nerdexam
IIA

IIA-CIA-PART2 · Question #152

Prior to performing testing an internal auditor has determined that a primary process control failed due to design weakness. Which of the following actions should the auditor perform next?

The correct answer is A. Determine whether there are any compensating controls in place to reduce the nsk to an. When an internal auditor identifies a primary control failure due to a design weakness, the next step is to assess the risk and determine if there are any compensating controls that mitigate this risk. Compensating controls can help to reduce the overall risk to an acceptable…

Performing the Engagement

Question

Prior to performing testing an internal auditor has determined that a primary process control failed due to design weakness. Which of the following actions should the auditor perform next?

Options

  • ADetermine whether there are any compensating controls in place to reduce the nsk to an
  • BTest the control anyway to determine the likelihood that the control was not performed property,
  • CConclude that the process control environment is weak, issue a finding on this conclusion and
  • DConfer with a second internal auditor to determine whether the control failure is legitimate issue a

How the community answered

(34 responses)
  • A
    82% (28)
  • B
    3% (1)
  • C
    3% (1)
  • D
    12% (4)

Explanation

When an internal auditor identifies a primary control failure due to a design weakness, the next step is to assess the risk and determine if there are any compensating controls that mitigate this risk. Compensating controls can help to reduce the overall risk to an acceptable level. Engaging with management to discuss the issue and determine the necessary corrective actions ensures that the control environment is adequately addressed. This approach aligns with the internal auditor's role in providing assurance and consulting services designed to add value and improve an organization's operations.

Topics

#compensating controls#control design weakness#risk assessment#audit procedures

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART2 Practice