Auditor response to management risk remediation claims?
When planning a follow-up, the IS auditor is informed by operational management that recent organizational changes have addressed the previously identified risk and implementing the action plan is no longer necessary. What should the auditor do NEXT?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the auditor's obligation to validate evidence rather than relying on management assertions, with the trap being the temptation to skip verification or focus prematurely on new risks.
Auditors must independently verify management's claims regarding risk remediation during follow-up procedures. The consensus is that accepting assertions without testing violates audit independence and due diligence.
Selecting B (Accept management's assertion) because it seems efficient, or D (Determine new risks) before confirming the original risk is actually resolved.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A is correct because auditors must maintain objectivity and independence. Relying solely on management's word is insufficient; the auditor must review the specific changes to validate that the controls effectively mitigate the previously identified risk.Why the Other Options Are Wrong
Option B violates the principle of independent verification. Option C is incorrect because auditors are expected to assess changes, not declare them impractical to evaluate. Option D is a secondary step; one must first confirm the original risk is addressed before assessing for new ones.Community Comment Notes
Comment [1] emphasizes the need to validate claims and ensure independence. Comment [3] clarifies the sequence: "First A, then D," reinforcing that reviewing the changes is the immediate priority before looking for new risks.Exam Strategy
Always prioritize the sequence of audit steps. When management claims a fix, verify the fix first (testing), then look for side effects (new risks).
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →