IIA-CIA-Part1 Exam Question 496

Which of the following is not an appropriate type of coordination between the internal audit activity and regulatory auditors?
  • IIA-CIA-Part1 Exam Question 497

    An internal auditor has taken an attributes sample of a bank's existing loan portfolio. Out of a sample of 60 loans, the auditor found:
    -Four that were not properly collateralized.
    -Five that were not in compliance with bank policies (other than lack of collateralization). -Four that were part of a related-party group,but were set up as separate loan entities. -Of the 60 loans selected in the sample,these errors were noted on a total of 10 loans. -Several loans had multiple problems.
    Which of the following conclusions can the auditor reach from these observations?
    There is sufficient evidence that fraudulent activity is taking place by one or more of the bank's lending officers.
    The financial statements will be misstated as a result of these actions.
    There are significant noncompliance audit findings that should be reported.
  • IIA-CIA-Part1 Exam Question 498

    Which of the following actions would be considered a violation of the Standards?
    I. Drafts of engagement communications were reviewed with the audit client to obtain input. The client's comments were considered when developing the engagement final communication.
    II. An auditor participated as part of a development team to review the control procedures to be incorporated into a major computer application under development.
    III. Given limited resources, the chief audit executive performed a risk analysis to determine which functions to audit.
  • IIA-CIA-Part1 Exam Question 499

    Some of a company's payroll transactions were batch posted to the payroll file but were not uploaded correctly to the general ledger file on the mainframe. The best control to detect this type of error would be.
  • IIA-CIA-Part1 Exam Question 500

    Which of the following are components of the COSO enterprise risk management
    framework?
    1.Objective setting.
    2.External environment.
    3.Data collection.
    4.Control activities.