Risky Business!
(Impact of the risk)
Control Patrol!
(Effective control?)
Test Quest!
(To test a control or Not?)
Finding Frenzy!
(Risk level classification)
Trivia Time!
(General knowledge)
100

Cash was stolen from a retail store’s register after hours.

What is loss of funds, theft, or financial hit?

100

Compliance filings are always sent for review, and at least one manager usually glances over them before submission.

What is ineffective?

100

Examine a sample of employee files for evidence of completed annual policy training.

What is substantive testing?

100

Vendor compliance certificates are occasionally missing, but the majority are collected and logged.

What is a medium-risk finding?

100

Which planet has the shortest day in our solar system?

What is Jupiter?

300

Sensitive customer data emailed unencrypted.

What are data breaches, privacy violations, fines, etc.?

300

Managers regularly remind employees to complete annual compliance training, and a centralized log helps track engagement.

What is effective?

300

Trace a sample of vendor compliance certifications to validate their authenticity and date.

What is substantive testing?

300

Sensitive customer information found on unsecured, shared drives.

What is a high-risk finding?

300

The Mona Lisa hangs in which world-famous museum

What is the Louvre (Paris)?

500

Employees manipulated overtime records for higher pay.

What are payroll inflation, reputational risk, and wasted resources?

500

Staff are promptly told about new policy updates in weekly meetings, and attending staff generally hear about key changes.

What is ineffective?

500

Observe whether approvals are documented for all exceptions to standard regulatory procedures.

What is a test of control?

500

One training session was scheduled late; staff still completed within the acceptable window.

What is a low-risk finding?

500

Which province is the only officially bilingual province in Canada?

What is New Brunswick?

M
e
n
u