Certified Internal Auditor (CIA) Part 1: Business Acumen — Question 99
Once an organization’s risks are identified, what would be the next step to ensure resources are properly allocated to manage those risks?
Answer options
- A. Risk responses must be selected.
- B. Risks must be assessed.
- C. The risk universe must be established.
- D. Risk responses must be aligned.
Correct answer: A
Explanation
The correct answer is A because selecting risk responses is essential for determining how to allocate resources effectively to mitigate identified risks. Options B and C focus on assessing risks and establishing a risk framework, which are important but precede the action of resource allocation. Option D, aligning responses, is a subsequent step that assumes responses have already been selected.