The chief audit executive at Redmayne Group is standardising a control rating scale so that ratings are applied consistently across engagements and support the residual risk conclusion. What should each control rating primarily be anchored to?
- ABoth the design adequacy and the operating effectiveness of the control, so the rating conveys how much residual risk remains once the control is taken into account. Correct
- BThe count of exceptions found during testing, assigning the weakest rating whenever an exception is identified regardless of its effect.
- CThe inherent risk of the process the control sits in, so that controls in higher-risk processes receive weaker ratings irrespective of the test results.
- DManagement's own assessment of how the control performs, adopted into the rating without independent testing by the engagement team.
Why A is correct: A rating scale is useful when it reflects design and operation together, because that is what determines the residual exposure the rating is meant to communicate.
Why B is wrong: This is tempting because exceptions clearly matter, but an exception count alone ignores materiality and the control's design, so it distorts how much residual risk the rating should convey.
Why C is wrong: This is tempting because riskier processes deserve scrutiny, but it confuses the process risk with the control's own performance; a strong control in a risky process can still be rated strong.
Why D is wrong: This is tempting because management understands its controls, but adopting a self-assessment without independent evidence undermines the objectivity the rating is supposed to provide.