Parties Involved in Communicating Risk Acceptance
In CIA Part 3, under Engagement Results and Monitoring, risk acceptance occurs when management decides not to implement corrective action and accepts the related risk. The IIA Standards (formerly Standard 2600, retained in the Global Internal Audit Standards) define who must be involved when the ac… In CIA Part 3, under Engagement Results and Monitoring, risk acceptance occurs when management decides not to implement corrective action and accepts the related risk. The IIA Standards (formerly Standard 2600, retained in the Global Internal Audit Standards) define who must be involved when the accepted risk may exceed the organization's risk appetite. Several parties are involved. First, internal auditors and engagement supervisors identify the issue. They may find it during an engagement, through follow-up and monitoring of action plans, or through other activities. They document the finding, the risk exposure, and management's response, then escalate concerns to the Chief Audit Executive (CAE). Second, the CAE is the central party. The CAE judges whether the accepted risk is unacceptable to the organization, using the organization's risk appetite, tolerance levels, and potential impact. The CAE owns the communication process. Third, operational or process-owner management is usually the party that accepted the risk. Internal auditors first discuss findings with this level and confirm that management understands the exposure and the consequences of inaction. Fourth, senior management must be consulted. If the CAE concludes that management has accepted an unacceptable level of risk, the CAE must discuss the matter with senior management. This gives senior management a chance to reconsider, mitigate, or formally confirm the decision. Fifth, the board or audit committee serves as the final escalation point. If the CAE determines that the matter has not been resolved with senior management, the CAE must communicate it to the board. This supports governance oversight and the CAE's functional reporting relationship. Sixth, external parties such as regulators may receive information only when laws, regulations, or policy require it, following organizational protocols. Key exam points include the following. Internal audit does not resolve the risk or decide on acceptance, because management owns risk decisions. The CAE's role is to communicate and escalate, not to impose remedies. Escalation follows a defined sequence: management, then senior management, then the board. All discussions and conclusions should be documented to preserve objectivity, accountability, and a clear audit trail.
Parties Involved in Communicating Risk Acceptance: A Complete CIA Exam Guide
Introduction
One of the most sensitive moments in internal auditing comes after an engagement is complete and its recommendations have been issued. Sometimes management decides not to act on a finding and to live with the risk instead. When the chief audit executive (CAE) believes the risk accepted is beyond what the organization can tolerate, the IIA Standards set out exactly who must be involved and in what order.
This guide explains that topic: what it is, why it matters, how the escalation works, and how to answer exam questions on it. The Standards reference is Standard 2600, Communicating the Acceptance of Risks, in the former IPPF, and Standard 11.5, Communicating the Acceptance of Risks, in the 2024 Global Internal Audit Standards. The topic sits within the communicating results and monitoring progress area of the CIA syllabus.
Why It Is Important
The topic matters for five reasons:
- It protects the organization. Risks that exceed the organization's risk appetite should not stay hidden at the operational level. Escalation makes sure the people who own governance know about exposures that could harm strategic objectives.
- It respects the division of responsibilities. Management owns risk and decides how to respond to it. The board oversees risk management. Internal audit provides assurance and advice. Knowing who does what avoids confusion and keeps internal audit independent.
- It preserves independence and objectivity. Internal audit must not make risk decisions for management. However, it must not stay silent when a decision looks unacceptable either.
- It completes the monitoring process. Following up on engagement results is not only about checking whether actions were taken. It also covers situations where management chose not to act.
- It is heavily tested. The exam often asks who the CAE should talk to first, who receives the matter next, and who is responsible for resolving it.
What It Is
Communicating risk acceptance is the process by which the CAE handles a situation in which management has accepted a level of risk that may be unacceptable to the organization.
Under the 2024 Global Internal Audit Standards (Standard 11.5), the requirements are:
- When the CAE concludes that management has accepted a level of risk that exceeds the organization's risk appetite or risk tolerance, the CAE must discuss the matter with senior management.
- If the CAE determines that the matter has not been resolved by senior management, the CAE must escalate it to the board.
- The CAE is not responsible for resolving the risk.
Key Parties and Their Roles
1. Internal auditors and the engagement team
- They identify findings, recommend actions and track management's responses during follow-up.
- They are often the first to notice that management has declined to act, delayed indefinitely or formally accepted a risk.
- They report this to the CAE. They do not escalate to the board on their own.
- The CAE is the central party. He or she judges whether the accepted risk is unacceptable, meaning it exceeds the organization's risk appetite or tolerance.
- The CAE starts the discussion with senior management and decides whether board escalation is needed.
- The CAE communicates the matter but does not resolve it or force management to act.
- These are the managers responsible for the audited area. They respond to recommendations and may choose to accept a risk.
- Management has the authority to accept risk. Accepting a risk is a legitimate response, but it should fall within the organization's appetite.
- Senior management is the first escalation point for the CAE.
- It is responsible for resolving the matter, for example by reversing the decision, adding controls or confirming that the risk is within appetite.
