Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IIA Exam IIA-CHAL-QISA Topic 3 Question 19 Discussion

Actual exam question for IIA's IIA-CHAL-QISA exam
Question #: 19
Topic #: 3
[All IIA-CHAL-QISA Questions]

Following an IT systems audit, management agreed to implement a specific control in one of the IT systems. After a period, the internal auditor followed up and learned that management had not implemented the agreed management action due to the decision to move to another IT system that has built-in controls, which may address this risks highlighted by the Internal audit Which of the following Is the most appropriate action to address the outstanding audit recommendation?

Show Suggested Answer Hide Answer
Suggested Answer: A

Verification of Controls: The auditor should verify that the new IT system addresses the previously identified risks. This involves reviewing the system documentation and ensuring that the controls in the new system effectively mitigate the risks.


Reporting: Once the auditor has confirmed that the new system controls address the risks, they can report to senior management and close the outstanding issue, ensuring that all audit recommendations are appropriately resolved.

Other Options:

Accepting Management's Explanation: Without verification (option B) is not appropriate as it may leave risks unmitigated.

Escalating Without Verification: Advising management and escalating (option C) is premature if the new system may already address the issues.

Detailed Process Evaluation: Requiring additional details about the process (option D) may be unnecessary if the auditor can verify the controls directly.

Contribute your Thoughts:

Eveline
2 months ago
Option D seems prudent. The auditor should validate that the new system actually addresses the risk before closing the issue. Can't just take management's word for it.
upvoted 0 times
Linsey
21 days ago
Definitely, the auditor should not just rely on management's assurance without verifying the effectiveness of the new system.
upvoted 0 times
...
Glenn
28 days ago
I agree, it's important to ensure that the risk is truly mitigated before closing the issue.
upvoted 0 times
...
Felicidad
1 months ago
Option D seems like the best course of action. The auditor needs to verify that the new system actually addresses the risk.
upvoted 0 times
...
...
Carlota
2 months ago
Even if the new system has built-in controls, the agreed action plan should still be implemented.
upvoted 0 times
...
Mauricio
2 months ago
Haha, this reminds me of that time my boss tried to solve a problem by buying a new printer. Didn't work then, and it won't work here either. Option C is the way to go.
upvoted 0 times
Cristal
16 days ago
It's important to hold management accountable for addressing the audit recommendation.
upvoted 0 times
...
Rosann
16 days ago
Exactly, the auditor should escalate the issue to senior management and the board.
upvoted 0 times
...
Felicitas
19 days ago
I agree, just because they're getting a new system doesn't mean they can ignore the original issue.
upvoted 0 times
...
Monroe
21 days ago
Option C is definitely the best choice here.
upvoted 0 times
...
...
Huey
2 months ago
But what if the new system really does address the risk?
upvoted 0 times
...
Nieves
2 months ago
Option B seems reasonable to me. If the new system really does address the risk, then the auditor should trust management's judgment and close the issue.
upvoted 0 times
Alaine
2 months ago
But what if the new system doesn't actually address the risk? Shouldn't the auditor verify that first?
upvoted 0 times
...
Wilbert
2 months ago
I agree with you, option B does seem like a reasonable approach.
upvoted 0 times
...
...
Gilma
2 months ago
I agree with Carlota, management should not dismiss the prior obligation.
upvoted 0 times
...
Jannette
2 months ago
I think option C is the most appropriate action. Management can't just replace the system and ignore the previously agreed upon control implementation.
upvoted 0 times
Jeanice
2 months ago
That makes sense, it's important to follow up on audit recommendations to maintain control and compliance.
upvoted 0 times
...
Phung
2 months ago
The auditor should still escalate the issue to senior management and the board to ensure accountability.
upvoted 0 times
...
Vivienne
2 months ago
But what if the new system already has built-in controls that address the risks highlighted by the internal audit?
upvoted 0 times
...
Shakira
2 months ago
I agree, management should not dismiss the prior obligation to implement the agreed action plan.
upvoted 0 times
...
...
Carlota
3 months ago
I think option C is the most appropriate action.
upvoted 0 times
...

Save Cancel