A state department of transportation wants internal audit to plan engagements from a living risk register. Which use-case approach fits IRM?
Select an answer to reveal the explanation.
Short Explanation
If audit wants a living risk register, put Audit and Risk on the same IRM data—not a lonely spreadsheet universe. Shared entities and risks let engagement planning follow where the heat actually is. That is risk-based audit on the platform, not side-channel planning.
Full Explanation
A risk-based audit use case connects Audit engagement planning to the IRM risk register and shared entities rather than a standalone spreadsheet universe. Integration across Risk and Audit on common GRC data supports prioritization and traceability. ITSM calendars or VR groups alone do not satisfy the intent of planning from IRM risk posture.