IIA-CIA-Part1 Internal Audit Fundamentals Questions and Answers
Which of the following describes the internal audit activity ' s most appropriate role in an organization ' s risk management process?
During an assurance engagement the internal audit team discovers that employees performing a control do not understand the principles behind it. Before the engagement concludes, at management ' s request the audit team facilitates several formal training sessions to help explain those principles to the employees. Which of the following best describes the engagement provided by the internal audit activity in this scenario?
Which of the following represents an example of an ethical issue that the organization should address ' ?
Which of the following best describes the risk contained in an initial public offering for a new stock?
What should be the first step for a newly hired chief audit executive to build and maintain the proficiency of the internal audit activity ' ?
Which of the following types of policies best helps promote objectivity in the interna! audit activity ' s work?
The chief audit executive (CAE) planned an in-person group training to help internal auditors perform onsite inspections of an automobile manufacturing facility. The training would have allowed the auditors to better understand the production of the organization ' s automobiles. However, a global health crisis has impacted the training by prohibiting in-person contact at the facility. Which of the following could the CAE use to provide auditors with a better understanding of the organization s production process?
According to IIA guidance, which of the following statements is true regarding the internal audit activity’s responsibilities in providing consulting services?
According to IIA guidance, which of the following is a required aspect of an internal audit charter?
Which of the following statements is true regarding the independent peer review process undertaken to fulfill the requirement for an external quality assessment?
An organization’s senior management team is awarding substantial bonuses if employees meet financial targets. Which of the following motivators to potentially commit fraud would become most likely in this scenario?
Which of the following statements is true regarding how the scope of a consulting engagement should be established?
Which of the following is an example of impairment to internal auditor independence or objectivity ' ?
Which of the following demonstrates that the internal audit activity exercises due professional care?
An electric company hires several independent contractors to trim trees that are in close proximity to electricity lines. Which of the following would be the most effective control to mitigate the risk of contractors submitting fraudulent invoices regarding work completed?
Which of the following situations is most likely to heighten an internal auditor ' s professional skepticism regarding potential fraud?
At what point in time can an organization conclude that the established organizational governance framework was correctly implemented?
Which principle of the HA Code of Ethics focuses on continuing education and professional development?
An organization ' s operations management is aware of existing internal control deficiencies but they lack the competency to execute internal control measures. Which of the following actions if taken by the internal audit activity is appropriate to assist operating management in achieving continuous improvement on internal controls?
Which of the followIng would permit an internal audit activity to use the statement " conducted m conformance with the International Standards for the Professional Practice of Internal Auditing m audit reports?
Which of the following best demonstrates conformance with the Standards regarding the internal audit activity ' s purpose authority, and responsibility?
Which of the following is the best example of an ongoing independent monitoring activity?
An internal audit activity includes in its audit reports the assertion that its work is performed in conformance with the International Standards for the Professional Practice of Internal Auditing ( Standards). A recent external quality assessment concluded that the internal audit activity had substantial deficiencies that impact its overall operations.
According to IIA guidance, which of the following is the most appropriate action for issuing future audit reports?
In which of the following situations may the internal audit activity report conformance with the Standards?
Management decided to post the organization ' s newly established code of conduct on its website. This decision is primarily intended to mitigate which of the following risks?
Which of the following statements demonstrates that internal auditors are in conformance with the standard of due professional care?
During a payroll audit, a staff internal auditor suspects that signatures on some of the documents being sampled for examination are not authentic. Which of the following actions should the auditor take before proceeding with the examination?
A newly hired internal auditor is most likely to need further education in the area of business acumen in which of the following situations?
According to IIA guidance, which of the following actions best demonstrates that due professional care has been considered by the internal audit activity when conducting a review of an organization ' s assets?
A series of incidents over the past year reveals several members of senior management possess a limited understanding of the concept and impact of fraud. Which of the following would be the most effective way to approach this issue?
