CRISC · Question #164
CRISC Question #164: Real Exam Question with Answer & Explanation
The correct answer is C: A system-generated testing report. A system-generated testing report offers the most reliable evidence of a control's effectiveness because it provides objective, verifiable data from actual operations. Unlike human-driven assessments or attestations, automated reports offer consistent and unbiased proof of contro
Question
Which of the following provides the MOST reliable evidence of a control's effectiveness?
Options
- AA risk and control self-assessment
- BSenior management's attestation
- CA system-generated testing report
- Ddetailed process walk-through
Explanation
A system-generated testing report offers the most reliable evidence of a control's effectiveness because it provides objective, verifiable data from actual operations. Unlike human-driven assessments or attestations, automated reports offer consistent and unbiased proof of control performance.
Common mistakes.
- A. A risk and control self-assessment relies on internal personnel's subjective evaluation, which, while useful, is not as objective or verifiable as automated testing.
- B. Senior management's attestation is a statement of belief or confirmation, but it is not direct, objective evidence of a control's operational effectiveness.
- D. A detailed process walk-through can help understand how a control is designed to operate, but it does not provide consistent, verifiable data on its continuous effectiveness in the same way a system-generated report does.
Concept tested. Control effectiveness evidence
Topics
Community Discussion
No community discussion yet for this question.