The same analyst currently marks controls attested and also wants the audit role that signs off assurance on that work. What should the implementer enforce?
Select an answer to reveal the explanation.
Short Explanation
You wouldn’t let the same person grade their own homework and call it an external review. Keep audit roles separate from compliance operator roles so assurance stays independent. One super-role is how segregation dies.
Full Explanation
Segregation of duties between compliance operators (who run attestations and day-to-day control processes) and auditors (who provide independent assurance) is a core persona design for IRM Audit. Combining those roles, substituting ITSM fulfiller rights, or disabling Audit Management undermines objective assurance.