Study Guide, Practice Exam, Questions & Answers,
CIA Certification Exam Prep Test Bank, Internal
Auditing Standards, Risk Management, Internal
Controls, Governance, Business Processes, Financial
Reporting, Compliance, Fraud Risk, Ethics, Detailed
Rationales, Complete Review
Question 1: According to the International Professional Practices Framework
(IPPF), which of the following best describes the primary purpose of the
Mission of Internal Audit?
A. To provide consulting services that add value and improve an organization's
governance
B. To enhance and protect organizational value by providing risk-based and objective
assurance, advice, and insight
C. To ensure the accuracy of financial reporting and compliance with laws and
regulations
D. To evaluate the effectiveness of internal controls and make recommendations for
improvement
CORRECT ANSWER: B. To enhance and protect organizational value by
providing risk-based and objective assurance, advice, and insight
Rationale: The Mission of Internal Audit, as stated in the IPPF, is to enhance and protect
organizational value by providing risk-based and objective assurance, advice, and
insight. This mission is broad and encompasses the core purpose of the internal audit
activity.
Question 2: Which of the following is a mandatory element of the IPPF?
A. Practice Guides
B. Implementation Guidance
C. Core Principles for the Professional Practice of Internal Auditing
D. Supplemental Guidance
CORRECT ANSWER: C. Core Principles for the Professional Practice of Internal
Auditing
Rationale: The Core Principles, the Definition of Internal Auditing, the Code of Ethics,
and the International Standards for the Professional Practice of Internal Auditing are all
mandatory elements of the IPPF. Practice Guides, Implementation Guidance, and
Supplemental Guidance are considered strongly recommended or endorsed.
Question 3: An internal auditor is reviewing a process and discovers a
deviation from the organization's policies. The auditor determines the
deviation has a minimal financial impact but could damage the organization's
reputation if made public. According to the Standards, the auditor should:
,A. Report the finding to senior management and the board immediately.
B. Document the finding and include it in the final engagement report only if it poses a
significant risk.
C. Exclude the finding from the final report due to its immaterial financial impact.
D. Include the finding in the final engagement report because it is a control weakness
related to reputation.
CORRECT ANSWER: D. Include the finding in the final engagement report
because it is a control weakness related to reputation.
Rationale: Standard 2060 requires the chief audit executive to report periodically to
senior management and the board on the internal audit activity's purpose, authority,
responsibility, and performance relative to its plan. Standard 2420 requires
communications to be accurate, objective, clear, concise, constructive, complete, and
timely. While the financial impact is minimal, a risk to reputation is a valid concern and
should be included as it represents a control weakness that is part of the engagement's
scope.
Question 4: Which of the following statements best describes the
"independence" of the internal audit activity?
A. The internal audit activity is free from interference in determining the scope of work.
B. The internal audit activity reports functionally to the Chief Executive Officer.
C. Internal auditors are unbiased and do not subordinate their judgment on audit
matters.
D. Internal auditors have no organizational conflicts of interest.
CORRECT ANSWER: A. The internal audit activity is free from interference in
determining the scope of work.
Rationale: Independence is an organizational concept that refers to the freedom of the
internal audit activity to perform its work without interference. Objectivity is the
individual auditor's mental attitude. The correct answer describes the activity's
independence, while option C describes objectivity.
Question 5: According to the IPPF, which of the following is NOT an element of
the internal audit activity's Quality Assurance and Improvement Program
(QAIP)?
A. Internal assessments
B. External assessments
C. Ongoing monitoring
D. Continuous auditing
CORRECT ANSWER: D. Continuous auditing
Rationale: A QAIP is designed to assess the effectiveness of the internal audit activity. It
includes internal assessments (ongoing monitoring and periodic self-assessments) and
,external assessments (performed at least once every five years). Continuous auditing is
a technique and not a required element of the QAIP structure.
Question 6: An internal auditor is performing a consulting engagement. What
is the primary difference in the nature of the engagement compared to an
assurance engagement?
A. The purpose of the consulting engagement is to provide advice, and the auditor is not
expected to maintain objectivity.
B. The nature and scope of the consulting engagement are determined by the
engagement client, not the auditor.
C. The internal auditor is not required to identify and assess risks in a consulting
engagement.
D. The results of the consulting engagement are not required to be communicated to
senior management.
CORRECT ANSWER: B. The nature and scope of the consulting engagement are
determined by the engagement client, not the auditor.
Rationale: In consulting engagements, the purpose is advisory, and the nature and scope
of the work are generally determined by the engagement client. While objectivity must
be maintained, the scope is not necessarily set by the auditor as it is in assurance
engagements.
Question 7: Which of the following is a key responsibility of the Audit
Committee regarding the internal audit function?
A. Approving the internal audit budget and audit plan.
B. Performing the annual performance evaluation of the Chief Audit Executive.
C. Directly overseeing the day-to-day audit activities.
D. Ensuring the internal audit activity adheres to the International Standards.
CORRECT ANSWER: A. Approving the internal audit budget and audit plan.
Rationale: The Audit Committee typically approves the internal audit budget and the
audit plan to ensure the function is adequately resourced and has appropriate scope.
Option B is sometimes done with input from management, but A is a more universally
recognized primary responsibility. The CAE is responsible for ensuring adherence to the
Standards (D).
Question 8: When using a risk-based approach to develop the annual internal
audit plan, the primary consideration for the Chief Audit Executive (CAE)
should be:
A. The opinions of the external auditors.
B. The priorities of the board and senior management.
C. The organizational risk management framework and inherent risks.
D. The historical audit results and prior findings.
, CORRECT ANSWER: C. The organizational risk management framework and
inherent risks.
Rationale: A risk-based plan is developed by identifying, assessing, and prioritizing risks.
The audit plan must be derived from a risk assessment. While inputs from management
(B) are considered, the primary driver is the organization's risk universe.
Question 9: An internal auditor discovers a fraud scheme during an
engagement. What is the auditor's immediate primary responsibility?
A. To conduct a full investigation into the fraud.
B. To inform the appropriate authorities within the organization.
C. To suspend the employees involved in the scheme.
D. To expand the audit scope to quantify the financial loss.
CORRECT ANSWER: B. To inform the appropriate authorities within the
organization.
Rationale: Standards 1210.A2 and 1210.A3 require internal auditors to have sufficient
knowledge to evaluate the risk of fraud and how it is managed. The immediate
responsibility upon discovery is to inform the appropriate level of management and
potentially the audit committee, depending on the circumstances.
Question 10: Which of the following is considered a "key objective" of internal
audit activity?
A. To reduce the cost of the external audit.
B. To evaluate and improve the effectiveness of risk management, control, and
governance processes.
C. To prepare the organization's financial statements.
D. To implement internal controls for management.
CORRECT ANSWER: B. To evaluate and improve the effectiveness of risk
management, control, and governance processes.
Rationale: This is the essence of the Definition of Internal Auditing and the primary
objective of the internal audit activity: to provide assurance and consulting services to
evaluate and improve these processes.
Question 11: In the context of internal control, which of the following is a
"preventive" control?
A. Reconciliations of bank accounts.
B. Review of exception reports.
C. Physical access controls to a data center.
D. Managerial review of budget variances.
CORRECT ANSWER: C. Physical access controls to a data center.