since question stated the word FIRST, not the MOST IMPORTANT, the answer is C. Auditor will first need to review manuals, documentations and controls implemented then can be evaluating the risk associated https://www.examtopics.com/discussions/isaca/view/126715-exam-cisa-topic-1-question-596-discussion/#with operations or other implemented controls
Option D, "Assess the operational risks associated with the call center," is also important, but risk assessment is usually considered a process that takes place after a control check. By checking controls first, the accuracy and effectiveness of risk assessment will be improved.
Before gathering information from customers or conducting technical tests, it's important for the auditor to have a clear understanding of the internal controls that are in place. This includes both manual and automated controls that govern the operations of the call center. By reviewing these controls first, the auditor can identify potential weaknesses, gaps, or areas of concern that may need further investigation or testing.
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Malsaffar
6 days, 8 hours agoSwallows
6 months agoYejide03
10 months, 2 weeks agotakuanism
11 months, 3 weeks agoFAGFUR
1 year, 1 month ago