CISA Certified Information Systems Auditor – Question1929

Which of the following is appropriate when an IS auditor is conducting an exit meeting with senior management?

A.
Eliminate significant findings where audit and management agree on risk acceptance.
B. Agree with senior management on the risk grading of the audit report.
C. Document written responses from management along with an implementation plan.
D. Escalate disputed recommendations to the audit committee.

Correct Answer: C