IIA-CIA-PART1 · Question #183
Internal controls belong to which risk response category?
The correct answer is A. Reduction. Internal controls - such as segregation of duties, authorization requirements, and reconciliation procedures - are designed to reduce the likelihood or impact of a risk, which places them squarely in the Reduction (mitigation) category. They don't eliminate risk entirely, which…
Question
Internal controls belong to which risk response category?
Options
- AReduction.
- BAvoidance.
- CSharing.
- DAcceptance.
How the community answered
(23 responses)- A74% (17)
- B13% (3)
- C9% (2)
- D4% (1)
Explanation
Internal controls - such as segregation of duties, authorization requirements, and reconciliation procedures - are designed to reduce the likelihood or impact of a risk, which places them squarely in the Reduction (mitigation) category. They don't eliminate risk entirely, which is what Avoidance (B) requires - avoidance means ceasing the activity that creates the risk altogether. Sharing (C) involves transferring risk to a third party, such as through insurance or outsourcing, which controls don't do. Acceptance (D) means acknowledging the risk and taking no action, the opposite of implementing controls.
Memory tip: Think of the acronym RASA - Reduce, Avoid, Share, Accept. Internal controls control (i.e., reduce) risk; if the org wanted to avoid it, they'd stop the activity entirely.
Community Discussion
No community discussion yet for this question.