nerdexam
Isaca

CISA · Question #223

Management has decided to accept a risk in response to a draft audit recommendation. Which of the following should be the IS auditor's NEXT course of action?

The correct answer is C. Document management's acceptance in the audit report.. The IS auditor should record management's decision to accept the risk in the audit report, ensuring it is clearly documented. This provides transparency and accountability, noting that management has consciously decided to accept the identified risk. Escalating the acceptance to

Submitted by the_admin· Apr 18, 2026Information System Auditing Process

Question

Management has decided to accept a risk in response to a draft audit recommendation. Which of the following should be the IS auditor's NEXT course of action?

Options

  • AEnsure a follow-up audit is on next year's plan.
  • BEscalate the acceptance to the board.
  • CDocument management's acceptance in the audit report.
  • DEscalate acceptance to the audit committee.

How the community answered

(50 responses)
  • A
    12% (6)
  • B
    6% (3)
  • C
    80% (40)
  • D
    2% (1)

Explanation

The IS auditor should record management's decision to accept the risk in the audit report, ensuring it is clearly documented. This provides transparency and accountability, noting that management has consciously decided to accept the identified risk. Escalating the acceptance to the board or audit committee may be necessary only if the accepted risk is significantly outside the organization's risk appetite or policy. However, the first step is to document the decision. Ensuring a follow-up audit can be planned if required, but documenting the decision is the most immediate and essential action.

Topics

#Audit Reporting#Management Response#Risk Acceptance

Community Discussion

No community discussion yet for this question.

Full CISA Practice