Question

11) Risk management should A) Focus on loss minimization only B) Not be an objective by...

11) Risk management should

A) Focus on loss minimization only

B) Not be an objective by itself

C) Be driven by internal audit

D) Be rules-based so it is the same throughout the organization

E) Should be software driven

12) What is typically the weakest link in internal controls?

A) Technology

B) The human elements

C) Lack of funding

D) Lack of a risk assessment

E) No internal audit department

13) Which of the following is not likely to cause a system of internal controls to become ineffective?   

A) Mergers and acquisitions

B) Implementation of new technologies

C) Hiring a new external audit firm regulated by the PCAOB

D) Outsourcing business functions

E) All of the above

14) Risk appetite

A) Can be different for compliance vs. strategic objectives

B) Is the same as an organization’s risk tolerance

C) Is strictly a quantitative measure

D) Tends to be the same for all companies in the same industry

E)  Does not change over time

15) Separation of duties controls for application systems are typically applied by

A) IT governance

B) Physical security

C) Logging

D) Access security

E) System software

0 0
Add a comment Improve this question Transcribed image text
Answer #1

11) Risk management should be driven by internal audit

12) The weakest link in the internal control is the human elements

13) Outsourcing of business does not affect the internal control

14) Risk appetite can be different for compliance v/s strategic objectives

15) Separation of duties controls for application systems are typically applied by physical security

Add a comment
Know the answer?
Add Answer to:
11) Risk management should A) Focus on loss minimization only B) Not be an objective by...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • 6) In the Three Lines of Defense Model, the primary responsibility for managing risks belongs to...

    6) In the Three Lines of Defense Model, the primary responsibility for managing risks belongs to A)   The CEO B)   Internal auditing C)   The risk management function D)   Operational management E)   The board of directors 7) Which of the following components of the IPPF is not considered to be mandatory? A) The Code of Ethics B) Definition of Internal Auditing C) Implementation Guidance D) Mission of Internal Auditing E)  Standards 8) Which of the following best describes internal auditing’s primary purpose in reviewing the organization’s existing...

  • 16) What is the most common way risk is measured? A) Speed of onset and vulnerability...

    16) What is the most common way risk is measured? A) Speed of onset and vulnerability B) Likelihood and impact C) Impact and vulnerability D) Duration and impact E) Time to identify and likelihood 17) Which of the following is true about IT controls? A) Cost effectiveness is not a consideration in developing and implementing IT controls B) What IT controls need to be in place are standard across companies C) COSO is the universally accepted framework for IT controls...

  • e. Security risk analysis d Access restrictions e Monitoring log-in activity 23This securi ecurity measure records...

    e. Security risk analysis d Access restrictions e Monitoring log-in activity 23This securi ecurity measure records Virus protection software is b stivity of a sor within sowa Audit trails Security risk analysis d Access restrictions c. Monitoring log-in activity 24. This security measure monitors ir hackers are attempting to break into be locked a Virus protection software b. Audit trails c. Security risk analysis d. Access restrictions e. Monitoring log-in activity autempting to break into the network and accounts can...

  • obtaining an First auditor decided not to perform tests of controls for purposes A. The available evidential matter obtained darough tes control risk of the internal control structure and esing ca...

    obtaining an First auditor decided not to perform tests of controls for purposes A. The available evidential matter obtained darough tes control risk of the internal control structure and esing cantrol risk of an eatity.n decided ha most liknly on in the assessed level of control risk a juastified for certain in BA reducti of controls would not support an increased C. It would be inefficient to perforn tests of controls that would result ina tests. controls that would result...

  • Internal controls can be categorized using the following framework: 1. Control environment 2. Risk assessment 3....

    Internal controls can be categorized using the following framework: 1. Control environment 2. Risk assessment 3. Information and communication 4. Control activities 4.1. Authorization 4.2. Performance reviews 4.3. Information-processing controls 4.3.1. IT general controls 4.3.2. IT application controls 4.3.3. IT-dependent manual controls 4.4 Physical controls 4.5 Segregation of duties 5. Monitoring Following is a list of controls implemented by Waterfront, Inc. a. Management established a code of conduct that includes rules regarding conflicts of interest for purchasing agents. b. Waterfront's...

  • Urganizational governance is: O a. Tactical management O b. Day to day management of the organization...

    Urganizational governance is: O a. Tactical management O b. Day to day management of the organization O c Compliance O d A process by which organizations select objectives estab sh processes to achieve objectives, and monitor performance Type here to search 40 2 3 4 5 6 8 Risk responses do not include: O a. Staying in the activity that is giving rise to the risk O b. Sharing a risk by, for example, buying insurance or outsourcing the activity...

  • MULTIPLE CHOICE: 1. What is the long-run objective of financial management? A.      Maximize earnings per share B.      Maximize...

    MULTIPLE CHOICE: 1. What is the long-run objective of financial management? A.      Maximize earnings per share B.      Maximize the value of the firm's common stock C.      Maximize return on investment D.     Maximize market share 2. Which of the following statement (in general) is correct? A. A low receivables turnover is desirable B. The lower the total debt-to-equity ratio, the lower the financial risk for a firm C. An increase in net profit margin with no change in sales or assets means a weaker ROI...

  • KID CASTLE EDUCATIONAL CORPORATION AND BROCK, SCHECHTER & POLAKOFF LLP, PCAOB 10 3, 4, 5, 7,...

    KID CASTLE EDUCATIONAL CORPORATION AND BROCK, SCHECHTER & POLAKOFF LLP, PCAOB 10 3, 4, 5, 7, 8) PROFESSIONAL SKEPTICISM 7-58 General Background. On May 22, 2012, the audit firm of Brock Schechter & Polakoff LLP (hereafter BSP) was censured and fined 820,000 by the PCAOB in relation to its audits of public compa nies located in Taiwan and China. These public companies were listed on U.S. stock exchanges. James Waggoner, BSP's director of accounting and auditing, was the BSP auditor...

  • I need help with my very last assignment of this term PLEASE!!, and here are the instructions: After reading Chapter T...

    I need help with my very last assignment of this term PLEASE!!, and here are the instructions: After reading Chapter Two, “Keys to Successful IT Governance,” from Roger Kroft and Guy Scalzi’s book entitled, IT Governance in Hospitals and Health Systems, please refer to the following assignment instructions below. This chapter consists of interviews with executives identifying mistakes that are made when governing healthcare information technology (IT). The chapter is broken down into subheadings listing areas of importance to understand...

  • 1) Discuss the company's top risks? 2) Discuss whether the company treats risk reactively or proactively?...

    1) Discuss the company's top risks? 2) Discuss whether the company treats risk reactively or proactively? 3) Do you observe a lack of understanding of potential exposures? 4) Does the company focus on internal risks or external risks? 5) Do you think the company is well prepared to respond to potential risks? Orange County he t die Following the debocie Orange County o dmorych of control procedures and financial gove nonce and d e setof o n policies December 1994...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT