ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 280 - IIA-CIA-Part2 discussion

Report
Export

An internal auditor e assessing the design of a control and has identified a potential significant weakness. The auditor shared his concern with management however management does not agree that the weakness is significant. What should the internet auditor do next?

A.
Perform additional audit work to better articulate the risk
Answers
A.
Perform additional audit work to better articulate the risk
B.
Report the finding that management has accepted a level of risk that is unacceptable.
Answers
B.
Report the finding that management has accepted a level of risk that is unacceptable.
C.
Proceed to testing how effectively the control is opening.
Answers
C.
Proceed to testing how effectively the control is opening.
D.
Because the design weakness has been identified no additional audit work is needed
Answers
D.
Because the design weakness has been identified no additional audit work is needed
Suggested answer: A

Explanation:

When an internal auditor identifies a potential significant weakness in a control and management does not agree with the assessment, the appropriate next step is to perform additional audit work to better articulate the risk. This means gathering more evidence, conducting further analysis, and providing clearer examples of how the weakness could impact the organization. By doing this, the auditor can better communicate the potential consequences and severity of the risk to management, increasing the likelihood of reaching a mutual understanding and agreement on the necessary actions.

The Institute of Internal Auditors (IIA) Practice Guide: Communicating Risk and Control Information

IIA Standard 2310 - Identifying Information

IIA Standard 2410 - Criteria for Communicating

asked 18/09/2024
Cheri Brown
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first