Annual Risk Assessment

6 posts / 0 new
Last post
laurannrea

I have a couple of questions regarding annual risk assessments:

  1. Who conducts the annual risk assessment used for establishing a risk-based plan to determine priorities of the internal audit activity?
  2. Is this a risk assessment the Internal Audit Department develops, or do you use a risk assessment developed by Risk Management or Enterprise Risk Management?
  3. Does it impair independence or violate auditing standards to use a risk assessment developed by another party to determine your risk-based audit work plan? Why or why not?