The System Stuff
The Changing Stuff
The Boring Stuff
The Risky Stuff
The Artifical Stuff
100

Which of these date formats is correct in our Audit Report?

A: MM/DD/YYY

B: YYYY/DD/MM

C: YYYY/MM/DD

D: DD/MM/YYYY


C: YYYY/MM/DD

100

What is no longer part of the final audit report?

A: Risks covered

B: Details of C observations

C: Grading

D: Executive Summary

B: Details of C observations

100

How many times should you read the GA Audit Manual?

A. Once during onboarding

 B. Once every audit cycle

 C. Whenever Daniel creates a training deck

 D. As often as needed to avoid Jürgen, Sascha and myself saying: "Did you check the Manual?"

D. As often as needed to avoid Jürgen, Sascha and myself saying: "Did you check the Manual?"

100

If possible, the risks in our engagement letter should come from:

A: GA Risk Inventory

B: HR Risk Register

C: HR Risk Inventory

D: GA Risk Register

A: GA Risk Inventory

100

Which risk should always be considered when using AI?

A: Fatamorgana

B: Hallucinations

C: Illusions

D: Paranoia


B: Hallucinations

200

After the final report is send out, which status should these have:

A: Observations in progress; Measures completed

B: Measures completed, observations completed

C: Observations completed, measures in progress

D: Observations in progress, measures completed

C: Observations completed, measures in progress

200

We included audit approaches in our Engagement Letter. Which should be included here?

A: Planned samples

B: Planned AI use

C: Planned Data Analytics

D: all of the above

D: all of the above

200

What is required before a draft audit report can be sent to the audited unit?

A. Approval by the Audit Committee

B. Internal review and reconciliation through the prescribed workflow in TM+

C. Completion of all follow-up actions

D. Approval by External Audit

B. Internal review and reconciliation through the prescribed workflow in TM+

200

For which areas have we not yet analysed which risks need to be incoporated into our GA Risk Inventory?

A: Investments

B: Operations

C: A and B

D: None

C: A and B

200

What are the names of our three GA agents?

A: Holger, Ruth, Emma

B: Anna, Emma, Goethe

C: Schiller, Anna, Rodrigo

D: Anna, Holger, Goethe

D: Anna, Holger, Goethe

300

Normally, which of these is a correct Workflow entry for shared documents?

A: Jürgen as Manager; Nondumiso and Sascha as Reviewer

B: Sascha / Gabi as Manager, Jürgen as Reviewer

C: Marie as Manager; Sascha and Jürgen as Reviewer

C: Gabi and Nondumiso as Manager; Jürgen as reviewer

B: Sascha / Gabi as Manager, Jürgen as Reviewer

300

Working Papers now have to include:

A: Positive Assurance

B: Positive Attitude

C: Positive Corona Test

D: Positive Mindset

A: Positive Assurance

300

Audit Communication should be:

A. Detailed, lengthy and legally exhaustive

B. Accurate, objective, clear, concise, constructive, complete and timely

C. Written exclusively by ChatGPT 

D. Limited to PowerPoint slides

B. Accurate, objective, clear, concise, constructive, complete and timely

300

Which audit activity must be especially risk-based?

A: Documentation

B: Report writing

C: Quality Review

D: Planning

D: Planning

300

When using AI, who remains accountable for conclusions and audit results?

A: Co-Pilot

B: Jürgen

C: Goethe

D: Auditor

D: Auditor

400

In the scheduler there are four date fields: Scheduled Start, Scheduled end, Actual Start, Actual end

Once the audit is finished, which line should contain all four dates?

A. Closed

B. Field Work

C. Audit Scheduled

D. First Row (Audit)

D. First Row (Audit)

400

Which four Topical Requirements do we have to consider in the future, when planning and conducting an audit?

A: Organisational Resilience, Third Party, Cyber Security

B: Third Party, Organisational Well-being, Cyber Insecurity, Organisational Behaviour

C: Cyber Security, Organisational Behaviour, Third Party, Organisational Resilience

D: Organisational Behaviour, Organisational Resilience, Organisation Well-Being

C: Cyber Security, Organisational Behaviour, Third Party, Organisational Resilience

400

If an audit was not performed in accordance with the Global Internal Audit Standards (GIAS), what must happen?

A. Nothing

B. The deviation, reasons and impacts must be disclosed

C. The report must be deleted 

D. Only Jürgen needs to know

B. The deviation, reasons and impacts must be disclosed

400

A population of 10,000 transactions. A high-risk control, because failures could result in significant financial losses. The auditor proposes testing only five transactions because five were sufficient in the previous audit. Which statement is most appropriate?

A. Five is sufficient because the previous audit used the same sample size.

B. Sample size should be determined solely by population size.

C. The auditor should consider the significance of the risk and whether the proposed testing provides sufficient evidence to achieve the audit objective.

D. High-risk areas must always be tested using the entire population.

C. The auditor should consider the significance of the risk and whether the proposed testing provides sufficient evidence to achieve the audit objective.

400

Which is not a Law of Robotics by Asimov?

A: A robot may not harm a human, or, by failing to act, allow a human to come to harm.

B: A robot must obey orders given by humans, unless these orders break the First Law.

C: A robot cannot take more than three weeks of consecutive leave of absence.

D: A robot must protect its own life, unless this defense breaks the First or Second Laws.

C: A robot cannot take more than three weeks of consecutive leave of absence.

500

Which documents should be under shared documents?

A: Draft Engagement Letter, Wrap-Up Presentation, Audit Tests, Final Audit Report

B: Final Audit Report, Reconciliation Emails, Kick-Off Presentation, Draft Engagement Letter 

C: Draft/Final Engagement Letter, Kick-Off/Wrap-Up, Draft Audit Report, Final Audit Report

D: Draft Audit Report, Draft Engagement Letter, Wrap-Up presentation, Document Request

C: Draft/Final Engagement Letter, Kick-Off/Wrap-Up, Draft Audit Report, Final Audit Report

500

Which auditor attribute do we now confirm in our Engagement Letter?

A: Integrity

B: Objectivity

C: Independence

D: Credibility

B: Objectivity

500

Which statement best describes observation grading?

A. Grades are determined by report length 

B. Grades are assigned by AI

C. Grades support deriving the overall assessment of governance, risk management and control processes

D. Grades are assigned alphabetically 

C. Grades support deriving the overall assessment of governance, risk management and control processes

500

An Internal Audit engagement identifies a high risk that investment limit breaches may remain undetected due to weaknesses in the monitoring process. Which audit approach is most appropriate?

A. Perform a small sample of transactions

B: Consider using data analytics over the full population to identify potential breaches

C: Rely primarily on interviews with the control owner

D: Test the control once and conclude that it is effective if no exception is identified

B: Consider using data analytics over the full population to identify potential breaches

500

When using AI, what needs to be fulfilled?

A: AI-generated text must be clearly marked in working papers

B: Auditors must complete mandatory HR AI literacy training

C: none of the above

D: A and B

D: A and B