IIA-CIA-PART2 · Question #41
A large investment organization hired a chief risk officer (CRO) to be responsible for the organization's risk management processes. Which of the following people should prioritize risks to be used…
The correct answer is C. The chief audit executive, although he is not accountable for risk management in the organization. The chief audit executive (CAE) should prioritize risks to be used for the audit plan. Although the CAE is not accountable for managing risks, he is responsible for ensuring that the internal audit activity provides assurance on the effectiveness of the risk management…
Question
A large investment organization hired a chief risk officer (CRO) to be responsible for the organization's risk management processes. Which of the following people should prioritize risks to be used for the audit plan?
Options
- AOperational management, because they are responsible for the day-to-day management of the
- BThe CRO, because he is responsible for coordinating and project managing risk activities based
- CThe chief audit executive, although he is not accountable for risk management in the organization.
- DThe CEO, because he has ultimate responsibility for ensuring that risks are managed within the
How the community answered
(43 responses)- A9% (4)
- B14% (6)
- C72% (31)
- D5% (2)
Explanation
The chief audit executive (CAE) should prioritize risks to be used for the audit plan. Although the CAE is not accountable for managing risks, he is responsible for ensuring that the internal audit activity provides assurance on the effectiveness of the risk management processes. The CAE must understand the organization's risk landscape and determine which areas require audit attention based on their significance and potential impact.
Topics
Community Discussion
No community discussion yet for this question.