nerdexam
IIA

IIA-CIA-PART1 · Question #203

Which combination of strategies would provide the best evaluation of the effectiveness of the organization's risk assessment activity? 1. Interview staff at various levels to discuss the…

The correct answer is C. 1.3. and 4 only. Option C (strategies 1, 3, and 4) directly targets the three pillars of evaluating a risk assessment process: whether people understand and apply risk concepts (strategy 1), whether identified risks translate into appropriate control responses (strategy 3), and whether the…

Question

Which combination of strategies would provide the best evaluation of the effectiveness of the organization's risk assessment activity? 1. Interview staff at various levels to discuss the organization's objectives, significant risks, and risk appetite. 2. Review board meeting minutes to determine whether the significant risks identified are communicated timely to the board. 3. Evaluate the adequacy and timeliness of management remediation actions by reviewing the control design, testing the controls, and reviewing monitoring procedures. 4. Review the professional development plans of internal audit staff to ensure all are competent to assess the organization's risk assessment activity.

Options

  • B1.2, and 3 only.
  • C1.3. and 4 only.
  • D3 and 4 only.

How the community answered

(45 responses)
  • B
    16% (7)
  • C
    76% (34)
  • D
    9% (4)

Explanation

Option C (strategies 1, 3, and 4) directly targets the three pillars of evaluating a risk assessment process: whether people understand and apply risk concepts (strategy 1), whether identified risks translate into appropriate control responses (strategy 3), and whether the evaluators themselves are qualified to make this judgment (strategy 4). Strategy 2 is the distractor because reviewing board meeting minutes evaluates risk communication and governance, not the risk assessment activity itself - the question specifically asks about assessing the risk assessment process, not how findings are reported upward. Option B incorrectly includes strategy 2 while excluding strategy 4, missing the critical competency check on the auditors conducting the evaluation. Option D is too narrow, omitting the essential evidence-gathering step of interviewing staff (strategy 1), which is fundamental to understanding whether the organization's risk awareness is embedded at multiple levels.

Memory tip: Mentally separate "risk assessment" (identifying, analyzing, and prioritizing risks) from "risk reporting" (communicating results to the board) - any strategy focused on upward communication is evaluating governance, not the assessment process itself.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART1 Practice