IIA-CIA-PART2 · Question #117
An internal auditor receives a document displaying all the steps of a process and the path taken as transactions flow between each step of the process How is the internal auditor most likely to use…
The correct answer is B. To perform an assessment of the effectiveness of process controls. A document showing all process steps and the path transactions take as they flow through each step is a flowchart (or process flow diagram). Auditors use flowcharts to trace actual transactions through a process - a technique called walk-through testing - which directly tests…
Question
An internal auditor receives a document displaying all the steps of a process and the path taken as transactions flow between each step of the process How is the internal auditor most likely to use This document during the engagement?
Options
- ATo perform an assessment of the adequacy of process controls.
- BTo perform an assessment of the effectiveness of process controls
- CTo perform a detailed assessment of process risks
- DTo perform an assessment of the sufficiency of residual process risks.
How the community answered
(61 responses)- A3% (2)
- B79% (48)
- C5% (3)
- D13% (8)
Explanation
A document showing all process steps and the path transactions take as they flow through each step is a flowchart (or process flow diagram). Auditors use flowcharts to trace actual transactions through a process - a technique called walk-through testing - which directly tests whether controls are operating effectively (i.e., working as intended in practice), making B correct.
Why the distractors are wrong:
- A (adequacy) is incorrect because adequacy refers to control design - whether the right controls exist - which is assessed earlier during planning/design review, not by tracing transaction flows.
- C (detailed risk assessment) is incorrect because risk identification and assessment require tools like risk registers or risk matrices; a flowchart can hint at where risks exist but does not constitute a detailed risk assessment on its own.
- D (residual risk sufficiency) is incorrect because evaluating residual risk requires comparing inherent risk against control effectiveness - a higher-level risk management judgment, not the primary purpose of following transaction paths through a flowchart.
Memory tip: Link the word "flow" in the document to "effectiveness" - you follow the flow of a transaction to see if controls effectively catch problems at each step. If the question mentions tracing or transaction paths, think effectiveness testing.
Topics
Community Discussion
No community discussion yet for this question.