Which of the following is an activity that an internal auditor must not perform?
Which of the following is an activity that an internal auditor must not perform?
Internal auditors must maintain independence and objectivity in their role, which includes not establishing or managing operational programs. Establishing and providing continuing assurance on an anti-money laundering program for new hires (option A) would compromise this independence, as it would involve designing and implementing part of the internal control system, a responsibility that lies with management.
Why not D? Isn't it management responsibility to assess the risk?
Yes but in the first line of defense.