ITPEC IP April 2021 Question 64
ITPEC IP April 2021 — Question 64 of 100
The system auditor reports advice and recommendations to management, which requested the audit and has authority to act on the findings. Management is responsible for governance, risk treatment, resource allocation, and directing corrective improvements to information systems.
Answer (c)
Why not others:
- stockholders do not normally manage individual audit corrective actions
- a jurisdictional authority receives reports only under specific legal or regulatory requirements
- system users may provide evidence or receive changes but lack organization-wide authority
Key rule: Audit recommendations go to the responsible management level that can authorize and oversee corrective action.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.