Which of the following would decrease or be reduced if an organization establishes and implements excessive internal controls?
An accounts payable clerk has recently transferred Into the internal audit activity and has been assigned to an engagement related to accounts payable processes for which he was previously responsible Which of the following is the best action for the new internal auditor to take?
In an environment where employees are frequently penalized for mistakes and the organizational culture is one of fear and blame which of the following is an internal auditor most likely to find?
Which of the following statements is true regarding the internal audit activity ' s quality assurance and improvement program (QAIP)?
Which of the following controls would be most useful to prevent an employee from using the organization ' s funds for inappropriate expenditures and falsifying financial records to conceal the fraud?
Which type of engagement requires that the client agrees with the techniques used by the internal audit activity?
An internal auditor at a multinational organization is reviewing the effectiveness of the organization ' s risk management framework. In this scenario, which of the following statements is true?
Which of the following qualifies as an acceptable consulting service provided by the internal audit activity?
Which of the following best describes the internal audit activity ' s contribution to the implementation of the risk management framework?
Which of the following is a typical characteristic of an organization ' s risk management framework?
A new internal audit activity is considering the adoption of a risk and control framework. Which of the following is the most appropriate consideration during this process?
Which situation demonstrates an internal auditor’s due professional care?
An internal auditor is assessing how the organization processes financial transactions and whether written policies and procedures are followed. The auditor requested to meet with certain employees to understand their related roles and responsibilities. However the employees refuse to meet with the auditor claiming they are too busy. Which of the following responses would best demonstrate the auditor ' s conflict-resolution skills?
Which of the following best demonstrates conformance with the Standards relating to continuing professional development of internal auditors?
Which of the following represents a deficiency in the control environment?
In terms of governance, which of the following best characterizes the relationship between senior management, the board, and owners or investors?
Which of the following best demonstrates organizational independence of the internal audit activity?
According to IIA guidance, which of the following roles for the internal audit function regarding risk management are acceptable with appropriate safeguards in place?
The internal audit activity is responsible for conducting fraud investigations. A potential fraud instance was identified during an audit engagement. The chief audit executive appoints a lead investigator. Which of the following would most likely be the next step?
During the closing meeting of a procurement audit, the business manager disagrees with the observation presented by the engagement supervisor and accuses the team of not understanding the procurement objectives The engagement supervisor blames the manager for impeding the audit What skillset should the chief audit executive utilize to manage this situation?
According to IIA guidance, which of the following is a required aspect of an internal audit charter?
During the planning stage of an assurance engagement, the engagement supervisor initially reviews the control environment to identify and examine possible fraud risks.
Which finding should be considered a potential red flag?
Which of the following statements is the most appropriate for a chief audit executive to include in the internal audit policy manual in order to promote objectivity?
The board of directors of a global organization has found an increased number of reported cases of unethical practices since last year. To assist the board in gaining a better understanding of the degree of ethics awareness within the organization, which of the following actions should be undertaken?
An internal auditor is performing testing to gather evidence regarding an organization’s inventory account balance and is mindful of the possibility that the sample used might support the conclusion that the recorded account balance is not materially misstated when, in fact, it is. The auditor ' s concern best describes which of the following risks?
An organization is conducting a fraud risk assessment as part ol its risk management program. Which of the following steps is the organization most likely to perform first?
Which of the following is an example of impairment to an internal auditor’s independence?
Which of the following situations undermines the independence of the internal audit activity?
According to IIA guidance, which of the following best describes expense reimbursement fraud?
According to NA guidance, which of the following is true regarding typical fraud schemes?
1. A diversion occurs when an employee has an undisclosed personal economic interest in a transaction that adversely affects
the organization.
2. Tax evasion is intentional reporting of false or misleading information on a tax return by an organization to reduce taxes owed.
3. Skimming involves stealing cash or assets from the organization and is normally concealed by adjusting the organization’s
records.
4, Disbursement fraud occurs when a person causes the organization to issue a payment for fictitious goods or services.
Which of the following is the primary reason that the quality assurance and improvement program should be detailed in the internal audit charter?
According to IIA guidance, which of the following activities is appropriate for an internal auditor to perform with regard to the organization ' s corporate social responsibility (CSR) program?
1. Determine whether the organization has adequate controls to achieve its CSR objectives.
2. Facilitate a management self-assessment of CSR controls and results.
3. Consult on the project design and implementation for the CSR program.
4. Exclude CSR-related external risks that are beyond the control of the organization.
During a payroll audit, a staff internal auditor suspects that signatures on some of the documents being sampled for examination are not authentic. Which of the following actions should the auditor take before proceeding with the examination?
Which of the following statements is true regarding internal controls?
How do assurance services and consulting services differ?
Which documents would help a forensic auditor identify instances of collusion between an employee and vendor to defraud the organization?
Management decided to post the organization ' s newly established code of conduct on its website. This decision is primarily intended to mitigate which of the following risks?
While preparing the audit plan for an automobile manufacturing company, the chief audit executive (CAE) noted that the company ' s engineering department received a high risk ranking. However, the internal audit activity is understaffed, and current staff do not possess the necessary skills to adequately assess the effectiveness of the engineering department. What is the most appropriate course of action for the CAE to take?
Which of the following statements best illustrates why internal auditors assess soft controls?
An internal auditor is assessing the effectiveness of the organization ' s risk management practices. She checks to see whether risk management is an integral part of decision making and whether risk management is transparent, responsive to change, and addresses uncertainty. According to IIA guidance on risk management frameworks, which of the following approaches is the auditor most likely using?
The internal audit activity is undergoing a self-assessment as part of its quality assurance and improvement program Which of the following observations must be addressed in order for the internal audit activity to achieve conformance with the Standards?
In which of the following scenarios would the internal auditor’s objectivity be best protected?
After the draft engagement report is issued, the manager of the area that was reviewed is informally interviewed by the engagement supervisor regarding the audit experience. Which of the following is most likely the purpose for this interview?
Which of the following represents a breach to the principle of maintaining objectivity?
Which of the following controls would most likely prevent fraud related to the overpayment of vendors?
An organization holds 40% of its long-term assets in stocks and wants to hedge for the possibility of potential losses in the foreseeable future.
Which of the following statements is true regarding this risk management approach?
Which of the following best describes a consulting engagement rather than an assurance engagement?
The head of human resources notified the internal audit activity that a key account manager was fired because he did not register a large number of contracts with clients As a result the organization was unaware of its duties and would suffer some financial loss Which of the following should be expected from a competent internal auditor who is analyzing this situation?
Which of the following actions by the internal audit activity requires disclosure to the board of nonconformance with the Standards?
Which of the following best describes the board’s role in establishing effective organizational governance?
The chief risk officer (CRO) requested the internal audit function’s assistance during the implementation of the organization’s risk management process. The board wants the CRO and chief audit executive to define what the internal audit function’s role will be before it approves or denies the request.
Which of the following internal audit roles would be the most appropriate in this scenario?
During a payroll audit, the internal auditor discovered that several individuals who have the same position classification as he are earning a significantly higher salary. The auditor noted the names and amounts of each, and he planned to prepare a request to the chief audit executive for a salary increase based on this information. Which of the following IIA Code of Ethics principles was violated in this scenario?
Which type(s) of assessments in an internal audit activity’s quality assurance and improvement program requires ongoing monitoring to evaluate internal audit activity ' s efficiency and effectiveness?
Which of the following activities best demonstrates an internal auditor’s commitment to developing professional competencies?
Which of the following is ultimately responsible for the continuing professional development of internal audit activity staff?
According to IIA guidance, which of the following activities are considered a core internal audit role with regard to enterprise risk management?
Reviewing the management of key risks.
Evaluating the reporting of key risks.
Evaluating risk management processes.
Consolidating the reporting of risks.
Which of the following drivers of fraud is directly controllable by an organization?
Senior management requested that the internal audit function conduct an advisory engagement to evaluate the design and implementation of the project for setting up a new accounting system.
Which approach should the auditors perform that relates only to an advisory engagement?
Which of the following situations is most likely to prompt the internal audit activity to disclose its nonconformance with the Standards?
Management would like to self-assess the overall effectiveness of the controls in place for its 200-person manufacturing department. Which of the following client-facilitated approaches is likely to be the most efficient way to accomplish this objective?
An internal auditor is trying to evaluate what could go wrong after determining that a risk management technique is operating effectively. What type of risk is the auditor assessing?
Which of the following tests would most likely help discover a fictitious invoice?
The management team of an agricultural organization has prioritized corporate social responsibility (CSR) initiatives. Which of the following would be considered a CSR activity?
