Isaca Certified in Risk and Information Systems Control CRISC Question # 347 Topic 35 Discussion
CRISC Exam Topic 35 Question 347 Discussion:
Question #: 347
Topic #: 35
During the internal review of an accounts payable process, a risk practitioner determines that the transaction approval limits configured in the system are not being enforced. Which of the following should be done NEXT?
A.
Identify the extent of the approval limit violations.
B.
Notify senior management of the system deficiency.
C.
Update the risk register with higher risk likelihood of violation.
D.
Remind users of the importance of adhering to approval limits.
Before taking further action, it is essential to understand the scope of the issue. Identifying the extent of violations helps determine the potential risk impact and informs appropriate corrective actions.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit