Audit Management Implementation Flashcards

1
Q

Audit admin (sn_audit.admin)

A

Set up the Audit Management application
Coordinate and facilitate configuration requests
Delete engagements, audit tasks, test templates, and test plans

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Audit manager (sn_audit.manager)

A

Create audit plans and engagements, including records necessary to conduct the audit, such as milestones, tasks, and evidence requests
Approve audit tasks, workpapers, and engagements
Track and monitor audit findings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Audit user (sn_audit.user)

A

Perform fieldwork (walkthroughs, interviews, control testing, etc.)
Document the work and findings
Resolve and/or follow up with audit findings
Create test templates and test plans
Read-only access to Policy and Compliance and Risk Management applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Engagement project manager (sn_audit_advanced.engagement_project_manager)

A

Complete advanced planning with audit plans and engagements

Create resource and costs plans and approve time cards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

External auditor (sn_audit.external_auditor)

A

Assigned as auditor for an engagement and audit tasks
Perform audit against specific regulation
View closed engagements and tasks
View published policies, controls, and risks in the Monitor state

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

GRC business user (sn_grc.business_user)

A

Leveraged across GRC applications. Audit-specific activities include:

Partner with the auditor on the action plan
Respond to observations and evidence requests
Resolve issues converted from the observation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is an audit plan?

A

An audit plan helps to manage different types of audits in a periodic manner and group engagements in a logical manner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is an audit engagement?

A

An audit engagement is an audit project that may include audit tasks that accomplish a set of objectives or goals.
Audit engagements are scoped with auditable units or entities
An entity type called ‘auditable units’ is created for auditable units.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the 4 audit tasks?

A

An engagement’s four types of tasks are: control tests, interviews, walkthroughs, and/or activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How are audit issues created?

A

Automatically, if the indicator result is failed or not passed.
Automatically, if the attestation result is not implemented.
Automatically, if the control test effectiveness is Ineffective and the state of the test is closed complete.
Manually to document audit observations, the intention of remediations, or to accept any problems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Do you recall the conditions which move the audit engagement into the Closed state?

A

The engagement is closed as incomplete during the Scope, Validate, or Fieldwork states.

Incorrectly unchecked
There are no open audit tasks, observations, or issues after the engagement is approved. In this case, the engagement automatically moves from Awaiting Approval to the Closed state.

Incorrectly unchecked
All of the follow up tasks, observations and issues are closed. In this case, the engagement automatically moves from the Follow Up state to the Closed state.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly