IIA-CIA-PART2 · Question #9
When setting the scope for the identification and assessment of key risks and controls in a process, which of the following would be the least appropriate approach?
The correct answer is A. Develop the scope of the audit based on a bottom-up perspective to ensure that all business. When setting the scope for identifying and assessing key risks and controls in a process, developing the scope of the audit based on a bottom-up perspective is the least appropriate approach. A bottom-up perspective typically focuses on individual controls and processes without…
Question
When setting the scope for the identification and assessment of key risks and controls in a process, which of the following would be the least appropriate approach?
Options
- ADevelop the scope of the audit based on a bottom-up perspective to ensure that all business
- BDevelop the scope of the audit to include controls that are necessary to manage risk associated
- CSpecify that the auditors need to assess only key controls, but may include an assessment of non-
- DEnsure the audit includes an assessment of manual and automated controls to determine whether
How the community answered
(44 responses)- A84% (37)
- B9% (4)
- C5% (2)
- D2% (1)
Explanation
When setting the scope for identifying and assessing key risks and controls in a process, developing the scope of the audit based on a bottom-up perspective is the least appropriate approach. A bottom-up perspective typically focuses on individual controls and processes without necessarily aligning with the organization's critical business objectives and risk appetite. Effective risk assessment should begin with a top-down approach, identifying key business objectives and the associated risks, and then determining the necessary controls to manage these risks.
Topics
Community Discussion
No community discussion yet for this question.