Exam CISA Topic 3 Question 734 Discussion
Actual exam question for ISACA's CISA exam
Question #: 734
Topic #: 3
Question #: 734
Topic #: 3
Which of the following groups is PRIMARILY accountable for establishing a culture that facilitates an effective and efficient internal control system?
Suggested Answer: B Vote an answer
The correct answer is B. Senior management.
Senior management is primarily accountable for establishing the organization's control culture, commonly described as setting the "tone at the top." Senior management is responsible for designing, implementing, communicating, and enforcing the internal control environment through policies, procedures, accountability, performance expectations, and ethical conduct.
Option A has ultimate oversight responsibility, but senior management is the group primarily accountable for establishing and operating the control culture. Option C is responsible for executing controls within business processes, but line management does not set the overall enterprise culture alone. Option D is incorrect because internal audit evaluates and provides assurance over controls; it does not own or establish the internal control system.
This maps to Governance and Management of IT because ISACA's CISA Exam Content Outline includes organizational structure, IT governance, IT policies, standards, procedures, practices, and enterprise risk management under Domain 2.
References: ISACA CISA Exam Content Outline, Domain 2; ISACA governance and internal control concepts.
Senior management is primarily accountable for establishing the organization's control culture, commonly described as setting the "tone at the top." Senior management is responsible for designing, implementing, communicating, and enforcing the internal control environment through policies, procedures, accountability, performance expectations, and ethical conduct.
Option A has ultimate oversight responsibility, but senior management is the group primarily accountable for establishing and operating the control culture. Option C is responsible for executing controls within business processes, but line management does not set the overall enterprise culture alone. Option D is incorrect because internal audit evaluates and provides assurance over controls; it does not own or establish the internal control system.
This maps to Governance and Management of IT because ISACA's CISA Exam Content Outline includes organizational structure, IT governance, IT policies, standards, procedures, practices, and enterprise risk management under Domain 2.
References: ISACA CISA Exam Content Outline, Domain 2; ISACA governance and internal control concepts.
by Ken at Aug 01, 2026, 04:42 PM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).