The correct answer is B. Discuss the matter with IS audit management and executive management.
Residual risk is the risk remaining after management has implemented a risk response. Risk acceptance must be made within the organization’s risk appetite and risk tolerance. ISACA defines risk acceptance as a decision to accept risk according to the risk appetite and tolerance set by senior management, where the enterprise can assume the risk and absorb any losses.
If the IS auditor believes management accepted a risk level that is not appropriate, the auditor should not ignore the issue or simply document it without further discussion. The appropriate first step is to discuss the matter with IS audit management and executive management. This gives the organization an opportunity to reassess the decision, confirm whether the risk is within appetite, and determine whether additional treatment is required.
Option A may become appropriate later if executive management continues to accept a risk that exceeds risk appetite. ISACA guidance on follow-up activities states that when accepted risk is greater than the enterprise’s risk appetite, it should be discussed with senior management and brought to the attention of the audit committee or board if necessary.
Option C is incorrect because taking no further action would be inappropriate when the auditor believes the accepted residual risk is excessive. Option D is also incorrect because the audit report should fairly represent management’s response, including risk acceptance, rather than omitting it.
This question maps to Information Systems Auditing Process because it concerns audit judgment, communication of audit findings, escalation, and reporting.
[References: ISACA CISA Exam Content Outline, Domain 1; ISACA Interactive Glossary, “Residual risk,” “Risk acceptance,” and “Risk appetite”; ISACA guidance on audit follow-up activities., ===================, ]
Submit