Topic 2, Exam Pool B
Management would like to self-assess the overall effectiveness of the controls in place for its 200-person manufacturing department. Which of the following client-facilitated approaches is likely to be the most efficient way to accomplish this objective?
A. Workshops.
B. Surveys.
C. Interviews.
D. Observation.
Explanation:
For a self-assessment of overall control effectiveness in a 200-person manufacturing department, the most efficient client-facilitated approach is a workshop. Workshops bring together a cross-functional group of managers and key staff (e.g., production supervisors, quality control, maintenance, and shift leads) in a facilitated session to collectively evaluate controls against established objectives and risks.
Why Other Options Are Incorrect
B (Surveys):
While quick to distribute, surveys lack interactive dialogue. They often yield superficial or ambiguous responses, miss contextual nuances, and cannot resolve conflicting views without follow-up. For a 200-person unit, analyzing and reconciling survey data would be time-consuming and less reliable for assessing overall effectiveness.
C (Interviews):One-on-one interviews with 200 people or even key managers are highly resource-intensive, time-consuming, and inconsistent. They do not facilitate cross-validation or group consensus, making them inefficient for a broad self-assessment.
D (Observation):
Observation is useful for testing specific control activities but is inefficient for assessing overall control effectiveness across an entire department. It is narrowly focused on what is seen at a point in time and misses management's perspective on design, risk coverage, and systemic issues.
References
IIA Standard 2120 – Risk Management: Internal audit must evaluate risk management processes, and self-assessments (facilitated workshops) are recognized as effective tools for management to evaluate controls.
According to IIA guidance, which of the following scenarios demonstrates an internal auditor exercising due professional care? When auditing investments, the auditor identified instruments with which he was unfamiliar. He decided not to select that type of investment in his sample, as he did not have the knowledge needed to A. perform a proper assessment.
A. An auditor was reviewing inventory counts conducted by the warehouse staff. One truck containing an immaterial amount of inventory was off-site and wasn't verified by the auditor.
B. An auditor visited a plant that produces a significant portion of the organization's inventory. The day he arrived, the plant manager was out sick, so the auditor issued the report without interviewing the manager.
C. An auditor in charge needed to have testing completed by the end of the month, but was behind schedule. He identified a junior auditor to conduct the work for him on a complex area of the organization.
Explanation:
Due professional care under IIA guidance (Standard 1220) requires internal auditors to apply the care and skill expected of a reasonably prudent and competent auditor in similar circumstances. It does not require perfection or absolute certainty. It involves using sound judgment, considering materiality, and balancing cost, time, and risk.
Why Other Options Are Incorrect
B (Auditor issued report without interviewing the plant manager):
This is a failure of due professional care. The plant produces a significant portion of inventory, making it a high-risk area. The auditor should have rescheduled, interviewed the manager via phone/video, or interviewed the assistant manager/supervisors. Issuing a report without obtaining critical management input is negligent and fails the "reasonably prudent" standard.
C (Auditor in charge delegated complex work to a junior auditor):
While delegation is permitted, due professional care requires that staff assigned to an engagement possess the necessary knowledge, skills, and competencies (Standard 1210). Assigning a complex area to a junior auditor without proper supervision, training, or validation demonstrates a failure to exercise due care. The in-charge should have either performed the work himself, assigned a more experienced auditor, or provided close oversight.
D (Auditor avoided unfamiliar investment instruments):
This is a clear violation of due professional care. When an auditor encounters unfamiliar financial instruments, due professional care requires them to obtain additional knowledge, consult with experts, or seek supervisory guidance—not simply exclude them from the sample. Omitting known high-risk or complex instruments from audit scope without justification is professional negligence.
References
IIA Standard 1220 – Due Professional Care: "Internal auditors must apply the care and skill expected of a reasonably prudent and competent internal auditor. Due professional care does not require infallibility."
Which of the following controls could an internal auditor reasonably conclude is effective by observing the physical controls of a large server room?
A. Adequate signs are in place to assist in locating safety equipment.
B. Servers are secured individually to their racks by locks.
C. Foam fire extinguishers are operable to protect against electrical fires.
D. Swipe card access is required to gain access to the server room.
Explanation:
Observation is a powerful audit technique for evaluating physical controls, which are designed to safeguard assets and restrict access. When an auditor observes a physical control in action, they can directly verify its existence and operating effectiveness at that moment .
