CISA Certified Information Systems Auditor – Question0377

When determining which IS audits to conduct during the upcoming year, internal audit has received a request from management for multiple audits of the contract division due to fraud findings during the prior year. Which of the following is the BEST basis for selecting the audits to be performed?

A.
Select audits based on an organizational risk assessment.
B. Select audits based on collusion risk.
C. Select audits based on the skill sets of the IS auditors.
D. Select audits based on management's suggestion.

Correct Answer: B