audit staff have the competency to address high-priority risks.

Question 147

Which of the following statements is true regarding organizational independence of the internal audit activity (IAA)?

Options:

A.

Reporting to a higher level within the organization reduces the potential scope of engagements that can be undertaken by the IAA.

B.

The benefit of the IAA ' s organizational independence is realized primarily via reduced costs for the external auditor.

C.

Independence is impaired when the scope of the IAA is subject to changes required by senior management.

D.

Inadequate organizational independence can result in the chief audit executive being able to fire staff without consulting the audit committee.

Question 148

A chief audit executive (CAE) recruited a few new internal auditors to reduce the resource gaps identified in this year ' s internal audit plan. One of the new recruits has several years of experience with the organization. Ten months ago. she served as a senior supervisor in the finance department. However, for the past 10 months, she has been helping the organization with implementing a new IT system. What approach should the CAE take for the upcoming financial statement controls audit?

Options:

A.

Assign the new auditor to assist with conducting the fieldwork. but ensure that her work is reviewed by the CAE.

B.

Assign the new auditor to assist with developing the audit program, but ensure that the audit program is executed by other audit staff.

C.

Ensure that the new auditor ' s previous manager, and other close former coworkers, are excused during the audit.

D.

Ensure that the new auditor is responsible only for the supervisory review, but not the execution of the audit field work.

Question 149

In its five years of existence, an internal audit activity conducted a single internal assessment of its quality assurance and improvement program (QAIP). The results of that assessment showed that the internal audit activity did not conform with the Standards. Prior to this, an external assessment of the internal audit activity ' s QAIP was conducted, which reported that the internal audit activity was in conformance with the Standards. Considering the two assessments, what would be the internal audit activity ' s current state of conformance with the Standards?

Options:

A.

Conformance with the Standards.

B.

Nonconformance with the Standards

C.

Unable to determine conformance with the Standards.

D.

Partial conformance with the Standards

Question 150

Which of the following represents a deficiency in the control environment?

Options:

A.

The sales department has failed to achieve targets for the last nine months.

B.

Employees report suspicious activity by calling the organization ' s ethics hotline.

C.

Hiring procedures do not include background checks for prospective job candidates.

D.

Management reports three potential ethics issues to the board of directors.

Question 151

A chief audit executive (CAE) was asked by senior management to establish and manage a risk management function. A new chief risk officer was hired a year later to assume these responsibilities. As this function was included in the current annual audit plan, the CAE engaged an external resource for a risk management engagement. Which of the following potential threats to objectivity was the CAE likely addressing?

Options:

A.

Self-review threat.

B.

Advocacy threat.

C.

Familiarity threat.

D.

Personal relationship threat.

Question 152

Which of the following actions by an internal auditor would be the most relevant to determine the effectiveness of controls?

Options:

A.

Participate in a fraud risk-assessment session as an in-house facilitator.

B.

Send regular written updates to senior management on new control-related regulations.

C.

Lead a seminar on internal controls and provide numerous examples to the audience.

D.

Conduct a surprise inventory count at the raw materials warehouse.

Question 153

A sales manager was recently bypassed for a promotion. He feels entitled to a higher salary and is angry that management does not recognize his contributions. To make up for this perceived injustice, he begins to record false expenses on his travel expense reports. This scenario best illustrates which of the following fraud risk factors?

Options:

A.

Incentive.

B.

Rationalization.

C.

Pressure.

D.

Opportunity.

Question 154

According to IIA guidance, a new internal auditor is expected to possess which of the following competencies?

Options:

A.

Technical industry-specific expertise.

B.

Expertise in cybersecurity, an area of increasing risk.

C.

Knowledge of IT risks and controls.

D.

Knowledge of forensic accounting.

Question 155

Which of the following represents an example of an ethical issue that the organization should address ' ?

Options:

A.

An employee discovered that there is no personal protective equipment at a temporary construction site

B.

An employee saw that a group of other employees were smoking in close proximity to petrol distribution tanks

C.

A supervisor insists that an employee complete time sheets regularly

D.

An employee received concert tickets from a vendor and asked whether she could keep them

Question 156

Which of the following is the primary engagement responsibility of an entry-level internal auditor?

Options:

A.

Leadership.

B.

