QuestionQ114

Information System Auditing Process

An IS auditor’s draft report recommends developing a procedure for IT server backups. During the closing meeting, the IT manager agrees to implement only some of the report’s recommendations. What action should the auditor take FIRST to address this situation?

Explanation

When management accepts only part of an audit recommendation, the unaddressed portion remains a risk that requires review by audit management. Audit management can assess the significance of the residual risk, determine whether to accept it, and decide whether escalation is warranted before the report is finalized.

Community Discussion

No comments yet. Be the first to start the discussion!