CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 297


Following an IS audit, which of the following types of risk would be MOST critical to communicate to key stakeholders?

Show Answer
Correct Answer: AD

Residual risk represents the risk that remains even after controls have been implemented. This type of risk is critical to communicate to key stakeholders because it provides a clear picture of the actual risk exposure that the organization faces after considering the effectiveness of existing controls. By understanding residual risk, stakeholders can make informed decisions about whether additional controls are needed or if the current risk level is acceptable.

Discussion

11 comments
Sign in to comment
IjahbeeOption: A
Mar 17, 2024

Control Risk This means the control is not operating effectively. If the control is not operating effectively there is no residual risk...

007GeorgeoOption: D
May 6, 2023

residual risk would be the most critical type of risk to communicate to stakeholders as it represents the risk that remains after controls have been implemented

DeeplaxmiOption: D
Sep 30, 2022

D-Residual Risk

JulianleehkOption: D
Oct 8, 2022

It should be D

peeluOption: D
Dec 10, 2022

Residual risk

3008Option: D
Apr 30, 2023

d is answer

hohoOption: D
Jun 22, 2023

Most on D, Residual risk

cidigiOption: A
Dec 17, 2023

A - Control risk. Because it means that the controls are not working effectively. Residual riks is the risk accepted and monitored by the business. So there is no big issue with it.

cidigi
Dec 17, 2023

Changing my answer. I still believe Control risk is important. In this case, i would go with AUDIT as audit risk includes all 3 options , Auti Risk=( Control Risk+Residual Risk+Inherent Risk)

blues_leeOption: D
Jan 31, 2024

Residual risk

a84nOption: D
Apr 27, 2024

Answer: D Residual risk, encompasses both inherent risk (the risk without considering the effect of controls) and control risk (the risk that remains after controls are implemented). Therefore, communicating residual risk provides stakeholders with a comprehensive understanding of the actual risk exposure that the organization faces, taking into account both inherent risks and the effectiveness of controls.

analuisamoreiraOption: A
Jun 27, 2024

A is correct. It represents an unexpected situation