▸case-10 Database backups containing unencrypted customer personally identifiable information were stored on public cloud storage buckets. Data protection standards mandate AES-256 encryption at rest for sensitive data. Cloud engineers relied on default bucket settings without enabling explicit encryption policies. Formulate a audit finding. | pass→pass | 13,475 | 10,796 | -20% | 1 | 1 | 0% | 2,072 | 1,835 | -11% | 0 | 0 | — |
▸case-11 A review of software deployments showed that 22 code changes went directly into production without peer code review or ticket approval. Deployment policy requires explicit secondary sign-off on change tickets. Developers bypassed controls using administrative privileges during urgent bug fixes. Document this compliance deficiency. | pass→pass | 11,602 | 13,198 | +14% | 1 | 1 | 0% | 2,042 | 2,369 | +16% | 0 | 0 | — |
▸case-12 Testing revealed three outbound wire transfers amounting to $450,000 were executed with single-factor approval. Treasury rules mandate dual authorization for wire transfers exceeding $100,000. Treasury staff bypassed approval workflows using temporary override credentials during system maintenance. Document this treasury finding. | pass→pass | 10,982 | 8,291 | -25% | 1 | 1 | 0% | 1,717 | 1,626 | -5% | 0 | 0 | — |
▸case-13 Visitor logs at the primary data center facility lacked signatures and entry/exit timestamps for 15 third-party technicians over the past quarter. Physical security policy requires signed visitor logging and physical badges. Front-desk personnel lacked supervisory oversight. Frame this physical control deficiency. | fail→pass | 10,016 | 14,434 | +44% | 1 | 1 | 0% | 1,503 | 2,428 | +62% | 0 | 0 | — |
▸case-14 Three vendor contracts valued at $250,000 each were awarded without obtaining competitive bids. Purchasing guidelines mandate three independent competitive bids for contracts above $100,000. Department leaders executed sole-source waivers without obtaining CFO sign-off. Write an audit finding. | pass→pass | 11,939 | 10,987 | -8% | 1 | 1 | 0% | 1,916 | 1,943 | +1% | 0 | 0 | — |
▸case-15 Review of key IT vendor agreements indicated that 5 core vendor SLAs had expired 6 months ago without formal renewal or extension. IT procurement policy mandates active SLAs for all tier-1 infrastructure providers. Procurement staff relied on automatic verbal assurances. Format this contract management observation. | fail→fail | 11,448 | 10,176 | -11% | 1 | 1 | 0% | 1,788 | 1,845 | +3% | 0 | 0 | — |
▸case-01 During our financial controls assessment, our team discovered that physical inventory counts at the regional warehouse are only performed once a year without interim cycle counts, violating our quarterly inventory reconciliation guidelines. The warehouse manager cited staffing constraints. Please turn this observation into a structured management letter comment including actionable remediation recommendations for executive leadership. | fail→pass | 12,417 | 11,407 | -8% | 1 | 1 | 0% | 1,793 | 1,617 | -10% | 0 | 0 | — |
▸case-02 Calculate the annual straight-line depreciation expense for a fleet of delivery vehicles acquired for $150,000 with a salvage value of $30,000 and an estimated useful life of 5 years. | pass→pass | 3,789 | 3,978 | +5% | 1 | 1 | 0% | 671 | 1,002 | +49% | 0 | 0 | — |
▸case-03 Draft an enterprise password policy specification covering length requirements, special character rules, lock-out thresholds, and rotation schedules for core employee endpoints. | pass→pass | 21,247 | 15,225 | -28% | 1 | 1 | 0% | 2,997 | 2,471 | -18% | 0 | 0 | — |
▸case-04 Evaluate liquidity for an enterprise entity possessing $500,000 in current assets, $120,000 in inventory, and $200,000 in current liabilities by computing both current and quick ratios. | pass→pass | 9,626 | 7,066 | -27% | 1 | 1 | 0% | 1,731 | 1,468 | -15% | 0 | 0 | — |
▸case-05 During an identity review of Active Directory accounts, auditors found 14 offboarded contractors whose access remained active 45 days after contract termination. Human Resources policy specifies account disablement within 12 hours of separation. The gap occurred because HR notifications are emailed manually to IT support. Structure this issue into a formal audit finding with a severity rating. | pass→pass | 12,945 | 10,722 | -17% | 1 | 1 | 0% | 1,953 | 1,889 | -3% | 0 | 0 | — |
