nerdexam
IIA

IIA-CIA-PART1 · Question #217

According to the Standards, in today's technology and business environments, how much computer and information systems-related knowledge and skills must an internal auditor have to be effective in…

The correct answer is D. Auditors must understand their organization's IT governance, risk, and control processes. Option D reflects the IIA Standards (specifically Standard 1210), which require internal auditors to have sufficient knowledge of IT risks, governance, and control processes to evaluate them - not deep technical expertise. This is a broad, organization-wide understanding, not a…

Question

According to the Standards, in today's technology and business environments, how much computer and information systems-related knowledge and skills must an internal auditor have to be effective in fulfilling his job responsibilities?

Options

  • AAuditors must have an IT specialty in at least one of their organization's key information
  • BAuditors must be proficient in data analysis and computer assisted audit techniques for their
  • CAuditors must understand their organization's integrated test facilities and generalized audit
  • DAuditors must understand their organization's IT governance, risk, and control processes.

How the community answered

(56 responses)
  • A
    4% (2)
  • B
    7% (4)
  • C
    16% (9)
  • D
    73% (41)

Explanation

Option D reflects the IIA Standards (specifically Standard 1210), which require internal auditors to have sufficient knowledge of IT risks, governance, and control processes to evaluate them - not deep technical expertise. This is a broad, organization-wide understanding, not a narrow technical skill set.

Why the distractors are wrong:

  • A is too strong - auditors are not required to hold an IT specialty in any particular system; they need awareness, not specialization.
  • B is too narrow and prescriptive - while data analysis skills are valuable, the Standards don't mandate proficiency in specific techniques like CAATs for all auditors.
  • C is too specific - integrated test facilities and generalized audit software are particular tools; the Standards speak to broader governance and control understanding, not mastery of specific software.

Memory tip: Think of it as the "governance lens" - internal auditors are expected to understand IT at the oversight level (governance, risk, controls), just as they would for any other business process. If an answer option names a specific tool, technique, or specialty, it's almost certainly too narrow to be the Standards-based answer.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART1 Practice