According to IIA guidance, which of the following statements is true regarding the internal audit activity's quality assurance and improvement program (QAIP)?
Which of the following actions should the organization's governing body perform to provide the most effective governance over the organization's culture?
Which of the following would be the most effective fraud prevention control?
During a review of employee benefits, a staff internal auditor observed an ambiguity in the incentive compensation policy. If reported, it could negatively impact the internal auditor's compensation. Which of the following would encourage the internal auditor to be objective in his work?
Which of the following best demonstrates conformance with the Standards relating to continuing professional development of internal auditors?
According to IIA guidance, which of the following statements regarding the internal audit charter is true?
With regard to IT governance, which of the following is the most effective and appropriate role for the internal audit activity?
Which of the following describes two duties that should not be performed by the same person?
Which of the following is true regarding the use of a formal risk management framework?
1. It facilitates a methodical approach to risk mitigation.
2. It defines and standardizes the terminology used in risk communication.
3. It establishes the risk tolerance levels to be accommodated in the strategy.
4. It facilitates the alignment of risk mitigation strategies with management priorities.
The chief audit executive of a large national retailer is reviewing the purpose and objectives of the organization's internal audit activity
Which of the following objectives is best aligned with The IIA's Mission of Internal Audit?
Which of the following describes the internal audit activity's most appropriate role in an organization's risk management process?
An internal auditor performed a risk assessment and concluded that the controls over access privileges to a bank account were appropriate. Later, the auditor learned that a contractor was using a shared password provided by an authorized user of the account. Which of the following statements best describes the auditor's application of due professional care?
Internal audit is performing an engagement to determine whether there were indications of questionable bidding on a city s infrastructure project. As part of the engagement the internal audit activity became aware that certain firms tend to receive the contracts for large city projects. How should the internal audit activity proceed with the engagement and identify questionable bidding practices?
Which of the following would a chief audit executive most likely use to identify a need for improvement in a staff internal auditor's business acumen?
Which of the following would decrease or be reduced if an organization establishes and implements excessive internal controls?