IIA-CIA-PART2 · Question #370
Following an IT systems audit, management agreed to implement a specific control in one of the IT systems. After a period, the internal auditor followed up and learned that management had not…
The correct answer is A. The auditor examines the system documentation of the new system to verify that the risk has been. In this scenario, the most appropriate action for the internal auditor is to verify that the risk highlighted by the previous audit has indeed been addressed by the new IT system. This involves a detailed examination of the system documentation and possibly testing the controls…
Question
Following an IT systems audit, management agreed to implement a specific control in one of the IT systems. After a period, the internal auditor followed up and learned that management had not implemented the agreed management action due to the decision to move to another IT system that has built-in controls, which may address the risks highlighted by the internal audit. Which of the following is the most appropriate action to address the outstanding audit recommendation?
Options
- AThe auditor examines the system documentation of the new system to verify that the risk has been
- BThe auditor accepts management's explanation that the previously identified issue is adequately
- CThe auditor advises management that replacing the IT system does not dismiss the prior obligation
- DThe auditor requires management to provide details regarding the process for selecting the new IT
How the community answered
(47 responses)- A66% (31)
- B21% (10)
- C4% (2)
- D9% (4)
Explanation
In this scenario, the most appropriate action for the internal auditor is to verify that the risk highlighted by the previous audit has indeed been addressed by the new IT system. This involves a detailed examination of the system documentation and possibly testing the controls within the new system. Once the auditor confirms that the new system adequately addresses the identified risk, they should report this finding to senior management and close the issue. This approach ensures that the internal audit activity adheres to the IIA Standards regarding follow- up on audit findings, which requires auditors to ensure that agreed-upon actions have been implemented
Topics
Community Discussion
No community discussion yet for this question.