Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free IIA Qualified Info Systems Auditor CIA Challenge IIA-CHAL-QISA Exam Questions

Page: 1 / 15 Total 150 questions

Want more questions? Get Premium Access.

Question 1

According to IIA guidance, which of the following statements regarding the internal audit charter is true?

Correct Answer: D. The charter typically defines the internal audit activity's position within the organization.
Explanation:

The internal audit charter outlines the internal audit activity's purpose, authority, and responsibility within the organization.

It defines the internal audit activity's position within the organization, including reporting lines, independence, and access to records, personnel, and physical properties relevant to the performance of engagements.

This clarity helps ensure that the internal audit activity can operate independently and effectively


Question 2

Which of the following statements is true regarding the reporting of tangible and intangible assets?

Correct Answer: A. For plant assets, cost includes the purchase price and the cost of design and construction
Explanation:

Plant Assets Cost: For plant assets, which are tangible fixed assets such as buildings and machinery, the cost includes all expenditures necessary to acquire the asset and prepare it for its intended use. This includes the purchase price and additional costs such as design and construction.


Intangible Assets Cost: The cost of intangible assets, such as patents and trademarks, typically includes the purchase price and development costs. However, option B refers to this, but the correct focus for plant assets is emphasized in option A.

Amortization of Intangible Assets: Intangible assets with finite useful lives are subject to amortization, contradicting option C. Those with indefinite lives are not amortized but tested annually for impairment.

Expense of Developing Plant Assets: Development costs for plant assets are capitalized, not expensed immediately, making option D incorrect.

Question 3

According to IIA guidance, which of the following best describes the purpose of a planning memorandum for an audit engagement?

Correct Answer: A. It documents the audit steps and procedures to be performed.
Explanation:

The planning memorandum serves as a comprehensive blueprint for an audit engagement, outlining the specific steps, procedures, and strategies that will be employed to carry out the audit. According to IIA guidance, the purpose of this document is to ensure that the audit team is well-prepared and that the audit process is systematic and thorough.

Documentation of Audit Steps and Procedures: The primary purpose of a planning memorandum is to detail the steps and procedures that the audit team will follow. This ensures consistency and clarity throughout the audit process and provides a clear framework for team members to follow.


Preparation and Coordination: It serves as a preparatory document that helps in coordinating the activities of the audit team, ensuring that everyone is aware of their roles and responsibilities.

Practical Example: If an audit is being conducted on the financial reporting processes, the planning memorandum would include specific procedures for testing internal controls over financial reporting, timelines for each phase of the audit, and responsibilities assigned to each team member.

Risk Management: While it includes information on preliminary risks, its main focus is on documenting the audit steps rather than managing risks or existing measures, which would be covered in other documents or sections of the audit plan.

Clarification: Options B, C, and D may include elements found within broader audit planning, but the planning memorandum specifically focuses on the procedural roadmap.

Conclusion: The correct answer is A, as the planning memorandum's primary function is to document the audit steps and procedures to be performed, ensuring a structured and organized approach to the audit engagement.

Question 4

According to IIA guidance, which of the following is a limitation of a heat map?

Correct Answer: B. Impact and likelihood at times cannot be differentiated as to which is more important.
Explanation:

Introduction:

Heat maps are tools used in risk management to visualize the impact and likelihood of risks.

Limitations of Heat Maps:

Despite their usefulness, heat maps have several limitations, including difficulties in prioritizing risks when impact and likelihood are closely matched.

Options Analysis:

Option A: Impact can be represented qualitatively as well, not just in financial terms.

Option B: Differentiating the relative importance of impact versus likelihood can be challenging, leading to potential misinterpretation of risk priorities.

Option C: Heat maps can be used without a risk and control matrix, although such a matrix enhances their effectiveness.

Option D: Qualitative factors can be incorporated into heat maps, adding depth to the analysis.

Conclusion:

The limitation of a heat map is that at times, impact and likelihood cannot be differentiated as to which is more important, making it difficult to prioritize risks accurately.


Internal Audit Standards and Practice Guides .

Question 5

An internal auditor observed that sales staff are able to modify or cancel an order in the system prior to shipping She wonders whether they can also modify orders after shipping. Which of the following types of controls should she examine?