Among the options, swipe card access is the only control whose functionality can be conclusively verified through simple observation. By watching individuals enter the server room, the auditor can confirm that a card reader is installed, that it is operational, and that access is being denied to unauthorized persons. This provides direct, visual evidence that the access restriction control is functioning as intended .
Why Other Options Are Incorrect
A. Adequate signs are in place to assist in locating safety equipment:
Observing signs only confirms they are posted, not that they are "adequate" to help locate equipment in an emergency. Adequacy is a matter of design and effectiveness, which requires reviewing safety protocols or conducting drills—not just visual inspection.
B. Servers are secured individually to their racks by locks:
An auditor can see a lock is present, but cannot determine if it is actually secured or simply closed. The only way to verify this control is to physically test the lock, which goes beyond passive observation.
C. Foam fire extinguishers are operable to protect against electrical fires:
Observation can confirm an extinguisher is present, but it cannot verify it is "operable" or fully charged. Operability must be confirmed by reviewing inspection tags, service records, or performing maintenance tests .
References
IIA Standard 1220 – Due Professional Care: Auditors must consider the complexity, materiality, and risk associated with the area being audited. Direct observation is a valid procedure for obtaining evidence on the existence and operation of physical controls.
Which of the following responsibilities would fall under the role of the chief audit executive, rather than internal audit staff or the audit manager?
A. Manage and support a quality assurance and improvement program.
B. Maintain industry-specific knowledge appropriate to the audit engagements
C. Set clear performance standards for internal auditors and the internal audit activity.
D. Apply problem-solving techniques for routine situations.
Explanation:
The Chief Audit Executive (CAE) holds the highest-level strategic and oversight responsibilities within the internal audit activity. Under IIA Standard 1300 – Quality Assurance and Improvement Program, the CAE is directly and personally responsible for developing, maintaining, and supporting a quality assurance and improvement program (QAIP) that covers all aspects of the internal audit activity. This includes overseeing both internal and external assessments, ensuring conformance with the Standards, and reporting results to senior management and the board. This is a non-delegable, executive-level responsibility that distinguishes the CAE's role from that of staff or audit managers.
Why Other Options Are Incorrect
B (Maintain industry-specific knowledge):
This is a responsibility of all internal auditors (Standard 1210 – Proficiency). While the CAE must ensure the team collectively possesses this knowledge, the maintenance of individual technical expertise falls on each auditor, not exclusively on the CAE.
C (Set clear performance standards):
While the CAE ultimately oversees performance, the day-to-day setting of clear performance standards for individual auditors and engagements is typically the responsibility of the audit manager or supervisor, who directly assigns work, provides feedback, and conducts performance evaluations.
D (Apply problem-solving techniques for routine situations):
This is a basic operational skill expected of internal audit staff. Routine problem-solving is part of executing daily audit tasks, not a strategic function reserved for the CAE.
References:
IIA Standard 1300 – Quality Assurance and Improvement Program: "The chief audit executive must develop and maintain a quality assurance and improvement program that covers all aspects of the internal audit activity."
IIA Standard 1310 – Requirements of the Quality Assurance and Improvement Program: Requires the CAE to establish a program that includes both internal and external assessments.
Which of the following is a detective control strategy against fraud?
A. Requiring employees to attend ethics training.
B. Performing background checks on employees.
C. Implementing a control self-assessment.
D. Performing a surprise audit.
Explanation:
Control strategies are generally categorized as preventive (deterring errors/fraud before they occur) or detective (identifying errors/fraud after they have occurred). A surprise audit is a classic detective control because it is conducted unexpectedly, with the primary purpose of uncovering irregularities, fraud, or control breakdowns that may already exist. The element of surprise increases the likelihood of catching fraudulent activities that perpetrators might otherwise conceal during scheduled audits.
Why Other Options Are Incorrect
A (Requiring employees to attend ethics training):
This is a preventive control. It aims to deter fraud by educating employees on acceptable behavior, organizational values, and the consequences of misconduct, thereby reducing the likelihood of fraudulent actions occurring in the first place.
B (Performing background checks on employees):
This is a preventive control. By vetting candidates before hiring, the organization screens out individuals with a history of dishonesty or criminal behavior, preventing potential fraudsters from entering the organization.
