{"id":20542,"date":"2026-09-24T06:01:52","date_gmt":"2026-09-24T06:01:52","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20542"},"modified":"2026-09-24T06:01:52","modified_gmt":"2026-09-24T06:01:52","slug":"iia-iia-cia-part2-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iia-iia-cia-part2-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"IIA IIA-CIA-Part2 Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/iia-cia-part2-exam-dumps\"><b>IIA IIA-CIA-Part2 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 101.<\/b><\/p>\n<p><b>What is the primary purpose of an internal audit engagement opening conference?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Confirm objectives, scope, timing, responsibilities, and information needs with relevant stakeholders<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Finalize all findings before fieldwork begins<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow management to determine the audit conclusion<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transfer risk ownership to internal audit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Confirm objectives, scope, timing, responsibilities, and information needs with relevant stakeholders<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An opening conference helps establish a common understanding of the engagement before detailed work begins. Internal audit can explain the objectives, scope, timing, communication process, and documentation requirements, while management can provide operational context and identify relevant contacts. This reduces misunderstandings and helps the engagement proceed efficiently without compromising internal audit\u2019s independence or professional judgment.<\/span><\/p>\n<p><b>Question 102.<\/b><\/p>\n<p><b>Which factor should MOST influence the selection of audit procedures for a specific engagement objective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The auditor\u2019s familiarity with a particular procedure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The amount of evidence needed to address the relevant risk<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The length of the prior report<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The number of managers involved in the process<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The amount of evidence needed to address the relevant risk<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Audit procedures should be selected based on the engagement objective, the significance of the related risk, the reliability of available controls, and the nature of the evidence needed. The auditor should choose procedures that are capable of producing sufficient, reliable, relevant, and useful information. Familiarity or convenience should not determine the testing approach if another procedure would provide stronger evidence.<\/span><\/p>\n<p><b>Question 103.<\/b><\/p>\n<p><b>What is the primary purpose of tracing transactions from source documents into accounting or operational records?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Test whether recorded transactions are complete<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether recorded transactions actually occurred<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace reconciliation procedures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Evaluate employee competence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Determine whether recorded transactions actually occurred<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tracing from source documents into records is generally used to determine whether transactions that occurred were properly captured in the organization\u2019s records. Depending on the direction of testing, auditors may address completeness or occurrence. The auditor should understand the specific assertion being tested and select the direction of testing accordingly so that the procedure supports the intended conclusion.<\/span><\/p>\n<p><b>Question 104.<\/b><\/p>\n<p><b>Which procedure BEST tests whether all transactions that should have been recorded were actually captured?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reviewing only recorded transactions for approval<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Examining only high-value journal entries<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Comparing source documents to the related recorded transactions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Asking management whether records are complete<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Comparing source documents to the related recorded transactions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Testing completeness usually begins with evidence that a transaction occurred and follows it into the organization\u2019s records. For example, an auditor might select receiving documents and trace them to inventory or accounts payable records. This helps determine whether transactions that should have been recorded were omitted. Inquiry alone is less persuasive because management may not be aware of all missing items.<\/span><\/p>\n<p><b>Question 105.<\/b><\/p>\n<p><b>What is the primary purpose of vouching recorded transactions back to supporting documentation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether recorded transactions are supported and actually occurred<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Test only population completeness<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate the need for authorization testing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine the final audit rating<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether recorded transactions are supported and actually occurred<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vouching generally starts with a recorded transaction and moves back to source documentation. It helps determine whether the transaction is genuine, supported, authorized, and accurately recorded. This procedure is commonly used to address occurrence or existence concerns. It should be distinguished from tracing, which often begins with source evidence and follows it into the records to test completeness.<\/span><\/p>\n<p><b>Question 106.<\/b><\/p>\n<p><b>Which technique is MOST appropriate for determining whether a process is being performed in accordance with documented procedures?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> External confirmation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Observation combined with inquiry and document review<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Recalculation only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reviewing the organizational chart<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Observation combined with inquiry and document review<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Observation allows the auditor to see how the process actually operates, while inquiry provides context and document review shows what procedures require. Combining these techniques helps identify differences between documented and actual practice. Observation alone may be limited to the period observed, so corroborating evidence improves the strength of the conclusion.<\/span><\/p>\n<p><b>Question 107.<\/b><\/p>\n<p><b>What is the primary purpose of testing user access rights during an information systems audit?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether users have permissions appropriate to their job responsibilities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase the number of system users<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace authentication controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate the need for access reviews<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether users have permissions appropriate to their job responsibilities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Access testing helps internal audit determine whether system permissions follow principles such as least privilege and appropriate segregation of duties. Excessive or inappropriate access can create risks of unauthorized transactions, data exposure, or control override. Auditors may compare user rights with job responsibilities, review privileged accounts, and test whether terminated or transferred employees retained unnecessary access.