To determine whether risk mitigation exists in change management, the internal auditor should validate the core change controls: authorization, segregation of duties, testing, and approval before migration to production. These controls reduce the risk of unauthorized, untested, or poorly designed changes disrupting operations or compromising data integrity. Option A is inappropriate because internal audit should not develop and enforce management policies. Option B is partly relevant but too general and includes “impose,” which is not internal audit’s role. Option C is also insufficient because a threat analysis alone does not prove that change controls operate. Internal audit should test whether changes are requested, documented, approved, tested, migrated, and reviewed. Therefore, Option D is correct.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit