During a follow-up audit, an IS auditor finds that some critical recommendations have not been addressed as management has decided to accept the risk. Which of the following is the IS auditor's BEST course of action?
- Adjust the annual risk assessment accordingly.
- Require the auditee to address the recommendations in full.
- Evaluate senior management's acceptance of the risk.
- Update the audit program based on management's acceptance of risk.
Reveal Solution Next Question