Which of the following best describes a proactive role for the internal audit activity with regard to the organization ' s ethics program?
During a quality assessment of the internal audit activity an auditor is assessing whether the independence of the internal audit activity is at risk of being compromised. According to IIA guidance, which of the following would provide the best source of evidence for such an assessment?
According to IIA guidance, the nature and scope of assurance and consulting services to be offered must be clearly delineated in which of the following internal audit documents?
Which of the following would be included in quality assurance and improvement program (QAIP) reporting?
Which of the following best describes a consulting engagement rather an assurance engagement?
Which of the following best describes a consulting engagement rather than an assurance engagement?
According to IIA guidance, a new internal auditor is expected to possess which of the following competencies?
The internal audit activity is asked to review the effectiveness of controls around the disposal of chemical waste. However, the internal auditors on staff lack the necessary skills to conduct this review. Which of the following would be the most appropriate approach?
Which of the following is the best reason why the engagement supervisor should take care in explaining to local management the criteria that will be used to measure the effectiveness of the control environment?
Which of the following indicates an appropriate disclosure of a potential nonconformance with the Standards?
Which of the following statements best describes the difference between risk appetite and risk tolerance?
Which of the following conditions classifies an engagement as a consulting service provided by the internal audit activity?
It is important for the chief audit executive to consider the level of competence of the internal audit staff because their competence influences which of the following?
Which of the following is an example of an impairment to an internal auditor ' s independence?
According to IIA guidance, which of the following is an appropriate role for the internal audit activity?
When an organization purchases a derivative contract in the stock market to limit the potential loss in the value of a security, the organization is applying which of the following risk management techniques?
During an audit of the purchasing department, an internal auditor identifies significant issues that could affect the organization ' s financial reporting. Management disagrees with the audit results. Which of the following responses best demonstrates the internal auditor has the necessary competencies related to professional Judgment and conflict management?
Which of the following best illustrates the principle of due professional care?
An internal auditor extended the scope of testing for a disbursements engagement following a fraud risk assessment Despite the investment of additional audit resources no significant issues were found Unfortunately a major payment fraud was discovered several
months later According to IIA guidance which of the following statements is true regarding the internal auditor ' s application of due professional care?
Which of the following is a typical characteristic of an organization ' s risk management framework?
Which of the following describes a responsibility of operating management in an organization ' s corporate social responsibility (CSR) efforts?
Which of the following scenarios demonstrates an impairment to internal audit independence?
Which of the following options describes the reason that conformance with The IIA ' s Code of Ethics is mandatory for internal auditors?
Which of the following most accurately describes corporate social responsibility at an organization?
Which of the following best describes the approach the internal audit activity should take to assess and make appropriate recommendations to improve the organization?
A new chief audit executive wants to develop a formal internal control framework for her organization. She uses globally accepted frameworks as a guide. Which of the following would she likely find critical in creating the new framework for her organization?
An internal auditor is reviewing employee travel expenses from the previous six months for fraud. Which of the following tests would best detect instances where personal travel has been claimed?
Which of the following tests would most likely help discover a fictitious invoice?
According to IIA guidance, which of the following is the strongest indicator of deficiencies in the risk management process?
An internal auditor assigned to a supplier management process engagement reviews the risk assessment with the process owner The auditor inquires about the risk response for potentially engaging unqualified third-party service providers The process owner responds that due diligence checks are undertaken to make sure that third parties possess requisite competencies before they are engaged Which of the following risk management techniques is the process owner using?
What is an appropriate first step in an internal auditor’s fraud risk assessment to evaluate how the organization manages such risk?
An auditor for a large wholesaler is evaluating the controls over the approval and oversight of credit sales. Which of the following procedures would be a control weakness?
In which of the following ways can a chief audit executive demonstrate to the board that the internal audit activity collectively possesses all of the skills needed to complete its annual goals?
