WGU D561 Information Systems for Accounting and
Control
Objective Assessment Preparation
2026/2027 Edition Verified Questions with Rationales
SECTION 1: INTERNAL CONTROLS AND COSO FRAMEWORK (Questions 1-30)
Q1. In an ERP system, which of the following best describes the primary advantage of using a single
integrated database for accounting and operational data?
A. Reduced need for data validation
B. Elimination of data redundancy
C. Real-time data consistency across modules
D. Simplified user access controls
Correct ANSWER: C. Real-time data consistency across modules
Rationale:
A single integrated database ensures that data entered in one module (e.g., sales) is immediately
available in others (e.g., inventory, accounting), providing real-time consistency. While it reduces
redundancy (B), it does not eliminate it entirely, and it does not reduce the need for data validation (A)
or simplify access controls (D).
Why Other Options Are Incorrect:
A - Data validation is still required to ensure accuracy and completeness of all data entries.
,B - Redundancy is reduced but not fully eliminated; duplicate data can still exist through different
modules.
D - Access controls become more complex rather than simplified due to integrated data across multiple
modules requiring granular permissions.
Reference: Romney, M. B., & Steinbart, P. J. (2022). Accounting Information Systems, 15th Ed., Ch. 5
Q2. A company uses a continuous auditing approach that relies on embedded audit modules (EAMs) to
monitor transactions. Which of the following is a key limitation of this approach?
A. EAMs cannot detect unauthorized access to the system
B. EAMs require significant manual intervention to set parameters
C. EAMs are ineffective for detecting errors in non-financial data
D. EAMs may slow down transaction processing due to real-time monitoring
Correct ANSWER: D. EAMs may slow down transaction processing due to real-time monitoring
Rationale:
Embedded audit modules operate in real-time, which can degrade system performance and slow
transaction processing, especially in high-volume environments. EAMs can detect unauthorized access
(A) if programmed to do so. They are automated and require minimal manual intervention after setup
(B). They can be configured to monitor any data type, not just financial (C).
Why Other Options Are Incorrect:
A - EAMs can be specifically designed to detect and flag unauthorized access patterns.
B - Once configured, EAMs operate automatically with little ongoing manual effort required.
C - EAMs can monitor any type of data, including non-financial information, based on programmed rules.
Reference: Hall, J. A. (2021). Accounting Information Systems, 10th Ed., Ch. 12
,Q3. Which component of the COSO Internal Control Framework addresses an organization's
commitment to integrity and ethical values?
A. Risk assessment
B. Control environment
C. Information and communication
D. Monitoring activities
Correct ANSWER: B. Control environment
Rationale:
The control environment represents the foundation of the COSO framework and encompasses the
organization's commitment to integrity, ethical values, competence, and the overall tone at the top. Risk
assessment (A) focuses on identifying and analyzing risks. Information and communication (C) deals with
capturing and communicating relevant information. Monitoring activities (D) assess the quality of
internal control performance over time.
Why Other Options Are Incorrect:
A - Risk assessment focuses on identifying risks to achieve objectives, not ethical values.
C - Information and communication addresses how information is captured and communicated
throughout the organization.
D - Monitoring activities involve ongoing evaluations of control performance, not ethical foundations.
Reference: COSO (2013). Internal Control - Integrated Framework
Q4. When assessing control risk in an accounting information system, which factor should an auditor
most consider?
A. Complexity of the IT environment
B. Qualifications of the external audit team
C. Profitability of the organization
, D. Market share of the company
Correct ANSWER: A. Complexity of the IT environment
Rationale:
The complexity of the IT environment directly affects control risk because more complex systems
typically have more points of potential failure, greater exposure to cyber threats, and more challenging
control implementation. Qualifications of the external audit team (B) affect audit risk, not control risk.
Profitability (C) and market share (D) are not direct indicators of control risk.
Why Other Options Are Incorrect:
B - External audit team qualifications relate to audit risk, not the organization's control environment.
C - Profitability does not indicate the effectiveness or weakness of internal controls.
D - Market share is a business performance metric, not a control risk factor.
Reference: AICPA (2021). AU-C Section 315: Understanding the Entity and Its Environment
Q5. In the context of the COSO framework, which of the following is an example of a control activity?
A. Conducting regular employee training sessions
B. Performing reconciliations between subsidiary ledgers and general ledger
C. Establishing a whistleblower hotline
D. Preparing quarterly financial statements
Correct ANSWER: B. Performing reconciliations between subsidiary ledgers and general ledger
Rationale:
Reconciliations are a classic example of control activities - policies and procedures that help ensure
management directives are carried out. Employee training (A) falls under the control environment
component. A whistleblower hotline (C) is part of monitoring activities. Preparing financial statements
(D) is a routine accounting function, not specifically a control activity.
