IIA-CIA-PART1 · Question #167
When performing an audit of the risk management process an auditor makes the observations listed below. Which poses the greatest risk to the organization?
The correct answer is C. The process in place to identify and evaluate new risks to the organization is informal and poorly. Option C represents the greatest risk because a flawed or informal risk identification process means the organization may be entirely unaware of new and emerging threats - you cannot manage risks you haven't identified. All subsequent risk management activities (prioritization…
Question
When performing an audit of the risk management process an auditor makes the observations listed below. Which poses the greatest risk to the organization?
Options
- AThe identified risks have not undergone a detailed review to ensure completeness in the past two
- BThe controls in place to mitigate the risks are not tested on an annual basis to confirm operating
- CThe process in place to identify and evaluate new risks to the organization is informal and poorly
- DThe identified risks have not been ranked to establish their importance and risk management
How the community answered
(38 responses)- A5% (2)
- B16% (6)
- C74% (28)
- D5% (2)
Explanation
Option C represents the greatest risk because a flawed or informal risk identification process means the organization may be entirely unaware of new and emerging threats - you cannot manage risks you haven't identified. All subsequent risk management activities (prioritization, controls, testing) are only as good as the risk inventory feeding them, so a broken identification process undermines the entire framework.
Why the distractors fall short:
- A is a gap in review completeness, but the risks were identified - the concern is whether the list is still current, not whether threats are being missed in real time.
- B relates to control effectiveness testing, which is important, but controls exist and are presumably working; lack of periodic testing is a gap, not a blind spot.
- D (failure to rank/prioritize risks) makes resource allocation harder, but the risks are still known - the organization can still act on them even without formal ranking.
Memory tip: Think of risk management as a pipeline - Identify → Evaluate → Prioritize → Control → Test. A failure at the very first stage poisons everything downstream. On exam questions about "greatest risk," look for the option that breaks the foundation, not one that creates inefficiency in a later stage. Informal or missing identification = flying blind.
Community Discussion
No community discussion yet for this question.