An internal auditor discovered that a former colleague from the internal audit activity now works in a junior position in a department scheduled for an upcoming audit. How can the auditor best ensure his objectivity for this engagement?
To encourage internal audit objectivity, which of the following is an appropriate policy the chief audit executive should establish?
According to IIA guidance, which of the following statements is true of assurance services provided by the internal audit activity?
The internal audit activity conducted an organization wide risk assessment. One of the most significant risks identified is associated with the oil price market. The chief audit executive (CAE) is considering including in the annual audit plan an assessment of the effectiveness of oil price risk management. The manager responsible commented that the assessment was not needed, as market risks were regularly addressed by the financial risk committee. If the CAE decides to include this activity in the annual audit plan anyway, how should it be recorded?
Which of the following best describes the board’s role in establishing effective organizational governance?
The internal audit activity is undergoing a self-assessment as part of its quality assurance and improvement program Which of the following observations must be addressed in order for the internal audit activity to achieve conformance with the Standards?
A manufacturer of power tools is experiencing regular fluctuations in the price of electrical power which is having a serious impact on the bottom line. Which of the following would be the most effective risk strategy to reduce the impact of these fluctuations?
Which of the following would be considered a monitoring activity in organization wide risk management?
Which of the following statements is true regarding an organization ' s code of ethics?
An internal auditor was offered expensive tickets to a sporting event by the manager of an area that she was currently auditing. The auditor politely declined. Which of the following fundamental principles of the MA Code of Ethics did she display?
Which of the following statements is correct regarding disclosure of conformance or Standards?
Which of the following is an indicator that an organization ' s risk management processes are effective?
What should the chief audit executive do when the internal audit activity is found to be in nonconformance with the Code of Ethics or the Standards?
According to IIA guidance, which of the following best demonstrates how the chief audit executive may ensure that due professional care is applied?
Which of the following would show appropriate disclosure of nonconformance with the Standards?
Which of the following activities would breach the principles of The IIA ' s Code of Ethics?
Which of the following situations undermines the independence of the internal audit activity?
The organization s procurement manager asks the internal auditor to deliver training to the procurement team on the organization’s third-party risk management process. Which of the following is the most appropriate response?
Which of the following best demonstrates that an internal auditor is applying due professional care when planning an assurance engagement?
An engagement supervisor noted that an internal auditor ' s personal relationship with a process owner resulted in the auditor providing a favorable and partial assessment during an audit within that process owner ' s area. According to MA guidance, which of the following should be used to manage this impairment?
Which of the following is a key determinant used by external auditors to decide whether they can rely on work performed by the internal audit activity?
The chief audit executive (CAE) is drafting the annual internal audit plan and seeks input from senior management and the external auditor prior to submitting it for approval to the board. According to MA guidance, which of the following statements is true regarding this scenario?
An internal audit of warehouse inventory revealed no material deficiencies. However, management later discovered fraud, which occurred during the period that was audited, and determined that a major control deficiency allowed the fraud to occur. Given management ' s discovery, which of the following statements is valid?
Which of the following types of fraud tests would be most effective if an internal auditor was looking for possible fictitious vendors?
According to MA guidance, which of the following is the most accurate statement regarding the internal audit charter?
An internal audit activity is using the auditing-by-element approach to audit the organization ' s controls around corporate social responsibility. Which of the following would be an element for the internal audit activity to consider?
An automobile manufacturer will become one of the first in the industry to adopt a new inventory management software. Despite the system being new to the market, senior management believes that the benefits are great enough to offset the potential risks. Which of the following aspects of risk management does senior management’s decision best illustrate?
According to IIA guidance, which of the following is most critical to ensuring that an organization ' s risk management program remains effective over time?
Which of the following would most likely be classified as a consulting engagement?
Which of the following describes two duties that should not be performed by the same person?
According to the Standards, which of the following demonstrates the proficiency of an internal auditor?