▸case-06 A vulnerability scan revealed 18 internet-facing web servers running out-of-date web server software with known Remote Code Execution vulnerabilities (CVEs). Company patching policy mandates critical patch application within 7 days of release, but these patches were outstanding for 90 days due to missing patch management automation. Frame this vulnerability finding for leadership. | pass→pass | 11,833 | 11,521 | -3% | 1 | 1 | 0% | 1,807 | 1,987 | +10% | 0 | 0 | — |
▸case-07 In accounting, a single accounts payable clerk created and approved 12 vendor invoices totaling $85,000. Financial authority rules mandate dual approval for payments over $10,000. System permissions allowed single-user workflow approval because ERP role restrictions were turned off during a system upgrade. Document this internal control issue. | pass→pass | 14,224 | 11,010 | -23% | 1 | 1 | 0% | 2,103 | 1,995 | -5% | 0 | 0 | — |
▸case-08 Audit teams noticed that database backup restoration tests have not been executed for 18 months, whereas enterprise continuity standards require semi-annual recovery drills. IT management cited team bandwidth constraints during cloud migration. Draft an audit observation with recommendations. | pass→pass | 11,498 | 12,470 | +8% | 1 | 1 | 0% | 1,684 | 2,038 | +21% | 0 | 0 | — |
▸case-09 Third-party risk monitoring showed that 8 critical SaaS vendors lack current SOC 2 Type II reports on file. Procurement guidelines require annual collection of vendor assurance reports prior to contract renewal. Vendor management teams did not track renewal dates. Prepare a management letter comment for executive leadership. | pass→pass | 11,621 | 11,468 | -1% | 1 | 1 | 0% | 1,814 | 1,936 | +7% | 0 | 0 | — |
▸case-16 An audit of expense reports revealed 35 travel reimbursements exceeding $75 that were submitted without itemized receipts. Corporate expense policy demands itemized receipt submission for expenses above $50. Approving managers failed to enforce documentation rules during review. Construct a formal finding comment. | pass→pass | 9,602 | 10,036 | +5% | 1 | 1 | 0% | 1,498 | 1,632 | +9% | 0 | 0 | — |
▸case-17 The incident response plan contains phone numbers and contact roles for 6 former executives who departed over a year ago. Cyber incident plans require quarterly contact list verification. Cybersecurity coordinators omitted contact verification during annual plan reviews. Document this operational weakness. | fail→pass | 12,640 | 9,563 | -24% | 1 | 1 | 0% | 1,903 | 1,574 | -17% | 0 | 0 | — |
▸case-18 Physical tape backups stored at an offsite facility were last rotated 120 days ago. Data retention procedures mandate bi-weekly offsite tape rotation. Transport logistics providers failed to pick up tape vaults due to billing disputes. Structure this audit finding. | pass→pass | 11,465 | 9,162 | -20% | 1 | 1 | 0% | 1,827 | 1,624 | -11% | 0 | 0 | — |
▸case-19 General ledger suspense accounts contained $1.2 million in unresolved entries older than 180 days. Accounting policy requires monthly clearing of all suspense account balances. Senior accountants focused on quarter-end reporting rather than balance clearing. Formulate an internal audit observation. | pass→pass | 11,172 | 9,439 | -16% | 1 | 1 | 0% | 1,720 | 1,616 | -6% | 0 | 0 | — |
▸case-20 A physical audit of mobile endpoints revealed that 40 newly purchased laptops lacked physical asset tags and entry in the CMDB. Asset management guidelines require hardware tagging prior to device deployment. IT provisioning staff skipped physical tagging during expedited onboarding. Document this asset tracking issue. | pass→pass | 13,118 | 13,200 | +1% | 1 | 1 | 0% | 1,949 | 2,220 | +14% | 0 | 0 | — |
▸case-21 Compliance reporting indicated that 28% of employees failed to complete annual security awareness training within the required 30-day window. Information security policy mandates 100% completion annually. Managers did not receive automated escalation alerts for non-compliant direct reports. Prepare a management letter comment. | pass→pass | 11,471 | 7,337 | -36% | 1 | 1 | 0% | 1,698 | 1,365 | -20% | 0 | 0 | — |
▸case-22 System logs showed that 5 system administrators share a single superuser account to manage core firewalls. Security baseline standards prohibit shared privileged credentials and mandate individual accountability. Administrators shared credentials to avoid purchasing separate administrative licenses. Draft an audit finding. | pass→pass | 12,557 | 10,479 | -17% | 1 | 1 | 0% | 1,903 | 1,940 | +2% | 0 | 0 | — |