During the planning stage of a compliance audit, an IS auditor discovers that a bank's inventory of compliance requirements does not include recent regulatory changes related to managing data risk. What should the auditor do FIRST?
- Ask management why the regulatory changes have not been included.
- Report the missing regulatory updates to the chief information officer (CIO).
- Discuss potential regulatory issues with the legal department.
- Exclude recent regulatory changes from the audit scope.
Reveal Solution Next Question