IIA-CHAL-QISA Exam Question 51

An organization does not have a formal risk management function. According to the Standards, which of the following are conditions where the internal audit activity may provide risk management consulting?
1.There is a clear strategy and timeline to migrate risk management responsibility back to management.
2.The internal audit activity has the final approval on any risk management decisions.
3.The internal audit activity gives objective assurance on all parts of the risk management framework for which it is responsible.
4.The nature of services provided to the organization is documented in the internal audit charter.
  • IIA-CHAL-QISA Exam Question 52

    The organization's internal audit charter was last updated six years ago to update the charter, which of the following actions is most appropriate for the chief audit executive to take?
  • IIA-CHAL-QISA Exam Question 53

    Which of the following statements is true regarding the management-by-objectives method?
  • IIA-CHAL-QISA Exam Question 54

    Applying ISO 31000; which of the following is part of the external context for risk management?
  • IIA-CHAL-QISA Exam Question 55

    During which phase of the contracting process are contracts drafted for a proposed business activity'