Which of the following documents should define roles and responsibilities within an IT audit organization?
Correct Answer: A
Comprehensive and Detailed Step-by-Step Explanation:
Theaudit charteris a formal document that definesthe purpose, authority, and responsibilitiesof the internal audit function.
* Audit Charter (Correct Answer - A)
* Establishesroles, reporting structure, and independenceof the audit team.
* Example:TheIS audit team's roleinrisk assessmentsis outlined in the charter.
* Annual Audit Plan (Incorrect - B)
* Outlinesaudit activitiesbutdoes not define roles and responsibilities.
* Engagement Letter (Incorrect - C)
* Used forspecific audits, not theentire audit function.
* Audit Scope Letter (Incorrect - D)
* Detailswhat is coveredin an audit but doesnot define responsibilities.
References:
* ISACA CISA Review Manual
* COBIT 2019 (Audit Governance)