A chief audit executive (CAE) determined that management chose to accept a high-level risk that may be unacceptable lo the organization. Which is the best course of action for the CAE to Follow?
Which of the following constitutes supervisory activity undertaken during the planning phase of an assurance engagement?
During follow-up, the chief audit executive (CAE) is having a discussion with management about the internal audit team ' s recommendations related to a significant issue Management accepted the issue but took no remedial action What is the next step for the CAE?
Which of the following factors should a chief audit executive consider when determining the audit universe?
1. Components of the organization ' s strategic plan.
2. Inputs from senior management and the board.
3. Views of competitors and business associates.
4. Results of exit interviews with departing employees.
A technology organization is developing an artificial intelligence (AI) program for use on its social media platform. The AI program is meant to help content creators with images and posts that will acquire followers more efficiently. The internal audit function is planning an engagement of the AI program development. Which of the following should be considered a significant, immediate, and inherent risk?
Which of the following evaluation criteria would be the most useful to help the chief audit executive determine whether an external service provider possesses the knowledge, skills, and other competencies needed to perform a review?
Which of the following would most likely cause an internal auditor to consider adding fraud work steps to the audit program?
An internal auditor developed a list of internal and external risk considerations across the organization ' s processes, developed a scale to assess each risk and allocated the relative importance of each risk. When of the following approaches did the auditor take?
If there is a significant error or omission in the final audit report that was communicated to management, which of the following is the key action for the internal audit activity?
Which of the following steps should an internal auditor complete when conducting a review of an electronic data interchange application provided by a third-party service?
Ensure encryption keys meet ISO standards.
Determine whether an independent review of the service provider ' s operation has been conducted.
Verify that the service provider’s contracts include necessary clauses.
Verify that only public-switched data networks are used by the service provider.
In which of the following ways can the internal audit activity new engagement opportunities?
According to IIA guidance, which of the following statements about analytical procedures is true?
Which of the following internal audit activity staffing models has the disadvantage that auditors are always new and in training?
According to IIA guidance, which of the following best describes the purpose of a planning memorandum for an audit engagement?
Which of the following structures would best suit a maintenance organization that needs to adapt quickly to rapidly changing technology?