CoStudy

HomeCertificationsCPA AUD › Internal controls

Internal controls — CPA AUD practice questions

23 multiple-choice questions and 22 flashcards on Internal controls, about 6% of the CPA AUD bank. Every one carries a written rationale.

Written and maintained by Nick Burton · last updated 2026-08-22 · how we write and review questions

What this chapter covers

Internal controls is one of 6 chapters in CoStudy's CPA — Auditing & Attestation (AUD) [Core] bank, and it holds 23 of the bank's 410 multiple-choice questions — roughly 6% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.

Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.

Free Internal controls practice questions

10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.

IT general controls typically include controls over:

  1. The classification of individual sales transactions
  2. The completeness of a specific inventory count
  3. Access, change management, and computer operations
  4. The valuation of a single fair-value estimate

Answer: C — Access, change management, and computer operations

A) That is an application/transaction-level control. B) Inventory counts are business-process controls. C) Correct — IT general controls (ITGCs) cover access, change management, computer operations, and program development — the environment supporting all applications. D) Fair-value valuation is a substantive matter.

A client's computer operations general controls include job scheduling and backup procedures. These controls are MOST directly intended to provide assurance that:

  1. All manually prepared journal entries are properly authorized
  2. Revenue is recognized in accordance with ASC 606
  3. Data processing jobs run completely, in the correct sequence, and recoverable data exists if processing is disrupted
  4. The chart of accounts is properly mapped to the financial statement line items

Answer: C — Data processing jobs run completely, in the correct sequence, and recoverable data exists if processing is disrupted

A) Manual journal entry authorization is a separate control activity unrelated to computer operations scheduling and backup. B) Revenue recognition policy compliance is an accounting matter, not a computer-operations general control objective. C) Correct — computer operations controls are designed to provide assurance that processing occurs completely and in proper sequence and that data can be recovered after disruption. D) Chart-of-accounts mapping relates to application configuration or master data controls, not computer operations scheduling and backup.

A control deficiency that is LESS SEVERE than a material weakness but merits attention by those charged with governance is a:

  1. Control deficiency of minor consequence
  2. Reportable condition under prior standards
  3. Basic control operating exception
  4. Significant deficiency in internal control

Answer: D — Significant deficiency in internal control

A) The lowest-level category does not require TCWG attention. B) 'Reportable condition' is legacy pre-2007 terminology. D) Correct — under AU-C 265 / AS 2201, a significant deficiency is less severe than a material weakness but important enough to merit governance attention. C) That is not a defined category.

Testing IT general controls over logical access is important to the auditor primarily because:

  1. It replaces the need to test any automated application controls
  2. Weak access controls increase the risk that unauthorized users could initiate or alter transactions or data processed by otherwise reliable-looking application controls
  3. It is required only for public company audits under PCAOB standards and not for private companies
  4. It substitutes for testing the completeness of journal entries

Answer: B — Weak access controls increase the risk that unauthorized users could initiate or alter transactions or data processed by otherwise reliable-looking application controls

A) Testing ITGCs does not eliminate the need to test application controls; they are complementary layers. B) Correct — inadequate access controls increase the risk that data or programs are altered inappropriately, undermining reliance on application controls even if those controls appear well designed. C) ITGC testing is relevant whenever the auditor intends to rely on IT-dependent controls, in both public and private company audits. D) Access control testing does not substitute for separate procedures addressing completeness of journal entries.

Under the COSO 2013 framework, the FIVE components of internal control are supported by:

  1. Seventeen principles
  2. Ten principles
  3. Five principles
  4. Fifty subprinciples

Answer: A — Seventeen principles

C) There are more than five principles. B) There are not ten. A) Correct — COSO 2013 identifies 17 principles supporting the five components; each principle must be present and functioning. D) There are not fifty subprinciples in the framework.

