CPA Exam — AUDAssessing Risk and Developing a Planned ResponseHard

A client operates in a highly regulated industry with frequent changes to compliance requirements. The auditor observes that the client's internal audit function is understaffed and primarily focuses on operational efficiencies rather than financial reporting compliance. This situation most likely renders which COSO component ineffective?

  1. ARisk Assessment
  2. BControl Environment
  3. CControl Activities
  4. DMonitoring Activities
Show answer & explanation

Correct answer: D. Monitoring Activities

Monitoring activities involve ongoing evaluations and separate evaluations to ascertain whether the components of internal control are present and functioning. An understaffed internal audit function, misdirected from financial reporting compliance in a highly regulated industry, directly impairs the effectiveness of the entity's monitoring activities.

Why the other options are wrong

  • A. The entity's risk assessment process might identify compliance risks, but the failure is in monitoring the response to those risks.
  • B. While the control environment might be indirectly affected, the direct impact is on the function designed to monitor controls.
  • C. Control activities are the policies and procedures; the issue here is ensuring those activities are actually working effectively.

COSO - Monitoring Activities

Monitoring activities are ongoing evaluations, separate evaluations, or a combination of both, used to ascertain whether the components of internal control are present and functioning. They ensure the continued effectiveness of internal control over time.

  • Includes internal audit, supervisory reviews, and self-assessments.
  • Ensures controls are operating as intended.
  • Timely communication of deficiencies is crucial.

Memory trick: Monitoring is the 'watchdog' keeping controls in check.

More Assessing Risk and Developing a Planned Response questions