ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 313 - IIA-CIA-Part2 discussion

Report
Export

In the following risk control map risks have been categorized based on the level of significance and the associated level of control. Which of the following statements is true regarding Risk C?

A.
The level of control is appropriate given the level of risk
Answers
A.
The level of control is appropriate given the level of risk
B.
The level of control is excessive given the level of risk
Answers
B.
The level of control is excessive given the level of risk
C.
The level of control is inadequate given the level of risk
Answers
C.
The level of control is inadequate given the level of risk
D.
There is not enough of information to determine whether the controls are appropriate or not
Answers
D.
There is not enough of information to determine whether the controls are appropriate or not
Suggested answer: C

Explanation:

In the risk control map, Risk C is positioned in the upper left quadrant, indicating it is critical (high risk significance) but with a low level of control. This suggests that the current controls are insufficient to mitigate the high level of risk associated with Risk C. For critical risks, a higher level of control is necessary to ensure that the risk is properly managed and mitigated.

Reference:

'Internal Auditing: Assurance & Advisory Services' (The Institute of Internal Auditors)

'Risk Management Framework' (COSO)

asked 18/09/2024
Exam Prepping
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first