<\/span><\/p>\n<p><b>Question 108.<\/b><\/p>\n<p><b>Which control would BEST reduce the risk of inappropriate privileged system activity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow administrators to review their own activities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate system logging<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give all users administrator rights<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Independently monitor and review privileged-user activity**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Independently monitor and review privileged-user activity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged users may have the ability to modify systems, data, user accounts, or logs. Independent monitoring helps reduce the risk that inappropriate activity will go undetected. Organizations may use logging, approval controls, session monitoring, access reviews, or segregation of duties. The monitoring should be performed by someone sufficiently independent of the privileged activity.<\/span><\/p>\n<p><b>Question 109.<\/b><\/p>\n<p><b>What is the primary purpose of change-management testing during an IT audit?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether system changes were appropriately authorized, tested, approved, and implemented<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Prevent all technology changes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace system backup procedures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether users like the new system<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether system changes were appropriately authorized, tested, approved, and implemented<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Poorly controlled changes can introduce errors, security weaknesses, outages, or unauthorized functionality. Internal audit may examine change requests, approvals, testing evidence, migration procedures, emergency changes, and production access. The goal is to determine whether changes are managed in a controlled way while still supporting legitimate business needs.<\/span><\/p>\n<p><b>Question 110.<\/b><\/p>\n<p><b>What is the primary purpose of reviewing emergency system changes separately from normal changes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Emergency changes are always unauthorized<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They may bypass normal procedures and therefore require appropriate retrospective review and approval<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They never require documentation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They are automatically low risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. They may bypass normal procedures and therefore require appropriate retrospective review and approval<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Emergency changes may need to be implemented quickly to restore service or address urgent problems. Because the normal change process may be shortened, organizations should still require documentation, appropriate approval, testing where feasible, and retrospective review. Internal audit may evaluate whether the emergency process is used only when justified and whether controls compensate for reduced preimplementation review.<\/span><\/p>\n<p><b>Question 111.<\/b><\/p>\n<p><b>What is the primary purpose of reviewing interfaces between systems?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether data transferred between systems is complete, accurate, and appropriately controlled<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate the need for reconciliations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Guarantee that systems use identical software<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace user access testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether data transferred between systems is complete, accurate, and appropriately controlled<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">System interfaces can create risks when records are dropped, duplicated, altered, or transmitted incorrectly. Internal audit may examine reconciliations, error logs, control totals, automated validation, and exception handling. Reliable interface controls are important when critical information flows between operational, financial, or third-party systems.<\/span><\/p>\n<p><b>Question 112.<\/b><\/p>\n<p><b>Which procedure would BEST help determine whether automated application controls are operating as designed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reading only the system manual<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Asking the developer whether the control works<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Testing transactions or configurations and comparing results with expected outcomes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reviewing the organization chart<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Testing transactions or configurations and comparing results with expected outcomes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Automated controls should be tested using evidence that demonstrates how the system actually behaves. This may involve inspecting configuration settings, processing test transactions, reperforming system logic, or analyzing system outputs. Written documentation and inquiry are helpful for understanding the control but generally do not provide enough evidence by themselves to conclude on operating effectiveness.<\/span><\/p>\n<p><b>Question 113.<\/b><\/p>\n<p><b>What is the primary purpose of reviewing exception reports generated by an automated system?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether unusual or rejected transactions are identified and appropriately followed up<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace preventive controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Guarantee that every exception represents fraud<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate the need for management review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether unusual or rejected transactions are identified and appropriately followed up<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Exception reports are useful only when significant exceptions are reviewed and resolved. Internal audit should assess whether the report captures relevant conditions, whether responsible personnel investigate exceptions, and whether follow-up is documented. Large volumes of unresolved alerts can weaken the control because important items may be overlooked.<\/span><\/p>\n<p><b>Question 114.<\/b><\/p>\n<p><b>Which factor is MOST important when relying on an automated report used by management as a key control?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the report is visually attractive<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the report logic and underlying data are complete and accurate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether management prints the report<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the report is generated daily<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Whether the report logic and underlying data are complete and accurate<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A management review control may fail if the report being reviewed contains inaccurate or incomplete information. Internal audit should therefore consider the reliability of the underlying data, filters, calculations, report logic, and access controls. The frequency or appearance of the report does not compensate for unreliable information.