nerdexam
IIA

IIA-CIA-PART1 · Question #24

An internal auditor at a multinational organization is reviewing the effectiveness of the organization's risk management framework. In this scenario, which of the following statements is true?

The correct answer is B. Regardless of their location, employees at all levels share responsibility for designing effective. Option B correctly reflects a foundational principle from the COSO Internal Control framework and IIA Standards: internal control is a shared responsibility across all employees at all organizational levels, regardless of geographic location. In a multinational setting, this is…

Question

An internal auditor at a multinational organization is reviewing the effectiveness of the organization's risk management framework. In this scenario, which of the following statements is true?

Options

  • AThe auditor should consider local cultures and customs in various regions when assessing control
  • BRegardless of their location, employees at all levels share responsibility for designing effective
  • CTo achieve an effective internal control environment, the organization's risk management plan
  • DSetting clear objectives is a precondition to effectively identifying, assessing, and responding to

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    79% (22)
  • C
    14% (4)
  • D
    4% (1)

Explanation

Option B correctly reflects a foundational principle from the COSO Internal Control framework and IIA Standards: internal control is a shared responsibility across all employees at all organizational levels, regardless of geographic location. In a multinational setting, this is especially important - a subsidiary in one country cannot claim exemption from control responsibilities simply due to regional differences.

Why the distractors are wrong:

  • A is misleading because while cultural awareness is relevant context for an auditor, local customs do not override or redefine what constitutes effective control - standards apply organization-wide.
  • C conflates the risk management plan with the broader internal control environment; a documented plan alone does not create an effective control environment - it also requires tone at the top, monitoring, and active participation at all levels.
  • D is partially true (setting objectives is important in COSO ERM), but it presents this as the primary precondition in a way that oversimplifies the framework; multiple interrelated components are required, not just objective-setting.

Memory tip: Think of the phrase "Everyone, Everywhere, Every Level" - internal control responsibility is universal across geography, role, and rank. If an answer limits that responsibility by location or job level, it's likely wrong.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART1 Practice