List of questions
Related questions
Question 205 - IIA-CIA-Part2 discussion
An internal auditor at a bank informed the branch manager of a malfunctioning lock on one of the vaults. The risk associated with this issue was deemed significant by the chief audit executive (CAE), and immediate remediation was recommended However during a follow-up engagement the branch manager told the CAE that the risk was actually not significant, hence no action was taken. What is the most appropriate next step for the CAE?
A.
Inform senior management that the branch manager deeded to cancel the committed action plan without any previous communication
B.
Discuss the issue with the board which has ultimate responsibility to resolve the risk
C.
Have another discussion with the branch manager attempt to change his view, and encourage him to movement the recommendations
D.
Document the branch manager's decision to accept the risk otherwise, no other speak: course of action is required.
Your answer:
0 comments
Sorted by
Leave a comment first