Documentation.

C.

Analysis.

D.

Reporting.

Question 157

Which of the following scenarios best illustrates the concept of due professional care?

Options:

A.

After establishing engagement objectives and reviewing a process, the internal auditor assured process owners that all significant risk events were identified and tested using a systematic, disciplined approach.

B.

After conducting an audit based upon a predefined scope and objective, the internal auditor guaranteed management that the system of internal controls in an audited area operates effectively.

C.

As head of the internal audit activity, the chief audit executive reported functionally to the organization ' s board and administratively to senior management.

D.

As head of the internal audit activity, the chief audit executive ensures that engagement supervisors conduct post-engagement staff meetings.

Question 158

Which of the following is the most effective way for internal auditors to determine whether ethical values are followed throughout the organization?

Options:

A.

Review the organization ' s ethical value structure and reporting procedures.

B.

Review what the organization considers to be ethical behavior, such as the employee code of conduct.

C.

Review employee survey responses and follow up on those that suggest weaknesses in the ethical climate.

D.

Review the organization ' s records to ensure all employees have signed statements that they will follow ethical practices.

Question 159

Which of the following qualifies as an acceptable consulting service provided by the internal audit activity?

Options:

A.

Develop training and system rollout plans in response to the results of the change readiness assessment of a new sales distribution model

B.

Lead a risk self assessment session for laboratory managers to help identify inherent risks and provide recommendations on how to evaluate the risks

C.

Audit a third party cloud service provider to review the effectiveness of governance and management controls in providing secure services to its customers

D.

Conduct a post-implementation assessment of the enterprise resource planning system to determine whether project objectives were met and to identify opportunities to maximize potential benefits

Question 160

During an assurance engagement, an internal auditor identified that a developer of the organization ' s enterprise resource planning (ERP) system had intentionally modified the production code to commit a fraudulent transaction. Which control activity should be implemented to prevent such issues in the future?

Options:

A.

Segregate duties between code development and migrating changes into production.

B.

Conduct fraud training for the IT team responsible for the ERP system.

C.

Penalize the developer who committed the fraud by terminating employment.

D.

Restrict developers ' access to the ERP system ' s test environment.

Question 161

According to IIA guidance, which of the following actions is a chief audit executive required to take with regard to reporting the results of the quality assurance and improvement program?

Options:

A.

Report external assessments upon completion of such assessments

B.

Report external assessments at least annually

C.

Report ongoing monitoring quarterly

D.

Report post-engagement reviews at least once every five years

Question 162

Which of the following would be addressed in the internal audit charter?

Options:

A.

Expertise requirements for internal auditors

B.

Functional and administrative reporting lines for the chief audit executive

C.

Audit engagements to be completed in the next fiscal year

D.

Budget requirements for each engagement

Question 163

The level of authority for the internal audit activity is granted by which of the following?

Options:

A.

The chief audit executive.

B.

The internal audit charter.

C.

The International Professional Practices Framework.

D.

The IIA ' s Code of Ethics.

Question 164

During a procurement process audit the internal audit activity undertakes a fraud risk assessment and considers a range of possible fraud scenarios within the process. Which of the following scenarios constitutes a pressure to commit fraud?

Options:

A.

An employee believes his poor compensation package justifies engaging in unethical behavior.

B.

The head of the department is the only signatory to purchase orders issued to third party contractors.

C.

Some employees strongly believe monetary gifts from vendors is a means of saving for life after employment.

D.

One of the employees was found to have an obsession with expensive jewelry

Question 165

According to NA guidance, which of the following provides the best evidence of conformance with the Standards with respect to the proficiency required of the internal audit activity?

Options:

A.

Discussions with the chief audit executive.

B.

A listing of employee profiles and certifications.

C.

Inquiry of external auditors.

D.

Validation by human resources.

Question 166

During a quality assessment of the internal audit activity an auditor is assessing whether the independence of the internal audit activity is at risk of being compromised. According to IIA guidance, which of the following would provide the best source of evidence for such an assessment?

Options:

A.

An organizational chart showing the reporting line of the chief audit executive to the CEO

B.

The internal audit charter as endorsed by the organization’s governing body

C.

A review of the audit opinions issued from a sample of recent audit engagements

D.

