A shared-services center consolidates accounts payable from twelve country offices into one hub, cuts headcount by 40%, and moves the surviving staff fully remote. Nothing in the process narrative changed. Every risk in it did.
The annual plan's risk assessment ranks auditable entities against each other. The engagement-level risk assessment goes inside the selected entity and identifies the specific risks to the activity's objectives, then evaluates and prioritizes them so scope and procedures follow. Standard 13.1 (Engagement Risk Assessment) anchors this in the Global Internal Audit Standards.
The sequence is fixed: understand the activity and its objectives, identify risks to those objectives, evaluate each risk on likelihood and impact, identify the controls management relies on, then prioritize what the engagement will test.
KEY: You assess risk before controls, then overlay controls. Starting from the control list means you only ever find risks management already thought of, which guarantees you miss the unmitigated ones.
A topical requirement is a mandatory element issued by The IIA that prescribes minimum coverage when an internal audit function performs assurance work over a named subject such as cybersecurity...
Common mistakes
- Scoring residual risk before confirming controls exist. Assuming the designed control operates gives a residual of 12 where the true figure is the inherent 20. Verify operation, then discount.
- Dropping a prescribed element because your score was low. A score of 6 against a 12 threshold reduces testing depth, never applicability.
- Treating cybersecurity as an IT sub-category. They fail independently. A system with clean change management and no privileged-access monitoring passes IT and fails cyber.
Bottom line
- Sequence: understand the activity, identify risks to its objectives, evaluate likelihood and impact, then overlay controls and prioritize.
- Residual risk = (likelihood × impact) × (1 − control effectiveness); engagement priority follows residual risk, not inherent risk.
- Topical requirements set a mandatory floor: prescribed elements are assessed regardless of your score, and exclusions need a documented rationale with chief audit executive approval.
- Five pervasive categories: financial, operational, IT, cybersecurity, regulatory. Cybersecurity fails independently of IT.
Exam shortcut
Read the stem for change words first. "Recently implemented," "consolidated," "reorganized," "outsourced," and "migrated" all mean the prior risk assessment is stale, and the correct answer is to reassess current-state risk before testing. Stem signals to memorize: "no historical loss data" means scenario-based estimation, never exclusion.
The full lesson (about 2,613 words, 17 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 5
Browse all free CIA Part 2 lessons or jump into free CIA Part 2 practice questions.