IIA-CIA-PART1 · Question #92
Which of the following best describes the approach the internal audit activity should take to assess and make appropriate recommendations to improve the organization?
The correct answer is B. To determine how an organization provides oversight of its risk management and control activities. Option B is correct because internal audit's core mandate - as defined by the IIA's International Standards - is to evaluate and improve the effectiveness of risk management, control, and governance processes. "Oversight of risk management and control activities" captures the…
Question
Which of the following best describes the approach the internal audit activity should take to assess and make appropriate recommendations to improve the organization?
Options
- ATo evaluate an organization s governance processes for making strategic and operational decisions
- BTo determine how an organization provides oversight of its risk management and control activities
- CTo assess how an organization promotes ethics and values both internally and among its external
- DTo evaluate how an organization ensures effective performance management and accountability
How the community answered
(47 responses)- A4% (2)
- B74% (35)
- C6% (3)
- D15% (7)
Explanation
Option B is correct because internal audit's core mandate - as defined by the IIA's International Standards - is to evaluate and improve the effectiveness of risk management, control, and governance processes. "Oversight of risk management and control activities" captures the comprehensive, organization-wide assurance scope that internal audit is uniquely positioned to provide.
Why the distractors fall short:
- A is too narrow: evaluating governance for strategic/operational decisions is just one slice of governance, not the full risk-and-control picture.
- C is also too narrow: ethics and values promotion is a governance sub-element, not a complete description of how internal audit drives improvement across the organization.
- D describes a management and HR function (performance management/accountability), not an internal audit responsibility.
Memory tip: Remember the IIA's three-pillar acronym RCG - Risk management, Control, Governance. Internal audit's job is to provide assurance and recommendations across all three. Option B is the only choice that explicitly covers risk and control (with governance implied through "oversight"), making it the most complete answer.
Community Discussion
No community discussion yet for this question.