nerdexam
IIA

IIA-CIA-PART1 · Question #3

During the planning stage of an assurance engagement, a payroll clerk informed the internal auditor that he is often asked to add new employees to the payroll without any formal new-hire…

The correct answer is C. Ask the clerk to provide a list of any suspicious new employee names on the payroll. Option C is correct because the auditor is still in the planning stage and needs to gather more specific preliminary information before designing audit procedures or escalating the issue. Asking the clerk for names of suspicious employees is a targeted, low-cost way to assess…

Question

During the planning stage of an assurance engagement, a payroll clerk informed the internal auditor that he is often asked to add new employees to the payroll without any formal new-hire documentation from human resources. The auditor is concerned that this increases the risk for fraud. To complete engagement planning, which of the following is the most appropriate next step for the auditor to take?

Options

  • AIncrease the sample size to be tested, ensuring a thorough review of the payroll records.
  • BAdvise the chief audit executive of the clerk's assertion, despite the lack of supporting evidence.
  • CAsk the clerk to provide a list of any suspicious new employee names on the payroll.
  • DInvestigate the matter further to understand precisely how many payroll records were affected.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    16% (5)
  • C
    72% (23)
  • D
    9% (3)

Explanation

Option C is correct because the auditor is still in the planning stage and needs to gather more specific preliminary information before designing audit procedures or escalating the issue. Asking the clerk for names of suspicious employees is a targeted, low-cost way to assess the potential scope and magnitude of the risk, which directly informs how the engagement should be structured.

Why the distractors are wrong:

  • A - Increasing sample size is a fieldwork/execution decision, not a planning step; it's also a generic response that doesn't address the specific fraud risk identified.
  • B - Escalating to the CAE based on a single, uncorroborated assertion from one clerk is premature; the auditor should substantiate the claim with more detail first.
  • D - Determining "precisely how many" records were affected describes a full investigation, which belongs in the execution phase - not planning.

Memory tip: Think of planning as the "What are we dealing with?" stage. You've heard a tip - now ask a follow-up question to size the problem before you commit to a course of action. Escalation (B) and investigation (D) come after you have enough to go on.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART1 Practice