What is the MAIN purpose of an organization's internal IS audit function?
A.
Identify and initiate necessary changes in the control environment to help ensure sustainable improvement.
B.
Independently attest the organization’s compliance with applicable legal and regulatory requirements.
C.
Review the organization's policies and procedures against industry best practices and standards.
D.
Provide assurance to management about the effectiveness of the organization's risk management and internal controls.
The Answer Is:
D
This question includes an explanation.
Explanation:
Comprehensive and Detailed Step-by-Step Explanation:
Theprimary roleof an internalIS audit functionis to provideindependent assuranceonrisk management, internal controls, and governance processes.
Option A (Incorrect):While audits may identifycontrol improvements, they donot initiate changes; management is responsible for implementation.
Option B (Incorrect):Compliance audits arepartof IS auditing, but the main focus isassurance on risk and controls, not just compliance.
Option C (Incorrect):Best practices and standards reviews are useful, but theydo not definethecore objectiveof an internal audit.
Option D (Correct):The internal audit function'smain goalis toassess and assurethe effectiveness of an organization’srisk management and internal controls.
[Reference:ISACA CISA Review Manual –Domain 1: Information Systems Auditing Process– Coversaudit objectives, assurance functions, and risk management., , ]
CISA PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"