Certification in Risk Management Assurance (CRMA) Exam
Last exam update: Nov 18 ,2025
Page 1 out of 19. Viewing questions 1-15 out of 283
Question 1
What is the primary purpose of a fishbone diagram?
A.
To depict the areas of responsibility for departments in an organization.
B.
To plan and control complex projects, such as internal audits.
C.
To represent the frequencies of adverse conditions in a given process.
D.
To identify the possible causes of adverse conditions.
Answer:
D
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 2
In which of the following scenarios would a customer service hotline receive a high volume of complaints regarding payments not being applied to customers’ accounts?
A.
Invoices are not being mailed to customers.
B.
An employee is tampering with customer checks.
C.
Employees are submitting fraudulent expense reports.
D.
The customer service department is not forwarding complaints to the accounts receivable department.
Answer:
B
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 3
Which of the following is a valid statement about the use of visual observations during an audit engagement? 1. Visual observations can be used to detect ineffective controls, idle resources, and safety hazards. 2. Visual observations can be used during both preliminary survey and fieldwork stages of the audit engagement. 3. Visual observations can provide unsubstantiated facts to management if the internal auditor believes the information is useful. 4. Visual observations can assist an auditor in determining if a material observation should be communicated through informal means to the organization’s senior management.
A.
1 and 2 only
B.
1 and 4 only
C.
2 and 3 only
D.
3 and 4 only
Answer:
A
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 4
An internal auditor for a large retail chain suspects that a store manager has been stealing money from cash sales by listing the sales as accounts receivable and then writing off the accounts as bad debts. Which of the following irregularities is the most likely cause of the auditor's suspicion?
A.
A much higher bad debt expense as a percentage of sales than that of previous years.
B.
A much higher bad debt expense as a percentage of sales than that of other stores.
C.
A much higher percentage of past-due accounts receivable than that of other stores.
D.
A much higher percentage of past-due accounts receivable than that of previous years.
Answer:
B
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 5
Which of the following would provide the best guidance to a chief audit executive who is setting internal audit staff requirements?
A.
A review of audit staff education and training records.
B.
Information about the audit staff size and composition of comparable organizations.
C.
Results from discussions of audit needs with executive management and the audit committee.
D.
The results of the audit staff's most recent performance reviews.
Answer:
C
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 6
An organization's chief audit executive (CAE) determines that the internal audit staff does not have the requisite skills to conduct an audit of the financial derivatives area. Which of the following would be the best course of action for the CAE to follow?
A.
Outsource the audit engagement to a qualified external auditing firm without burdening the audit committee with the decision.
B.
Determine the requisite knowledge needed, and obtain the proper training for auditors, even if the training will significantly push back the project's timeframe as outlined by the audit committee.
C.
Notify the audit committee of the problem, and assign the most competent auditors on staff to perform the audit engagement.
D.
Employ the skills of a financial derivatives expert to consult on the project, and supplement the consulting with a local seminar on financial derivatives.
Answer:
D
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 7
Management of a publicly-held organization requires the internal audit activity to be involved with quarterly financial statements, which are made public and used internally. Which of the following explanations of management's decision is least plausible?
A.
Management may be concerned about its reputation in the financial markets.
B.
Management is following best-practice protocol, as stipulated by the Standards, which states that internal auditors must review quarterly financial statements.
C.
Management may be concerned about potential penalties that could occur if quarterly financial statements are misstated.
D.
Management may perceive that having quarterly financial information examined by the internal auditors enhances the information's value to internal decision making.
Answer:
B
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 8
Which of the following scenarios exemplifies a potential internal control weakness?
A.
The same employee who receives cash from customers prepares a prelisting of cash receipts.
B.
The same employee who records cash receipts in the accounts receivable subsidiary ledger ensures that the ledger automatically updates the information.
C.
The same employee who restrictively endorses checks received from customers prepares the bank's check deposit slips.
D.
The same employee who makes deposits at the bank prepares the monthly bank reconciliation.
Answer:
D
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 9
After being terminated due to downsizing, an internal auditor finds a different job with an organization in the same industry. Which of the following actions would violate the IIA Code of Ethics?
A.
To determine audit priorities in the new job, the auditor uses the audit risk approach that the auditor's previous employer used, without receiving permission to do so.
B.
At the new organization, the auditor is asked to develop forms to implement probability- proportional-to-size sampling. Although unsure of how to perform this type of sampling, the auditor proceeds without asking for assistance.
C.
In preparing for an audit at the previous organization, the auditor had conducted a great deal of research on the Internet at home to identify best practices for the management of a treasury function. The auditor has retained much of the research and uses it to conduct an audit of the new employer's treasury function.
D.
In the first week at the new organization, the auditor discovers a high fraud risk surrounding the organization's database and suggests that the information technology department implement a new password system to prevent fraudulent actions before they occur.
Answer:
B
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 10
An organization has implemented a new automated payroll system that contains a table of pay rates that are matched to employee job classifications. Which control should an internal auditor suggest in order to ensure that the table is updated correctly, and is used only for valid pay changes?
A.
Restrict data-table access from management and line supervisors who have the authority to determine pay rates.
B.
Require a supervisor in the department, who has the ability to change the table, to compare the changes to a signed management authorization.
C.
Ensure that adequate edit and reasonableness checks are built into the automated system.
D.
Require a manager, who is independent of the system and who cannot change the table, to authorize and sign-off on any employee pay changes.
Answer:
D
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 11
Which of the following actions does not violate the IIA Code of Ethics or Standards?
A.
An internal auditor performing an audit on an operation that they managed less than a year ago.
B.
An internal auditor performing an audit on procedures that they were responsible for creating.
C.
An internal auditor disclosing details of an audit report to colleagues from a different organization.
D.
An internal auditor disclosing confidential information in response to a lawsuit.
Answer:
D
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 12
Which of the following controls is not appropriate for sales in a manufacturing organization?
A.
Customers' orders are recorded promptly.
B.
Goods shipped are matched with valid customer orders.
C.
Goods returned are inspected for damage by the receiving department for proper disposition.
D.
Sales department approval is required for credit sales transactions.
Answer:
D
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 13
A manufacturing organization discovers that the waste water released has failed to meet permitted limits. Which control function will be least effective in correcting the issue?
A.
Performing a chemical analysis of the water, prior to discharge, for components specified in the permit.
B.
Posting signs that tell employees which substances may be disposed of via sinks and floor drains within the facility.
C.
Diluting pollutants by flushing sinks and floor drains daily with large volumes of clean water.
D.
Establishing a preventive maintenance program for the pretreatment system.
Answer:
C
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 14
A computer system automatically locks a user's account after three unsuccessful attempts to log on. Which type of control does this scenario represent?
A.
Corrective control.
B.
Preventive control.
C.
Detective control.
D.
Compensating control.
Answer:
B
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 15
Why is it important for the chief audit executive to periodically review the audit charter and present the results to senior management and the board?
A.
Because management requires the review to measure effectiveness of the internal audit activity.
B.
So that the individual objectivity of the internal audit staff can be more clearly established.
C.
So that there is assurance of the internal audit staff's proficiency to complete audit activities.
D.
Because changes in the organization may impair the internal audit activity's ability to meet its objectives.