IIA-CIA-PART1 · Question #140
Which of the following should be considered in developing a risk and control model for use in an engagement?
The correct answer is B. The risk and control model should be strictly adhered to in performing the engagement. Note: There may be an error in the answer key provided - the most defensible correct answer for this question is C, not B. Here's the explanation: --- Why C is correct: A risk and control model must be tailored to the specific organization being audited, because every…
Question
Which of the following should be considered in developing a risk and control model for use in an engagement?
Options
- AThe risk and control model should be globally accepted by the profession.
- BThe risk and control model should be strictly adhered to in performing the engagement.
- CThe risk and control model should be tailored to the organization that will be the subject of the
- DThe risk and control model should be developed individually by the auditor for use on individual
How the community answered
(39 responses)- A8% (3)
- B72% (28)
- C5% (2)
- D15% (6)
Explanation
Note: There may be an error in the answer key provided - the most defensible correct answer for this question is C, not B. Here's the explanation:
Why C is correct: A risk and control model must be tailored to the specific organization being audited, because every organization has a unique risk environment, culture, structure, and control framework. Applying a generic or rigid model would fail to capture organization-specific risks and could lead to flawed audit conclusions.
Why the other choices are wrong:
- A is wrong because no single risk and control model is (or needs to be) universally accepted across the entire profession - models vary by industry, framework, and context.
- B is wrong because "strictly adhered to" implies no flexibility; professional judgment must be exercised throughout an engagement, and models may need to be adjusted as new information emerges.
- D is wrong because developing a completely individual model for each engagement - without organizational context or alignment - lacks the consistency and rigor an engagement requires.
Memory tip: Think "fit to the client." Just as a tailor measures the individual before cutting cloth, an auditor tailors the risk and control model to fit the specific organization - not a one-size-fits-all template.
If your exam source consistently marks B as correct, double-check the source's edition, as this may reflect a transcription or keying error.
Community Discussion
No community discussion yet for this question.