IIA-CIA-PART2 · Question #161
An internal audit activity is planning its first audit of IT shared services. Which of the following controls would typically be evaluated first?
The correct answer is A. Entity-level controls. When planning the first audit of IT shared services, it is typical to evaluate entity-level controls first. Entity-level controls are overarching controls that affect the entire organization and are foundational for ensuring that specific application and transaction controls…
Question
An internal audit activity is planning its first audit of IT shared services. Which of the following controls would typically be evaluated first?
Options
- AEntity-level controls
- BApplication controls
- CGeneral controls.
- DTransaction controls
How the community answered
(30 responses)- A93% (28)
- C3% (1)
- D3% (1)
Explanation
When planning the first audit of IT shared services, it is typical to evaluate entity-level controls first. Entity-level controls are overarching controls that affect the entire organization and are foundational for ensuring that specific application and transaction controls operate effectively. These controls include the organization's governance, risk management processes, and the overall control environment. Assessing entity-level controls provides a broad understanding of the control environment and highlights any pervasive issues that might impact more detailed areas of
Topics
Community Discussion
No community discussion yet for this question.