C (Implementing a control self-assessment):
This is primarily a monitoring / preventive control. While it can help identify control weaknesses, its main purpose is to involve process owners in evaluating and improving their own controls proactively. It is not specifically designed to detect ongoing fraud, and it lacks the element of surprise or independent verification that a surprise audit provides.
References
IIA Standard 2120 – Risk Management: Internal audit must evaluate the effectiveness and contribute to the improvement of risk management processes, including fraud risk management. Detective controls are a key component of a robust fraud risk framework.
A former line supervisor from the Financial Services Department has completed six months of a two-year development opportunity with the internal audit activity (IAA). She is assigned to a team that will audit the organization's payroll function, which is managed by the Human Resources Department. Which of the following statements is most relevant regarding her independence and objectivity with respect to the payroll audit?
A. She may participate, but only after she has completed one year with the IAA.
B. She may participate, because she did not previously work in the Human Resources Department.
C. She may participate, but she must be supervised by the auditor in charge.
D. She may participate for training purposes, to build her knowledge of the IAA.
Explanation:
The core issue here is individual objectivity, a fundamental principle requiring internal auditors to perform their work with an unbiased mental attitude and avoid conflicts of interest. Objectivity is considered impaired if an auditor is assigned to provide assurance on an activity for which they had direct responsibility or management oversight within the previous year .
Why Other Options Are Incorrect
A (May participate only after one year with the IAA):
Incorrect. IIA guidance presumes objectivity is impaired if an auditor audits a specific operation they were previously responsible for within the last year . This restriction is tied to the specific operation, not the auditor's length of service in the internal audit activity. The one-year cooling-off period applies to auditing her former department (Financial Services), not the unrelated HR/payroll function.
C (Must be supervised by the auditor in charge):
Incorrect. While all auditors require supervision, this is not a specific safeguard triggered by an objectivity impairment because, as established, no actual or perceived impairment exists. Additional supervision is not mandated simply due to her being in a development role .
D (May participate for training purposes only):
Incorrect. While training is a benefit, her participation is not limited solely to that purpose. Since she has no conflict with the payroll audit, she can fully participate as a team member and exercise her professional judgment without restriction .
References
IIA Standard 1130.A1:
"Internal auditors must refrain from assessing specific operations for which they were previously responsible. Objectivity is presumed to be impaired if an internal auditor provides assurance services for an activity for which the internal auditor had responsibility within the previous year."
An organization has implemented a software system that requires a supervisor to approve transactions that would cause treasury dealers to exceed their authorized limit. This is an example of which of the following types of controls?
A. Preventive controls.
B. Detective controls.
C. Soft controls.
D. Directive controls.
Explanation:
A preventive control is designed to deter, stop, or prevent an error, misstatement, or undesirable event from occurring in the first place. It operates proactively—before the transaction is completed—to block non-compliant or unauthorized actions.
In this scenario, the software system requires a supervisor to approve any transaction that would cause a treasury dealer to exceed their authorized trading limit. Because the system physically prevents the dealer from executing the excess transaction without prior supervisory approval, it stops the violation before it happens. This is a classic example of a preventive control—specifically, an application-level authorization control embedded in the software.
Why Other Options Are Incorrect
B. Detective controls:
Detective controls identify errors or irregularities after they have occurred (e.g., reconciliations, exception reports, surprise audits). This system does not merely flag the excess after execution; it blocks it upfront, making it preventive, not detective.
C. Soft controls:
Soft controls refer to intangible elements like organizational culture, ethics, values, and management style. They are not embedded in software nor do they involve formal approval workflows. This is a hard, system-based control.
D. Directive controls:
Directive controls are designed to encourage or cause a desirable action to occur (e.g., policies, procedures, training, job descriptions). They guide behavior but do not physically prevent or block non-compliance. Requiring approval is a preventative barrier, not merely a directive.
References
IIA Standard 2120 – Risk Management: Internal audit must evaluate the effectiveness of risk management processes, which include the design and operating effectiveness of control activities (preventive, detective, directive, and corrective).
COSO Internal Control – Integrated Framework: Defines preventive controls as those that "deter problems before they arise" and cites authorization and approval limits as key preventive control activities.
