While planning an assurance engagement over an insurer's claims-handling process, the internal audit team learns a new data-protection regulation took effect this quarter and directly governs how claims data is stored. The original scope, drafted last year, does not mention it. What is the best next step?
- AKeep the original scope and note the regulation as a matter for next year's engagement plan instead.
- BAsk management to confirm in writing that the process already complies, and rely on that confirmation for scope.
- CRevise the engagement objectives and scope to reflect the new regulation's requirements affecting claims-data controls. Correct
- DExpand the scope to audit the organisation's entire regulatory-compliance function across all departments.
Why A is wrong: Deferring is tempting to protect the timeline, but a live regulation governing the very data under review is a current risk the scope should address.
Why B is wrong: A management assurance is low-reliability evidence and does not replace the team's own scoping judgement about a newly relevant regulation.
Why C is correct: Regulatory requirements shape objectives, so updating scope to cover the new data-protection rules keeps the engagement relevant to current risk.
Why D is wrong: This overreaches; the trigger is one regulation affecting claims data, and ballooning scope organisation-wide dilutes the engagement objectives.