The chief audit executive (CAE) annually develops a budget and resource plan and submits it to the board for approval. This action best fulfills which of the following responsibilities of the CAE?
While conducting an engagement in the procurement department, the internal auditor noticed that the department head’s travel reports showed minor travel expenses, and there were no charges for hotels, meals, or transportation. However, the auditor knew that the department head frequently traveled worldwide to meet with suppliers and visit their production sites. Which of the following would be the most appropriate next step for the auditor?
Which of the following is an example of an application control?
Which of the following is an example of impairment to internal auditor independence or objectivity ' ?
Which of the following would be considered a primary control to reduce the risk associated with setting up duplicate vendors?
Which action, if taken by an internal auditor, most directly demonstrates objectivity?
Which of the following statements is true regarding organization wide risk management?
Which of the following is an example of an impairment to an internal auditor ' s independence?
Which of the following practices is generally most effective to protect internal audit objectivity?
Which of the following scenarios best demonstrates the application of internal audit proficiency?
Which of the following is the primary benefit of an effective professional development program for internal auditors?
For a new board chair who has not previously served on the organization ' s board, which of the following steps should first be undertaken to ensure effective leadership to the board?
According to The IIA’s Code of Ethics, which of the following scenarios offers the best example of violating the principle of integrity?
Which of the following is a legitimate requirement for an internal audit activity’s quality assurance and improvement program (QAIP)?
During an assurance engagement, an internal auditor identified that a developer of the organization ' s enterprise resource planning (ERP) system had intentionally modified the production code to commit a fraudulent transaction. Which control activity should be implemented to prevent such issues in the future?
An organization is in the process of hiring a new chief audit executive (CAE). Which of the following can the potential candidates expect to be a part of the recruiting process or in place when the CAE is hired?
At a construction company, supervisors are entitled to bonus payments if there are no safety rule violations on their teams. There are several channels available for workers to report accidents and violations, and all reported violations are investigated. Bonus payment calculations are approved by managers and the head of safety. Which of the controls best addresses the risk that supervisors will conceal accidents on their teams in order to receive the bonus?
According to the Standards, which of the following is a requirement for internal audit professional development plans?
During the planning stage of an assurance engagement, a payroll clerk informed the internal auditor that he is often asked to add new employees to the payroll without any formal new-hire documentation from human resources. The auditor is concerned that this increases the risk for fraud. To complete engagement planning, which of the following is the most appropriate next step for the auditor to take?
Which statement accurately describes the authority of the internal audit activity as outlined in the audit charter?
A business unit manager was impressed by the competence of the internal auditor who was conducting an assurance engagement in his area and the manager made the auditor an attractive job offer to begin after the audit was completed The auditor later told her auditor in charge that she was considering the offer. Which of the following IIA Code of Ethics principles was most likely violated?
What is the best course of action when the internal audit activity does not have the knowledge necessary to perform a planned audit of the organization ' s new IT data backup process?
Which of the following best describes a purpose for the internal audit charter?
The chief audit executive (CAE) has assigned an internal auditor to an upcoming engagement. Which of the following requirements would most likely indicate that the internal auditor was assigned to an assurance engagement?
Which of the following fraud schemes is often an off-book fraud*?
In which of the following situations would the organizational independence of an internal audit activity be impaired?
The internal audit activity is asked to provide consulting services regarding the risks related to implementing a proposed new Inventory management system. Which of the following would be a key consideration of the internal audit activity in accepting this engagement?
Which of the following is the appropriate next step after management identifies and implements risk responses?
Which of the following is true regarding the use of a formal risk management framework?
1. It facilitates a methodical approach to risk mitigation.
2. It defines and standardizes the terminology used in risk communication.
3. It establishes the risk tolerance levels to be accommodated in the strategy.
4. It facilitates the alignment of risk mitigation strategies with management priorities.
What should the internal audit function promote to most effectively deter fraud?
Which of the following situations is most likely to heighten an internal auditor ' s professional skepticism regarding potential fraud?
Which of the following practices, applied by the chief audit executive {CAE), most likely indicates an effective continuing professional educational program for the internal audit activity?
Nearing the completion of fieldwork, an internal auditor shared the draft report findings with management prior to the closing meeting. During the closing meeting, management expressed dissatisfaction in that they were not familiar with some of the findings. Management also noted that some aspects of the report seemed confusing. Which of the following competencies appears to have been lacking in this scenario?
A new CEO authorizes a vendor’s access to the organization’s vendor payment and contracting database as part of a review to identify wasteful spending. An employee in the contracting department raised concerns to the internal audit function about potential fraud involving the vendor’s access to the database’s sensitive information, including that of the vendor’s competitors.
Which is a potential fraud risk that requires special consideration during an internal audit engagement?
A sales manager was recently bypassed for a promotion. He feels entitled to a higher salary and is angry that management does not recognize his contributions. To make up for this perceived injustice, he begins to record false expenses on his travel expense reports. This scenario best illustrates which of the following fraud risk factors?
Which of the following is the best way for internal auditors to demonstrate their proficiency to effectively carry out their professional responsibilities?
According to IIA guidance, which of the following statements is true regarding proficiency?
Which of the following skills is critical for assessing corporate social responsibility through a self-assessment?
In which of the following situations has the internal auditor violated the IIA ' s Code of Ethics?
A chief audit executive (CAE) has no direct access to the board. According to IIA guidance, which of the following is the most appropriate way for the CAE to react?
According to HA guidance, which of the following is true regarding independence and objectivity for small internal audit activities?
A chief audit executive (CAE) recruited a few new internal auditors to reduce the resource gaps identified in this year ' s internal audit plan. One of the new recruits has several years of experience with the organization. Ten months ago. she served as a senior supervisor in the finance department. However, for the past 10 months, she has been helping the organization with implementing a new IT system. What approach should the CAE take for the upcoming financial statement controls audit?
Which of the following statements is true regarding the use of risk frameworks?
During his quarterly meeting with the chief audit executive (CAE), it was recommended to an experienced staff internal auditor that he complete a communication and leadership training. The training was also included in the auditor’ yearly professional development plan. The auditor is confused, as he believes he should attend trainings on technical areas rather than spend time on communication and leadership.
According to IIA guidance, which of the following statements regarding this scenario is true?
An internal auditor has completed an assurance engagement Which of the following is most likely true regarding the engagement?
An organization allows the same individuals to physical access inventory and purchase new assets when supplies are depleted. Which of the following would best help the organization manage the risk of fraud?
According to the 11A Code of Ethics, which of the following is required with regard to communicating results?
According to The IIA’s Code of Ethics, which of the following statements is true?
Which of the following scenarios is a characterize of an organization with a highly effective ethical culture?
According to IIA guidance, which of the following statements is true regarding the knowledge, skills, and competencies required of internal auditors?
An internal auditor is reviewing the results of an employee survey at a mining company. Which of the following would alert the auditor to a potential ethics issue?
Which of the following actions by the chief audit executive (CAE) best describes a potential impairment to the internal audit function’s independence?
Which of the following would provide the best support for internal auditors to meet their continuing professional development requirements?
Which of the following is a primary benefit of implementing a governance, risk management, and compliance framework within an organization?
Which of the following statements is true regarding corporate social responsibility (CSR)?
An internal auditor was completely honest with operational management when delivering unfavorable audit results. Which of the following best describes the IIA Code of Ethics principle that the auditor demonstrated?
The board scheduled a meeting with the chief audit executive (CAE) to determine why the internal audit function’s training budget is significantly higher compared to other departments within the organization. The CAE is expected to provide evidence to support that the internal audit function conforms with continuing professional development requirements.
Which of the following supporting documents should the CAE provide?
A newly hired internal auditor is most likely to need further education in the area of business acumen in which of the following situations?
Which of the following is the best way for an internal auditor to demonstrate due professional care?
According to IIA guidance, which of the following best demonstrates how the chief audit executive may ensure that due professional care is applied?
Which of the following actions would an internal auditor perform primarily during a consulting engagement of a debt collections process?
According to NA guidance, which of the following conditions would enhance the independence of the internal audit activity?
Which of the following should a general internal auditor be able to characterize as an IT-related risk?
Which of the following is a true statement regarding controls such as ethical values, tone at the top and operational style?
An internal audit activity is using the auditing-by-element approach to audit the organization ' s controls around corporate social responsibility. Which of the following would be an element for the internal audit activity to consider?
According to IIA guidance, which of the following training methods is considered most effective in assisting new entry-level internal auditors in achieving competence with internal audit practices in the workplace?
To comply with the proficiency standard which of the following would the chief audit executive likely consider as the primary hiring criterion when choosing a new internal auditor?
The internal audit activity is undergoing a self-assessment as part of its quality assurance and improvement program. Which of the following observations must be addressed in order for the internal audit activity to achieve conformance with the Standards?
Which of the following could increase risks to the organization’s control environment?
Which of the following best describes the risk created when a manager bypasses organizational policies and procedures in order to meet an organization’s objective?
Which principle of the HA Code of Ethics focuses on continuing education and professional development?
An internal auditor wants to compare her organization’s governance processes to those of a well-known governance model. Which of the following approaches would the auditor take for this purpose?
Which of the following strategies would be the most effective to share an organization ' s risk of losses through foreign currency transactions related to the accounts payable process?
Which of the following actions should the organization ' s governing body perform to provide the most effective governance over the organization ' s culture?
During a complex financial compliance engagement, a senior internal auditor determines that current audit procedures are not sufficient for adequate testing She consults with a colleague and learns that a spreadsheet application contains a helpful tool She proceeds to use the tool to properly complete the evaluation Which of the following best describes the core competency displayed by the senior auditor?
What must a chief audit executive do if significant changes to regulations may affect the nature of internal audit services?
In which of the following scenarios is the internal auditor in conformance with The IIA ' s Code of Ethics and the Standards?
Which of the following would be an important aspect of an internal auditor ' s role in fraud management?
Which of the following specifications in an internal audit charter is the most important factor in the internal audit activity’s independence?
Which of the following is an example of risk monitoring to ensure a system is performing as intended?
The organization ' s chief audit executive (CAE) is planning an immediate assurance engagement following several product recalls. However, the internal audit staff does not have the required Knowledge and experience to adequately assess all the relevant processes and procedures. According to 11A guidance, which of the following actions should the CAE take under these circumstances?
Which of the following would best assist the internal audit activity in assessing whether an organization ' s responses to risk are aligned with its risk appetite?
Whch ol the following would show appropriate disclosure of nonconformance with the Standards?
How can internal auditors best enhance the credibility and value of their work?
Which of the following best describes why a chief audit executive might obtain the services of a fraud specialist to assist in a major fraud investigation?
Which of the following corporate social responsibility strategies is associated with responding to outside pressure by assuming additional responsibility?
Which of the following best describes the type of organizational culture known as adaptability culture ' ?
Which of the following statements best describes internal auditors ' role in fraud detection?
Which of the following documents are internal auditors most likely to be asked to sign as a demonstration of due professional care?
A description of their job responsibilities,
Which of the following best describes the internal audit activity’s responsibility within a risk and control framework?
Which of the following scenarios would most significantly restrict the areas where internal audit could perform assurance services?
Which of the following is a threat to the internal audit function’s organizational independence?
An organization’s management has asked the chief audit executive to help the HR team facilitate identifying corrective actions that will address gaps from a lack of succession planning.
Which of the following engagements would be the most appropriate to accomplish the objective?
When a plant manager from within the organization is hired as a rotational internal auditor within the internal audit activity which area should he most likely be trained for immediately?
The chief audit executive (CAE) of a multinational corporation has been assigned to assist management in identifying an internal control framework for the organization. The CAE wants to ensure the framework is comprehensive and will effectively meet the needs of various stakeholders.
Which factor should the CAE primarily consider?
Which of the following is a control that is used mainly to check the integrity of data entered into a business application, whether the data is entered directly by staff, remotely by a business partner, or through a web-enabled application?
According to IIA guidance, which of the following activities would typically be examined when using the maturity model approach for assessing an organization ' s risk management program?
It is important for the chief audit executive to consider the level of competence of the internal audit staff because their competence influences which of the following?
An employee accepts cash payments from customers and does not record the sale. This is an example of which of the following types of fraud?
Which of the following is a way to demonstrate an individual internal auditor ' s competency through continuing professional development?
Which of the following is true regarding internal audit role ' s in The IIA ' s Three Lines Model?
Which of the following is the primary engagement responsibility of an entry-level internal auditor?
IT management requires all employees in the IT department to attend annual training on the department’s mission values and key performance measures This activity is designed to prevent which of the following conditions?
According to The IIA ' s Competency Framework, which competency is considered the mandatory minimum for internal auditors to possess when performing internal audit engagements?
