nerdexam
IIA

IIA-CIA-PART2 · Question #161

An internal audit activity is planning its first audit of IT shared services. Which of the following controls would typically be evaluated first?

The correct answer is A. Entity-level controls. When planning the first audit of IT shared services, it is typical to evaluate entity-level controls first. Entity-level controls are overarching controls that affect the entire organization and are foundational for ensuring that specific application and transaction controls…

Planning the Engagement

Question

An internal audit activity is planning its first audit of IT shared services. Which of the following controls would typically be evaluated first?

Options

  • AEntity-level controls
  • BApplication controls
  • CGeneral controls.
  • DTransaction controls

How the community answered

(30 responses)
  • A
    93% (28)
  • C
    3% (1)
  • D
    3% (1)

Explanation

When planning the first audit of IT shared services, it is typical to evaluate entity-level controls first. Entity-level controls are overarching controls that affect the entire organization and are foundational for ensuring that specific application and transaction controls operate effectively. These controls include the organization's governance, risk management processes, and the overall control environment. Assessing entity-level controls provides a broad understanding of the control environment and highlights any pervasive issues that might impact more detailed areas of

Topics

#entity-level controls#IT audit planning#control hierarchy#shared services

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART2 Practice