An assessment of the scope of the audit work performed by the internal au < M activity

Question 167

To comply with the proficiency standard which of the following would the chief audit executive likely consider as the primary hiring criterion when choosing a new internal auditor?

Options:

A.

The length and consistency of the auditor ' s work experience

B.

The auditor ' s demonstrated problem-solving skills

C.

The auditor ' s skills compared to those already possessed by other audit staff

D.

The auditor ' s ability to be self motivated and a good team player

Question 168

Which of the following statements is true regarding the quality assurance and improvement program (QAIP)?

Options:

A.

Reporting on the QAIP to the board should occur at least once every five years

B.

The responsibility for the selection of an external assessor rests with the board

C.

The qualifications of the assessors must be communicated to the board

D.

The reporting of outcomes of the QAIP can be delegated to senior audit staff

Question 169

According to IIA guidance, which of the following corporate social responsibility {CSR) evaluation activities may be performed by the internal audit activity?

1. Consult on CSR program design and implementation

2. Serve as an advisor on CSR governance and risk management.

3. Review third parties for contractual compliance with CSR terms.

4. Identify and mitigate risks to help meet the CSR program objectives.

Options:

A.

1,2, and 3.

B.

1,2, and 4.

C.

1, 3, and 4.

D.

2, 3, and 4

Question 170

Which of the following is an example of an impairment to an internal auditor ' s independence?

Options:

A.

An internal auditor delays reporting material financial statement audit findings until after his parents sell all of their stock in the company

B.

Following the restructuring of the organization, the internal audit activity now reports functionally to the chief financial officer

C.

A new member of the internal audit activity, who was the accounts payable supervisor for two years, is asked to consult on the implementation of a new accounts payable system

D.

Believing there must be errors in a given balance sheet account the internal auditor decides to expand his testing

Question 171

Which type of engagement requires that the client agrees with the techniques used by the internal audit activity?

Options:

A.

A performance audit.

B.

A sensitive fraud investigation.

C.

A compliance audit

D.

A consulting service.

Question 172

Which of the following best demonstrates the board of directors ' governance over internal control?

Options:

A.

The board bears direct responsibility for developing and implementing the internal control system.

B.

The majority of board members are experienced and qualified members of the organization ' s executive management team.

C.

The board may be assisted by an audit committee, chaired by the chief audit executive.

D.

The board is responsible for succession planning for the CEO and other key members of the executive management team.

Question 173

A risk assessment showed that the cost of addressing a particular risk in the organization ' s human resources department is greater than the perceived benefit. Which risk response approach should the organization take in this scenario?

Options:

A.

Reduce the risk.

B.

Transfer the risk.

C.

Accept the risk.

D.

Share the risk.

Question 174

An internal auditor has suspicions that some fictitious vendors have been created in the organization ' s computer system. Which of the following would be the best technique to detect this fraud?

Options:

A.

Review for duplicate invoice numbers, duplicate dates, and duplicate amounts

B.

Run checks to find matches between vendor and employee addresses

C.

Check for recurring requests for refunds where invoices are paid twice

D.

Review for unexplained increases in inventory

Question 175

Which of the following statements is the most appropriate for a chief audit executive to include in the internal audit policy manual in order to promote objectivity?

Options:

A.

Internal auditors may conduct a financial effectiveness engagement in a business unit at any point after being transferred from that area.

B.

Internal auditors may conclude that a business unit ' s current control environment is adequate and effective if the review of the prior year ' s workpapers and audit report supports that conclusion.

C.

Internal auditors may conduct an engagement in a business unit at any point after providing a training workshop in that area.

D.

Internal auditors should limit the scope of an engagement if they become aware of a potential impairment of their objectivity in order to reduce the potential impact of the impairment on the engagement results.

Question 176

Which of the following is (he most effective way any organization can ensure proper governance over its internal controls?

Options:

A.

By adopting the best practices of similar organizations in the industry.

B.

By adjusting their internal control framework as business practices evolve.

C.

By introducing the universally accepted COSO internal control framework.

D.

By encouraging the internal audit activity to provide training on internal controls.

Question 177

Who has the ultimate responsibility of implementing the organization’s governance system?

Options:

A.

Stakeholders

B.

The board

C.

The chief executive officer

D.