Which of the following situations undermines the independence of the internal audit activity?
In an assurance engagement focused on the adequacy of organizationwide risk management practices, which of the following best describes a primary area of interest for the engagement?
The chief audit executive of an organization assigns audit resources to undertake a consulting engagement requested by senior management the previous year, and a scheduled assurance audit of the procurement process Which of the following appropriately differentiates the two engagements?
The board has not delegated responsibility for risk oversight and therefore does not receive regular reports on the organization’s most significant risks.
This situation signals that there is a potential problem related to which of the following?
Which of the following can be used to minimize employees’ resentment of controls?
Senior management purchased surveillance cameras and installed them over a door that provides entry to an area where according to a recent internal audit report, hazardous materials exist and there is a high risk of explosion Which type of control was implemented in this situation?
An internal auditor discovers that a production manager has been understating stock items produced in the factory and concealing it by accounting for it as abnormal waste.
Which of the following types of fraud does this exemplify?
Which of the following statements is true regarding the internal audit activity ' s quality assurance and improvement program (QAIP)?
To assure that the technical proficiency of internal auditors is appropriate for the audit engagements to be performed, a chief audit executive should:
During an audit of company expenses, the internal auditor performed a test using data analytics and identified a violation of the company ' s expenses policy. The auditor who discovered the issue considered it a potential fraudulent transaction and informed the chief financial officer (CFO). The CFO dismissed the concern because he did not understand the data analytics test that was performed and the transaction was of a low value. Given this situation, which skills or competencies should this internal auditor seek to improve?
Which of the following functions does an internal audit charter serve?
What should be the first step for a newly hired chief audit executive to build and maintain the proficiency of the internal audit activity ' ?
An internal auditor is preparing for an overseas engagement. As part of the engagement, the auditor will conduct interviews with managers from various regional offices around the world.
Which of the following is the most important for the auditor to consider in establishing good relationships with regional managers?
With regard to IT governance, which of the following is the most effective and appropriate role for the internal audit activity?
The board of a newly established organization was discussing the contents of the draft internal audit charter One board member suggested adding to the charter an obligation for the internal audit activity to develop controls in business procedures. The board member explained that the new organization needs professional-level developers, internal auditors have the necessary skills and competencies, and the internal audit activity is well positioned to assume this responsibility. Which of the following would be a potential concern if the board member’s suggestion is adopted?
Which of the following statements is true regarding control activities ' ?
Once an organization ' s risks are identified, what would be the next step to ensure resources are properly allocated to manage those risks?
Operational management in the IT department has developed key performance indicator reports, which are reviewed in detail during monthly staff meetings. This activity is designed to prevent which of the following conditions?
Senior management relies on the professional judgment of an internal auditor and uses outcomes of her audit work to make business decisions Which of the following personal qualities displayed by the internal auditor is most likely the foundation for this relationship?
According to NA guidance which of the following should be documented in the internal audit chatter?
Management assessed the organization’s risk of expanding operations into a new, but volatile, region and began looking for a compatible local partner to manage sales and distribution. Which of the following best describes this risk management technique?
The internal audit activity conducted an organization wide risk assessment. One of the most significant risks identified is associated with the oil price market. The chief audit executive (CAE) is considering including in the annual audit plan an assessment of the effectiveness of oil price risk management. The manager responsible commented that the assessment was not needed, as market risks were regularly addressed by the financial risk committee. If the CAE decides to include this activity in the annual audit plan anyway, how should it be recorded?
Management has implemented a segregation-of-duties policy for handling inventory. Which of the following fraud risks would be more concerning to an internal auditor following the implementation of this new policy?
Which of the following best illustrates the application of due professional care during an audit of the procurement department?
Which of the following is included in the risk identification process?
Which of the following best demonstrates conformance with IIA standards related to continuing professional development?
The largest risks facing an organization should be mitigated by which type of controls?
An internal auditor is updating the risk register for risks identified during a recent organizational risk assessment. According to the Standards, which of the following would the auditor include in the risk register?
Which of the following is an indicator that the internal audit activity does not fully conform with the Standards?
What controls could be implemented as a preventive measure against malicious insider threats, such as an unauthorized employee obtaining electronic customer sales information and later selling them to a competitor?
Which of the following indicates an appropriate disclosure of a potential nonconformance with the Standards?
Which of the following statements is true regarding assurance and advisory services provided by an internal audit function?
