CAF-8 · Chapter 5
Internal Control MCQs with Answers
10 multiple-choice questions on Internal Control for CAF-8 Audit and Assurance Essentials. Try each one before revealing the answer and explanation.
Practise this chapter interactivelyQuestion 1
The policies and procedures that help ensure management directives are carried out, such as authorizations, physical security, and reconciliations, are known as:
- A) The risk assessment process
- B) Control activities
- C) Information systems
- D) The control environment
Show answer & explanation
Answer: B) Control activities
Control activities are the specific actions and procedures (like reconciliations, physical counts, and segregation of duties) established to prevent or detect misstatements.
Question 2
A client separates the duties of the person handling physical cash receipts from the person recording the cash entries in the ledger. What is the primary purpose of this control?
- A) To speed up the accounting process.
- B) To reduce the likelihood of an employee being able to both commit and conceal a fraud or error.
- C) To eliminate the need for an external audit.
- D) To comply with tax filing regulations.
Show answer & explanation
Answer: B) To reduce the likelihood of an employee being able to both commit and conceal a fraud or error.
Segregation of duties separates custody, authorization, and recording functions to minimize the risk that one person can steal an asset and hide the theft in the records.
Question 3
Which of the following is an example of a 'General IT Control' rather than an 'Application Control'?
- A) A check digit used to verify a customer account number upon input.
- B) A firewall and password system restricting access to the server room and overall network.
- C) A sequence check ensuring all sales invoice numbers are accounted for.
- D) An on-screen prompt ensuring a mandatory date field is filled before saving.
Show answer & explanation
Answer: B) A firewall and password system restricting access to the server room and overall network.
General IT controls apply broadly to the IT environment (security, backups, network access), while application controls apply to specific business software processes (input checks, batch totals).
Question 4
An auditor performs a 'Walk-through test'. What is the objective of this procedure?
- A) To verify the physical existence of the client's office building.
- B) To confirm their understanding of the internal control system by tracing a few transactions from start to finish.
- C) To calculate the exact monetary value of expected misstatements.
- D) To test the final year-end bank reconciliation.
Show answer & explanation
Answer: B) To confirm their understanding of the internal control system by tracing a few transactions from start to finish.
A walk-through test involves tracing a transaction through the entire accounting system to confirm that the auditor's documentation and understanding of the design of the controls are accurate.
Question 5
Which of the following internal controls is inherently 'Detective' rather than 'Preventive'?
- A) Requiring two authorized signatures on high-value purchase orders.
- B) Locking physical inventory in a secure warehouse.
- C) Preparing a monthly bank reconciliation to find unrecorded bank charges.
- D) Implementing a login password for the payroll system.
Show answer & explanation
Answer: C) Preparing a monthly bank reconciliation to find unrecorded bank charges.
Detective controls, like reconciliations and post-event reviews, are designed to discover errors or fraud *after* they have occurred, whereas preventive controls block them from happening initially.
Question 6
What is an inherent limitation of ANY internal control system?
- A) It cannot process foreign currency transactions.
- B) It is useless against a systems-based audit approach.
- C) It can be circumvented by collusion among employees or management override.
- D) It eliminates the need for professional skepticism.
Show answer & explanation
Answer: C) It can be circumvented by collusion among employees or management override.
No internal control system is perfect. Inherent limitations include human error, collusion between two or more staff members to bypass controls, and management overriding the system.
Question 7
Which component of internal control encompasses management's attitude, awareness, and actions concerning the entity's internal controls and its commitment to ethical values?
- A) Control environment
- B) Risk assessment process
- C) Monitoring of controls
- D) Application controls
Show answer & explanation
Answer: A) Control environment
The control environment sets the tone at the top of the organization, influencing the control consciousness of its people through ethics, integrity, and management philosophy.
Question 8
If an auditor evaluates the client's internal controls and finds them to be highly effective and properly implemented, what impact does this have on the audit strategy?
- A) The auditor can issue the audit report immediately without testing numbers.
- B) The auditor will adopt a systems-based approach and perform a reduced level of substantive testing.
- C) The auditor must perform 100% substantive testing of all ledgers.
- D) The auditor increases the overall materiality threshold to maximum.
Show answer & explanation
Answer: B) The auditor will adopt a systems-based approach and perform a reduced level of substantive testing.
If control risk is assessed as low (because controls are strong), the auditor can rely on them, reducing the extent of detailed substantive testing required (systems-based approach).
Question 9
In an IT application control, what is a 'Range Check'?
- A) Ensuring the user is physically located within the office.
- B) A check that ensures inputted numerical data falls within a predetermined set of acceptable values (e.g., age between 18 and 65).
- C) A calculation summing up the total number of documents in a batch.
- D) A backup procedure to copy data to a remote server.
Show answer & explanation
Answer: B) A check that ensures inputted numerical data falls within a predetermined set of acceptable values (e.g., age between 18 and 65).
A range check is an application control that rejects data input if it falls outside logically predefined minimum and maximum values.
Question 10
When documenting a client's internal control system, an auditor uses a diagram that uses standardized symbols to show the flow of documents and processes between departments. What is this method called?
- A) Narrative notes
- B) Internal control questionnaire (ICQ)
- C) Systems flowchart
- D) Control evaluation matrix
Show answer & explanation
Answer: C) Systems flowchart
A systems flowchart provides a visual, diagrammatic representation of the accounting system, showing document flows, processes, and departmental responsibilities.
