712-50 · Question #431
Who is responsible for verifying that audit directives are implemented?
The correct answer is B. Internal Audit. Internal Audit (B) is responsible for verifying that audit directives are implemented because its core function is to provide independent assurance that recommendations and corrective actions from audits are actually carried out - not just issued. IT Management (A) is…
Question
Who is responsible for verifying that audit directives are implemented?
Options
- AIT Management
- BInternal Audit
- CIT Security
- DBOD Audit Committee
How the community answered
(39 responses)- A3% (1)
- B74% (29)
- C8% (3)
- D15% (6)
Explanation
Internal Audit (B) is responsible for verifying that audit directives are implemented because its core function is to provide independent assurance that recommendations and corrective actions from audits are actually carried out - not just issued. IT Management (A) is responsible for implementing the directives, not verifying them; conflating the doer with the verifier would undermine audit independence. IT Security (C) handles operational security controls and may be subject to audit findings, but lacks the oversight mandate to verify cross-functional compliance. The BOD Audit Committee (D) sets audit direction and receives reports, but relies on Internal Audit to do the ground-level follow-up verification work.
Memory tip: Think of Internal Audit as the "audit police" - they issue the ticket (finding), and they also come back to check that you paid it (verified implementation). Management drives the car; audit checks the license.
Topics
Community Discussion
No community discussion yet for this question.