An internal audit team was assigned to review the organization’s information security protocol After fieldwork was completed an internal auditor identified an error in the review of security access The error could affect the overall results of the engagement Which of the following is the most appropriate course of action for the internal auditor?
Which of the following is a primary responsibility of senior management with respect to ethical violations?
To comply with the proficiency standard which of the following would the chief audit executive likely consider as the primary hiring criterion when choosing a new internal auditor?
Which of the following is the best way for an internal auditor to demonstrate due professional care?
For a high-risk observation, which is the best approach to follow when management takes an aggressive, uncompromising position in opposition to the internal audit activity?
While preparing the audit plan for an automobile manufacturing company, the chief audit executive (CAE) noted that the company ' s engineering department received a high risk ranking. However, the internal audit activity is understaffed, and current staff do not possess the necessary skills to adequately assess the effectiveness of the engineering department. What is the most appropriate course of action for the CAE to take?
Which of the following statements is true regarding reporting results of the quality assurance and improvement program to senior management and the board?
Which of the following is a responsibility of the internal audit activity as it relates to risk and risk management?
According to NA guidance, which of the following practices by the chief audit executive (CAE) best enhances the organizational independence of the internal audit activity?
Which of the following would provide the best support for internal auditors to meet their continuing professional development requirements?
Which of the following actions would best help the internal audit activity promote continuous improvement in control effectiveness within the organization?
According to the Standards, which of the following is a requirement for internal audit professional development plans?
A chief audit executive assigned an internal auditor to perform an assurance engagement. The auditor concluded with a major audit finding based on hearsay evidence Which of the following competencies did the auditor appear to be lacking?
Which of the following statements is the most appropriate for a chief audit executive to include in the internal audit policy manual in order to promote objectivity?
Which of the following circumstances would most likely be considered a potential red flag for fraud by the internal audit activity?
The management at a national consumer goods organization implements a fair work and pay practice as well as a policy to treat employees equitably and consistently.
Which common characteristics of fraud will the practice and policy most likely reduce?
Which of the following written documents typically offers the best evidence that internal auditors exercise due professional care in conformance with the Standards?
Which of the following is an indicator that the organization s risk management process is effective?
Which of the following actions is the internal audit activity best positioned within the organization to perform?
The chief audit executive (CAE) has assigned an internal auditor to an upcoming engagement. Which of the following requirements would most likely indicate that the internal auditor was assigned to an assurance engagement?
Which of the following statements best demonstrates application of due professional care during an assurance engagement?
Which of the following best describes why a chief audit executive might obtain the services of a fraud specialist to assist in a major fraud investigation?
A subsidiary of the organization was preparing for an initial public offering (IPO). Af the request of the audit committee, the chief audit executive (CAE) and all senior audit staff were actively involved in the process by helping collect and validate financial data, conducting assessments, and participating in meetings with IPO advisors. Six months later, it became obvious that the IPO had to be canceled. Newly appointed audit committee members requested an assurance engagement that v/ould assess the IPO preparation process. Which of the following would be the best course of action for the chief audit executive (CAE) to take?
After being assigned to an audit of the accounts payable process, an internal auditor privately notifies the chief audit executive that she is a finalist for an open manager position within the accounts payable department. Which of the following is the IIA Code of Ethics principle that the auditor upheld?
According to IIA guidance, which of the following conditions would enhance the independence of the internal audit activity?
Which action by senior management indicates to the internal auditor that there may be fraudulent activities occurring within the organization?
Which of the following would be the best choice for a continuing professional development requirement for a newly created internal audit activity?
Which of the following scenarios best illustrates a rationalization as the root cause of potential fraud?
According to IIA guidance, which of the following is required of an internal audit activity?
Which of the following situations presents the lowest risk of impairing an internal audit activity ' s independence?
Which of the following scenarios best demonstrates the application of internal audit proficiency?
Which of the following statements would typically be included in the responsibility section of the internal audit charter?
