IIA-CIA-PART1 · Question #193
Which should the internal auditor first consider when assessing fraud risks during an engagement?
The correct answer is B. Review any related prior fraud investigations. Reviewing prior fraud investigations (B) is the correct first step because historical patterns reveal where the organization has been vulnerable, what fraud schemes have been attempted, and whether control weaknesses were remediated - giving the auditor a grounded starting…
Question
Which should the internal auditor first consider when assessing fraud risks during an engagement?
Options
- ACompare the organizations fraud strategies with the industry's strategies.
- BReview any related prior fraud investigations.
- CInvestigate any related fraud allegations.
- DCommunicate any suspicious fraud activities to management.
How the community answered
(23 responses)- A4% (1)
- B78% (18)
- C4% (1)
- D13% (3)
Explanation
Reviewing prior fraud investigations (B) is the correct first step because historical patterns reveal where the organization has been vulnerable, what fraud schemes have been attempted, and whether control weaknesses were remediated - giving the auditor a grounded starting point before expanding the assessment.
Why the distractors are wrong:
- A - Benchmarking industry fraud strategies is useful for context but isn't the first priority; internal history is more directly relevant to the specific organization's risk profile.
- C - Investigating allegations is reactive and premature at the assessment stage; investigation comes after sufficient planning and evidence-gathering, not as an initial step.
- D - Communicating suspicious activity to management is an action taken once something specific is identified, not a consideration during the assessment phase before findings exist.
Memory tip: Think "look back before you leap" - an auditor always reviews the organization's own fraud history first, because past fraud is the strongest predictor of where future fraud risk lives.
Community Discussion
No community discussion yet for this question.