CGEIT · Question #211
Which of the following is the MOST important reason to include internal audit as a stakeholder when establishing clear roles for the governance of IT?
The correct answer is D. Internal audit provides input on relevant issues and control processes.. Including internal audit in IT governance roles is crucial because they provide independent input on control processes and relevant IT risk issues.
Question
Which of the following is the MOST important reason to include internal audit as a stakeholder when establishing clear roles for the governance of IT?
Options
- AInternal audit has knowledge and technical expertise to advise on IT infrastructure.
- BInternal audit is accountable for the overall enterprise governance of IT.
- CInternal audit implements controls over IT risks and security.
- DInternal audit provides input on relevant issues and control processes.
How the community answered
(32 responses)- B3% (1)
- C6% (2)
- D91% (29)
Why each option
Including internal audit in IT governance roles is crucial because they provide independent input on control processes and relevant IT risk issues.
While internal auditors may possess some IT knowledge, their primary function is assurance and control evaluation, not advising on IT infrastructure design or technical solutions.
Enterprise governance of IT is a responsibility of the board and executive management, not solely internal audit, which provides an assurance role.
Internal audit assesses the effectiveness of controls over IT risks and security, but they do not implement these controls; that is the responsibility of management.
Internal audit's primary role is to provide independent and objective assurance and consulting services designed to add value and improve an organization's operations. By including them, they can offer critical insights into the effectiveness of proposed control processes, identifying potential weaknesses or areas of non-compliance before they become issues, thus enhancing the overall governance framework.
Concept tested: Internal audit role in IT governance
Topics
Community Discussion
No community discussion yet for this question.