UPDATE 2026
A system or process an organization uses to achieve its operational goals, internal and external
financial reporting goals and legal and regulatory compliance goals - Answers Internal Controls
The degree of importance a board of directors and management place on their organization's internal
control system and their related actions - Answers Control Environment
A federal statutory law governing corporate directors in the areas of investor protection, internal
controls, and penalties, both civil and criminal - Answers Sarbanes-Oxley Act of 2002
A system of specified standards or objectives against which an organization's management measures
performance - Answers Management Controls
Controls designed to prevent errors or inconsistencies - Answers Preventive Controls
Controls designed to detect error or inconsistencies after they have occurred - Answers Detective
Controls
A systematic investigation of records, documents, systems, and operations - Answers Audit
A standard defining the attributes of organizations and individuals performing internal auditing -
Answers Attribute Standard
A standard defining the nature of internal auditing and providing quality criteria against which the
performance of these services can be measured. - Answers Performance Standard
In accordance with the Three Lines of Defense Model, how does risk management act as the second
line of defense?
Select one:
A. Risk management provides oversight to the operational management's assessment of risk and
internal controls.
B. Risk management supports and monitors operational management's implementation of risk
management practices.
C. Risk management has authority to initiate activity demanding an external audit should a risk be
deemed imminent.
D. Risk management alerts internal audit of potential threats within a department and works with
internal audit to neutralize the threat. - Answers B. Risk management supports and monitors
operational management's implementation of risk management practices.
Many banks are using technology to search for and detect cyber-security threats locally and in the
cloud. This application of technology, in which machines learn from humans, illustrates the use of
Select one:
A. Data analytics.
B. Machine learning.
C. Risk management information systems.
D. Artificial intelligence. - Answers D. Artificial intelligence.
Which one of the following best explains how the role of the internal auditor changed with the
passage of the Sarbanes-Oxley Act of 2002?
Select one:
A. The internal auditor must adopt the attitude of an external auditor, carefully reviewing and
critiquing the finances of an organization.
B. The internal auditor must adapt to the ever changing environment of risk control through the use
of electronic reconciliation programs.
C. The internal auditor must adopt a stakeholder orientation by anticipating, monitoring and assessing
business and operational risk.
D. The internal auditor must be able to recognize current fraud risks as well computer theft of
intellectual property. - Answers C. The internal auditor must adopt a stakeholder orientation by
anticipating, monitoring and assessing business and operational risk.
Which one of the following best describes how internal audit supports enterprise risk management
(ERM)?
Select one:
A. ERM provides the assessments that internal audit uses to test the viability of controls.
B. ERM implements risk management activities and internal audit assesses the results.
C. Internal audit implements the risk assessments provided by ERM.
, D. Internal audit finds risks overlooked by ERM. - Answers B. ERM implements risk management
activities and internal audit assesses the results.
An auditor identifies risks under the risk-based approach by
Select one:
A. Looking at each objective and its controls identifying risks by asking, "What might go wrong?"
B. Reviewing prior audits, comparing results and asking, and "Has the control environment changed?"
C. Reviewing the organization, department by department to determine if the controls overlap asking,
"Is the redundancy needed?"
D. Looking at each objective, testing each control by asking, "Does this seem appropriate? - Answers
A. Looking at each objective and its controls identifying risks by asking, "What might go wrong?"
Which one of the following best describes why many purchasers require an ISO 9001 certification
prior to buying a business?
Select one:
A. To obligate the seller to perform audits for conformance prior to the sale.
B. To transfer liability should the financial statements prove erroneous.
C. To ensure that internal standards and controls are in place.
D. To have an outside audit company attest to its conclusive audit. - Answers C. To ensure that
internal standards and controls are in place.
Which one of the following best describes if it is within the scope of duties for an internal auditor to
assist the company's enterprise risk management (ERM) program?
Select one:
A. It is not within the scope. Assisting with review of key risks, identification and evaluating risks
compromises the overall functions of internal audit.
B. It is within the scope. Assisting with implementation of new controls and providing feedback on
controls will lend support to the ERM program.
C. It is within the scope. Assisting with the management of key risks, including effectiveness of
controls lend support to the ERM program.
D. It is not within the scope. Assisting the ERM program is outside of the functions of internal audit
and can compromise the objectivity of internal audit. - Answers C. It is within the scope. Assisting
with the management of key risks, including effectiveness of controls lend support to the ERM
program.
An independent auditor has been given the task of evaluating internal controls at Westside Company
(Westside). The auditor has determined that Westside's board of directors has endorsed a framework
requiring management to have documented internal reporting controls to ensure efficient operations,
accuracy of financial statements, and compliance with regulations. The framework is applied at the
entity and divisional levels, but not the operating unit or functional levels. The program is new so it
has not yet been monitored. The auditor is likely to report that
Select one:
A. The selected method aligns with the Committee of Sponsoring Organizations of the Treadway
Commission's (COSO) Internal Control—Integrated Framework because it is applied at the entity level.
Monitoring is not a requirement.
B. The selected method does not align with the Committee of Sponsoring Organizations of the
Treadway Commission's (COSO) Inte - Answers B. The selected method does not align with the
Committee of Sponsoring Organizations of the Treadway Commission's (COSO) Internal Control—
Integrated Framework because it must also be applied at the operating unit and functional levels and
it must be monitored.
Which one of the following describes the role of internal audit according to the Federation of
European Risk Management Associations (FERMA) and the European Commission of Institutes of
Internal Audit (ECIIA) model?
Select one:
A. Internal audit is the second line of defense providing support for the implementation of controls,
particularly with law and regulations.
B. Internal audit is the fourth line of defense providing oversight to the organization as a whole,
reporting to the board and senior management on compliance by the various departments with
regulations.
C. Internal audit is the third line of defense providing assurance to the board and senior management
on organizational effectiveness of risk management and assessment efforts.