New employees, consultants and contractors must receive security awareness training and supporting documentation at the time of employment refers to:
A process to identify events potentially affecting the entity and manage risk within its risk appetite is known as:
Risk assessment characteristic of the internal auditor’s paradigm has scenario planning as its new paradigm and its old paradigm is:
The level of control risk k cannot be modified during testing if test results indicate a change is warranted.
The delegation of authority is not well appropriate in relation to the assignment of responsibility.
Work group participants may be suspicious and even hostile, seeing CSA as a management ploy to find out more about them, when:
Which factor is inherent in all business activities and as a result must be routinely addressed in internal and external audits?
The policy statement that defines the objectives for and commitment to risk management within the organization’s strategic and operational context is called:
The change that results in a need to change policies, procedures, staffing levels or goals refers to which change?
Comparison of cost of a program or activity to a measurable unit of output or outcome is called cost-residuary impact.
Which auditors provide varying degrees of assurance about the state of effectiveness of the risk management and control processes of the organization?
No proper documentation of adds, changes or deletions to vendor master file is a fraud warning sign of:
When organizations delegate authority and make decisions by using managers from more then one subarea, these refer to:
Which of the following is NOT the step involved in evaluating the internal controls?
To improve the quality of financial reporting through a focus on corporate governance, internal controls and ethical standards, is the mission of:
The process of helping management and/or work teams assess the likelihood of meeting business objectives is called:
Organizations with centralized structures with a strict chain of command and typically perform highly repetitive tasks grouped within their functional areas, have:
Performance measures should be comprehensive enough to reach valid conclusions about the program.
Severity of consequences is often dependent on the operation of internal controls.
_________ refers to recommended actions should take into account relevant resource limitations.
What has the ability to combine both qualitative and quantitative data in imaginative ways?
The ability to take charge and inspire with a compelling vision is known as:
Which of the following is NOT the factor involved that influence the state of an organization’s control environment?
What aims to allow individuals involved in the process to assist the CSA team in identifying the risks and control weaknesses in the processes being reviewed?
Programmed procedures designed to prevent, detect and correct errors or irregularities that could adversely impact the organization’s business activities are called:
The organization has a mechanism to ensure the prompt resolution of findings from audits and other reviews through:
Accurate self-assessment is a realistic evaluation of your strengths and limitations.
Post implementation reviews of projects allow management to assess the degree to which the objectives were achieved for the resources expended in which phase of project management?