nerdexam
IIA

IIA-CIA-PART3 · Question #13

An internal auditor is assigned to perform data analytics. Which of the following is the next step the auditor should undertake after she has ascertained the value expected from the review?

The correct answer is C. Identify the risks. Identifying risks (C) is the correct next step because after establishing the expected value of the review, the auditor must define what she is looking for - the specific risks that data analytics will help assess. Without this scoping step, she wouldn't know which data to…

Question

An internal auditor is assigned to perform data analytics. Which of the following is the next step the auditor should undertake after she has ascertained the value expected from the review?

Options

  • ANormalize the data,
  • BObtain the data
  • CIdentify the risks.

How the community answered

(39 responses)
  • A
    15% (6)
  • B
    5% (2)
  • C
    79% (31)

Explanation

Identifying risks (C) is the correct next step because after establishing the expected value of the review, the auditor must define what she is looking for - the specific risks that data analytics will help assess. Without this scoping step, she wouldn't know which data to request or how to interpret it.

Why B is wrong: Obtaining data comes after risk identification. Collecting data before knowing the target risks wastes effort and may result in pulling irrelevant datasets that don't address audit objectives.

Why A is wrong: Normalizing (cleaning/standardizing) data is a later-stage technical step that logically requires the data to already be in hand - it cannot precede either risk identification or data collection.

Memory tip: Use the acronym VROD - Value → Risks → Obtain → Data-normalize. Each step answers a question in sequence: Why are we doing this? What are we looking for? What do we need? Is the data clean? The exam will often test whether you know that risk identification drives data selection, not the other way around.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART3 Practice