Which of the following standards would be most useful in evaluating the performance of a customer-service group?
The chief audit executive (CAE) identified an unacceptable risk and believes that the risk is not being mitigated to an acceptable level. Which of the following is the CAE ' s next step in this situation?
At what point during the systems development process should an internal auditor verify that the new application ' s connectivity to the organization ' s other systems has been established correctly?
Which of the following is the most appropriate way to record each partner’s initial investment in a partnership?
An organization with global headquarters in the United States has subsidiaries in eight other nations. If the organization operates with an ethnocentric attitude, which of the following statements is true?
A new chief audit executive (CAE) reviews long overdue audit recommendations, which have been repeatedly reported to senior management but have not been implemented, and is unsure which issues should be escalated to the board. Which of the following would serve as the best guide in this scenario?
Which of the following documents would provide an internal auditor with information on the length of time to maintain documents after the completion of an engagement?
Which of the following control techniques would minimize the risk of interception during transmission in an electronic data interchange system?
Encryption.
Traffic padding.
Edit checks.
Structured data format.
An organization is considering outsourcing its IT services, and the internal auditor as assessing the related risks. The auditor grouped the related risks into three categories;
- Risks specific to the organization itself.
- Risks specific to the service provider.
- Risks shared by both the organization and the service provider
Which of the following risks should the auditor classify as specific to the service provider?
Which of the following types of date analytics would be used by a hospital to determine which patients are likely to require remittance for additional treatment?
An organization prepares a statement of privacy to protect customers ' personal information. Which of the following might violate the privacy principles?
Which of the following is an example of a key systems development control typically found in the in-house development of an application system?
Which of the following key performance indicators would serve as the best measurement of internal audit innovation?
During a review of the accounts payable process, an internal auditor gathered all of the vendor payment transactions for the past 24 months. The auditor then used an Analytics tool to identify the top five vendors that received the highest sum of payments. Which of the following analytics techniques did the auditor apply?
Which of the following is a disadvantage in a centralized organizational structure?