IIA-CIA-Part2 Exam Question 176

An internal auditor at a bank informed the branch manager of a malfunctioning lock on one of the vaults. The risk associated with this issue was deemed significant by the chief audit executive (CAE), and immediate remediation was recommended. However, during a follow-up engagement, the branch manager told the CAE that the risk was actually not significant, hence no action was taken. What is the most appropriate next step for the CAE?
  • IIA-CIA-Part2 Exam Question 177

    An internal auditor is conducting a financial audit. Which of the following audit procedures is most appropriate when existing internal controls are weak?
  • IIA-CIA-Part2 Exam Question 178

    An internal auditor discovered that equipment used to monitor air quality was not maintained according to the established maintenance schedule. If the issue is not addressed, the equipment may not provide accurate information on pollutant levels, which could result in regulatory sanctions and reputational damage. The auditor discussed the issue with both the manager in charge and the CEO, who explained that they understand the risk, but it has become too expensive to maintain the equipment as scheduled. In this situation, what should the chief audit executive do?
  • IIA-CIA-Part2 Exam Question 179

    Flowcharts are useful during audit planning because they contain information that may help internal auditors with which of the following?
  • IIA-CIA-Part2 Exam Question 180

    A customer has supplied personal information to a bank to facilitate opening an account. The bank is part of a larger group of companies with core businesses including general insurance, life insurance, and investment products. Considering that the customer has closed his only account with the bank and the statutory data retention period has elapsed, which of the following actions by the bank is most likely to align with appropriate data privacy principles?