nerdexam
IIA

IIA-CIA-PART1 · Question #70

An organization allows the same individuals to physical access inventory and purchase new assets risk of fraud?

The correct answer is D. Management should established a policy requiring new inventory asset purchases to be made on. Option D is correct because it addresses the root cause of the risk - the lack of segregation of duties. Requiring a policy that separates the authority to purchase assets from those who physically handle inventory is a preventive control, meaning it stops the fraud opportunity…

Question

An organization allows the same individuals to physical access inventory and purchase new assets risk of fraud?

Options

  • AAccounting personnel should regularly perform reconciliation between invoices and purchase
  • BAccounting personnel should conduct a periodic inventory count and reconcile inventory
  • Cinternal auditors should review Vie frequency and volume of purchased assets to detect trends in
  • DManagement should established a policy requiring new inventory asset purchases to be made on

How the community answered

(32 responses)
  • A
    9% (3)
  • B
    16% (5)
  • C
    3% (1)
  • D
    72% (23)

Explanation

Option D is correct because it addresses the root cause of the risk - the lack of segregation of duties. Requiring a policy that separates the authority to purchase assets from those who physically handle inventory is a preventive control, meaning it stops the fraud opportunity before it can occur, rather than detecting it afterward.

Options A, B, and C are all detective controls - they identify problems after the fact (reconciling invoices, counting inventory, auditing trends) but do nothing to prevent the same individual from exploiting their dual access in the first place. Catching fraud after it happens is far less effective than preventing the conflict of interest from existing at all.

Memory tip: Think "D for Divide" - Segregation of duties divides incompatible responsibilities. Whenever a question describes the same person having two roles that could enable fraud, the best control is always a policy that separates those roles, not a monitoring activity that happens later.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART1 Practice