<\/span><\/p>\n<p><b>Question 115.<\/b><\/p>\n<p><b>What is the primary purpose of reviewing system logs during an audit?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identify relevant user, transaction, security, or configuration activity recorded by the system<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace all interviews<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Guarantee that no unauthorized activity occurred<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate the need for access controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Identify relevant user, transaction, security, or configuration activity recorded by the system<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">System logs can provide valuable evidence about user access, changes, failures, security events, and transaction activity. However, internal audit should assess whether logging is complete and whether logs are protected from alteration. Logs may be especially useful when investigating unusual events or confirming whether activities occurred at specific times.<\/span><\/p>\n<p><b>Question 116.<\/b><\/p>\n<p><b>What is the main risk if users can alter or delete logs that record their own activity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Logs will become easier to analyze<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> System performance will always improve<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The evidence may be unreliable because inappropriate activity could be concealed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The system will automatically prevent fraud<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The evidence may be unreliable because inappropriate activity could be concealed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If users can change records of their own activity, they may be able to conceal errors or unauthorized actions. Appropriate logging controls may include restricted access, centralized log storage, retention settings, independent monitoring, and alerts for suspicious activity. Internal audit should consider log integrity before relying on system-generated evidence.<\/span><\/p>\n<p><b>Question 117.<\/b><\/p>\n<p><b>What is the primary purpose of reviewing disaster recovery testing results?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether recovery procedures and resources are capable of restoring critical systems within established expectations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Guarantee that no disaster will occur<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace business continuity planning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate the need for backups<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether recovery procedures and resources are capable of restoring critical systems within established expectations<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Disaster recovery plans should be tested to determine whether systems, data, people, and procedures can support recovery objectives. Internal audit may review test scenarios, results, unresolved weaknesses, restoration times, and lessons learned. A plan that has never been tested may contain outdated assumptions or procedures that fail under actual conditions.<\/span><\/p>\n<p><b>Question 118.<\/b><\/p>\n<p><b>Which factor should MOST influence the frequency and depth of disaster recovery testing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The size of the audit department<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The criticality of systems and the potential impact of disruption<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether management prefers testing less often<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The age of the recovery plan document<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The criticality of systems and the potential impact of disruption<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">More critical systems generally warrant stronger recovery capabilities and more meaningful testing. The organization should consider business impact, recovery objectives, system complexity, significant changes, regulatory expectations, and prior test results. Internal audit should evaluate whether the testing approach is proportionate to the importance of the systems being protected.<\/span><\/p>\n<p><b>Question 119.<\/b><\/p>\n<p><b>What is the primary purpose of reviewing cybersecurity incident-response procedures during an engagement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether responsibilities and processes are established for identifying, containing, investigating, recovering from, and communicating incidents<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Guarantee that attacks cannot occur<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace preventive security controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transfer incident ownership to internal audit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether responsibilities and processes are established for identifying, containing, investigating, recovering from, and communicating incidents<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Incident response planning helps the organization react quickly and consistently when cybersecurity events occur. Internal audit may assess escalation procedures, responsibilities, evidence preservation, legal involvement, recovery steps, communications, and lessons learned. The audit role is to evaluate preparedness and controls rather than to assume operational responsibility for responding to incidents.<\/span><\/p>\n<p><b>Question 120.<\/b><\/p>\n<p><b>Which approach BEST supports effective internal audit testing of information systems and technology controls?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Rely only on written IT policies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Focus exclusively on user passwords<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Test relevant access, change, interface, automated, logging, recovery, and incident-response controls using reliable evidence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume automated controls are effective because they are system-based<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Test relevant access, change, interface, automated, logging, recovery, and incident-response controls using reliable evidence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Technology risks often span several control domains. Effective internal audit work should identify the systems and risks relevant to the engagement and test controls with procedures capable of producing reliable evidence. Automated controls are not automatically effective simply because they are system-based. Their configuration, dependencies, access, data quality, and operation should be evaluated in the context of the risks they are intended to manage.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IIA IIA-CIA-Part2 Exam Dumps and Practice Test Dumps &nbsp; Question 101. What is the primary purpose of an internal audit engagement opening conference? Confirm objectives, scope, timing, responsibilities, and information needs with relevant stakeholders Finalize all findings before fieldwork begins Allow management to determine the audit conclusion Transfer risk ownership to internal audit [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20542"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20542"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20542\/revisions"}],"predecessor-version":[{"id":20543,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20542\/revisions\/20543"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20542"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}