ExamGecko
Question list
Search
Search

Related questions

Question 94 - CISA discussion

Report
Export

Which of the following should be the PRIMARY basis for prioritizing follow-up audits?

A.
Audit cycle defined in the audit plan
Answers
A.
Audit cycle defined in the audit plan
B.
Complexity of management's action plans
Answers
B.
Complexity of management's action plans
C.
Recommendation from executive management
Answers
C.
Recommendation from executive management
D.
Residual risk from the findings of previous audits
Answers
D.
Residual risk from the findings of previous audits
Suggested answer: D

Explanation:

Residual risk from the findings of previous audits should be the primary basis for prioritizing follow-up audits, because it reflects the level of exposure and potential impact that remains after management has implemented corrective actions or accepted the risk. Follow-up audits should focus on verifying whether the residual risk is within acceptable levels and whether the corrective actions are effective and sustainable.Audit cycle defined in the audit plan, complexity of management's action plans, and recommendation from executive management are not valid criteria for prioritizing follow-up audits, because they do not consider the residual risk from previous audits.Reference:CISA Review Manual (Digital Version), Chapter 2, Section 2.4.3

asked 18/09/2024
Marcelo Oliveira
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first