IIA-CIA-PART1 · Question #90
What is an appropriate first step in an internal auditor's fraud risk assessment to evaluate how the organization manages such risk?
The correct answer is B. Identify potential fraud scenarios. Identifying potential fraud scenarios (B) is the correct first step because you cannot manage, assess, or respond to risks you haven't yet named - the entire risk assessment process depends on first establishing what frauds could actually occur in the organization's specific…
Question
What is an appropriate first step in an internal auditor’s fraud risk assessment to evaluate how the organization manages such risk?
Options
- ADevelop preventive and detective controls
- BIdentify potential fraud scenarios
- CAssess the impact and likelihood of fraud risks
- DDetermine fraud risk responses
How the community answered
(50 responses)- A6% (3)
- B84% (42)
- C2% (1)
- D8% (4)
Explanation
Identifying potential fraud scenarios (B) is the correct first step because you cannot manage, assess, or respond to risks you haven't yet named - the entire risk assessment process depends on first establishing what frauds could actually occur in the organization's specific context. Option A (developing controls) skips ahead to solutions before the problem is fully understood. Option C (assessing impact and likelihood) is the second step - you can only score risks after you've identified what they are. Option D (determining responses) comes even later, after risks have been identified and assessed.
Memory tip: Think of fraud risk assessment like a doctor's visit - you identify symptoms (scenarios) before you diagnose severity (impact/likelihood) before you prescribe treatment (controls and responses). B → C → A/D is the logical sequence, and the exam will often test whether you know that identification always precedes evaluation.
Community Discussion
No community discussion yet for this question.