Internal auditors

Question 178

During the closing meeting of a procurement audit, the business manager disagrees with the observation presented by the engagement supervisor and accuses the team of not understanding the procurement objectives The engagement supervisor blames the manager for impeding the audit What skillset should the chief audit executive utilize to manage this situation?

Options:

A.

The ability to negotiate

B.

The ability to use analytical tools

C.

The ability to foresee issues

D.

The ability to manage conflict

Question 179

An internal audit activity maintains a quality assurance and improvement program that includes annual self-assessments. The internal audit activity includes in each engagement report a clause that the engagement is conducted in conformance with the International

Standards for the Professional Practice of Internal Auditing ( Standards) Which of the following justifies inclusion of this clause in the reports?

Options:

A.

Internal audit activity policies and engagement records provide relevant, sufficient, and competent evidence that the statement is correct

B.

The audit committee has reviewed the annual self-assessment results and approved the use of the clause

C.

The self-assessment results were validated by a qualified external review team three years prior

D.

The internal audit charter, approved by the audit committee requires conformance with the Standards

Question 180

Nine months ago, an employee who was responsible for collections in the accounts receivables department joined the internal audit team. There is an accounts receivables assurance audit scheduled as part of this year ' s approved audit plan, which will include a review of the collections unit. With the knowledge and experience of this individual in the area, which of the following is the best approach for the chief audit executive (CAE) to take?

Options:

A.

Have the auditor formerly with the collections unit assist with planning and documenting the audit field work.

B.

Have the auditor formerly with the collections unit not participate on the audit team.

C.

Have the auditor formerly with the collections unit conduct the fieldwork and ensure it is reviewed by the CAE.

D.

Have the auditor formerly with the collections unit review all fieldwork done to ensure that there was adequate coverage.

Question 181

To comply with the proficiency standard, which of the following would the chief audit executive likely consider as the primary hiring criterion when choosing a new internal auditor?

Options:

A.

The auditor ' s demonstrated problem-solving skills.

B.

The auditor ' s skills compared to those already possessed by other audit staff.

C.

The auditor ' s ability to be self-motivated and a good team player.

D.

The length and consistency of the auditor ' s work experience.

Question 182

An internal auditor assessed the controls within his organization ' s payroll process and suspects that erroneous payments may have been made to a fraudulent bank account. What is the best course of action for the auditor to take?

Options:

A.

Speak to the payroll manager so he may investigate the auditor ' s observations.

B.

Continue to investigate the payments to confirm the accuracy of the observations, and determine whether further fraudulent payments have been made.

C.

Stop the audit and report the findings to senior management immediately.

D.

Escalate the concern to the engagement supervisor.

Question 183

The manager of the payroll department requested a review of the payroll process, but only wants the engagement to include processes related to approval of time worked. What type of activity is this?

Options:

A.

Financial assurance engagement.

B.

Operational consulting engagement.

C.

Compliance assurance engagement.

D.

Risk management consulting engagement.

Question 184

Which of the following statements is the most appropriate example of the internal audit activity exercising due professional care during an audit of the payroll department?

Options:

A.

Internal auditors ensure that the work program is appropriately designed in order to identify all of the risks surrounding the payroll process.

B.

Internal auditors determine whether the policies, procedures, and practices of the payroll department are operating in accordance with relevant laws.

C.

Internal auditors verify whether the board of directors has implemented effective internal controls over the processes used by the payroll department.

D.

Internal auditors ask the organization ' s risk manager to determine whether the degree of work planned is sufficient to determine whether payroll payments were complete and accurate.

Question 185

Which of the following fundamental principles of The IIA ' s Code of Ethics is best described as performing work honestly diligently and responsibly?

Options:

A.

Integrity

B.

Proficiency

C.

Due Professional Care

D.

Competency

Question 186

When performing an audit of the risk management process an auditor makes the observations listed below. Which poses the greatest risk to the organization?

Options:

A.

The identified risks have not undergone a detailed review to ensure completeness in the past two years.

B.

The controls in place to mitigate the risks are not tested on an annual basis to confirm operating effectiveness.

C.

The process in place to identify and evaluate new risks to the organization is informal and poorly documented.

D.

The identified risks have not been ranked to establish their importance and risk management priority.

