CIMA BA4 · Chapter 7
Internal control, risk and audit MCQs with Answers
10 multiple-choice questions on Internal control, risk and audit for CIMA BA4 Fundamentals of Ethics, Corporate Governance and Business Law. Try each one before revealing the answer and explanation.
Practise this chapter interactivelyQuestion 1
Which of the following is a limitation of any system of internal control?
- A) Controls eliminate all risk of error once in place
- B) Controls make the external audit unnecessary
- C) Controls can be overridden by management or circumvented by collusion
- D) Controls cannot be documented
Show answer & explanation
Answer: C) Controls can be overridden by management or circumvented by collusion
Internal control provides reasonable, not absolute, assurance. Limitations include human error, collusion between staff, management override and the cost of controls exceeding benefits. Controls do not remove all risk or replace external audit, and they can be documented.
Question 2
Which of the following is NOT one of the five components of internal control in the COSO framework?
- A) Control environment
- B) Risk assessment
- C) Monitoring activities
- D) Strategic planning
Show answer & explanation
Answer: D) Strategic planning
The COSO components are control environment, risk assessment, control activities, information and communication, and monitoring activities. Strategic planning is a management process but is not one of the five internal control components.
Question 3
Who is ultimately responsible for a company's system of internal control?
- A) The board of directors
- B) The external auditor
- C) The internal auditor
- D) The shareholders
Show answer & explanation
Answer: A) The board of directors
The board is responsible for the company's risk management and internal control systems and for reviewing their effectiveness. Internal audit evaluates controls and reports to the board or audit committee, and the external auditor considers controls for the audit, but neither is responsible for them.
Question 4
Requiring two separate people to authorise and record a payment is an example of which type of control?
- A) Physical control
- B) Arithmetic control
- C) Segregation of duties
- D) Supervision control
Show answer & explanation
Answer: C) Segregation of duties
Segregation of duties splits authorising, recording and custody between different people, so that one person cannot both commit and conceal an error or fraud. Physical controls protect assets, arithmetic controls check calculations, and supervision is oversight by a manager.
Question 5
Which of the following best describes the 'control environment'?
- A) The specific procedures such as reconciliations and authorisations
- B) The overall attitude, awareness and actions of directors and management regarding internal control, including 'tone at the top'
- C) The computer systems used to record transactions
- D) The external auditor's assessment of risk
Show answer & explanation
Answer: B) The overall attitude, awareness and actions of directors and management regarding internal control, including 'tone at the top'
The control environment is the foundation of internal control, covering management's philosophy and operating style, integrity and ethical values, organisational structure and commitment to competence. Reconciliations and authorisations are control activities. IT systems and auditor assessments are not the control environment itself.
Question 6
Which of the following is a key difference between internal audit and external audit?
- A) Internal audit is required by law for all companies, but external audit is optional
- B) External audit gives an opinion on the financial statements to shareholders, whereas internal audit is an appraisal function serving management and the board
- C) External auditors are employees of the company, whereas internal auditors are always external firms
- D) Internal audit gives an opinion on the truth and fairness of the financial statements
Show answer & explanation
Answer: B) External audit gives an opinion on the financial statements to shareholders, whereas internal audit is an appraisal function serving management and the board
External auditors report to shareholders on whether the financial statements give a true and fair view. Internal audit is an independent appraisal function established by the organisation to review risk management, controls and operations for management and the audit committee. Internal audit is not universally required by law, and external auditors must be independent of the company.
Question 7
To whom should the head of internal audit ideally have direct access in order to protect independence?
- A) The finance director only
- B) The sales director
- C) The company's bank
- D) The audit committee
Show answer & explanation
Answer: D) The audit committee
Internal audit independence is supported by a direct reporting line to the audit committee, so that findings about the finance function or senior executives cannot be suppressed. Reporting only to the finance director would create a conflict where internal audit reviews finance department controls.
Question 8
Which of the following describes a 'detective' control?
- A) A monthly bank reconciliation that identifies unrecorded or incorrect transactions
- B) Requiring passwords before staff can access the payroll system
- C) Training staff before they process invoices
- D) Locking inventory in a secure warehouse
Show answer & explanation
Answer: A) A monthly bank reconciliation that identifies unrecorded or incorrect transactions
Detective controls identify errors or irregularities after they have occurred, such as reconciliations and exception reports. Passwords, training and physical locks are preventive controls designed to stop problems happening in the first place.
Question 9
A company's purchase ledger clerk can set up new suppliers, approve invoices and make payments. Which risk is greatest and which control would best address it?
- A) Overstated sales; introduce sequentially numbered sales invoices
- B) Payments to fictitious suppliers; segregate supplier set-up, approval and payment between different staff
- C) Theft of inventory; install CCTV in the warehouse
- D) Errors in depreciation; require an annual impairment review
Show answer & explanation
Answer: B) Payments to fictitious suppliers; segregate supplier set-up, approval and payment between different staff
When one person controls the whole purchasing and payment cycle, they could create a fictitious supplier and pay it without detection. Segregating supplier set-up, authorisation and payment is the key control. The other options address unrelated risks in the sales, inventory and non-current asset cycles.
Question 10
Which statement about the board's responsibility for risk management in a listed company is most consistent with good governance practice?
- A) The board should delegate all responsibility for risk to the external auditor
- B) The board need only consider risk when the company makes a loss
- C) The board should aim to eliminate all business risk
- D) The board should determine the nature and extent of the principal risks it is willing to take and review the effectiveness of risk management and internal control at least annually
Show answer & explanation
Answer: D) The board should determine the nature and extent of the principal risks it is willing to take and review the effectiveness of risk management and internal control at least annually
Governance codes require the board to determine the principal risks it is willing to take in pursuing objectives (its risk appetite), maintain sound risk management and internal control systems and review their effectiveness at least annually. Responsibility cannot be delegated to the auditor, and risk cannot and should not be eliminated, since taking risk is needed to earn returns.
