List of questions
Related questions
Question 21 - IIA-CIA-Part2 discussion
When setting the scope for the identification and assessment of key risks and controls in a process, which of the following would be the least appropriate approach?
A.
Develop the scope of the audit based on a bottom-up perspective to ensure that all business objectives are considered.
B.
Develop the scope of the audit to include controls that are necessary to manage risk associated with a critical business objective.
C.
Specify that the auditors need to assess only key controls, but may include an assessment of non-key controls if there is value to the business in providing such assurance.
D.
Ensure the audit includes an assessment of manual and automated controls to determine whether business risks are effectively managed.
Your answer:
0 comments
Sorted by
Leave a comment first