nerdexam
IIA

IIA-CIA-PART1 · Question #183

Internal controls belong to which risk response category?

The correct answer is A. Reduction. Internal controls - such as segregation of duties, authorization requirements, and reconciliation procedures - are designed to reduce the likelihood or impact of a risk, which places them squarely in the Reduction (mitigation) category. They don't eliminate risk entirely, which…

Question

Internal controls belong to which risk response category?

Options

  • AReduction.
  • BAvoidance.
  • CSharing.
  • DAcceptance.

How the community answered

(23 responses)
  • A
    74% (17)
  • B
    13% (3)
  • C
    9% (2)
  • D
    4% (1)

Explanation

Internal controls - such as segregation of duties, authorization requirements, and reconciliation procedures - are designed to reduce the likelihood or impact of a risk, which places them squarely in the Reduction (mitigation) category. They don't eliminate risk entirely, which is what Avoidance (B) requires - avoidance means ceasing the activity that creates the risk altogether. Sharing (C) involves transferring risk to a third party, such as through insurance or outsourcing, which controls don't do. Acceptance (D) means acknowledging the risk and taking no action, the opposite of implementing controls.

Memory tip: Think of the acronym RASA - Reduce, Avoid, Share, Accept. Internal controls control (i.e., reduce) risk; if the org wanted to avoid it, they'd stop the activity entirely.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART1 Practice