Correct Answer: B. Application controls
Explanation:

Application controls are specific to software applications and ensure that transactions are processed correctly and accurately. They include controls over input, processing, and output. In this scenario, examining application controls will help determine if sales staff can modify orders after shipping, as these controls directly impact how data is handled within the system.


'Information Technology Auditing,' which explains the role of application controls in maintaining data integrity and security.

Question 6

Which of the following is the most important determinant of the objectives and scope of assurance engagements?

The organizational chart, business objectives, and policies and procedures of the area to be reviewed

Correct Answer: C. The preliminary risk assessment performed by internal auditors planning the engagement.
Explanation:

The primary determinant of the objectives and scope of assurance engagements is the preliminary risk assessment performed by internal auditors. This assessment identifies the key risks associated with the area under review and helps prioritize the audit efforts based on the significance and likelihood of these risks. This approach ensures that the engagement focuses on the most critical areas, thereby adding value to the organization.


Question 7

When reviewing workpapers, engagement supervisors may ask for additional evidence or clarification via review notes. According to IIA guidance, which of the following statements is true regarding the engagement supervisors review notes?

Correct Answer: A. The review notes may be cleared from the final documentation once the engagement supervisors concerns have been addressed
Explanation:

Introduction:

Review notes are comments or questions posed by engagement supervisors during the review of workpapers to ensure audit quality and completeness.

IIA Guidance on Review Notes:

According to the IIA, review notes serve as a tool for engagement supervisors to seek additional evidence or clarification.

Options Analysis:

Option A: This is correct as per IIA guidance, once concerns have been addressed, review notes can be cleared from the final documentation.

Option B: Management does not typically address review notes; these are internal audit processes.

Option C: The CAE does not need to initial or sign the review notes, as the engagement supervisor's review is sufficient.

Option D: While review notes must be addressed, they do not necessarily need to be retained after being resolved.

Conclusion:

The correct procedure allows for review notes to be cleared once the engagement supervisor's concerns are addressed, streamlining the documentation process.


IIA's International Professional Practices Framework (IPPF).

Question 8

Applying ISO 31000; which of the following is part of the external context for risk management?

Correct Answer: C. The regulatory and competitive environment.
Explanation:

ISO 31000 Context: ISO 31000 provides guidelines on risk management, emphasizing the importance of understanding the external context.

External Context: This includes external factors such as regulatory and competitive environments that can impact the organization's risk profile.

Regulatory Environment: Understanding regulations helps the organization ensure compliance and avoid legal risks.

Competitive Environment: Analyzing the competitive environment allows the organization to anticipate market changes and manage competitive risks.


ISO 31000 Risk Management Guidelines.

Question 9

Which requirement should the chief audit executive consider when communicating results of the quality assurance and improvement program to the board of a large organization?

Correct Answer: B. The rating conclusions and the impact from results of the external assessment should be explained
Explanation:

When communicating the results of the quality assurance and improvement program (QAIP) to the board of a large organization, the chief audit executive (CAE) should explain the rating conclusions and the impact of the results from the external assessment. This ensures transparency and helps the board understand the effectiveness and areas for improvement in the internal audit function.

Rating Conclusions: These provide a summary of the overall quality and performance of the internal audit function.

Impact Explanation: Discussing the impact helps the board understand how the results affect the internal audit's ability to fulfill its responsibilities and improve its processes.

Transparency: Clear communication of these aspects helps build trust and provides a basis for informed decision-making by the board.


'Internal Audit Quality Assurance and Improvement Program,' which emphasizes the importance of explaining rating conclusions and impacts to the board .

Question 10

According to IIA guidance, which of the following steps should precede the development of audit engagement objectives?

Correct Answer: C. Risk assessment.
Explanation:

Risk Assessment: Before developing audit engagement objectives, a thorough risk assessment should be conducted. This step helps identify and prioritize the areas of highest risk, ensuring that the audit focuses on the most critical issues.

Establishing Objectives: The results of the risk assessment guide the development of specific, relevant, and focused audit objectives. This ensures that the engagement addresses key risk areas and adds value to the organization.

Sequential Steps: Identification of controls, scope establishment, and review of resources are important steps but typically follow the initial risk assessment to ensure the audit is aligned with the organization's risk profile.