When evaluating the design of an internal control, an auditor is primarily assessing:
Opening subject page...
Loading your content
CPA Isc Quiz
Practice Evaluate Design And Implementation Of Controls in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
Question 1 / 20
0 of 20 answered
When evaluating the design of an internal control, an auditor is primarily assessing:
This quiz focuses on Evaluate Design And Implementation Of Controls, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
When evaluating the design of an internal control, an auditor is primarily assessing:
Explanation: Design evaluation asks whether the control as designed would be effective if it operated as intended. Answer B is correct. Operating effectiveness (A) is a separate assessment. Documentation (C) supports but does not define design. Budget (D) is irrelevant.
A control requiring manager approval of all journal entries above $10,000 before posting is designed to address which control objective?
Explanation: A management approval requirement is an authorization control. Answer A is correct. Completeness (B) ensures all entries are captured. Valuation (C) relates to amounts. Cutoff (D) relates to timing.
Which of the following best describes the difference between a preventive control and a detective control?
Explanation: The key distinction is timing: preventive controls stop undesired events; detective controls identify them after the fact. Answer C is correct. Answers A, B, and D mischaracterize the distinction.
An automated three-way match control in accounts payable is best classified as:
Explanation: Three-way match prevents payment unless a matching PO and receipt exist - stopping unauthorized payments before they occur. Answer D is correct. It prevents rather than detects (A), does not reverse payments (B), and is a primary control (C).
An auditor evaluates RBAC controls and finds that role definitions have not been updated in five years despite significant organizational changes. This represents:
Explanation: RBAC is only effective when role definitions match current job functions. Outdated roles create inappropriate access. Answer C is correct. Controls require ongoing maintenance (A, B, D).
Which of the following represents the strongest evidence that controls over financial reporting are well-designed?
Explanation: Well-designed controls are risk-based, comprehensive, well-positioned, and layered. Answer A is correct. Documentation (B), quantity (C), and designer (D) do not demonstrate design adequacy.
A reconciliation control is performed daily but variances are routinely noted and ignored without investigation. This indicates:
Explanation: A reconciliation that identifies variances but never resolves them fails its objective. Answer D is correct. Uninvestigated variances mean the control is ineffective (A, B, C).
An auditor tests a dual-approval control for wire transfers over $50,000 and finds 3 of 25 sampled transfers had only one approver. The auditor should conclude:
Explanation: Three exceptions out of 25 is a meaningful deviation rate for a key authorization control. The auditor must assess deficiency severity. Answer A is correct. 88% compliance may be insufficient for key financial controls (B). Lowering the standard weakens the control (C). Assumptions require evidence (D).
Compared to a manual approval control for purchase orders, an automated control that rejects POs with invalid vendor IDs is:
Explanation: Automated controls apply rules consistently to every transaction, eliminating human inconsistency. Answer B is correct. Automation is generally more consistent than humans for repetitive rules (A, C). Daily monitoring is not always required (D).
A payroll manager who enters payroll data and processes the payroll run also reviews and approves the payroll register. This represents:
Explanation: Having the same person prepare and approve payroll eliminates the independent check that approval provides. Answer C is correct. Knowledge (A) and efficiency (B) do not justify the gap. Small organization constraints require compensating controls, not acceptance (D).
An IT audit identifies that a critical financial system has no user acceptance testing (UAT) before changes are deployed to production. This is a gap in which stage?
Explanation: UAT is a quality assurance control in the implementation process. Its absence means defects could reach production. Answer D is correct. Authorization (A), monitoring (B), and risk assessment (C) are distinct control activities.
In COSO, 'risk assessment' as a component informs control design by:
Explanation: Risk assessment identifies what can go wrong, driving proportionate control design. Answer C is correct. Cost estimation (A) is a management decision. Risk assessment informs, not replaces, controls (B). Risk ownership belongs to management (D).
A daily cash receipts reconciliation is performed but not reviewed or signed off by a supervisor. The most significant design gap is:
Explanation: A reconciliation without independent review provides limited assurance - the preparer cannot objectively verify their own work. Answer A is correct. Daily frequency is appropriate for cash (B). Automation preference (C) is a separate consideration. Combined roles worsen segregation (D).
'Control rationalization' in control design refers to:
Explanation: Control rationalization improves efficiency by ensuring every control serves a clear purpose. Answer D is correct. Eliminating untested controls (A), external approval of all designs (B), and zero residual risk (C) are all incorrect.
When assessing whether a control is appropriately designed for a high-risk process, which factor is most important?
Explanation: Effective control design requires direct risk linkage, appropriate process positioning, and proportionate response. Answer C is correct. Timing (A), preparer experience (B), and auditor recommendation (D) do not determine design adequacy.
What is the primary risk of over-reliance on manual controls?
Explanation: Manual controls are less reliable than automated ones for high-volume processes - susceptible to fatigue, distraction, and inconsistency. Answer A is correct. Cost (B) varies. External auditors accept manual controls (C). Manual controls can prevent some fraud (D).
Which approach most effectively evaluates overall design adequacy of an organization's internal control framework?
Explanation: A risk-control mapping exercise reveals whether all significant risks are covered and whether each control is designed to address its target risk. Answer D is correct. Documentation (A), approval (B), and counts (C) provide administrative evidence but not design adequacy.
In the COSO Internal Control framework, the 'control environment' refers to:
Explanation: The control environment is the organizational foundation on which all other controls rest. Answer D is correct. Automated IT controls (A), reconciliations (B), and access controls (C) are specific control types within the framework.
An auditor finds a control requiring manager review of a 500-page monthly report to identify exceptions. The most significant design concern is:
Explanation: A control that is theoretically sound but practically unperformable due to volume is a design weakness - reliability of detection is low. Answer B is correct. Format (A), frequency (C), and evaluator (D) are secondary issues.
A company's internal audit team evaluates whether controls over a new cloud-based financial system are adequate. Which of the following should the auditors assess as part of the design evaluation?
Explanation: Control design evaluation for a cloud-based system requires assessing whether the system's configurable controls are set up to address the organization's specific risks - authorization settings, access restrictions, logging configurations. Answer B is correct. Vendor longevity (A), training (C), and project delivery (D) do not assess control design adequacy.