- The board is the final escalation point when senior management does not resolve the matter.
- It provides oversight and makes the final governance decision about whether the risk is acceptable.
- Once the board has been informed, internal audit has met its obligation under the Standards.
- External parties such as regulators, external auditors and shareholders are not part of the escalation chain under this Standard.
- Communication outside the organization falls under separate guidance on disseminating results to outside parties. It also typically requires legal review and senior management or board approval.
Step 1: Identify the risk acceptance. During follow-up, which is part of the monitoring process, the internal auditor finds that management has not implemented a recommendation and has decided to accept the risk. This may be explicit, through a formal risk acceptance, or implicit, through repeated delays or inaction.
Step 2: Assess whether the risk is unacceptable. The CAE judges whether the residual risk exceeds the organization's risk appetite or tolerance. Not every accepted risk needs escalation. Management is entitled to accept risks within appetite.
Step 3: Understand management's rationale. Before escalating, the internal auditor and CAE usually talk with the responsible management to understand why the risk was accepted. Possible reasons include cost-benefit decisions, compensating controls and resource constraints.
Step 4: Discuss with senior management. If the CAE still believes the risk is unacceptable, the CAE must raise it with senior management.
Step 5: Escalate to the board if unresolved. If senior management does not resolve the issue, the CAE communicates it to the board, typically the audit committee.
Step 6: Document. The CAE documents the risk accepted, the discussions held, the parties involved and the outcome. This supports accountability and later quality reviews.
Step 7: Continue monitoring. The CAE may consider the accepted risk in future risk assessments and the internal audit plan.
Key Concepts and Distinctions
- Risk acceptance is a management decision. Internal audit advises and escalates but never decides.
- The trigger is the CAE's conclusion. The test is whether the accepted risk may be unacceptable to the organization. It is not merely that management disagreed with a recommendation.
- The order matters. Senior management comes first, then the board. Skipping straight to the board is generally wrong, unless the scenario involves senior management itself or a conflict, such as fraud by senior executives. In that case the CAE's functional reporting line to the board applies.
- Resolution is not internal audit's job. The CAE's duty ends at communication.
- Risk acceptance differs from disagreement over findings. Disagreement over findings is normally documented in the engagement communication, with both positions stated. Risk acceptance concerns the decision not to act.
An IT audit recommends multi-factor authentication for remote access. The IT director declines, citing cost, and accepts the risk. The organization's risk appetite statement says there is low tolerance for cybersecurity breaches.
The CAE concludes that the risk exceeds appetite and discusses it with the CIO and CEO (senior management). Senior management upholds the decision without adding any mitigation. The CAE then reports the matter to the audit committee and documents everything. The CAE does not install the controls, refuse to close the audit or notify the regulator.
Exam Tips: Answering Questions on Parties Involved in Communicating Risk Acceptance
- Memorize the sequence. The order is management, then senior management, then the board. When a question asks for the first action after the CAE concludes the risk is unacceptable, the answer is to discuss it with senior management.
- Look for the word 'unresolved'. If the scenario says senior management has already been consulted and the issue remains, the correct answer is to communicate it to the board or audit committee.
- Eliminate options where internal audit resolves the risk. Answers such as 'the CAE implements the control', 'internal audit overrides management' or 'the CAE refuses to sign off' are wrong. The CAE is not responsible for resolving the risk.
- Eliminate external parties. Options to notify regulators, external auditors or shareholders are almost always distractors in this context.
- Eliminate options that do nothing. 'Accept management's decision and close the file' is wrong when the risk exceeds appetite. Silence fails the Standard.
- Check who decides acceptability. The CAE judges whether the risk may be unacceptable. Individual staff auditors report to the CAE rather than escalate on their own.
- Distinguish within-appetite acceptance. If management accepts a risk that is within appetite, no escalation is required. Documenting the decision and monitoring is enough.
- Recognize exceptions. If senior management is itself the source of the problem, for example by being involved in wrongdoing, the CAE may go directly to the board using the functional reporting relationship.
- Link the topic to monitoring. Questions may frame this within follow-up activities. The CAE must set up a process to monitor whether actions have been implemented, or whether senior management has accepted the risk of not taking action.
- Remember documentation. When options include documenting discussions and outcomes alongside the correct escalation step, documentation is a supporting best practice. Choose the escalation step when the question asks what the CAE 'must' do.
- Know both sets of terminology. Exam items may reference Standard 2600 or the newer Standard 11.5. The required actions are the same in both.
- Watch qualifiers. Words such as 'first', 'most appropriate' and 'next' determine which step in the sequence is correct.
Management may accept risk. When the CAE concludes that the accepted risk may be unacceptable to the organization, the CAE discusses it with senior management. If it is still unresolved, the CAE communicates it to the board. The CAE documents the process but never resolves the risk. Keep this chain of parties in mind and most exam questions on this topic become straightforward.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!