Which of the following should an internal auditor check for first when conducting an audit of the organization’s risk management program?
Choose an answer
Tap an option to check your answer.
Correct answer: Policies and procedures.
Why this is the answer
An internal auditor should first check for policies and procedures because these documents establish the framework, rules, and guidelines for the entire risk management program. Without clearly defined policies and procedures, it's impossible to objectively assess whether the program is being implemented correctly or effectively. They provide the criteria against which all other activities, such as asset management, vulnerability assessments, and business impact analyses, will be measured. Asset management, vulnerability assessments, and business impact analyses are all components or activities within a risk management program, but their effectiveness cannot be properly evaluated without first understanding the foundational policies and procedures that govern them.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed