WGU D560 Internal Auditing I |Objective Assessment | OA V1 and V2 | Full
Questions and Answers | 2026 Update | 100% Correct.
Questions 1–10: Internal Auditing Foundations and
Governance
Question 1
A company is establishing an internal audit function. Senior management drafts a charter
defining internal audit’s authority, responsibility, organizational position, and access to records.
Who should provide final approval of the charter?
A. Chief financial officer
B. Chief executive officer
C. Board or audit committee
D. External audit partner
Correct answer: C. Board or audit committee
Rationale: Board approval protects internal audit’s organizational independence and formally
authorizes its mandate. Senior management may provide input, but the board has final approval
authority.
Question 2
The chief audit executive (CAE) reports functionally to the audit committee and administratively
to the chief executive officer. Which responsibility should belong to the audit committee?
A. Approving the CAE’s expense reports
B. Assigning office space to internal audit
C. Approving the risk-based internal audit plan
D. Managing the department’s daily attendance
Correct answer: C. Approving the risk-based internal audit plan
Rationale: Functional reporting includes approving the charter, risk-based plan, budget,
resources, appointment, removal, and compensation of the CAE. Routine administrative matters
may be handled by executive management.
Question 3
,Management directs internal audit to exclude cybersecurity from an engagement even though the
CAE considers it a critical risk. What should the CAE do first?
A. Accept the restriction because management owns risk
B. Disclose and discuss the scope limitation with the board
C. Resign immediately
D. Ask the external auditor to perform the entire engagement
Correct answer: B. Disclose and discuss the scope limitation with the board
Rationale: Internal audit must be free from interference when determining scope and performing
and communicating its work. The CAE should disclose interference and its implications to the
board.
Question 4
Which statement best describes the primary purpose of internal auditing?
A. To eliminate every organizational risk
B. To assume responsibility for management’s controls
C. To strengthen the organization’s ability to create, protect, and sustain value
D. To guarantee the accuracy of every financial transaction
Correct answer: C. To strengthen the organization’s ability to create, protect, and sustain
value
Rationale: Internal auditing supports value through independent, risk-based assurance, advice,
insight, and foresight. It cannot eliminate all risk or guarantee absolute accuracy.
Question 5
A CAE prepares the annual audit plan by repeating the previous year’s schedule without
reviewing current risks. What is the primary weakness?
A. The plan does not contain enough financial audits
B. The plan is not based on a current risk assessment
C. The board should prepare the plan
D. Every department must be audited annually
Correct answer: B. The plan is not based on a current risk assessment
,Rationale: Audit priorities should reflect current strategies, objectives, risks, and organizational
changes. Repeating the prior plan may overlook emerging or changing risks.
Question 6
Who is primarily responsible for establishing and maintaining effective internal controls?
A. Internal auditors
B. External auditors
C. Management
D. Audit committee chair
Correct answer: C. Management
Rationale: Management owns organizational processes, risks, and controls. Internal audit
evaluates and advises on those controls but must not assume management’s responsibility.
Question 7
The audit committee asks internal audit to design and operate a new purchasing control. What is
the best response?
A. Accept because internal audit understands controls
B. Design and operate the control permanently
C. Advise on the design while leaving implementation and ownership to management
D. Refuse to discuss the control in any capacity
Correct answer: C. Advise on the design while leaving implementation and ownership to
management
Rationale: Internal audit may provide advisory services, including recommendations about
control design. It should not own or operate the control because doing so would impair
objectivity.
Question 8
Which arrangement most strongly supports internal audit independence?
A. The CAE reports only to the controller
B. The CAE has direct and unrestricted access to the board
, C. The chief operating officer approves every audit finding
D. Department managers determine audit scope
Correct answer: B. The CAE has direct and unrestricted access to the board
Rationale: Direct board access helps internal audit communicate sensitive issues and perform its
responsibilities without undue management influence.
Question 9
The board is reviewing whether internal audit has sufficient resources. Which consideration is
most relevant?
A. Whether every auditor receives identical assignments
B. Whether resources are appropriate, sufficient, and effectively deployed
C. Whether internal audit has more employees than external audit
D. Whether the budget increased from the previous year
Correct answer: B. Whether resources are appropriate, sufficient, and effectively deployed
Rationale: Resource adequacy involves the competencies, quantity, technology, and deployment
necessary to fulfill the approved audit plan and mandate.
Question 10
A company outsources its entire internal audit function. Who retains responsibility for ensuring
that the organization has an effective internal audit function?
A. External service provider alone
B. Organization and its board
C. Chief financial officer alone
D. Independent accounting regulator
Correct answer: B. Organization and its board
Rationale: Outsourcing performance does not transfer ultimate organizational responsibility for
maintaining an effective internal audit function.
Questions and Answers | 2026 Update | 100% Correct.
Questions 1–10: Internal Auditing Foundations and
Governance
Question 1
A company is establishing an internal audit function. Senior management drafts a charter
defining internal audit’s authority, responsibility, organizational position, and access to records.
Who should provide final approval of the charter?
A. Chief financial officer
B. Chief executive officer
C. Board or audit committee
D. External audit partner
Correct answer: C. Board or audit committee
Rationale: Board approval protects internal audit’s organizational independence and formally
authorizes its mandate. Senior management may provide input, but the board has final approval
authority.
Question 2
The chief audit executive (CAE) reports functionally to the audit committee and administratively
to the chief executive officer. Which responsibility should belong to the audit committee?
A. Approving the CAE’s expense reports
B. Assigning office space to internal audit
C. Approving the risk-based internal audit plan
D. Managing the department’s daily attendance
Correct answer: C. Approving the risk-based internal audit plan
Rationale: Functional reporting includes approving the charter, risk-based plan, budget,
resources, appointment, removal, and compensation of the CAE. Routine administrative matters
may be handled by executive management.
Question 3
,Management directs internal audit to exclude cybersecurity from an engagement even though the
CAE considers it a critical risk. What should the CAE do first?
A. Accept the restriction because management owns risk
B. Disclose and discuss the scope limitation with the board
C. Resign immediately
D. Ask the external auditor to perform the entire engagement
Correct answer: B. Disclose and discuss the scope limitation with the board
Rationale: Internal audit must be free from interference when determining scope and performing
and communicating its work. The CAE should disclose interference and its implications to the
board.
Question 4
Which statement best describes the primary purpose of internal auditing?
A. To eliminate every organizational risk
B. To assume responsibility for management’s controls
C. To strengthen the organization’s ability to create, protect, and sustain value
D. To guarantee the accuracy of every financial transaction
Correct answer: C. To strengthen the organization’s ability to create, protect, and sustain
value
Rationale: Internal auditing supports value through independent, risk-based assurance, advice,
insight, and foresight. It cannot eliminate all risk or guarantee absolute accuracy.
Question 5
A CAE prepares the annual audit plan by repeating the previous year’s schedule without
reviewing current risks. What is the primary weakness?
A. The plan does not contain enough financial audits
B. The plan is not based on a current risk assessment
C. The board should prepare the plan
D. Every department must be audited annually
Correct answer: B. The plan is not based on a current risk assessment
,Rationale: Audit priorities should reflect current strategies, objectives, risks, and organizational
changes. Repeating the prior plan may overlook emerging or changing risks.
Question 6
Who is primarily responsible for establishing and maintaining effective internal controls?
A. Internal auditors
B. External auditors
C. Management
D. Audit committee chair
Correct answer: C. Management
Rationale: Management owns organizational processes, risks, and controls. Internal audit
evaluates and advises on those controls but must not assume management’s responsibility.
Question 7
The audit committee asks internal audit to design and operate a new purchasing control. What is
the best response?
A. Accept because internal audit understands controls
B. Design and operate the control permanently
C. Advise on the design while leaving implementation and ownership to management
D. Refuse to discuss the control in any capacity
Correct answer: C. Advise on the design while leaving implementation and ownership to
management
Rationale: Internal audit may provide advisory services, including recommendations about
control design. It should not own or operate the control because doing so would impair
objectivity.
Question 8
Which arrangement most strongly supports internal audit independence?
A. The CAE reports only to the controller
B. The CAE has direct and unrestricted access to the board
, C. The chief operating officer approves every audit finding
D. Department managers determine audit scope
Correct answer: B. The CAE has direct and unrestricted access to the board
Rationale: Direct board access helps internal audit communicate sensitive issues and perform its
responsibilities without undue management influence.
Question 9
The board is reviewing whether internal audit has sufficient resources. Which consideration is
most relevant?
A. Whether every auditor receives identical assignments
B. Whether resources are appropriate, sufficient, and effectively deployed
C. Whether internal audit has more employees than external audit
D. Whether the budget increased from the previous year
Correct answer: B. Whether resources are appropriate, sufficient, and effectively deployed
Rationale: Resource adequacy involves the competencies, quantity, technology, and deployment
necessary to fulfill the approved audit plan and mandate.
Question 10
A company outsources its entire internal audit function. Who retains responsibility for ensuring
that the organization has an effective internal audit function?
A. External service provider alone
B. Organization and its board
C. Chief financial officer alone
D. Independent accounting regulator
Correct answer: B. Organization and its board
Rationale: Outsourcing performance does not transfer ultimate organizational responsibility for
maintaining an effective internal audit function.