According to the International Professional Practices Framework, internal auditors who are assessing the adequacy of organizational risk management processes should not:
A.
Recognize that organizations use different techniques for managing risk.
B.
Seek assurance that the key objectives of the risk management processes are being met.
C.
Determine and accept the level of risk for the organization.
D.
Treat the evaluation of risk management processes differently from the risk analysis used to plan audit engagements.
IA cannot determine the level of risk. Poor English / question structure as it can also mean that the IA seeks information to determine what the org level of risk is and accepts that as the basis for conducting the audit.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
137a7a9
2 weeks, 4 days ago34205ac
4 months, 3 weeks ago