Question 126

The chief audit executive (CAE) of a multinational entity with highly automated and complex operations has just completed the update of the risk-based audit plan. Interviews with management revealed the introduction of new technology and a significant increase in both the number and severity of technology-based risk exposures.
According to the International Professional Practices Framework, which of the following would be the best course of action for the CAE to undertake next?
  • Question 127

    Which of the following is least likely to vary when conducting audit engagements in different regions of an international organization?
  • Question 128

    An organization's internal auditors are reviewing production costs at a gas-powered electrical generating plant. They identify a serious problem with the accuracy of carbon dioxide emissions reported to the environmental regulatory agency, due to computer errors. The auditors should immediately report the concern to:
  • Question 129

    As a result of a recent discovery of false information on employment applications, an internal auditor has reviewed hiring procedures. Which of the following represents a weakness in the control system?
    I.Applicants are not required to have their signed applications legally authenticated.
    II.
    Applicants' educational information is not validated with the educational institution before employment is offered.
    III.
    Information related to applicants' long-term work history is not validated before employment is offered.
  • Question 130

    Which two of the following considerations must an internal auditor take into account while planning an audit of an accounting system/application that has been in use for the last five
    years?
    The level and manner of linkages between the business' mission, objectives, and structure and the accounting system/application.
    -
    --
    Presence or absence of computerized and manual controls that address risks.
    Identification of risks at the application level, e.g. availability and security of the
    system.
    Testing of the system/application for bugs and errors.
    -