Control
Objective Assessment Preparation
2026/2027 Edition Verified Questions with Rationales
SECTION 1: INTERNAL CONTROLS AND COSO FRAMEWORK (Questions 1-30)
Q1. In an ERP system, which of the following best describes the primary advantage of using a single
integrated database for accounting and operational data?
A. Reduced need for data validation
B. Elimination of data redundancy
C. Real-time data consistency across modules
D. Simplified user access controls
Correct ANSWER: C. Real-time data consistency across modules
Rationale:
A single integrated database ensures that data entered in one module (e.g., sales) is immediately
available in others (e.g., inventory, accounting), providing real-time consistency. While it reduces
redundancy (B), it does not eliminate it entirely, and it does not reduce the need for data validation (A)
or simplify access controls (D).
Why Other Options Are Incorrect:
A - Data validation is still required to ensure accuracy and completeness of all data entries.
,B - Redundancy is reduced but not fully eliminated; duplicate data can still exist through different
modules.
D - Access controls become more complex rather than simplified due to integrated data across multiple
modules requiring granular permissions.
Reference: Romney, M. B., & Steinbart, P. J. (2022). Accounting Information Systems, 15th Ed., Ch. 5
Q2. A company uses a continuous auditing approach that relies on embedded audit modules (EAMs) to
monitor transactions. Which of the following is a key limitation of this approach?
A. EAMs cannot detect unauthorized access to the system
B. EAMs require significant manual intervention to set parameters
C. EAMs are ineffective for detecting errors in non-financial data
D. EAMs may slow down transaction processing due to real-time monitoring
Correct ANSWER: D. EAMs may slow down transaction processing due to real-time monitoring
Rationale:
Embedded audit modules operate in real-time, which can degrade system performance and slow
transaction processing, especially in high-volume environments. EAMs can detect unauthorized access
(A) if programmed to do so. They are automated and require minimal manual intervention after setup
(B). They can be configured to monitor any data type, not just financial (C).
Why Other Options Are Incorrect:
A - EAMs can be specifically designed to detect and flag unauthorized access patterns.
B - Once configured, EAMs operate automatically with little ongoing manual effort required.
C - EAMs can monitor any type of data, including non-financial information, based on programmed rules.
Reference: Hall, J. A. (2021). Accounting Information Systems, 10th Ed., Ch. 12
,Q3. Which component of the COSO Internal Control Framework addresses an organization's
commitment to integrity and ethical values?
A. Risk assessment
B. Control environment
C. Information and communication
D. Monitoring activities
Correct ANSWER: B. Control environment
Rationale:
The control environment represents the foundation of the COSO framework and encompasses the
organization's commitment to integrity, ethical values, competence, and the overall tone at the top. Risk
assessment (A) focuses on identifying and analyzing risks. Information and communication (C) deals with
capturing and communicating relevant information. Monitoring activities (D) assess the quality of
internal control performance over time.
Why Other Options Are Incorrect:
A - Risk assessment focuses on identifying risks to achieve objectives, not ethical values.
C - Information and communication addresses how information is captured and communicated
throughout the organization.
D - Monitoring activities involve ongoing evaluations of control performance, not ethical foundations.
Reference: COSO (2013). Internal Control - Integrated Framework
Q4. When assessing control risk in an accounting information system, which factor should an auditor
most consider?
A. Complexity of the IT environment
B. Qualifications of the external audit team
C. Profitability of the organization
, D. Market share of the company
Correct ANSWER: A. Complexity of the IT environment
Rationale:
The complexity of the IT environment directly affects control risk because more complex systems
typically have more points of potential failure, greater exposure to cyber threats, and more challenging
control implementation. Qualifications of the external audit team (B) affect audit risk, not control risk.
Profitability (C) and market share (D) are not direct indicators of control risk.
Why Other Options Are Incorrect:
B - External audit team qualifications relate to audit risk, not the organization's control environment.
C - Profitability does not indicate the effectiveness or weakness of internal controls.
D - Market share is a business performance metric, not a control risk factor.
Reference: AICPA (2021). AU-C Section 315: Understanding the Entity and Its Environment
Q5. In the context of the COSO framework, which of the following is an example of a control activity?
A. Conducting regular employee training sessions
B. Performing reconciliations between subsidiary ledgers and general ledger
C. Establishing a whistleblower hotline
D. Preparing quarterly financial statements
Correct ANSWER: B. Performing reconciliations between subsidiary ledgers and general ledger
Rationale:
Reconciliations are a classic example of control activities - policies and procedures that help ensure
management directives are carried out. Employee training (A) falls under the control environment
component. A whistleblower hotline (C) is part of monitoring activities. Preparing financial statements
(D) is a routine accounting function, not specifically a control activity.