A chief audit executive (CAE) has just joined an organization with an existing internal audit activity. Based on her review of the current organizational structure, the CAE determines that the internal audit activity lacks adequate independence. Which of the following actions is the CAE ' s best step to take next to move the internal audit activity toward organizational independence?
Which of the following would be considered a violation of The HAfs mandatory guidance on independence?
Which of the following best describes the type of risk that an adequately designed and effectively operating system of internal controls should mitigate?
Which of the following best describes the internal audit activity ' s contribution to the implementation of the risk management framework?
In addition to her internal audit activity responsibilities, the chief audit executive has been asked to oversee the organization ' s insurance function. Which of the following responses is most appropriate?
Who has the ultimate responsibility of implementing the organization’s governance system?
An external assessment was performed as part of the organization ' s quality assurance and improvement program. Which of the following conclusions confirms that the internal audit activity is in conformance with the Standards ' ?
During an audit engagement of a large retail store, internal auditors noted significant discrepancies between available inventory and sales and suspect an abuse of cash register refunds and voids. Which of the following would be the most effective preventative control to reduce these losses?
Which of the following is a way to demonstrate an individual internal auditor ' s competency through continuing professional development?
Which of the following is considered to be a threat to the internal auditor ' s objectivity?
According to NA guidance, which of the following is true regarding typical fraud schemes?
1. A diversion occurs when an employee has an undisclosed personal economic interest in a transaction that adversely affects
the organization.
2. Tax evasion is intentional reporting of false or misleading information on a tax return by an organization to reduce taxes owed.
3. Skimming involves stealing cash or assets from the organization and is normally concealed by adjusting the organization’s
records.
4, Disbursement fraud occurs when a person causes the organization to issue a payment for fictitious goods or services.
Which of the following describes the most appropriate match between a potential temporary guest auditor candidate and an upcoming audit assignment?
An internal auditor has completed an assurance engagement Which of the following is most likely true regarding the engagement?
In a small company with a small budget, the board and senior management asked the chief audit executive (CAE) to develop specific controls prompted by a new regulatory requirement affecting a specific process. The CAE was also directed to report functionally to senior management. An audit engagement on this process was already set in the internal audit plan. Which of the following represents an impairment to the internal audit activity ' s independence?
Which of the following activities best demonstrates an internal auditor’s commitment to developing professional competencies?
Which of the following would best serve to deter unethical behavior and encourage internal auditors to be objective in their work?
According to IIA guidance, which of the following statements is true regarding mentoring programs designed to assist internal auditors with their professional development?
Guidelines need to be set for various levels of suspected fraud within an organization and when it would be reported to the audit committee. Which of the following would be
reported at the next meeting?
The accounting department asked the chief audit executive (CAE) to perform a review of suspicious transactions The CAE was an accounting manager for the organization six months ago How should she respond to the request?
Which of the following factors are commonly assessed to determine the magnitude of risk events?
An internal auditor believes that the internal audit activity ' s independence is impaired. Which of the following actions should the internal auditor take first?
According to IIA guidance, which of the following activities would typically be examined when using the maturity model approach for assessing an organization ' s risk management program?
According to IIA guidance, which of the following actions by the chief audit executive (CAE) best demonstrates the organizational independence of the internal audit activity?
Which of the following would best describe a control implemented to detect cash register disbursement fraud in a large retail store?
Management is installing security cameras to identify unauthorized physical access to the organization ' s warehouse. This is an example of which of the following types of controls?
Operational management in the IT department has developed key performance indicator reports, which are reviewed in detail during monthly staff meetings. This activity is designed to prevent which of the following conditions?
Which of the following actions should the internal audit activity take during an audit engagement when examining the effectiveness of risk management processes?
Which of the following statements is true regarding consulting and assurance engagements performed by the internal audit activity ' ?
Which of the following resources would be most effective for an organization that would like to improve how it informs stakeholders of its social responsibility performance?