Question 187

Which of the following can be used to minimize employees’ resentment of controls?

Options:

A.

Making sure employees are exempt from participating in control creation

B.

Implementing controls without lengthy explanations of their purpose

C.

Developing general constricting controls rather than detailed ones

D.

Not using controls to achieve goals

Question 188

An organization allows the same individual to physically access inventory and purchase new assets when supplies are depleted. Which of the following would best help the organization manage the risk of fraud?

Options:

A.

Accounting personnel should regularly perform a reconciliation between invoices and purchase orders.

B.

Accounting personnel should conduct a periodic inventory count and reconcile all inventory movements.

C.

Internal auditors should review the frequency and volume of purchased assets to detect trends in the inventory levels.

D.

Management should establish a policy requiring new inventory asset purchases to be made on serialized order forms with copies retained.

Question 189

Which of the following describes the internal audit activity ' s most appropriate role in an organization ' s risk management process?

Options:

A.

Reporting to the board on management ' s assessment of current risks

B.

Establishing a risk management policy and framework for the organization

C.

Assigning responsibility for identifying and managing significant risks

D.

Developing key controls to mitigate risks across the organization

Question 190

Which of the following is true about corporate social responsibility (CSR)?

Options:

A.

Social and environmental considerations are required parts of an organization ' s decision making

B.

The Global Reporting Initiative provides standards on required disclosures of CSR.

C.

CSR activities are overseen and managed by operational management.

D.

Internal auditors can provide assurance on reported sustainability results.

Question 191

Which of the following should an internal auditor take into consideration when making a judgement regarding whether management selected appropriate risk responses?

Options:

A.

Significant risks

B.

Risk capacity

C.

Risk appetite

D.

Risk tolerance

Question 192

According to IIA guidance, which of the following would be included in an internal audit charter to help establish the authority of the internal audit activity?

Options:

A.

Outline expectations for communicating the results of all aspects of the internal audit activity.

B.

Declare the internal audit activity’s accountability for safeguarding assets and confidentiality.

C.

Document the chief audit executive’s (CAE ' s) reporting line

D.

Document agreement between the CAE and the individual to whom the CAE reports

Question 193

In a small organization, management is unable to achieve adequate segregation of duties for its cash-handling procedures Therefore hidden surveillance cameras were installed to monitor cash-handling activities Which of the following best describes this type of control?

Options:

A.

Corrective control

B.

Process-level control

C.

Compensating control

D.

Preventive control

Question 194

Which of the following items related to the quality assurance and improvement program should the chief audit executive report to the board?

Options:

A.

Ongoing monitoring results

B.

Periodic management assessment results

C.

Annual risk assessment results

D.

Internal auditors ' training evaluation results

Question 195

In which of the following scenarios is the internal auditor in conformance with The IIA ' s Code of Ethics and the Standards?

Options:

A.

The auditor testifies in front of a jury about an organization ' s fraudulent financial practices after receiving a subpoena

B.

Management has agreed to remedy a significant control deficiency, so the auditor excludes the deficiency from the engagement report

C.

The chief audit executive declines an assurance engagement in IT because the internal audit activity is not proficient in IT

D.

The auditor communicates an audit opinion on fraud risk during an audit engagement’s preliminary fraud risk assessment

Question 196

The collaborating style for conflict resolution, where the parties promote assertiveness and work together to develop a mutually beneficial solution, is best used in which of the following situations?

Options:

A.

Parties are confident of the solution and are ready to defend it.

B.

There is a high level of trust among the parties.

C.

Resolution is time sensitive and a quick decision is necessary.

D.

The issue is more important to one patty than the others.

Question 197

When testing a sample of payroll records during an engagement, an internal auditor suspects mat fraud has been committed. What should be the next step?

Options:

A.

The auditor should increase the sample size to determine the extent ol the fraud.

B.

The suspicions should be communicated to the chief audit executive.

C.

The testing should be completed with the results reported in the final audit report.

D.

A fraud investigator should examine the evidence and report back to the auditor.

Question 198

A new internal audit activity is considering the adoption of a risk and control framework. Which of the following is the most appropriate consideration during this process?

Options:

A.

The framework should not be developed by the internal audit activity

B.

The framework should apply to individual projects rather than the organization as a whole

C.

