IIA-CIA-PART1 · Question #217
According to the Standards, in today's technology and business environments, how much computer and information systems-related knowledge and skills must an internal auditor have to be effective in…
The correct answer is D. Auditors must understand their organization's IT governance, risk, and control processes. Option D reflects the IIA Standards (specifically Standard 1210), which require internal auditors to have sufficient knowledge of IT risks, governance, and control processes to evaluate them - not deep technical expertise. This is a broad, organization-wide understanding, not a…
Question
According to the Standards, in today's technology and business environments, how much computer and information systems-related knowledge and skills must an internal auditor have to be effective in fulfilling his job responsibilities?
Options
- AAuditors must have an IT specialty in at least one of their organization's key information
- BAuditors must be proficient in data analysis and computer assisted audit techniques for their
- CAuditors must understand their organization's integrated test facilities and generalized audit
- DAuditors must understand their organization's IT governance, risk, and control processes.
How the community answered
(56 responses)- A4% (2)
- B7% (4)
- C16% (9)
- D73% (41)
Explanation
Option D reflects the IIA Standards (specifically Standard 1210), which require internal auditors to have sufficient knowledge of IT risks, governance, and control processes to evaluate them - not deep technical expertise. This is a broad, organization-wide understanding, not a narrow technical skill set.
Why the distractors are wrong:
- A is too strong - auditors are not required to hold an IT specialty in any particular system; they need awareness, not specialization.
- B is too narrow and prescriptive - while data analysis skills are valuable, the Standards don't mandate proficiency in specific techniques like CAATs for all auditors.
- C is too specific - integrated test facilities and generalized audit software are particular tools; the Standards speak to broader governance and control understanding, not mastery of specific software.
Memory tip: Think of it as the "governance lens" - internal auditors are expected to understand IT at the oversight level (governance, risk, controls), just as they would for any other business process. If an answer option names a specific tool, technique, or specialty, it's almost certainly too narrow to be the Standards-based answer.
Community Discussion
No community discussion yet for this question.