ExamGecko
Question list
Search
Search

Related questions











Question 629 - CISA discussion

Report
Export

What should an IS auditor do FIRST when a follow-up audit reveals some management action plans have not been initiated?

A.
Confirm whether the identified risks are still valid.
Answers
A.
Confirm whether the identified risks are still valid.
B.
Provide a report to the audit committee.
Answers
B.
Provide a report to the audit committee.
C.
Escalate the lack of plan completion to executive management.
Answers
C.
Escalate the lack of plan completion to executive management.
D.
Request an additional action plan review to confirm the findings.
Answers
D.
Request an additional action plan review to confirm the findings.
Suggested answer: C

Explanation:

The first thing that an IS auditor should do when a follow-up audit reveals some management action plans have not been initiated is to escalate the lack of plan completion to executive management. This is because the failure to implement the agreed management action plans may indicate that the management is not taking the audit findings and recommendations seriously, or that they are accepting too much risk by not addressing the identified issues.Escalating the lack of plan completion to executive management can help to raise awareness and accountability, as well as to seek support and intervention to ensure that the management action plans are executed in a timely and effective manner12.

Confirming whether the identified risks are still valid is not the first thing to do, although it may be a useful step to reassess the current situation and the potential impact of not implementing the management action plans.However, confirming the validity of the risks does not address the root cause of why the management action plans have not been initiated, nor does it provide any assurance or remediation for the unresolved issues34.

Providing a report to the audit committee is not the first thing to do, although it may be a necessary step to communicate and document the results of the follow-up audit.However, providing a report to the audit committee does not guarantee that the management action plans will be initiated, nor does it resolve any conflicts or challenges that may prevent the management from implementing them34.

Requesting an additional action plan review to confirm the findings is not the first thing to do, although it may be a prudent step to verify and validate the accuracy and completeness of the follow-up audit.However, requesting an additional review may delay or defer the implementation of the management action plans, as well as consume more internal audit resources and time

asked 18/09/2024
Ramesh Kumar Patel
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first