CON JOB
FRAUDITOR
SHH ... IT HAPPENS!!!
OPINIONATED
CAAT CALLS
100

Define the CONtrol Objective for the risk of systems not being maintained once implemented.

To assess the effectiveness of processes around maintaining the systems in order to prolong their useful life.

100

Name the most effective control to prevent fraud around the conflicting tasks of processing invoices and processing payments.

Segregation of Duties

100

Ensuring access to systems is restricted to authorized individuals only is an important aspect of management's controls as a part of Change Management processes.

Agree / Disagree with rationale.

Disagree.  Restricting access to authorized individuals falls under the Logical Access umbrella.

100

Which of the following best defines an internal auditor’s opinion expressed following an assurance engagement?

A. A summary of the significant engagement observations.

B. The internal auditor’s professional judgment about the situation that was reviewed.

C. Conclusions that must be included in the final engagement communication.

D. Recommendations for corrective action.

B. The internal auditor’s professional judgment about the situation that was reviewed.

100

ACL stands for 

Audit Command Language

200

Identify the underlying risk addressed by the CONtrol objective: To ascertain that system amendments are justified and authorized.

Unwanted and/or unauthorized system changes are initiated.

200

Which of the following activities represents both an appropriate personnel department function and a deterrent to payroll fraud?

A. Distribution of paychecks.

B. Authorization of overtime.

C. Authorization of additions and deletions from the payroll.

D. Collection and retention of unclaimed paychecks.

C. Authorization of additions and deletions from the payroll.

200

Due to limited resources, ACME Inc has the same individual responsible for developing and implementing system changes.  Name the next best control activity that can compensate for lack of sufficient Segregation of Duties.

Review of the Developer's activity log / trail

OR

Supervisor review of all changes implemented

200

Is this an appropriate OPINION in an internal auditing final communication of the results of an engagement to evaluate the organization’s branch operations:

"Statistical sampling was used to determine the extent of unauthorized purchases from the imprest fund."

Yes / No and Why?

No. This is a description of an audit procedure and not a conclusion.

200

What is the difference between CAATTs and CAATs?

CAATTs include all technologies for analysis, working paper management, and productivity management. 

CAATs focus on data extraction, analysis, fraud detection, and continuous auditing.

300

Draft a CONtrol objective to address the risk of untested system changes being implemented in the production environment.

To evaluate whether system amendments are comprehensively and independently tested prior to being correctly applied in the production environment.

300

The internal audit activity’s responsibility for preventing fraud is to

Evaluate the system of internal control.

300

The change request ticketing system is the best source for selecting samples of system changes for testing whether changes are authorized, developed, tested, implemented, and monitored.

Agree / Disagree with rationale

Disagree.  Selecting system-generated list of system code changes is the best source of complete population for testing change management controls.

300

Is this an appropriate OPINION in an internal auditing final communication of the results of an engagement to evaluate the organization’s branch operations:

"The engagement to review branch operations was conducted in accordance with the Standards."

Yes / No and Why?

No.  Stating that the engagement to review branch operations was conducted in accordance with the Standards is not a conclusion, that is, an evaluation of the effects of the observations and recommendations on the activities reviewed.

300

CLASSIFY function in ACL can be used to summarize payment amount by Vendor Name and Invoice Date.

Agree / Disagree with rationale.

No.  CLASSIFY function can only summarize by one field at a time and cannot summarize on a date/time field.

400

Name the two risks addressed by the CONtrol Objective: To evaluate whether only authorized and tested amendments are applied.

(1) Unauthorized changes are implemented; and 

(2) Untested changes are implemented

400

In an organization with a separate division that is primarily responsible for the prevention of fraud, the internal audit activity is responsible for

A. Examining and evaluating the adequacy and effectiveness of that division’s actions taken to prevent fraud.

B. Establishing and maintaining that division’s system of internal control.

C. Planning that division’s fraud prevention activities.

D. Controlling that division’s fraud prevention activities.

A. Examining and evaluating the adequacy and effectiveness of that division’s actions taken to prevent fraud.

400

If a system is maintained by a third-party, there is no need to test changes to those systems by the organization's internal auditor.

Agree / Disagree with rationale.

Disagree.  The internal auditor should either test the change management processes between own organization and the vendor OR review a third-party Service Organization Control (SOC) report.

400

Is this an appropriate OPINION in an internal auditing final communication of the results of an engagement to evaluate the organization’s branch operations:

"The vice-president of branch operations should require the timely review of the daily transaction report as a means of monitoring purchases from the imprest fund."

Yes / No and Why?

No.  Stating that the vice-president of branch operations should require the timely review of the daily transaction report is a recommendation.

400

Tracing transactions through the system to determine whether procedures are being applied as prescribed is a good example of an analytical procedure.

Agree / Disagree with rationale.

No.  Tracing transactions through the system is a test of controls directed toward the operating effectiveness of internal control, not an analytical procedure.

500

Define a CONtrol Objective to minimize the risk of poor documentation around system changes that would limit the ability of the IT function to maintain the system.

To evaluate how adequately system changes are documented so that they can be effectively maintained.

500

Which of the following fraudulent entries is most likely to be made to conceal the theft of an asset?

A. Debit expenses, and credit the asset.

B. Debit the asset, and credit another asset account.

C. Debit revenue, and credit the asset.

D. Debit another asset account, and credit the asset.

A. Debit expenses, and credit the asset.

500

Name the three system environments maintained as a part of effective change management processes.

Development environment 

Testing environment

Production environment

500

Is this an appropriate OPINION in an internal auditing final communication of the results of an engagement to evaluate the organization’s branch operations:

"Except for the unauthorized purchases from the imprest fund, the system of internal controls over branch operations appears to be working well."

Yes / No and Why?

Yes.  Conclusions (opinions) are the internal auditor’s evaluations of the effects of the observations and  recommendations on the activities reviewed. They usually put the observations and recommendations in perspective based upon their overall implications.

500

Which combination of the following analytical data provides the strongest indication of the possibility of the fraud?

A. Percentage increase in sales and inventory turnover.

B. Gross margin percentage and change in sales returns.

C. Inventory turnover and change in sales returns.

D. Percentage increase in sales and gross margin percentage.

B. Grow margin % and change in sales returns.  

Rapid increases in gross margin percentage are expected if sales are fictitious, that is, if sales are recorded without shipments and a consequent increase in cost of sales. The large increase in returns is also symptomatic of falsified sales.

M
e
n
u