CIA Exam: Part 1Questions and Answers
Acceptable Risk - -Correct Answer-A type of risk that revolves around the
business impact that would be experienced if certain risks became realized.
The loss is deemed to be acceptable; no additional controls are warranted.
Acceptable Risk Level - -Correct Answer-A risk level derived from an
organizations' legal and regulatory compliance responsibilities, its threat
profile, and its business drivers and impacts.
Adequate Control - -Correct Answer-A level of control that is present if
management has planned and organized (designed) in a manner that
provides reasonable assurance that the organization's risk have been
managed effectively and that the organization's goals and objectives will be
achieved efficiently and economically.
Audit Risk - -Correct Answer-The risk that internal auditors may arrive at the
wrong conclusions and opinions of the work that they have undertaken.
Compliance - -Correct Answer-Conformity and adherence to policies, plans,
procedures, laws, regulations, contracts, or other requirements.
Control Deficiency - -Correct Answer-A condition that warrants attention as a
potential or real shortcoming that leaves an organization excessively at risk.
1
, 2
Control Environment - -Correct Answer-The attitude and actions of the board
and management regarding the significance of control within the organization.
The control environment provides the discipline and structure for the
achievement of the primary objectives of the system of internal control.
Elements of the Control Environment - -Correct Answer-1) Integrity and
ethical values
2) Management's philosophy and operating style
3) Organizational structure
4) Assignment of authority and responsibility
5) Human Resource policies and practices
6) Competence of personnel
Control Process - -Correct Answer-The policies, procedures, and activities
that are part of a control framework, designed to ensure that risks are
contained within the risk tolerances established by the risk management
process.
Control Risk - -Correct Answer-The potential that control activities will fail to
reduce controllable risk to an acceptable level.
Enterprise risk management (ERM) - -Correct Answer-A structured,
consistent, and continuous process across the whole organization for
identifying, assessing, deciding on responses to, and reporting on
opportunities and threats that affect the achievement of its objectives.
2