CIA-3 - Engagement Results and Monitoring - Section D.6

Describe the chief audit executive's responsibility for assessing residual risk for the engagement, including methodologies for assessing control design and effectiveness and aggregating findings.

Recognise the methodologies for assessing the design adequacy and operating effectiveness of existing controls to determine the resulting level of residual risk. Describe the purpose of aggregating and prioritising engagement findings, and the purpose of using a rating scale to reflect the overall assessment of controls for the engagement.

Residual riskControl rating scaleAggregated findings

Practice question for this objective

Free sampleEngagement Results and Monitoringhard

The chief audit executive at Redmayne Group is standardising a control rating scale so that ratings are applied consistently across engagements and support the residual risk conclusion. What should each control rating primarily be anchored to?

  • ABoth the design adequacy and the operating effectiveness of the control, so the rating conveys how much residual risk remains once the control is taken into account. Correct
  • BThe count of exceptions found during testing, assigning the weakest rating whenever an exception is identified regardless of its effect.
  • CThe inherent risk of the process the control sits in, so that controls in higher-risk processes receive weaker ratings irrespective of the test results.
  • DManagement's own assessment of how the control performs, adopted into the rating without independent testing by the engagement team.
A control rating should reflect both design adequacy and operating effectiveness, because together they determine the residual risk the rating communicates. A consistent control rating scale conveys residual exposure only when it is anchored to how well a control is designed and how well it operates, rather than to exception counts, process risk, or unverified self-assessment.

Why A is correct: A rating scale is useful when it reflects design and operation together, because that is what determines the residual exposure the rating is meant to communicate.

Why B is wrong: This is tempting because exceptions clearly matter, but an exception count alone ignores materiality and the control's design, so it distorts how much residual risk the rating should convey.

Why C is wrong: This is tempting because riskier processes deserve scrutiny, but it confuses the process risk with the control's own performance; a strong control in a risky process can still be rated strong.

Why D is wrong: This is tempting because management understands its controls, but adopting a self-assessment without independent evidence undermines the objectivity the rating is supposed to provide.

See more CIA-3 practice questions, answers explained.

More in this domain

Back to all Engagement Results and Monitoring objectives, or the CIA-3 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.