nerdexam
IIA

IIA-CIA-PART1 · Question #12

The largest risks facing an organization should be mitigated by which type of controls?

The correct answer is A. Entity-level. Entity-level controls are the appropriate mitigation for an organization's largest risks because they operate across the entire organization, addressing systemic exposures that no narrower control could adequately contain - examples include the control environment, board…

Question

The largest risks facing an organization should be mitigated by which type of controls?

Options

  • AEntity-level
  • BActivity-level
  • CTransaction-level
  • DProcess-level

How the community answered

(33 responses)
  • A
    82% (27)
  • B
    3% (1)
  • C
    9% (3)
  • D
    6% (2)

Explanation

Entity-level controls are the appropriate mitigation for an organization's largest risks because they operate across the entire organization, addressing systemic exposures that no narrower control could adequately contain - examples include the control environment, board oversight, company-wide policies, and enterprise risk management frameworks. Activity-level controls (B) apply only to specific functional areas or business units, making them too narrow in scope for organization-wide risks. Transaction-level controls (C) are the most granular, governing individual transactions like invoice approvals or cash receipts - useful for operational accuracy but not designed to address strategic or entity-wide threats. Process-level controls (D) govern specific business processes and sit between activity and entity scope, but they still lack the reach needed to mitigate the largest risks that cut across the whole organization.

Memory tip: Think of a pyramid - Entity is the apex, covering everything beneath it. The biggest risks live at the top, so they need top-level controls. When you see "largest risks," think "highest level" → Entity.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART1 Practice