For a high-risk observation, which is the best approach to follow when management takes an aggressive, uncompromising position in opposition to the internal audit activity?
Which of the following should be implemented to promote independence of the internal audit activity?
Which of the following best describes a consulting engagement rather an assurance engagement?
Which step should an internal auditor complete during fieldwork to detect fraudulent activities during an audit?
With regard to organizational governance assurance, which of the following is an appropriate role for the internal audit activity ' ?
Which of the following should be part of the internal audit activity ' s duties?
Which of the following needs to be established prior to undertaking an assessment of the quality assurance and improvement program?
After an engagement was completed and the final communication was issued, it came to the attention of the engagement supervisor that additional work was required to review some significant risks in the processes of the area under review.
How should the engagement supervisor proceed after completing the additional work?
An organization has discovered that an excessive number of labor hours has been entered into a costing system.
Which of the following controls should the organization implement to prevent this issue from reoccurring?
An internal auditor assessed the controls within his organization ' s payroll process and suspects that erroneous payments may have been made to a fraudulent bank account. What is the best course of action for the auditor to take?
In which of the following ways could stakeholders be engaged in corporate social responsibility efforts?
Which of the following best describes organizational governance processes?
The results of an assessment of the adequacy of controls would be considered incomplete or misleading unless the internal auditor considers which of the following?
An organization is testing a new IT system for digital data storage and security. The internal audit activity has been asked to evaluate the system in a consulting engagement. Although several internal auditors on staff are qualified to perform basic assessments of IT systems, none are familiar with the new system. Which of the following is a legitimate response to the prospective client?
1. Decline the engagement.
2. Proceed with the engagement, performing only those parts of the engagement that the internal auditors are qualified to perform.
3. Accept the engagement and develop the additional competencies in-house prior to the engagement ' s starting date.
4. Make arrangements to obtain assistance from a competent IT auditing expert.
According to IIA guidance, which of the following actions by a new chief audit executive would be most appropriate to gain an understanding of the current level of knowledge, skills, and competencies required by an internal audit activity to fulfill its responsibilities?
Which of the following would best preserve the organizational independence of the internal audit activity?
An organization is implementing a new cybersecurity policy and has established a committee to ensure stakeholder alignment across the organization ' s infrastructure, network, and security teams. The head of the committee has asked the chief audit executive if the internal audit activity could play a role in these efforts. According to HA guidance, which of the following is the most appropriate response?
The collaborating style for conflict resolution, where the parties promote assertiveness and work together to develop a mutually beneficial solution, is best used in which of the following situations?
According to IIA guidance, which of the following actions by the chief audit executive (CAE) best demonstrates the organizational independence of the internal audit activity?
According to IIA guidance which of the following correctly describes the standard risk treatments outlined in the process element approach of the framework for risk management?
An internal auditor notes that inventory counts are conducted on Mondays only and that all documentation is on paper as there are no computers in the underground warehouses. Also she notices that the person responsible for receiving the goods is the same one who distributes materials and spare parts Finally, she sees that spare parts are written off and taken by the heads of mining units to different underground locations to wait for their turn to be installed. Which of the described findings requires more consideration from a fraud risk perspective?
Which of the following is true about a system of internal control?
In which of the following scenarios would it be appropriate for the chief audit executive (CAE) to report that the internal audit activity conforms with the Standards?
Which of the following is a detective control?
According to IIA guidance, which of the following statements regarding ethics is true?
A significant number of employees expressed concerns of a hostile work environment within a large manufacturing plant, which is in contrast to the organization ' s stated culture of tolerance and open communication. Which of the following approaches would be most effective for an internal auditor to assess whether the organization supports a culture of tolerance and open communication?
The internal audit activity completed its analysis of sample transactions to determine occurrences of double billings According to If A guidance, which of the following best demonstrates that internal auditors exercised due professional care during the review?
Which of the following accurately describes the concept of inherent risk?
An internal auditor in a busy internal audit activity reviews her continuing professional development records toward the end of the year and is concerned to find she has undertaken limited training and formal professional development. Which of the following actions is the most appropriate for her to take?
Prior to commencing a financial compliance engagement, the engagement supervisor reads the business plan for the finance department and meets informally with the director to learn more about any key issues. Which of the following competencies is the engagement supervisor demonstrating?
