The CA Hub
All CIMA BA4 chapters

CIMA BA4 · Chapter 7

Internal control, risk and audit MCQs with Answers

10 multiple-choice questions on Internal control, risk and audit for CIMA BA4 Fundamentals of Ethics, Corporate Governance and Business Law. Try each one before revealing the answer and explanation.

Practise this chapter interactively
  1. Question 1

    Which of the following is a limitation of any system of internal control?

    • A) Controls eliminate all risk of error once in place
    • B) Controls make the external audit unnecessary
    • C) Controls can be overridden by management or circumvented by collusion
    • D) Controls cannot be documented
    Show answer & explanation

    Answer: C) Controls can be overridden by management or circumvented by collusion

    Internal control provides reasonable, not absolute, assurance. Limitations include human error, collusion between staff, management override and the cost of controls exceeding benefits. Controls do not remove all risk or replace external audit, and they can be documented.

  2. Question 2

    Which of the following is NOT one of the five components of internal control in the COSO framework?

    • A) Control environment
    • B) Risk assessment
    • C) Monitoring activities
    • D) Strategic planning
    Show answer & explanation

    Answer: D) Strategic planning

    The COSO components are control environment, risk assessment, control activities, information and communication, and monitoring activities. Strategic planning is a management process but is not one of the five internal control components.

  3. Question 3

    Who is ultimately responsible for a company's system of internal control?

    • A) The board of directors
    • B) The external auditor
    • C) The internal auditor
    • D) The shareholders
    Show answer & explanation

    Answer: A) The board of directors

    The board is responsible for the company's risk management and internal control systems and for reviewing their effectiveness. Internal audit evaluates controls and reports to the board or audit committee, and the external auditor considers controls for the audit, but neither is responsible for them.

  4. Question 4

    Requiring two separate people to authorise and record a payment is an example of which type of control?

    • A) Physical control
    • B) Arithmetic control
    • C) Segregation of duties
    • D) Supervision control
    Show answer & explanation

    Answer: C) Segregation of duties

    Segregation of duties splits authorising, recording and custody between different people, so that one person cannot both commit and conceal an error or fraud. Physical controls protect assets, arithmetic controls check calculations, and supervision is oversight by a manager.

  5. Question 5

    Which of the following best describes the 'control environment'?

    • A) The specific procedures such as reconciliations and authorisations
    • B) The overall attitude, awareness and actions of directors and management regarding internal control, including 'tone at the top'
    • C) The computer systems used to record transactions
    • D) The external auditor's assessment of risk
    Show answer & explanation

    Answer: B) The overall attitude, awareness and actions of directors and management regarding internal control, including 'tone at the top'

    The control environment is the foundation of internal control, covering management's philosophy and operating style, integrity and ethical values, organisational structure and commitment to competence. Reconciliations and authorisations are control activities. IT systems and auditor assessments are not the control environment itself.

  6. Question 6

    Which of the following is a key difference between internal audit and external audit?

    • A) Internal audit is required by law for all companies, but external audit is optional
    • B) External audit gives an opinion on the financial statements to shareholders, whereas internal audit is an appraisal function serving management and the board
    • C) External auditors are employees of the company, whereas internal auditors are always external firms
    • D) Internal audit gives an opinion on the truth and fairness of the financial statements
    Show answer & explanation

    Answer: B) External audit gives an opinion on the financial statements to shareholders, whereas internal audit is an appraisal function serving management and the board

    External auditors report to shareholders on whether the financial statements give a true and fair view. Internal audit is an independent appraisal function established by the organisation to review risk management, controls and operations for management and the audit committee. Internal audit is not universally required by law, and external auditors must be independent of the company.

  7. Question 7

    To whom should the head of internal audit ideally have direct access in order to protect independence?

    • A) The finance director only
    • B) The sales director
    • C) The company's bank
    • D) The audit committee
    Show answer & explanation

    Answer: D) The audit committee

    Internal audit independence is supported by a direct reporting line to the audit committee, so that findings about the finance function or senior executives cannot be suppressed. Reporting only to the finance director would create a conflict where internal audit reviews finance department controls.

  8. Question 8

    Which of the following describes a 'detective' control?

    • A) A monthly bank reconciliation that identifies unrecorded or incorrect transactions
    • B) Requiring passwords before staff can access the payroll system
    • C) Training staff before they process invoices
    • D) Locking inventory in a secure warehouse
    Show answer & explanation

    Answer: A) A monthly bank reconciliation that identifies unrecorded or incorrect transactions

    Detective controls identify errors or irregularities after they have occurred, such as reconciliations and exception reports. Passwords, training and physical locks are preventive controls designed to stop problems happening in the first place.

  9. Question 9

    A company's purchase ledger clerk can set up new suppliers, approve invoices and make payments. Which risk is greatest and which control would best address it?

    • A) Overstated sales; introduce sequentially numbered sales invoices
    • B) Payments to fictitious suppliers; segregate supplier set-up, approval and payment between different staff
    • C) Theft of inventory; install CCTV in the warehouse
    • D) Errors in depreciation; require an annual impairment review
    Show answer & explanation

    Answer: B) Payments to fictitious suppliers; segregate supplier set-up, approval and payment between different staff

    When one person controls the whole purchasing and payment cycle, they could create a fictitious supplier and pay it without detection. Segregating supplier set-up, authorisation and payment is the key control. The other options address unrelated risks in the sales, inventory and non-current asset cycles.

  10. Question 10

    Which statement about the board's responsibility for risk management in a listed company is most consistent with good governance practice?

    • A) The board should delegate all responsibility for risk to the external auditor
    • B) The board need only consider risk when the company makes a loss
    • C) The board should aim to eliminate all business risk
    • D) The board should determine the nature and extent of the principal risks it is willing to take and review the effectiveness of risk management and internal control at least annually
    Show answer & explanation

    Answer: D) The board should determine the nature and extent of the principal risks it is willing to take and review the effectiveness of risk management and internal control at least annually

    Governance codes require the board to determine the principal risks it is willing to take in pursuing objectives (its risk appetite), maintain sound risk management and internal control systems and review their effectiveness at least annually. Responsibility cannot be delegated to the auditor, and risk cannot and should not be eliminated, since taking risk is needed to earn returns.

Sponsored slot availableRun a CA academy or hiring firm? Put your name in front of students preparing for this exam.Advertise →