With regard to organizational governance assurance, which of the following is an appropriate role for the internal audit activity ' ?
An internal auditor in a busy internal audit activity reviews her continuing professional development records toward the end of the year and is concerned to find she has undertaken limited training and formal professional development. Which of the following actions is the most appropriate for her to take?
Which of the following would be an important aspect of an internal auditor ' s role in fraud management?
Which of the following describes a primary responsibility for the internal audit activity in helping management maintain effective controls?
According to MA guidance, which of the following gives the internal audit activity the authority to request supporting documentation for the invoices of a third-party service provider?
IT management requires all employees in the IT department to attend annual training on the department ' s mission, values, and key performance measures. This activity is designed to prevent which of the following conditions?
In which of the following scenarios is the internal auditor in conformance with The IIA ' s Code of Ethics and the Standards?
Which of the following is a legitimate requirement for an internal audit activity’s quality assurance and improvement program (QAIP)?
According to IIA guidance, which of the following is an appropriate role for the internal audit activity?
Which of the following is an advantage of using nongovernmental organization (NGO) members on an assurance team when auditing corporate social responsibility?
The organization ' s chief audit executive (CAE) is planning an immediate assurance engagement following several product recalls. However, the internal audit staff does not have the required Knowledge and experience to adequately assess all the relevant processes and procedures. According to 11A guidance, which of the following actions should the CAE take under these circumstances?
Which of the following approaches will internal audit utilize when developing a set of performance standards to measure an organization’s risk management process against?
Which of the following scenarios provides the most concerning red flag or indicator of possible fraud?
To comply with the proficiency standard, which of the following would the chief audit executive likely consider as the primary hiring criterion when choosing a new internal auditor?
Which of the following must be considered by the chief audit executive before writing the internal audit charter?
Which of the following requests, if accepted by the internal audit activity, would impair its independence?
Which of the following would be considered a primary control to reduce the risk associated with setting up duplicate vendors?
Which of the following should catch the internal auditor ' s attention as a potential red flag for fraud?
An internal audit team analyzed the organization ' s value-at-risk model during an assurance engagement and suggested several useful improvements. Management was impressed by the internal audit team’s work and requested additional actions. Which of the following requested actions would impact internal audit independence most severely if fulfilled?
A technology company recently hired an entry-level internal auditor. To achieve conformance with the Standards, which of the following must the newly hired internal auditor possess?
An existing Internal audit charter is currently under review for revision. Who is responsible for assuring that all required components are included?
During fieldwork, an internal auditor located a significant internal control issue. Without identifying the origins of the issue, the auditor concluded the engagement and included the issue in the final audit report. To enhance audit quality, which of the following skills should the internal auditor improve?
An internal auditor performed a risk assessment and concluded that the controls over access privileges to a bank account were appropriate. Later, the auditor learned that a contractor was using a shared password provided by an authorized user of the account. Which of the following statements best describes the auditor ' s application of due professional care?
According to IIA guidance, which of the following is true of the internal audit activity’s quality assurance and improvement program?
1 Monitoring the internal audit activity’s performance must be ongoing
2 All aspects of the internal audit activity should be evaluated
3 The requirement for external assessments can be satisfied through self-assessments that are validated by an independent external party
4 The review of assurance services should be the primary focus
A chief audit executive ensures that the internal audit activity provides annual training to management on internal controls. Where is the nature of these services defined?
A chief audit executive has reported to the board that the internal audit activity is lacking financial accounting knowledge for specific audit projects. Upon approval from the board which of the following hiring approaches is best in this situation?
An organization’s board of directors has decided that the internal audit activity must have greater access to different pans of the organization in order to perform their assurance work effectively Which of !he following areas is the board seeking to improve by making this change?
Which of the following best describes the Standards requirement for collective proficiency of the internal audit activity?
Which of the following survey questions would be most effective to identify ethics violations within the organization?
Considering the concepts of organization wide risk management and the system of internal controls, the internal audit activity as a whole can be considered which of the following types of control?
Which of the following is the best example of a risk appetite statement concerning an investment portfolio?
An organization ' s board has approved an expansion plan into a new market. The board acknowledged that if the expansion is not successful, the organization would encounter large monetary losses consisting of legal fees, research and development costs, rent expenses, and labor fees. Which of the following has the board approved?
Which of the following principles of The IIA ' s Code of Ethics implies that internal auditors should refrain from performing assurance services when there is an impairment to audit independence that has not been declared?
Which of the following is a primary benefit of implementing a governance, risk management, and compliance framework within an organization?
A chief audit executive added more money to the IT training budget to ensure the organization ' s internal auditors were able to perform data analytics while performing an audit. Which core competency is being addressed?
Which of the following fundamental principles of The IIA ' s Code of Ethics is best described as performing work honestly diligently and responsibly?
According to MA guidance, which of the following best describes how often the chief audit executive should review the quality assurance and improvement program of the internal audit activity?
The chief audit executive (CAE) annually develops a budget and resource plan and submits it to the board for approval. This action best fulfills which of the following responsibilities of the CAE?
An organization allows the same individual to physically access inventory and purchase new assets when supplies are depleted. Which of the following would best help the organization manage the risk of fraud?
An organization is implementing a new cybersecurity policy and has established a committee to ensure stakeholder alignment across the organization ' s infrastructure, network, and security teams. The head of the committee has asked the chief audit executive if the internal audit activity could play a role in these efforts. According to HA guidance, which of the following is the most appropriate response?
An organization is testing a new IT system for digital data storage and security. The internal audit activity has been asked to evaluate the system in a consulting engagement. Although several internal auditors on staff are qualified to perform basic assessments of IT systems, none are familiar with the new system. Which of the following is a legitimate response to the prospective client?
1. Decline the engagement.
2. Proceed with the engagement, performing only those parts of the engagement that the internal auditors are qualified to perform.
3. Accept the engagement and develop the additional competencies in-house prior to the engagement ' s starting date.
4. Make arrangements to obtain assistance from a competent IT auditing expert.
Which of the following risk management techniques best describes the strategy of obtaining insurance to protect against losses due to bad weather conditions?
An engagement supervisor notes that an internal auditor usually documents and submits draft audit reports for review without giving the process owners the opportunity to state their position on the issues raised. How should the engagement supervisor respond?
A chief audit executive (CAE) is concerned that the internal audit activity is not receiving adequate training and continuing education. Which of the following approaches should the CAE take?
An organization allows the same individuals to physical access inventory and purchase new assets when supplies are depleted. Which of the following would best help the organization manage the risk of fraud?
At the beginning of an IT development project key risks were identified and assessed and risk owners were appointed Six months later the IT development team reported that the project Is significantly over budget, it will not be completed on time and key personnel had left the organization. Which of the following risk management practices should be improved for future projects?
An internal auditor assessed that the risk of steel theft at a plant is high. In response, the plant ' s management introduced a number of controls, including fences around the facility, a metal detector at the entrance, and monthly steel inventory counts. If the controls operate as intended, which of the following outcomes would the internal auditor hope to see?
Which of the following best demonstrates organizational independence of the internal audit activity?
The internal audit activity was denied access to expenditure and budget reports because they were considered to be confidential. This situation would result in which of the following limitations of the internal audit activity?
Which of the following is the best example of a computer forensic audit activity?
During the planning stage of an assurance engagement, a payroll clerk informed the internal auditor that he is often asked to add new employees to the payroll without any formal new-hire documentation from human resources. The auditor is concerned that this increases the risk for fraud. To complete engagement planning, which of the following is the most appropriate next step for the auditor to take?
The chief audit executive (CAE) of a new internal audit activity is creating an internal audit charter According to IIA guidance, which of the following terms is most likely to
be included in the charter?