Audit and Advanced Audit
CIS-RC · 15 questions
- Internal Audit must plan an engagement on the city’s payments environment with clear objectives and a defined period. What lifecycle step should they complete first in Audit Management?
- During an EHR security audit, auditors need structured tasks and a place to store working papers and evidence. What should they use in the engagement lifecycle?
- Auditors note weak privilege reviews on a benefits system, then confirm the gap is real. How should the engagement progress that item?
- Findings from the payments audit are either remediated or formally risk-accepted. What should Internal Audit do to finish the engagement?
- Advanced Audit planning for a utilities review should pull scope from live IRM data. What is the best scoping approach?
- The CAE wants a maintained list of potential future audits across civic departments, not only the one engagement in flight. What should Audit maintain?
- Designers propose a second, audit-only catalog of controls that duplicates Policy and Compliance. What architecture guidance should CIS-RC favor?
- A compliance manager asks to score residual risk inside the same engagement where they designed the controls under review. Why is that a problem in IRM audit architecture?
- The annual audit plan needs to favor areas with the highest live risk. What selection approach matches IRM audit architecture?
- A confirmed audit finding on weak backup testing needs remediation tracking visible to compliance and risk teams. How should findings integrate?
- Recent control tests for encryption controls are effective and independence rules allow reliance. What should auditors do to avoid wasteful duplicate testing?
- Who should plan the audit engagement versus who should own remediation of control gaps found?
- Auditors scoping three civic entities need broad read visibility into policies, risks, and controls in scope. What access pattern is appropriate?
- Auditee groups must upload evidence for fieldwork tasks. What permission boundary should remain in place?
- The same analyst currently marks controls attested and also wants the audit role that signs off assurance on that work. What should the implementer enforce?