Mod1 Flashcards

1
Q

An independent and objective assessment of the adequacy and effectiveness of risk management across the organization based on a systematic and disciplined approach.

A

Assurance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Independent and objective insights and advice on the development, maintenance, and improvement of risk management systems, processes, structures, and implementation.

A

Consulting (or Advisory Services)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Active engagement with the board and senior management (comprising first and second line roles) to support integrated enterprise-wide strategic risk management through alignment with organizational priorities, effective ongoing communication, joint planning, and use of a common taxonomy and methods.

A

Coordination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

An organization wide perspective of significant risk and the sources of assurance on risk management to ensure sufficient coverage without unnecessary duplication.

A

Assurance Mapping

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

To enhance and protect organizational value by providing risk based objective assurance, advice, and insight.

A

Mission of Internal Auditing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Independent and objective assurance and consulting activities designed to add value and improve an organization’s operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes.

A

Definition of Internal Auditing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The primary reporting line of the CAE is to the board. This is the “________” reporting line.

A

Functional Reporting Line

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The secondary reporting line may be to an appropriate member of senior management. This is the “______” reporting line.

A

Administrative Reporting Line

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the 8 requirements for Independence of the Internal Audit Activity?

A

Internal audit charter.
Freedom from interference.
Access to people, resources, and information.
Necessary resources.
Accountability and functional reporting line to the board.
Administrative reporting line to senior management at an appropriate level.
Annual confirmation to the board of organizational independence and disclosure of any interference.
Application and safeguards when required.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the 7 requirements for Objectivity of the Internal Auditor?

A

Functional independence of the internal audit activity from senior management.
Absence of, and the appearance of, conflicts of interest.
Objective mindset.
Disciplined and systematic procedures.
Adherence to professional standards.
Supervision, monitoring, and quality assurance.
Application of safeguards when required.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the 5 core internal audit rules in regard to ERM?

A

Giving assurance on the risk management processes.
Giving assurance that the risks are correctly evaluated.
Evaluating risk management processes.
Evaluating the reporting of key risks.
Reviewing the management of key risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are legitimate internal audit roles with safeguards?

A

Facilitating identification & evaluation of risks.
Coaching management in responding to risks.
Coordinating ERM activities.
Consolidated reporting on risks.
Maintaining and developing the ERM framework.
Championing establishment of ERM.
Developing ERM strategy for board approval.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are 6 roles that Internal Auditing should not undertake?

A
Setting the risk appetite.
Imposing risk management processes.
Management assurance on risks.
Taking decisions on risk responses.
Implementing risk responses on managements behalf.
Accountability for risk management.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the five personal characteristics of internal auditors? This is also referred to as the five Cs.

A
Competence. 
Credibility.
Connectivity.
Communication.
Courage.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the 3 components of competency? This is also referred to as KSAs.

A

Knowledge.
Skill.
Abilities (attitudes and behaviors).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the five steps in the risk management assurance process?

A

Pre-planning, planning, performing, communicating, and follow up.

17
Q

What are the five stages in the consulting process?

A

Preplanning, planning, performing, communicating, and follow up.

18
Q

A structured, consistent and continuous process across the whole organization for identifying, assessing, deciding on responses to and reporting on opportunities and threats that affect the achievement of its objectives.

A

Enterprise-wide risk management

19
Q

Is the likelihood and impact of a risk before applying a risk response.

A

Inherent risk (or gross risk)

20
Q

Is the magnitude after applying a risk response.

A

Residual risk

21
Q

What are the 5 risk management maturity model stages?

A

Stage 1 - Initial, Stage 2 - Repeatable, Stage 3 - Defined, Stage 4 - Managed, and Stage 5 - Optimized.