Which of the following controls would best mitigate the risk of fraud in the bidding process?
Correct Answer: A
Having a bidding committee open the tender bids is the best control to mitigate the risk of fraud in the bidding process. This approach ensures transparency and reduces the risk of manipulative practices by involving multiple stakeholders in the bid opening, thereby preventing any single individual from influencing the outcome unduly.References: Best practices in procurement and internal controls related to tender processes.
Question 357
An internal auditor notes that inventory counts are conducted on Mondays only and that all documentation is on paper as there are no computers in the underground warehouses. Also she notices that the person responsible for receiving the goods is the same one who distributes materials and spare parts Finally, she sees that spare parts are written off and taken by the heads of mining units to different underground locations to wait for their turn to be installed. Which of the described findings requires more consideration from a fraud risk perspective?
Correct Answer: A
The job responsibilities of the warehouse employee, where the same individual is responsible for receiving goods and distributing materials and spare parts, compromise segregation of duties. This lack of segregation poses a significant fraud risk because it allows a single individual to control multiple aspects of the inventory process, increasing the opportunity for misappropriation or manipulation of inventory without adequate checks or oversight.References: Institute of Internal Auditors (IIA) - International Professional Practices Framework (IPPF), Practice Guide: Assessing Fraud Risks
Question 358
Which of the following is true with regard to an organization's risk management practices?
Correct Answer: C
It is true that risks may relate to failing to achieve positive outcomes. This statement recognizes that risks are not only about preventing losses or avoiding negative consequences but also about failing to capitalize on opportunities that could lead to positive outcomes. This perspective aligns with a broader, more holistic view of risk management.References: IIA Position Paper on Risk Management
Question 359
Internal audit requests access to write and export specialized reports from the organization's database to aid with testing and analysis. Management authorizes internal audit only to view production reports that are built into the system. How can the chief audit executive create buy-in with management and attain the access required for the engagement?
Correct Answer: D
One of the key skills for a chief audit executive (CAE) is the ability to create buy-in with management and other stakeholders for the internal audit function. Buy-in means that management understands and supports the value and role of internal audit, and provides the necessary resources and access for internal audit to perform its work effectively. To create buy-in, the CAE should communicate clearly and persuasively the objectives, scope, and benefits of the internal audit engagements, and how they align with the organization's goals and risks. The CAE should also demonstrate the professionalism, competence, and independence of the internal audit team, and foster a collaborative and trusting relationship with management. In this case, the CAE should meet with the general manager to explain why access to write and export specialized reports from the organization's database is required for the engagement. The CAE should show how these reports will help to test and analyze the controls and processes that are relevant to the organization's risks and objectives. The CAE should also highlight the potential issues or opportunities that can be identified from using these reports, and how they can help to improve the organization's performance and governance. The CAE should also address any concerns or objections that the general manager may have, such as data security, confidentiality, or system integrity, and assure that internal audit will follow the appropriate standards and protocols when accessing and using the data. The other options are not likely to create buy-in with management. Sending the internal audit charter or a staff auditor may not be sufficient or persuasive enough to convince the general manager of the need for access. Explaining that internal audit's work program requires the reports may not explain how they are relevant or beneficial to the organization. These options may also appear as confrontational or demanding, rather than collaborative or consultative, which may damage the relationship between internal audit and management.
Question 360
According to IIA guidance which of the following statements regarding ethics is true?
Correct Answer: A
According to IIA guidance, business ethics may indeed vary within an organization with both domestic and foreign operations. This variation is due to differing cultural norms, legal requirements, and business practices across countries, which may necessitate adaptations in ethical policies and practices. While the core principles of ethics might be universally upheld, their application can differ based on local contexts.References: Institute of Internal Auditors (IIA) - Code of Ethics, International Professional Practices Framework (IPPF)