ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 3 - IIA-CIA-Part2 discussion

Report
Export

Which of the following is an appropriate responsibility for the internal audit activity with regard to the organization's risk management program?

A.
Identifying and managing risks in line with the entity's risk appetite.
Answers
A.
Identifying and managing risks in line with the entity's risk appetite.
B.
Ensuring that a proper and effective risk management process exists.
Answers
B.
Ensuring that a proper and effective risk management process exists.
C.
Attaining an adequate understanding of the entity's key mitigation strategies.
Answers
C.
Attaining an adequate understanding of the entity's key mitigation strategies.
D.
Identifying and ensuring that appropriate controls exist to mitigate risks.
Answers
D.
Identifying and ensuring that appropriate controls exist to mitigate risks.
Suggested answer: B

Explanation:

The internal audit activity's role in regard to the organization's risk management program includes ensuring that a proper and effective risk management process is in place. This involves evaluating the risk management processes and providing assurance that risks are identified and managed effectively. The internal audit activity should not be responsible for managing risks (Option A), but should ensure there is a systematic process (Option B). Attaining an adequate understanding of key mitigation strategies (Option C) and identifying appropriate controls (Option D) are part of the audit process, but ensuring the existence of a proper process is the primary responsibility.

Reference: IIA Standard 2120 -- Risk Management

asked 18/09/2024
Francis Sailer
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first