The framework should always be tailored to the organization

D.

The framework should require fewer resources to implement

Question 199

Why is it imperative for the chief audit executive to track and develop the educational qualifications of internal audit staff?

Options:

A.

To accurately conduct performance appraisals

B.

To ensure that staff complete required continuing professional education credits annually.

C.

To ensure that the resources needed to complete the audit plan are available.

D.

To satisfy the audit committee requirements.

Question 200

The largest risks facing an organization should be mitigated by which type of controls?

Options:

A.

Entity-level

B.

Activity-level

C.

Transaction-level

D.

Process-level

Question 201

An internal auditor extended the scope of testing for a disbursements engagement following a fraud risk assessment Despite the investment of additional audit resources no significant issues were found Unfortunately a major payment fraud was discovered several

months later According to IIA guidance which of the following statements is true regarding the internal auditor ' s application of due professional care?

Options:

A.

Due professional care was not applied because no additional work should have been performed unless there was actual evidence of fraud

B.

Due professional care was not applied because the extended scope resulted in no issues being identified, while fraud actually existed

C.

Due professional care was applied as the internal auditor modified the scope based on reasonable judgment, despite the additional cost of resources

D.

Due professional care was applied as the cost of audit resources should not be a determining factor in the degree of testing undertaken

Question 202

A large commercial bank was fined by regulators for fraudulent practices when employees, over a period of time, opened thousands of new accounts for existing clients without the clients ' consent. It was later found that employees were given unrealistic new account targets and were aggressively monitored by management on a daily basis.

Which of the following controls would have most likely reduced the likelihood of the fraudulent practice from occurring?

Options:

A.

An evaluation of the current performance and compensation program.

B.

The performance of background investigations on all existing employees.

C.

The availability of fraud training to all employees.

D.

The availability of an employee whistleblower hotline

Question 203

Which of the following disclosures must the chief audit executive (CAE) include when communicating the results of the quality assurance and improvement program to senior management and the board?

Options:

A.

Authority and responsibility of the internal audit activity

B.

Hours and sources of continuing professional education

C.

Scope and frequency of both the internal and external assessments

D.

independence and objectivity impairments of the CAE

Question 204

Whch ol the following would show appropriate disclosure of nonconformance with the Standards?

Options:

A.

The chief audit executive (CAE) documented in the personal file a critical conflict of interest involving an internal audit on a upcoming contracting engagement.

B.

The CAE discussed with the board an issue regarding the internal activity performing an IT engagement without proper skills and knowledge.

C.

The CAE met with the peer review team to discuss an internal auditor’s failure to meet the annual requirements for continuing professional education.

D.

The CAE revealed to revealed to operational manager that he failed to appropriately consider risks while he was developing the audit plan.

Question 205

According to IIA guidance, which of the following most appropriately justifies the CEO’s decision that the internal audit activity shall be responsible for risk management and investigation at a multinational organization?

Options:

A.

The recommendation of the parent office external auditors.

B.

The provisions of the internal audit charter

C.

The authority of the CEO.

D.

The level of proficiency of the chief audit executive

Question 206

Which statement is accurate regarding reporting on the quality assurance and improvement program (OAIP) to conform with the International Standards for the Professional Practice of Internal Auditing?

Options:

A.

The chief audit executive (CAE) should report all stages of the OAlP ' s development and key milestones.

B.

The CAE should report only corrective action plans that meet external assessor or stakeholder requirements.

C.

The CAE should establish the form and content of program communication so that it is in alignment with the internal audit activity charter.

D.

The CAE should disclose program details only after both internal and external assessments have been completed.

Question 207

During an audit of an organization ' s accounts payable area, an internal auditor identified anomalies in the information examined that may indicate potential fraud. Which test should the auditor perform first to verify this?

Options:

A.

Verify the completeness and integrity of the data being analyzed.

B.

Identify duplicated organizational transactions.

C.

Analyze all transactions within the targeted area.

D.

Check control totals that have may have been falsified.

Question 208

The internal audit activity is responsible for which of the following actions related to an organization’s internal controls?

Options:

A.

Mitigating risks affecting achievement of organizational objectives.

B.

Enabling opportunities affecting achievement of organizational objectives.

C.

Analyzing and advising regarding costs versus benefits of control activities,

D.