Which of the following would be considered a monitoring activity in organization wide risk management?
An internal auditor assessed that the risk of steel theft at a plant is high. In response, the plant ' s management introduced a number of controls, including fences around the facility, a metal detector at the entrance, and monthly steel inventory counts. If the controls operate as intended, which of the following outcomes would the internal auditor hope to see?
Which of the following statements is true regarding corporate social responsibility (CSR)?
An internal audit activity is taking steps to promote professional development among the staff, and is in the process of implementing a mentorship program. According to HA guidance, which of the following is important for a successful mentorship program?
An auditor for a large wholesaler is evaluating the controls over the approval and oversight of credit sales. Which of the following procedures would be a control weakness?
Which of the following is most accurate concerning corporate social responsibility?
A medical clinic has developed a policy that prohibits its doctors from performing certain high-risk optional medical procedures.
Which of the following best describes this risk management technique?
According to IIA guidance, which of the following best demonstrates that the chief audit executive is properly reporting the results of the quality assurance and improvement program to senior management and the board?
An internal auditor has documented several instances in which management asked employees to ad against the policies and procedures. Which of the following is the most appropriate next step?
Which of the following internal control attributes would an internal auditor test to understand whether organizational structure supports effective internal control?
According to MA guidance, which of the following is true with regard to the internal audit charter?
1. It specifies the minimum resources needed for assurance engagements.
2. It requires final approval from senior management.
3. It defines the internal audit activity ' s authority and responsibilities.
4. It describes the expectations for communicating the results of a quality assurance and Improvement program.
Which of the following preventative controls would be most effective for organizations facing business disruptions and respective financial losses?
A financial services organization ' s board is assessing increased regulations and its effect on current industry lending practices. Which of the following committees would help the board identify and assess the effects of the increased regulations?
Which of the following is an example of the chief audit executive (CAE) demonstrating due professional care?
An internal auditor identified an inefficiency in a control and made recommendations to strengthen the control environment, but senior management was reluctant to adopt the recommendations because there were concerns regarding staff acceptance of the change of processes. Consequently, the auditor agreed to remove the observation from the audit report.
Which of the following competencies does the auditor lack?
According to IIA guidance, which of the following best describes the chief audit executive s responsibility for confirming to the board the organizational independence of the internal audit activity ' ?
Which of the following is an indicator that an organization ' s risk management processes are effective?
An internal auditor performed a consulting engagement last year which included assisting with management ' s design of controls over the procurement function. How should the chief audit executive plan an assurance engagement on the adequacy of the internal control system in the procurement function in the current year?
Which of the following best demonstrates the board of directors ' governance over internal control?
Which of the following is true about corporate social responsibility (CSR)?
A senior executive at a government-owned organization received an invitation to attend a public exhibition where he can learn about new trucks relevant to the organization ' s business. As a special perk, the executive is offered an opportunity to drive a luxury vehicle manufactured by one of the exhibiting companies. Prior to the event, the executive asked for the chief audit executive s (CAE’s) advice. What should the CAE recommend as the most appropriate course of action for the executive?
The chief audit executive of a large national retailer is reviewing the purpose and objectives of the organization ' s internal audit activity
Which of the following objectives is best aligned with The IIA ' s Mission of Internal Audit?
An internal auditor assigned to a supplier management process engagement reviews the risk assessment with the process owner The auditor inquires about the risk response for potentially engaging unqualified third-party service providers The process owner responds that due diligence checks are undertaken to make sure that third parties possess requisite competencies before they are engaged Which of the following risk management techniques is the process owner using?
With regard to governance, which of the following is a board-level responsibility rather than a management responsibility?
An organization sells products through distributors. The organization ' s chief audit executive insists that the organization ' s code of conduct be applicable to their distributors as well. Which of the following risks would this mitigate?
An internal auditor is reviewing the organization’s procurement processes. The procurement manager states that suppliers’ bank details are verified by phone call directly with the supplier before being updated in the procurement system. The organization has around 3,000 suppliers. The auditor is skeptical that a phone call is made for each supplier when bank details are changed.
The auditor decides to verify the manager’s statement by analyzing the change to one supplier’s bank details.
Which piece of evidence would convince the auditor that the control described by the procurement manager is effective?
Which of the following statements best describes a functional difference between external auditors and internal auditors?
Which of the following actions does a competency assessment tool help the chief audit executive perform?