Question Bank Flashcards
The decisions and actions of an IS auditor areMOSTlikely to affect which of the following types of risk?
A. Inherent
B. Detection
C. Control
D. Business
B.
A.Inherent risk is the risk that a material error could occur, assuming that there are no related internal controls to prevent or detect the error. Inherent risk is not usually affected by an IS auditor.
B. Detection risk is directly affected by the IS auditor’s selection of audit procedures and techniques. Detection risk is the risk that a review will not detect or notice a material issue.
C.Control risk is the risk that a material error exists that would not be prevented or detected on a timely basis by the system of internal controls. Control risk can be mitigated by the actions of the company’s management.
D.Business risk is a probable situation with uncertain frequency and magnitude of loss (or gain). Business risk is usually not directly affected by an IS auditor.