Which of the following should be the PRIMARY basis for prioritizing follow-up audits?
A.
Audit cycle defined in the audit plan
B.
Complexity of management's action plans
C.
Recommendation from executive management
D.
Residual risk from the findings of previous audits
The Answer Is:
D
This question includes an explanation.
Explanation:
Residual risk from the findings of previous audits should be the primary basis for prioritizing follow-up audits, because it reflects the level of exposure and potential impact that remains after management has implemented corrective actions or accepted the risk. Follow-up audits should focus on verifying whether the residual risk is within acceptable levels and whether the corrective actions are effective and sustainable. Audit cycle defined in the audit plan, complexity of management’s action plans, and recommendation from executive managementare not valid criteria for prioritizingfollow-up audits,because they do not consider the residual risk from previous audits. References: CISA Review Manual (Digital Version), Chapter 2, Section 2.4.3
CISA PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"