US CMA Part 1 ยท Chapter 5
Internal Controls MCQs with Answers
23 multiple-choice questions on Internal Controls for US CMA Part 1 Financial Planning, Performance and Analytics. Try each one before revealing the answer and explanation.
Practise this chapter interactivelyQuestion 1
Under Section 302 of the Sarbanes-Oxley Act, who must certify each periodic report filed with the SEC, including statements about disclosure controls?
- A) The audit committee chair and the external audit partner
- B) The head of internal audit and the company secretary
- C) All members of the board of directors
- D) The principal executive officer and the principal financial officer
Show answer & explanation
Answer: D) The principal executive officer and the principal financial officer
Section 302 requires the CEO and CFO (or equivalents) to certify that the report does not contain material misstatements or omissions, that the financial statements fairly present the company's condition, and that they are responsible for disclosure controls and procedures.
Question 2
Which of the following is NOT one of the five components of internal control in the COSO Internal Control - Integrated Framework (2013)?
- A) Objective setting
- B) Control environment
- C) Monitoring activities
- D) Information and communication
Show answer & explanation
Answer: A) Objective setting
The five COSO internal control components are control environment, risk assessment, control activities, information and communication, and monitoring activities. Objective setting is a component of the earlier COSO enterprise risk management framework, not of the internal control framework.
Question 3
Management's integrity, ethical values and 'tone at the top' are part of which COSO internal control component?
- A) Risk assessment
- B) Control environment
- C) Control activities
- D) Monitoring activities
Show answer & explanation
Answer: B) Control environment
The control environment is the foundation of internal control and includes the organization's commitment to integrity and ethical values, board oversight, organizational structure, commitment to competence and accountability.
Question 4
Which combination of duties for a single employee represents the most serious weakness in segregation of duties?
- A) Preparing sales invoices and filing copies of shipping documents
- B) Opening mail and stamping checks 'for deposit only'
- C) Receiving customer cash payments and posting entries to the accounts receivable ledger
- D) Reconciling the bank statement and reviewing the payroll register for unusual items
Show answer & explanation
Answer: C) Receiving customer cash payments and posting entries to the accounts receivable ledger
Effective segregation separates authorization, custody of assets and recording. An employee who both handles cash and records receivables could steal receipts and conceal the theft by altering customer accounts (lapping or false credits).
Question 5
A monthly bank reconciliation prepared by an employee who has no access to cash is an example of which type of control?
- A) A preventive control
- B) A directive control
- C) A detective control
- D) A compensating application control
Show answer & explanation
Answer: C) A detective control
Detective controls identify errors or irregularities after they have occurred; a bank reconciliation highlights unrecorded or unauthorized transactions after the fact. Preventive controls, such as authorization limits and passwords, aim to stop problems occurring in the first place.
Question 6
Why can an internal control system provide only reasonable, rather than absolute, assurance that objectives will be achieved?
- A) External auditors are not permitted to test internal controls
- B) Controls can be circumvented by collusion or management override, and their cost must be weighed against their benefits
- C) Internal controls apply only to financial reporting objectives
- D) COSO prohibits controls that cost more than 1% of revenue
Show answer & explanation
Answer: B) Controls can be circumvented by collusion or management override, and their cost must be weighed against their benefits
Inherent limitations include human error and faulty judgment, collusion among employees, management override and the need to balance the cost of a control against its expected benefit. These limitations mean no system can guarantee that objectives will be met.
Question 7
Under Section 404 of the Sarbanes-Oxley Act, management of a public company must:
- A) Rotate the external audit firm every five years
- B) Certify that the company has no deficiencies in internal control of any kind
- C) Obtain shareholder approval for the design of internal controls
- D) Include in the annual report an assessment of the effectiveness of internal control over financial reporting
Show answer & explanation
Answer: D) Include in the annual report an assessment of the effectiveness of internal control over financial reporting
Section 404(a) requires management to include in the annual report its assessment of the effectiveness of internal control over financial reporting. Section 404(b) requires the external auditor to attest to that assessment only for accelerated filers and large accelerated filers; non-accelerated filers are exempt from 404(b) but still must provide management's 404(a) report. Management reports any material weaknesses rather than certifying that no deficiencies exist, and SOX requires rotation of the lead audit partner, not of the audit firm.
Question 8
Under the Sarbanes-Oxley Act, which body of a listed company is directly responsible for appointing, compensating and overseeing the external auditor?
