CIA-3 - Engagement Results and Monitoring - Section D.7

Describe the process for communicating risk acceptance when management has accepted a level of risk that may be unacceptable to the organization, including the appropriate parties and sequence of steps.

Recognise the method for determining whether a level of risk that management has accepted is actually unacceptable to the organisation as a whole. Recognise the appropriate parties who must be involved in communicating a risk acceptance decision, and the proper sequence of steps the internal audit function follows to escalate it.

Risk acceptanceEscalation of unacceptable risk

Practice question for this objective

Free sampleEngagement Results and Monitoringhard

A chief audit executive at Brentwood Utilities concludes that senior management has accepted a level of cyber risk that may exceed what the organisation can bear. The chief audit executive wants to follow the correct sequence for communicating this concern. What is the appropriate course?

  • ADiscuss the matter with senior management first, and if the chief audit executive concludes it remains unresolved, communicate it to the board. Correct
  • BReport the accepted risk directly to the external regulator before raising it internally, since the exposure could harm parties beyond the organisation.
  • CRecord the disagreement in the working papers and take no further step unless the risk later materialises into an actual loss.
  • DEscalate the matter to the board straight away without first discussing it with senior management, to protect the function's independence.
Communicating an unacceptable risk acceptance follows a sequence: raise it with senior management first, then escalate to the board if unresolved. The process gives senior management the first opportunity to address the accepted risk, and only where the chief audit executive concludes the matter is still unresolved does the obligation to inform the board arise, preserving an ordered escalation path.

Why A is correct: Correct: the sequence is to raise the accepted risk with senior management, and where the chief audit executive judges it unresolved, escalate to the board for their attention.

Why B is wrong: Tempting because cyber failures can affect outsiders, but the defined process routes the concern through senior management and the board internally, not to a regulator ahead of any internal escalation.

Why C is wrong: Tempting because documentation is expected, but recording alone does not satisfy the duty to discuss the matter with senior management and escalate it if it stays unresolved.

Why D is wrong: Tempting because independence matters, but bypassing senior management skips the first step of the process, which gives management the chance to resolve the concern before board escalation.

See more CIA-3 practice questions, answers explained.

More in this domain

Back to all Engagement Results and Monitoring objectives, or the CIA-3 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.