IIA-CIA-PART1 · Question #104
When the chief audit executive Is responsible for risk management in an organization, which of the following parties is responsible for overseeing the internal audit activity's assurance over risk…
The correct answer is C. A party outside of the internal audit activity. When a Chief Audit Executive (CAE) holds dual responsibility for risk management, they face an inherent self-review threat - they cannot independently oversee assurance on a function they themselves manage. IIA standards (specifically guidance on CAE roles beyond internal…
Question
When the chief audit executive Is responsible for risk management in an organization, which of the following parties is responsible for overseeing the internal audit activity's assurance over risk management?
Options
- AThe chief audit executive.
- BA member of the compliance function.
- CA party outside of the internal audit activity.
- DA member of the risk management function.
How the community answered
(25 responses)- A12% (3)
- B4% (1)
- C80% (20)
- D4% (1)
Explanation
When a Chief Audit Executive (CAE) holds dual responsibility for risk management, they face an inherent self-review threat - they cannot independently oversee assurance on a function they themselves manage. IIA standards (specifically guidance on CAE roles beyond internal auditing) require that a party outside the internal audit activity - typically the board or audit committee - take on that oversight role to preserve objectivity.
Why the distractors are wrong:
- A (the CAE): The CAE is the one with the conflict; having them oversee their own assurance work defeats the purpose of independent oversight entirely.
- B (compliance function member): Compliance staff have no authority or appropriate positioning to oversee internal audit's assurance activities - that's not their governance role.
- D (risk management function member): Risk management is the very area being audited; someone from that function overseeing the audit of it creates the same objectivity problem as option A.
Memory tip: Use the phrase "You can't grade your own exam." Whenever the CAE "owns" a business function, the board or audit committee (an outside party) must step in to review the IA work on that function - just as a student can't mark their own test fairly.
Community Discussion
No community discussion yet for this question.