CIA Part 3 · Engagement Results and Monitoring · Free Lesson

Describe the process for communicating risk acceptance

Free IIA CIA Part 3 (Internal Audit Function) lesson in Engagement Results and Monitoring. 15 min read, ~2,240 words.

A plant manager reads your finding about unsegregated payment approvals, agrees the exposure is real, and writes "accepted, cost of controls exceeds benefit" in the action-plan column. That is management's right. Whether your obligation ends there depends on one judgment you have to make and defend.

Risk acceptance is a deliberate decision by management to take no action on an identified risk and retain the exposure. It sits alongside avoid, reduce, and share as one of the four standard treatment responses. Recognizing when management has accepted a risk is the first step; internal audit does not own the decision, and does not overrule it. Internal audit owns the question of whether that accepted risk exceeds what the organization has said it will tolerate, and what to do when it does.

KEY: The trigger is not "management disagreed with internal audit." The trigger is "the retained risk level may exceed the organization's risk appetite or tolerance." A disagreement inside tolerance is a professional difference; a disagreement above tolerance is an escalation obligation.

Read the full lesson, free →
Worked examples and practice. Free with a free account, no card.

Common mistakes

Bottom line

Exam shortcut

Read the stem for a number and a limit. If the residual figure is under the stated tolerance, the answer is document and close, and every escalation option is a distractor. If it is over, run the ladder and pick the option one rung above whoever accepted it, never the top of the ladder by default.

The full lesson (about 2,240 words, 15 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.

Learning objectives

Browse all free CIA Part 3 lessons or jump into free CIA Part 3 practice questions.