Q: 9
Which of the following is the BEST way for a risk practitioner to verify that management has
addressed control issues identified during a previous external audit?
Options
Discussion
B . Actually seeing the control enhancements working is the strongest evidence that issues were addressed, not just planned. Action plans (D) are good for intent but don't guarantee it's in place or effective. Saw similar wording on a practice test too. Pretty sure B's what they'd expect here, but open to pushback if anyone disagrees.
B . Trap is D, but seeing control enhancements in operation is better proof than just reviewing action plans.
Yeah, it's B here.
Option B. If the question asked for the FIRST step instead of BEST, would A make more sense?
Option B is probably right here since directly observing the control in action gives solid proof that management did something about the audit findings. The official study guide and practice exams both push for evidence that's actually operational, not just planned or documented. Action plans and interviews can help, but they're not as strong as seeing the fix work. I think B is safest, but happy to hear if anyone's seen guidance saying otherwise.
Definitely B. Directly observing the control fixes is the clearest way to know they've been handled. Anyone disagree?
I can see why B is usually correct, but what if the control enhancement isn't easily observable in practice, like with some automated controls or process changes that run infrequently? In those edge cases, reviewing documentation (C) might be more reliable. Still, B fits ISACA's typical preference. Open to pushback here!
C or D. Audit docs and action plans both show how management responded. I think direct observation is less practical sometimes.
C vs D? In some cases, inspecting audit docs or action plans is more reliable than direct observation, especially if controls aren't continuous.
D , since reviewing management's detailed action plans directly shows how they're addressing the issues. B is tempting though.
Be respectful. No spam.