CGFM EXAM 3 COMPREHENSIVE TEST
PAPER WITH SOLVED QUESTIONS
◉ Control Environment - HR Policies and Practices
Answer: * run background checks on potential new EE's
* counsel EE's with poor performance appraisals
* recognize high performers
* conduct ethics training programs that reinforce entity core
values
* take appropriate actions for policy violations
◉ IC Standard 2: Risk Assessment - 4 Principles
Answer: 4 Principles of Risk Assessment:
1) Specify objectives with reasonable clarity
2) Identifies risks to achievement of objectives
3) Consider potential for fraud
4) Identify changes that could impact system of I/C
* Evaluate risk by rating likelihood of occurrence and severity of
impact.
,Vulnerable items = cash, small-size/high dollar items, personal
data, prescription drugs
◉ Inherent Risks
Answer: * sensitive items impacting health, safety, and security
* vulnerable items that are easily converted to cash
* programs with large amounts of funding
* programs that are funded through third-party intermediaries
* social programs impacting vulnerable populations
* changing environment
* complex calculations
* diverse organizations
* programs that disperse cash or its equivalent
◉ IC Standard 3: Control Activities - 3 Principles
Answer: organizations selects those activities that:
1) contribute to the mitigation of risk
2) contribute to technology that supports objectives
3) use policies and procedures to create action and lay out
expectations
◉ Control Activities Include:
Answer: * Separation of Duties
,* Reporting
* Physical controls of vulnerable assets
* Mgmt review of performance
* Managing human capital
* Restricting access to resources and records
◉ Misuse in government environment
Answer: loss of public esteem and credibility often at greater risk
than monetary losses.
◉ General IT Controls
Answer: back-up and recovery procedures, contingency and
disaster planning, control over system acquisition and
implementation, access security, documentation and
authorization in system development and maintenance
◉ IC Standard 4: Information and Communication - 3 Principles
Answer: flow of info up, down, and across the entity
1) quality info used to support the internal control function
, 2) information is communicated internally, including objectives
and responsibilities
3) information is communicated with external parties
◉ IC Standard 5 : Monitoring - 2 Principles
Answer: 1) ongoing and separate evaluations
2) deficiencies communicated timely to those responsible for
corrective action and at least one mgmt level above them
* supervision most common monitoring acitivty
◉ Enterprise Risk Management (ERM)
Answer: Issued by COSO in Sept 2004
broader in scope with a focus on risk
addition of 4th category - strategic objectives
introduces risk appetite and risk tolerance
growing in emphasis for government financial managers
◉ Risk Appetite
PAPER WITH SOLVED QUESTIONS
◉ Control Environment - HR Policies and Practices
Answer: * run background checks on potential new EE's
* counsel EE's with poor performance appraisals
* recognize high performers
* conduct ethics training programs that reinforce entity core
values
* take appropriate actions for policy violations
◉ IC Standard 2: Risk Assessment - 4 Principles
Answer: 4 Principles of Risk Assessment:
1) Specify objectives with reasonable clarity
2) Identifies risks to achievement of objectives
3) Consider potential for fraud
4) Identify changes that could impact system of I/C
* Evaluate risk by rating likelihood of occurrence and severity of
impact.
,Vulnerable items = cash, small-size/high dollar items, personal
data, prescription drugs
◉ Inherent Risks
Answer: * sensitive items impacting health, safety, and security
* vulnerable items that are easily converted to cash
* programs with large amounts of funding
* programs that are funded through third-party intermediaries
* social programs impacting vulnerable populations
* changing environment
* complex calculations
* diverse organizations
* programs that disperse cash or its equivalent
◉ IC Standard 3: Control Activities - 3 Principles
Answer: organizations selects those activities that:
1) contribute to the mitigation of risk
2) contribute to technology that supports objectives
3) use policies and procedures to create action and lay out
expectations
◉ Control Activities Include:
Answer: * Separation of Duties
,* Reporting
* Physical controls of vulnerable assets
* Mgmt review of performance
* Managing human capital
* Restricting access to resources and records
◉ Misuse in government environment
Answer: loss of public esteem and credibility often at greater risk
than monetary losses.
◉ General IT Controls
Answer: back-up and recovery procedures, contingency and
disaster planning, control over system acquisition and
implementation, access security, documentation and
authorization in system development and maintenance
◉ IC Standard 4: Information and Communication - 3 Principles
Answer: flow of info up, down, and across the entity
1) quality info used to support the internal control function
, 2) information is communicated internally, including objectives
and responsibilities
3) information is communicated with external parties
◉ IC Standard 5 : Monitoring - 2 Principles
Answer: 1) ongoing and separate evaluations
2) deficiencies communicated timely to those responsible for
corrective action and at least one mgmt level above them
* supervision most common monitoring acitivty
◉ Enterprise Risk Management (ERM)
Answer: Issued by COSO in Sept 2004
broader in scope with a focus on risk
addition of 4th category - strategic objectives
introduces risk appetite and risk tolerance
growing in emphasis for government financial managers
◉ Risk Appetite