nerdexam
IIA

IIA-CIA-PART2 · Question #9

When setting the scope for the identification and assessment of key risks and controls in a process, which of the following would be the least appropriate approach?

The correct answer is A. Develop the scope of the audit based on a bottom-up perspective to ensure that all business. When setting the scope for identifying and assessing key risks and controls in a process, developing the scope of the audit based on a bottom-up perspective is the least appropriate approach. A bottom-up perspective typically focuses on individual controls and processes without…

Planning the Engagement

Question

When setting the scope for the identification and assessment of key risks and controls in a process, which of the following would be the least appropriate approach?

Options

  • ADevelop the scope of the audit based on a bottom-up perspective to ensure that all business
  • BDevelop the scope of the audit to include controls that are necessary to manage risk associated
  • CSpecify that the auditors need to assess only key controls, but may include an assessment of non-
  • DEnsure the audit includes an assessment of manual and automated controls to determine whether

How the community answered

(44 responses)
  • A
    84% (37)
  • B
    9% (4)
  • C
    5% (2)
  • D
    2% (1)

Explanation

When setting the scope for identifying and assessing key risks and controls in a process, developing the scope of the audit based on a bottom-up perspective is the least appropriate approach. A bottom-up perspective typically focuses on individual controls and processes without necessarily aligning with the organization's critical business objectives and risk appetite. Effective risk assessment should begin with a top-down approach, identifying key business objectives and the associated risks, and then determining the necessary controls to manage these risks.

Topics

#audit scope#risk identification#key controls#bottom-up approach

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART2 Practice