nerdexam
IIA

IIA-CIA-PART1 · Question #73

An internal auditor is assessing the effectiveness of the organization's risk management practices She checks to see whether risk management is an intégrai part of decision making and whether risk…

The correct answer is A. Maturity model approach. Option A is correct because a maturity model approach evaluates risk management by assessing its overall integration, quality, and sophistication within the organization - checking characteristics like whether RM is embedded in decision-making, transparent, adaptive, and…

Question

An internal auditor is assessing the effectiveness of the organization's risk management practices She checks to see whether risk management is an intégrai part of decision making and whether risk management is transparent, responsive to change and addresses uncertainty. According to HA guidance on risk management frameworks, which of the following approaches is the auditor most likely using?

Options

  • AMaturity model approach
  • BProcess element approach
  • CKey principles approach
  • DKey performance indicators approach.

How the community answered

(19 responses)
  • A
    74% (14)
  • B
    5% (1)
  • C
    5% (1)
  • D
    16% (3)

Explanation

Option A is correct because a maturity model approach evaluates risk management by assessing its overall integration, quality, and sophistication within the organization - checking characteristics like whether RM is embedded in decision-making, transparent, adaptive, and uncertainty-focused are hallmarks of gauging where an organization sits on a RM maturity spectrum. Option B (process element approach) is wrong because it focuses on specific procedural steps in the risk management cycle (e.g., identify → assess → treat → monitor), not on integrative qualities. Option C (key principles approach) is the most tempting distractor since these characteristics resemble ISO 31000 principles, but in IIA's framework, that approach examines adherence to explicitly named, numbered principles rather than holistic integration characteristics. Option D (KPI approach) is wrong because it relies on measurable, quantitative performance metrics rather than qualitative assessments of how RM functions organizationally.

Memory tip: Think "maturity = how grown-up RM is in the organization" - if the auditor is asking how well-embedded and culturally integrated RM is (transparent? part of decisions? adaptive?), that's maturity, not process steps or named principles.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART1 Practice