Which of the following would an internal auditor most likely use to document a complex process that includes risks and controls, timelines, and ownership of key steps?
Correct Answer: C
Comprehensive and Detailed Step-by-Step Explanation:
* Reference to IIA Standards:
* Standard 2330 - Documenting Information: Internal auditors are required to document audit evidence and processes in a way that is clear, complete, and supports audit conclusions.
* Risk and control matricesare effective for documenting risks, controls, and related responsibilities in a structured way.
* Reasoning:
* Option Cis correct because arisk and control matrixclearly documents processes, the associated risks, control activities, and ownership of each step. It is the most suitable tool for understanding risks and controls along with associated timelines and responsibilities.
* Option A(process map) documents the steps in a process but does not directly link risks and controls.
* Option B(detailed flowchart) is used to map the flow of a process but also lacks the structure for detailing risks and control ownership.
* Best Practice for Documentation:
* Arisk and control matrixis the most structured and comprehensive tool for documenting complex processes that involve risks, controls, and ownership.