nerdexam
IIA

IIA-CIA-PART1 · Question #95

A new internal audit activity is considering the adoption of a risk and control framework. Which of the following is the most appropriate consideration during this process?

The correct answer is C. The framework should always be tailored to the organization. Option C is correct because a risk and control framework must reflect the unique risk profile, industry, regulatory environment, and strategic objectives of the specific organization - a one-size-fits-all approach fails to address the actual risks the organization faces. Option…

Question

A new internal audit activity is considering the adoption of a risk and control framework. Which of the following is the most appropriate consideration during this process?

Options

  • AThe framework should not be developed by the internal audit activity
  • BThe framework should apply to individual projects rather than the organization as a whole
  • CThe framework should always be tailored to the organization
  • DThe framework should require fewer resources to implement

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    6% (1)
  • C
    76% (13)
  • D
    12% (2)

Explanation

Option C is correct because a risk and control framework must reflect the unique risk profile, industry, regulatory environment, and strategic objectives of the specific organization - a one-size-fits-all approach fails to address the actual risks the organization faces. Option A is wrong because while external frameworks (like COSO or ISO 31000) can serve as starting points, the internal audit activity plays a key role in adapting and applying the framework internally. Option B is wrong because an effective framework should operate at the organizational level to ensure consistency and comprehensive coverage, not be siloed to individual projects. Option D is wrong because resource efficiency is a secondary concern - the primary driver is fitness for purpose, and an under-resourced framework that fails to capture key risks is worse than no framework at all.

Memory tip: Think "tailor-made suit" - just as a suit needs to be fitted to the individual, a risk and control framework must be fitted to the organization. The word "tailored" in option C is your signal that this is the correct answer on any IIA-style question about framework adoption.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART1 Practice