During an audit, the client questions the internal audit activity's authority to perform procedures over fraud allegations. According to HA guidance, which of the following would provide the most relevant support to respond to the client's concerns?
A. Definition of Internal Auditing.
B. MA Standards.
C. Internal audit charter.
D. The IIA's Code of Ethics.
Explanation:
When a client questions the internal audit activity's (IAA) authority, the most relevant and authoritative document to reference is the internal audit charter. The charter is a formal, board-approved document that explicitly defines the IAA's purpose, authority, and responsibility within the organization. Under IIA guidance, the charter must establish the internal audit activity's position, grant it access to all necessary records and personnel, and define the scope of its work, which includes the authority to perform procedures over fraud allegations.
Why Other Options Are Incorrect:
A. Definition of Internal Auditing:
While the definition outlines the general purpose of internal auditing (e.g., evaluating risk management, control, and governance processes), it is a broad statement of philosophy, not a binding document that grants specific authority or investigative powers to the IAA.
B. IIA Standards:
The IIA Standards provide the mandatory requirements for the professional practice of internal auditing and outline responsibilities (e.g., evaluating fraud risk). However, they do not, by themselves, confer authority; the specific authority to act comes from the charter.
D. The IIA's Code of Ethics:
The Code of Ethics sets forth the principles and rules of conduct for internal auditors (e.g., integrity, objectivity). It guides behavior but does not define or grant the scope of authority to perform specific audit procedures.
References
IIA Global Internal Audit Standards (2024), Standard 6.2 – Internal Audit Charter: The charter must document the internal audit activity's purpose, authority, and responsibility, and is approved by the board.
An internal auditor needs to recommend a policy element to be included in an organization's code of ethics. Which of the following recommendations would be most effective?
A. Ethics should vary with local customs in the organization's foreign operations.
B. Whistleblowing should be discouraged because it can cause distrust among employees.
C. Ethical behavior should be incorporated into performance evaluations.
D. Senior management should be granted specific exemptions to the code of ethics.
Explanation:
A code of ethics establishes the core values, principles, and behavioral expectations for all employees within an organization. For a code of ethics to be effective, it must be embedded into the organization's culture and operational processes—not merely published as a standalone document.
Why Other Options Are Incorrect
A (Ethics should vary with local customs): This undermines the very purpose of a universal code of ethics. While organizations may adapt to local laws, core ethical principles (e.g., anti-bribery, honesty) must remain consistent across all operations to ensure integrity and avoid legal/regulatory violations.
B (Whistleblowing should be discouraged): This is contrary to best practices and IIA guidance. Encouraging whistleblowing is essential for detecting and addressing misconduct. Discouraging it creates a culture of secrecy, increases fraud risk, and violates the principles of transparency and accountability.
D (Senior management granted specific exemptions): Granting exemptions to senior management creates a "tone at the top" problem and undermines the credibility of the entire code. Ethical standards must apply equally to everyone, regardless of position, to maintain trust and fairness.
References
IIA Standard 2110 – Governance: The internal audit activity must assess and make appropriate recommendations for improving the governance process, which includes promoting appropriate ethics and values within the organization.
IIA Practice Guide – "Internal Auditing and Ethics": Recommends that ethics be integrated into performance management systems, including evaluations and compensation, to reinforce ethical behavior as a core competency.
An auditor in charge was reviewing the workpapers submitted by a newly hired internal auditor. She noted that the new auditor's analytical work did not include any rating or quantification of the risk assessment results, and she returned the workpapers for correction. Which section of the workpapers will the new auditor need to modify?
A. Condition section.
B. Criteria section.
C. Effect section.
D. Cause section.
Explanation:
The new auditor needs to modify the Condition section of the workpapers. The condition describes the actual situation or state observed during the audit . Key elements of an audit finding include a risk rating or quantification that highlights the issue's severity . This rating is part of the finding's description, not its cause or effect. By omitting the rating of the risk assessment results, the auditor failed to fully describe the condition.
Why Other Options Are Incorrect
B. Criteria section: This defines the benchmark or standard the condition is measured against (policies, procedures, or regulations). It does not contain the risk rating of the current situation .
C. Effect section: This describes the "so what" or the potential impact/consequence of the condition . While a risk rating is linked to impact, the rating itself is part of the condition's description.