- A) The chief financial officer
- B) The internal audit department
- C) The company's shareholders at each annual meeting
- D) The audit committee, composed of independent directors
Show answer & explanation
Answer: D) The audit committee, composed of independent directors
SOX Section 301 makes the audit committee directly responsible for the appointment, compensation and oversight of the external auditor, and requires its members to be independent. This reduces management's ability to influence the auditor.
Question 9
When auditing internal control over financial reporting, the PCAOB requires a top-down, risk-based approach. Where does this approach begin?
- A) With detailed testing of every transaction-level control in every location
- B) At the financial statement level, with an understanding of overall risks and entity-level controls
- C) With the controls that are cheapest to test
- D) With controls over non-financial operating objectives
Show answer & explanation
Answer: B) At the financial statement level, with an understanding of overall risks and entity-level controls
The top-down approach starts at the financial statement level, considers entity-level controls, then moves to significant accounts, disclosures and relevant assertions, and finally selects the controls that address the risk of material misstatement. This focuses effort where risk is greatest.
Question 10
In addition to its anti-bribery provisions, the Foreign Corrupt Practices Act (FCPA) requires SEC registrants to:
- A) Obtain an external audit of all foreign subsidiaries every quarter
- B) Disclose every payment made to foreign suppliers in the annual report
- C) Keep books and records that accurately reflect transactions and maintain a system of internal accounting controls
- D) Appoint a compliance officer approved by the Department of Justice
Show answer & explanation
Answer: C) Keep books and records that accurately reflect transactions and maintain a system of internal accounting controls
The FCPA's accounting provisions require issuers to make and keep books, records and accounts that accurately and fairly reflect transactions, and to devise and maintain a sufficient system of internal accounting controls. These apply to all SEC registrants, not only those operating abroad.
Question 11
An internal audit engagement evaluates whether the purchasing department uses its resources efficiently and achieves its objectives effectively. This is best described as:
- A) A compliance audit
- B) An operational audit
- C) A financial statement audit
- D) A forensic audit
Show answer & explanation
Answer: B) An operational audit
Operational audits assess the efficiency and effectiveness of an organization's activities and recommend improvements. Compliance audits test adherence to laws, regulations or policies, and financial statement audits express an opinion on fair presentation.
Question 12
Under PCAOB standards, a material weakness in internal control over financial reporting is a deficiency, or combination of deficiencies, such that:
- A) A material misstatement has definitely occurred and been corrected by the auditor
- B) Any misstatement, however small, could go undetected
- C) Management has failed to document a control in writing
- D) There is a reasonable possibility that a material misstatement of the financial statements will not be prevented, or detected and corrected, on a timely basis
Show answer & explanation
Answer: D) There is a reasonable possibility that a material misstatement of the financial statements will not be prevented, or detected and corrected, on a timely basis
A material weakness exists when there is a reasonable possibility of a material misstatement not being prevented or detected and corrected in a timely manner. A significant deficiency is less severe but still important enough to merit the attention of those responsible for oversight.
Question 13
How does a significant deficiency in internal control over financial reporting differ from a material weakness?
- A) It is more severe than a material weakness and must be reported to the SEC within four days
- B) It is less severe than a material weakness, yet important enough to merit the attention of those responsible for oversight of financial reporting
- C) It relates only to IT controls, whereas material weaknesses relate to manual controls
- D) It always results in an adverse audit opinion on the financial statements
Show answer & explanation
Answer: B) It is less severe than a material weakness, yet important enough to merit the attention of those responsible for oversight of financial reporting
Deficiencies are graded by severity: control deficiency, significant deficiency and material weakness. A significant deficiency should be communicated to the audit committee, but only a material weakness prevents management from concluding that ICFR is effective.
Question 14
Which of the following is a general (IT general) control rather than an application control?
- A) A check that a customer number entered on a sales order exists in the customer master file
- B) Procedures requiring authorization and testing before changes to programs are moved into production
- C) Calculation of a batch total for invoices entered into the payables system
- D) A report listing payroll transactions rejected by the system
Show answer & explanation
Answer: B) Procedures requiring authorization and testing before changes to programs are moved into production
General controls apply to the whole IT environment, covering program change management, access security, data center operations and system development. Validity checks, batch totals and error reports are application controls that operate within a specific application.
Question 15
A payroll system automatically rejects any time card that reports more than 70 hours worked in a week. This input control is best described as:
- A) A check digit
- B) A sequence check
- C) A limit (reasonableness) check
- D) A completeness check
Show answer & explanation
Answer: C) A limit (reasonableness) check
A limit or reasonableness check compares an input value with a predetermined boundary and rejects or flags values outside it. A check digit verifies the accuracy of an identification number, a sequence check tests ordering, and a completeness check ensures all required fields are entered.
