Valid IAA-IAP Dumps shared by ExamDiscuss.com for Helping Passing IAA-IAP Exam! ExamDiscuss.com now offer the newest IAA-IAP exam dumps, the ExamDiscuss.com IAA-IAP exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com IAA-IAP dumps with Test Engine here:
An internal auditor is performing an internal control assessment at a manufacturing company. The auditor observed that the accounts payable clerks have the ability to create new vendors without management's review and approval. How should the auditor document this observation?
Correct Answer: B
Comprehensive and Detailed Step-by-Step Explanation: * Reference to Internal Control Assessment: * Standard 2130 - Control: Internal auditors must evaluate the adequacy and effectiveness of controls in mitigating risks. * COSO Framework: Proper segregation of duties is essential for preventing unauthorized transactions and fraud. * Reasoning: * Option Bis correct because the lack of management review and approval for creating vendors indicates a control weakness, as it creates opportunities for unauthorized vendors or fraud. The auditor should investigate whether mitigating controls exist (e.g., periodic review of vendor lists) or recommend redesigning the process to include managerial oversight. * Option Adismisses the observation without considering its impact on control adequacy. Prompt payment alone does not address risks related to unauthorized vendors. * Option Cincorrectly assumes the observation reflects adequate controls, which is not the case given the lack of management approval. * Actionable Next Steps: * Document the observation as a control deficiency. * Perform additional testing to identify whether compensating controls mitigate the risk or recommend enhancements to strengthen controls.