nerdexam
IIA

IIA-CIA-PART2 · Question #370

Following an IT systems audit, management agreed to implement a specific control in one of the IT systems. After a period, the internal auditor followed up and learned that management had not…

The correct answer is A. The auditor examines the system documentation of the new system to verify that the risk has been. In this scenario, the most appropriate action for the internal auditor is to verify that the risk highlighted by the previous audit has indeed been addressed by the new IT system. This involves a detailed examination of the system documentation and possibly testing the controls…

Communicating Results and Monitoring Progress

Question

Following an IT systems audit, management agreed to implement a specific control in one of the IT systems. After a period, the internal auditor followed up and learned that management had not implemented the agreed management action due to the decision to move to another IT system that has built-in controls, which may address the risks highlighted by the internal audit. Which of the following is the most appropriate action to address the outstanding audit recommendation?

Options

  • AThe auditor examines the system documentation of the new system to verify that the risk has been
  • BThe auditor accepts management's explanation that the previously identified issue is adequately
  • CThe auditor advises management that replacing the IT system does not dismiss the prior obligation
  • DThe auditor requires management to provide details regarding the process for selecting the new IT

How the community answered

(47 responses)
  • A
    66% (31)
  • B
    21% (10)
  • C
    4% (2)
  • D
    9% (4)

Explanation

In this scenario, the most appropriate action for the internal auditor is to verify that the risk highlighted by the previous audit has indeed been addressed by the new IT system. This involves a detailed examination of the system documentation and possibly testing the controls within the new system. Once the auditor confirms that the new system adequately addresses the identified risk, they should report this finding to senior management and close the issue. This approach ensures that the internal audit activity adheres to the IIA Standards regarding follow- up on audit findings, which requires auditors to ensure that agreed-upon actions have been implemented

Topics

#follow-up procedures#IT systems audit#management action plans#risk verification

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART2 Practice