Question 16
Before a batch of time cards is processed, a clerk adds up the employee identification numbers on the cards, and the system recalculates the same total after input. What is this total called?
- A) A hash total
- B) A financial total
- C) A record count
- D) A check digit
Show answer & explanation
Answer: A) A hash total
A hash total is a sum of a field, such as employee or account numbers, that has no meaning in itself but helps detect lost, added or altered records. A financial total sums a meaningful amount field, and a record count simply counts the documents.
Question 17
For disaster recovery, a company arranges access to an alternative facility that is fully equipped with compatible hardware, software and up-to-date data, so processing can resume within hours. This is known as:
- A) A hot site
- B) A cold site
- C) A warm backup tape rotation
- D) A mirrored workstation
Show answer & explanation
Answer: A) A hot site
A hot site is a fully configured facility ready for almost immediate use. A cold site provides space, power and connections but no installed equipment, so recovery takes much longer. The choice depends on how quickly operations must be restored and on cost.
Question 18
Under a grandfather-father-son backup arrangement, what is retained?
- A) Only the most recent backup, overwritten each day
- B) Several successive generations of backup files, so that earlier versions can be used to recreate current data if the latest backup is damaged
- C) A single printed copy of all transactions
- D) Backups of program files only, with no data files
Show answer & explanation
Answer: B) Several successive generations of backup files, so that earlier versions can be used to recreate current data if the latest backup is damaged
Grandfather-father-son retains three generations of master files and transaction data. If the latest (son) file is corrupted, the father file can be updated with subsequent transactions to recreate it, and the grandfather provides a further layer of protection.
Question 19
Using public-key (asymmetric) encryption, a sender wants to ensure that only the intended recipient can read a confidential message. Which key should the sender use to encrypt it?
- A) The sender's private key
- B) The recipient's public key
- C) The sender's public key
- D) The recipient's private key
Show answer & explanation
Answer: B) The recipient's public key
With asymmetric encryption, a message encrypted with the recipient's public key can only be decrypted with the recipient's private key, which only the recipient holds. Encrypting with the sender's private key creates a digital signature that proves origin but does not provide confidentiality.
Question 20
What is the primary function of a firewall in a company's network security?
- A) To make backup copies of data files
- B) To encrypt all data stored on hard drives
- C) To detect errors in input data
- D) To monitor and filter traffic between networks, blocking unauthorized access according to defined rules
Show answer & explanation
Answer: D) To monitor and filter traffic between networks, blocking unauthorized access according to defined rules
A firewall sits between a trusted internal network and untrusted external networks, such as the internet, and allows or blocks traffic based on security rules. Backup, storage encryption and input validation are separate controls.
Question 21
Before a batch of 85 sales invoices is entered, a clerk records the number of documents. After input, the system reports that 84 records were processed. Which control has identified the problem?
- A) A record count
- B) A field (format) check
- C) A limit check
- D) A hash total of customer numbers
Show answer & explanation
Answer: A) A record count
A record count compares the number of documents in a batch with the number of records processed, so it detects lost or duplicated items. A hash total would also flag a missing record, but the control described here counts documents rather than summing a field.
Question 22
In a small company, the mail is opened by a receptionist who prepares a list of all checks received. Which additional procedure would most strengthen control over cash receipts?
- A) Sending the list to a person independent of cash handling and record-keeping, who compares it with the bank deposit slip and the receivables postings
- B) Asking the receptionist to post the receipts to customer accounts as well
- C) Having the cashier who deposits the checks prepare a second list from the deposit slip
- D) Holding checks in the office for a week so that deposits can be made less often
Show answer & explanation
Answer: A) Sending the list to a person independent of cash handling and record-keeping, who compares it with the bank deposit slip and the receivables postings
An independent comparison of the original remittance list with the deposit and the accounting records provides a detective control over cash receipts. Giving the receptionist recording duties combines custody and recording, a list prepared by the cashier is not independent, and delaying deposits increases the risk of loss.
Question 23
Under the COSO 2013 framework, considering the potential for fraud when assessing risks to the achievement of objectives is a principle within which component?
- A) Control environment
- B) Control activities
- C) Monitoring activities
- D) Risk assessment
Show answer & explanation
Answer: D) Risk assessment
Principle 8 of the 2013 COSO framework, within the risk assessment component, states that the organization considers the potential for fraud, including incentives, opportunities and rationalizations, when assessing risks to the achievement of objectives.
