CIA-2 - Engagement Planning - Section A.5

Complete a detailed risk assessment of each activity under review, applying Topical Requirements and recognizing pervasive risks, emerging risks, and the impact of organizational structure and culture on the assessment.

Complete a risk assessment of the activity under review that recognises pervasive financial, operational, IT, cybersecurity, and regulatory risks, and the impact of emerging risks. Determine appropriate methods and criteria to evaluate and prioritise identified risks and controls, and account for how changes in people, processes, and systems, organisational structure such as centralised versus decentralised, and culture and tone at the top affect the control environment.

Risk assessmentEmerging riskOrganizational cultureTopical Requirements

Practice question for this objective

Free sampleEngagement Planninghard

An auditor planning a review of a bank's small-business lending unit maps risks specific to that unit but omits considering the bank's recent group-wide switch to an aggressive growth incentive plan and a new data-privacy regulation taking effect next year. Which category of risk has the auditor most clearly failed to incorporate into the detailed risk assessment?

  • ADetection risk arising from the sampling approach the engagement team intends to apply to the loan files during fieldwork later this year.
  • BResidual risk, because the auditor recorded inherent exposures for the unit without netting them against the controls management operates.
  • CSampling risk, because omitting the group-level factors changes the population of individual loan files the team must select and test.
  • DPervasive and emerging risks, because the incentive plan can affect behaviour across the unit and the pending regulation is a developing external exposure. Correct
A detailed risk assessment must incorporate pervasive risks that cut across an activity and emerging risks from developing external conditions, not only unit-specific risks. A group-wide incentive plan influences conduct throughout the lending activity, making it pervasive, while a regulation that is not yet in force is an emerging risk that could reshape future exposure; both must feed the assessment so planning is not confined to isolated, current, unit-level risks.

Why A is wrong: Tempting because sampling affects assurance quality, but detection risk concerns the audit procedures themselves, not the external and organisation-wide exposures the auditor overlooked.

Why B is wrong: Tempting since residual risk matters, but the omission described is entering wider organisational and external factors, not the separate step of assessing control effectiveness.

Why C is wrong: Tempting as scope shapes populations, but sampling risk is about whether a sample represents a population, not about missing pervasive and emerging exposures in the assessment.

Why D is correct: Correct: an incentive that shifts conduct across the whole activity is pervasive, and a not-yet-effective regulation is an emerging risk; a detailed assessment must consider both alongside unit-specific risks.

See more CIA-2 practice questions, answers explained.

More in this domain

Back to all Engagement Planning objectives, or the CIA-2 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.