Question 36

Which of the following is a legitimate requirement for an internal audit activity's quality assurance and improvement program (QAIP)?
  • Question 37

    Which of the following is a true statement regarding whistleblowing?
  • Question 38

    Which of the following is a true statement regarding controls such as ethical values, tone at the top and operational style?
  • Question 39

    Which of the following best demonstrates the application of due professional care?
  • Question 40

    An organization is testing a new IT system for digital data storage and security. The internal audit activity has been asked to evaluate the system in a consulting engagement. Although several internal auditors on staff are qualified to perform basic assessments of IT systems, none are familiar with the new system. Which of the following is a legitimate response to the prospective client?
    1. Decline the engagement.
    2. Proceed with the engagement, performing only those parts of the engagement that the internal auditors are qualified to perform.
    3. Accept the engagement and develop the additional competencies in-house prior to the engagement's starting date.
    4. Make arrangements to obtain assistance from a competent IT auditing expert.