Attesting to fairness of financial statements.

Question 209

Which of the following is a strategic risk that internal auditors should consider when performing a third-party risk management engagement?

Options:

A.

Physical security

B.

Loss of intellectual property

C.

Cost overruns

D.

Conflict of interest

Question 210

An organization ' s board recommends revising the internal audit charter by adding requirements regarding the hiring and compensation of the chief audit executive as well as information on approving the internal audit budget. Which of the following is the board most likely defining in the charter?

Options:

A.

Functional and administrative responsibilities of internal audit activity.

B.

Authority and objectivity of internal audit activity.

C.

Independence and objectivity of internal audit activity.

D.

Assurance and improvement of internal audit activity.

Question 211

According to NA guidance, which of the following describes the primary reason to implement environmental and social safeguards within an organization?

Options:

A.

To enable Triple Bottom Line reporting capability.

B.

To facilitate the conduct of risk assessment.

C.

To achieve and maintain sustainable development.

D.

To fulfill regulatory and compliance requirements.

Question 212

Which of the following statements is true regarding consulting engagements?

Options:

A.

Internal auditors cannot provide consulting services related to operations for which they had previous responsibilities.

B.

The nature of consulting services to be performed by internal auditors must be defined in the internal audit charter

C.

If internal auditors have potential impairments to objectivity related to the proposed consulting engagement, the engagement must be declined.

D.

If internal auditors lack the knowledge, skills, or other competencies needed to perform the consulting engagement, the engagement can proceed with proper disclosures.

Question 213

In which of the following scenarios would the chief audit executive (CAE) be required to decline the assignment?

Options:

A.

The CAE would need to procure external services to deliver the internal audit assurance program.

B.

There is no expertise within the internal audit team for detecting and investigating fraud.

C.

There is no expertise within the internal audit team for auditing an IT engagement.

D.

There is no available expertise on the internal audit team to perform a consulting engagement

Question 214

According to MA guidance, which of the following statements is true regarding an effective governance process?

Options:

A.

It stipulates that risk needs to be considered when making strategic decisions.

B.

It encourages strict segregation of the risk management and internal control processes.

C.

It relies on effective risk management when establishing the organization ' s risk appetite.

D.

It relies on the board to devise ways to communicate the effectiveness of internal controls.

Question 215

IT management requires all employees in the IT department to attend annual training on the department’s mission values and key performance measures This activity is designed to prevent which of the following conditions?

Options:

A.

Knowledge’s kills gap

B.

Monitoring gap

C.

Accountability/reward failure

D.

Communication failure

Question 216

An internal auditor observed that sales staff are able to modify or cancel an order in the system prior to shipping* She wonders whether they can also modify orders after shipping. Which of the following types of controls should she examine?

Options:

A.

Batch controls.

B.

Application controls.

C.

General IT controls.

D.

Logical access controls

Question 217

A new company’s risk management function is developing its cybersecurity risk management program Which of the following actions should be the first priority when developing the program?

Options:

A.

Start building a cybersecurity culture and set the desired behavior using a bottom-up approach

B.

Determine the cybersecurity framework that will establish and report on the effectiveness of the program

C.

Define the cybersecurity risk appetite and perform a cost-benefit analysis of the program

D.

Raise cybersecurity awareness across various departments outside of the IT department

Question 218

According to IIA guidance, which of the following activities would typically be examined when using the maturity model approach for assessing an organization ' s risk management program?

Options:

A.

Monitor and review

B.

Performance measurement.

C.

Setting the context.

D.

Communication.

Question 219

Which of the following would be considered advanced expertise which most internal auditors are not expected to possess ' ?

Options:

A.

The ability to evaluate fraud risk

B.

The ability to detect and investigate fraud

C.

The ability to assess risk management strategies

D.

The ability to create test databases

Question 220

Which of the following needs to be established prior to undertaking an assessment of the quality assurance and improvement program?

Options:

A.

Department performance standards.

B.

Remediation timeframes.

C.

Nonconformance disclosures.

D.

External assessment resources

Exam Detail
Vendor: IIA
Certification: CIA
Exam Code: IIA-CIA-Part1
Last Update: Aug 14, 2026
IIA-CIA-Part1 Question Answers