An internal auditor is conducting an initial risk assessment of an audit area and wants to assess management's compliance with privacy laws for safeguarding customer information stored on the organization's servers. Which course of action is appropriate for this phase of the engagement?
For which of the following fraud engagement activities would it be most appropriate to involve a forensic auditor?
Which of the following is most likely to be judged as a significant residual risk that would exceed the organization's acceptable risk level?
A significant residual risk that would exceed the organization's acceptable risk level is likely to be one that has severe consequences, such as causing injuries or environmental pollution. These types of risks can have substantial legal, financial, and reputational impacts on an organization and are typically beyond acceptable levels of risk tolerance. Reference:
COSO's Enterprise Risk Management -- Integrating with Strategy and Performance.
The IIA's Practice Guide on Risk Management.
Which of the following would be most useful for an internal auditor to obtain during the preliminary survey of an engagement on internal controls over user access management?
Step-by-Step Detailed Explanation:
A . The policy for granting, modifying, and deleting user access:
Correct. Understanding the policy ensures the auditor knows the framework and controls in place.
B . A sample of change request forms:
Useful for testing but not as foundational as reviewing the policy.
C . User access reports reviewed by management:
This evaluates monitoring but does not establish a baseline understanding of controls.
D . A current listing of system users and employees:
Important for reconciliation but secondary to understanding the control framework.
CIA Exam Syllabus Reference:
Domain V: Performing Internal Audit Services -- Preliminary Surveys.
The internal audit activity of an insurance company is reviewing six of the company's 11 branches. During the review of the fourth branch that was selected, the internal audit team discovered control breaches that could result in regulatory sanctions if not addressed. How should the internal audit team proceed?
Dierdre
17 days agoCrissy
2 months agoLenna
3 months agoBlondell
4 months agoRonna
5 months agoCasandra
5 months agoEleonore
6 months agoLucy
7 months agoDenny
7 months agoDino
7 months agoChantay
8 months agoJaime
8 months agoMichal
8 months agoMerrilee
9 months agoPamella
9 months agoLenna
9 months agoLawanda
9 months agoAvery
10 months agoGail
10 months agoLeota
10 months agoDestiny
11 months agoElza
11 months agoJaime
1 years agoFrankie
1 years ago