IIA-CIA-PART2 · Question #57
An organization's board would like to establish a formal risk management function and has asked the chief audit executive (CAE) to be involved in the process. According to IIA guidance, which of the…
The correct answer is D. Accept management's responsibility for risk management without board approval. According to IIA guidance, the chief audit executive (CAE) should maintain independence and objectivity in their role. While the CAE can manage and coordinate risk management processes, audit those processes, and be involved in risk oversight committees, they should not accept…
Question
An organization's board would like to establish a formal risk management function and has asked the chief audit executive (CAE) to be involved in the process. According to IIA guidance, which of the following roles should the CAE not undertake?
Options
- AManage and coordinate risk management processes.
- BAudit risk management processes.
- CBecome involved in risk oversight committees, monitoring activities, and status reporting.
- DAccept management's responsibility for risk management without board approval.
How the community answered
(41 responses)- A2% (1)
- B7% (3)
- C12% (5)
- D78% (32)
Explanation
According to IIA guidance, the chief audit executive (CAE) should maintain independence and objectivity in their role. While the CAE can manage and coordinate risk management processes, audit those processes, and be involved in risk oversight committees, they should not accept management's responsibility for risk management without the board's approval. This ensures that there is no conflict of interest and maintains the CAE's independence.
Topics
Community Discussion
No community discussion yet for this question.