Under SEC cyber-disclosure rules effective 2023, an issuer must disclose a material cybersecurity incident on:

  1. Form 8-K generally within 4 business days
  2. Form 10-K within 60 days
  3. Form 10-Q at the next quarter end
  4. Form S-1 at the next registration filing

Answer: A — Form 8-K generally within 4 business days

B) 10-K covers annual disclosures, not incident reporting. A) Correct — the SEC rule requires disclosure of a material cybersecurity incident on Form 8-K generally within 4 business days of determining materiality. C) 10-Q is not the trigger. D) S-1 is a registration filing, not a real-time incident report.

Which of the following is a required communication under AU-C 265 regardless of engagement scope?

  1. All deficiencies identified, no matter how minor
  2. Only deficiencies that management has already remediated
  3. Significant deficiencies and material weaknesses identified during the audit
  4. Deficiencies only if the client specifically requests written communication

Answer: C — Significant deficiencies and material weaknesses identified during the audit

A) Auditors are not required to communicate every trivial deficiency identified. B) Remediated items are still communicated if identified during the period under audit. C) Correct — AU-C 265 requires written communication of significant deficiencies and material weaknesses to management and those charged with governance, on a timely basis. D) The requirement is mandatory, not contingent on client request.

A reasonable possibility exists that a material misstatement will not be prevented or detected on a timely basis, and the potential magnitude could be material. This fact pattern MOST likely indicates a:

  1. significant deficiency only, never rising to a material weakness
  2. deficiency in design only, with no operating effectiveness concern
  3. matter requiring communication solely to internal audit
  4. material weakness in internal control over financial reporting

Answer: D — material weakness in internal control over financial reporting

A) A reasonable possibility of a material, undetected misstatement is precisely the threshold that elevates a deficiency to a material weakness. B) The fact pattern doesn't distinguish design from operating deficiencies; either could produce this result. C) Material weaknesses must be communicated to management and those charged with governance, not merely internal audit. D) Correct — AS 2201 / AU-C 265 define a material weakness as a deficiency (or combination) where there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis.

A control deficiency exists when a control is designed, implemented, or operated in a manner that:

  1. does not allow management or employees to prevent or detect misstatements on a timely basis
  2. results in an immediate SEC enforcement referral
  3. is documented but never actually implemented
  4. is identified by the external auditor rather than management

Answer: A — does not allow management or employees to prevent or detect misstatements on a timely basis

A) Correct — AU-C 265 / AS 2201 define a control deficiency as one where the design or operation does not allow timely prevention or detection of misstatements. B) SEC referral is not part of the definition. C) An undocumented or unimplemented control describes one possible cause of a deficiency, not the general definition. D) Who identifies the deficiency (auditor vs. management) doesn't determine whether it exists.

An integrated audit under PCAOB AS 2201 is required when the client is a(n):

  1. Non-profit entity with federal funding
  2. Non-issuer with revenues above $50 million
  3. Accelerated or large accelerated SEC filer
  4. Emerging growth company in its second year

Answer: C — Accelerated or large accelerated SEC filer

A) Non-profits follow AICPA/GAGAS, not PCAOB. B) Non-issuer thresholds do not trigger PCAOB integrated audits. C) Correct — SOX §404(b) and AS 2201 require integrated audits for accelerated and large accelerated filers. D) Emerging growth companies are typically exempt from §404(b) auditor attestation.

Internal controls flashcards

4 cards from the 22 in this chapter.

Significant deficiency?

Less severe than a material weakness but important enough to merit attention from those charged with governance.

Why does weak change management undermine reliance on application controls?

Even a well-designed application control can't be relied upon if unauthorized, untested changes could have altered the program logic during the period.

AU-C 265 communication requirement?

Written communication of significant deficiencies and material weaknesses to management and those charged with governance, on a timely basis.

COSO internal control framework components?

Control environment, risk assessment, control activities, info & communication, monitoring.

Practise the full chapter

These are a sample. The full Internal controls chapter runs 45 items with per-chapter progress tracking, on the web and in the iOS app.

Open CPA AUD in CoStudy →

Other CPA AUD chapters

All CPA AUD practice questions →