D. Cause section: This explains the root reason "why" the condition occurred, such as a control gap or human error . The rating is not part of the root cause analysis.
References
IIA Standard 2330 – Documenting Information: Requires internal auditors to document sufficient, reliable, relevant, and useful information to support the engagement results and conclusions. Workpapers must support the bases for observations .
While preparing for an audit of senior management expenses, the chief audit executive (CAE) learns that management is unable to locate a number of original expense claims to support the related disbursements. She decides to defer the engagement until they can be located. Which of the following principles likely guided the CAE's decision?
A. Objectivity.
B. Proficiency.
C. Independence.
D. Due professional care.
Explanation:
The CAE's decision to defer the engagement until the original expense claims can be located is a direct application of due professional care. Under IIA Standard 1220, internal auditors must apply the care and skill expected of a reasonably prudent and competent auditor. This includes considering the sufficiency, reliability, and relevance of evidence before forming conclusions.
By deferring the audit, the CAE is acknowledging that without original supporting documentation, any audit opinion on senior management expenses would lack competent evidential matter. Proceeding without adequate evidence would be negligent and could lead to incorrect conclusions. Due professional care does not require perfection, but it does require auditors to obtain enough appropriate evidence to support their findings—and to pause when that evidence is unavailable.
Why Other Options Are Incorrect
A. Objectivity:
Objectivity refers to an unbiased mental attitude and avoiding conflicts of interest. While important, the CAE's decision is not about impartiality or personal bias—it is about evidence quality. Deferring does not resolve an objectivity threat; it resolves an evidence deficiency.
B. Proficiency:
Proficiency relates to possessing the necessary knowledge, skills, and competencies to perform the engagement. The CAE's decision is not about a lack of technical skill—it is about the unavailability of source documents, which is an evidence gathering issue, not a competency issue.
C. Independence:
Independence refers to the internal audit activity's freedom from interference in determining scope and performing work. While the CAE has the independence to defer the engagement, the reason for the decision is grounded in the professional obligation to obtain sufficient evidence, not in safeguarding independence from management influence.
References
IIA Standard 1220 – Due Professional Care: "Internal auditors must apply the care and skill expected of a reasonably prudent and competent internal auditor. Due professional care does not require infallibility."
IIA Standard 1220.A1: "Internal auditors must exercise due professional care by considering the... extent of work needed to achieve the engagement's objectives."
A headquarters-based internal auditor has been sent to a major overseas subsidiary to conduct various engagements. Initially, the internal auditor spends time to become familiar with local customs and organization's practices while embarking on the first engagement. Which of the following competencies does the internal auditor exercise?
A. Communication.
B. Persuasion and collaboration.
C. Business acumen.
D. Governance, risk, and control.
Explanation:
The internal auditor is actively familiarizing themselves with the local customs and practices of the overseas subsidiary. This directly demonstrates business acumen, a core competency defined by The IIA as understanding the business environment, industry practices, and the cultural and organizational factors that affect the entity . By learning how the local subsidiary operates, the auditor is building the knowledge needed to make sound judgments and apply their technical skills effectively within that specific context .
Why Other Options Are Incorrect
A. Communication:
This refers to the ability to convey information effectively and clearly. While interacting with the subsidiary may involve communication, the action in question is primarily about learning and understanding the business context, not about transmitting a message.
B. Persuasion and collaboration:
This involves influencing and motivating others. The auditor's focus is on gathering information to understand the environment, not on persuading or collaborating with staff at this stage.
D. Governance, risk, and control:
This competency involves applying a thorough understanding of internal control frameworks and risk management processes. While understanding the subsidiary's practices is important, the auditor's initial action of becoming familiar with local customs and operations is a foundational step that falls under business acumen. It precedes a detailed assessment of the subsidiary's governance and risk structures .
References
The IIA’s Global Internal Audit Competency Framework identifies "Business Acumen" as the competency that entails "maintaining expertise of the business environment, industry practices and organizational factors" .
| Page 10 out of 24 Pages |
| 678910111213 |
| IIA-CRMA-ADV Practice Test Home |
Real-World Scenario Mastery: Our IIA-CRMA-ADV practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Certification in Risk Management Assurance exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive IIA-CRMA-ADV practice exam questions pool covering all topics, the real exam feels like just another practice session.