Which of these date formats is correct in our Audit Report?
A: MM/DD/YYY
B: YYYY/DD/MM
C: YYYY/MM/DD
D: DD/MM/YYYY
C: YYYY/MM/DD
What is no longer part of the final audit report?
A: Risks covered
B: Details of C observations
C: Grading
D: Executive Summary
B: Details of C observations
How many times should you read the GA Audit Manual?
A. Once during onboarding
B. Once every audit cycle
C. Whenever Daniel creates a training deck
D. As often as needed to avoid Jürgen, Sascha and myself saying: "Did you check the Manual?"
D. As often as needed to avoid Jürgen, Sascha and myself saying: "Did you check the Manual?"
If possible, the risks in our engagement letter should come from:
A: GA Risk Inventory
B: HR Risk Register
C: HR Risk Inventory
D: GA Risk Register
A: GA Risk Inventory
Which risk should always be considered when using AI?
A: Fatamorgana
B: Hallucinations
C: Illusions
D: Paranoia
B: Hallucinations
After the final report is send out, which status should these have:
A: Observations in progress; Measures completed
B: Measures completed, observations completed
C: Observations completed, measures in progress
D: Observations in progress, measures completed
C: Observations completed, measures in progress
We included audit approaches in our Engagement Letter. Which should be included here?
A: Planned samples
B: Planned AI use
C: Planned Data Analytics
D: all of the above
D: all of the above
What is required before a draft audit report can be sent to the audited unit?
A. Approval by the Audit Committee
B. Internal review and reconciliation through the prescribed workflow in TM+
C. Completion of all follow-up actions
D. Approval by External Audit
B. Internal review and reconciliation through the prescribed workflow in TM+
For which areas have we not yet analysed which risks need to be incoporated into our GA Risk Inventory?
A: Investments
B: Operations
C: A and B
D: None
C: A and B
What are the names of our three GA agents?
A: Holger, Ruth, Emma
B: Anna, Emma, Goethe
C: Schiller, Anna, Rodrigo
D: Anna, Holger, Goethe
D: Anna, Holger, Goethe
Normally, which of these is a correct Workflow entry for shared documents?
A: Jürgen as Manager; Nondumiso and Sascha as Reviewer
B: Sascha / Gabi as Manager, Jürgen as Reviewer
C: Marie as Manager; Sascha and Jürgen as Reviewer
C: Gabi and Nondumiso as Manager; Jürgen as reviewer
B: Sascha / Gabi as Manager, Jürgen as Reviewer
Working Papers now have to include:
A: Positive Assurance
B: Positive Attitude
C: Positive Corona Test
D: Positive Mindset
A: Positive Assurance
Audit Communication should be:
A. Detailed, lengthy and legally exhaustive
B. Accurate, objective, clear, concise, constructive, complete and timely
C. Written exclusively by ChatGPT
D. Limited to PowerPoint slides
B. Accurate, objective, clear, concise, constructive, complete and timely
Which audit activity must be especially risk-based?
A: Documentation
B: Report writing
C: Quality Review
D: Planning
D: Planning
When using AI, who remains accountable for conclusions and audit results?
A: Co-Pilot
B: Jürgen
C: Goethe
D: Auditor
D: Auditor
In the scheduler there are four date fields: Scheduled Start, Scheduled end, Actual Start, Actual end
Once the audit is finished, which line should contain all four dates?
A. Closed
B. Field Work
C. Audit Scheduled
D. First Row (Audit)
D. First Row (Audit)
Which four Topical Requirements do we have to consider in the future, when planning and conducting an audit?
A: Organisational Resilience, Third Party, Cyber Security
B: Third Party, Organisational Well-being, Cyber Insecurity, Organisational Behaviour
C: Cyber Security, Organisational Behaviour, Third Party, Organisational Resilience
D: Organisational Behaviour, Organisational Resilience, Organisation Well-Being
C: Cyber Security, Organisational Behaviour, Third Party, Organisational Resilience
If an audit was not performed in accordance with the Global Internal Audit Standards (GIAS), what must happen?
A. Nothing
B. The deviation, reasons and impacts must be disclosed
C. The report must be deleted
D. Only Jürgen needs to know
B. The deviation, reasons and impacts must be disclosed
A population of 10,000 transactions. A high-risk control, because failures could result in significant financial losses. The auditor proposes testing only five transactions because five were sufficient in the previous audit. Which statement is most appropriate?
A. Five is sufficient because the previous audit used the same sample size.
B. Sample size should be determined solely by population size.
C. The auditor should consider the significance of the risk and whether the proposed testing provides sufficient evidence to achieve the audit objective.
D. High-risk areas must always be tested using the entire population.
C. The auditor should consider the significance of the risk and whether the proposed testing provides sufficient evidence to achieve the audit objective.
Which is not a Law of Robotics by Asimov?
A: A robot may not harm a human, or, by failing to act, allow a human to come to harm.
B: A robot must obey orders given by humans, unless these orders break the First Law.
C: A robot cannot take more than three weeks of consecutive leave of absence.
D: A robot must protect its own life, unless this defense breaks the First or Second Laws.
C: A robot cannot take more than three weeks of consecutive leave of absence.
Which documents should be under shared documents?
A: Draft Engagement Letter, Wrap-Up Presentation, Audit Tests, Final Audit Report
B: Final Audit Report, Reconciliation Emails, Kick-Off Presentation, Draft Engagement Letter
C: Draft/Final Engagement Letter, Kick-Off/Wrap-Up, Draft Audit Report, Final Audit Report
D: Draft Audit Report, Draft Engagement Letter, Wrap-Up presentation, Document Request
C: Draft/Final Engagement Letter, Kick-Off/Wrap-Up, Draft Audit Report, Final Audit Report
Which auditor attribute do we now confirm in our Engagement Letter?
A: Integrity
B: Objectivity
C: Independence
D: Credibility
B: Objectivity
Which statement best describes observation grading?
A. Grades are determined by report length
B. Grades are assigned by AI
C. Grades support deriving the overall assessment of governance, risk management and control processes
D. Grades are assigned alphabetically
C. Grades support deriving the overall assessment of governance, risk management and control processes
An Internal Audit engagement identifies a high risk that investment limit breaches may remain undetected due to weaknesses in the monitoring process. Which audit approach is most appropriate?
A. Perform a small sample of transactions
B: Consider using data analytics over the full population to identify potential breaches
C: Rely primarily on interviews with the control owner
D: Test the control once and conclude that it is effective if no exception is identified
B: Consider using data analytics over the full population to identify potential breaches
When using AI, what needs to be fulfilled?
A: AI-generated text must be clearly marked in working papers
B: Auditors must complete mandatory HR AI literacy training
C: none of the above
D: A and B
D: A and B