Sequence of Steps for Communicating Risk Acceptance: A Complete CIA Exam Guide
Overview
Communicating risk acceptance is a key topic in the Engagement Results and Monitoring area of the CIA exam. It covers what the Chief Audit Executive (CAE) must do when management has accepted a level of risk that may be unacceptable to the organization. Under the 2017 IPPF it is Standard 2600 – Communicating the Acceptance of Risks. Under the 2024 Global Internal Audit Standards it is Standard 11.5 – Communicating the Acceptance of Risks. Exam questions usually test the correct order of actions and who the CAE communicates with at each stage.
Why It Is Important
1. Protects the organization. Management may decide not to act on an audit observation because of cost, time, or a different view of the risk. If that decision leaves the organization exposed beyond its risk appetite, the people with ultimate oversight need to know.
2. Supports governance. The board relies on internal audit for independent assurance. Escalating unacceptable risk keeps the board informed and lets it exercise its oversight role.
3. Preserves independence and objectivity. The CAE does not accept or reject risk on management's behalf. The CAE makes sure the right decision-makers are informed, without taking on management's responsibility.
4. Respects the chain of authority. Senior management is given the chance to resolve the issue before the board is involved. This keeps working relationships constructive and avoids unnecessary escalation.
5. Creates accountability. Documenting who accepted the risk, and why, creates a clear record if the risk later materializes.
What It Is
Risk acceptance occurs when management knowingly decides to tolerate a risk. Typically this means:
• not implementing an agreed action plan, or
• rejecting an internal audit recommendation.
Accepting risk is a legitimate management decision and is not wrong in itself. Every organization accepts some risk. The Standards are triggered only when the CAE concludes that the accepted risk:
• may be unacceptable to the organization (2017 wording), or
• exceeds the organization's risk appetite or risk tolerance (2024 wording).
Internal auditors may learn of risk acceptance through:
• a current assurance or advisory engagement,
• the follow-up and monitoring process (Standard 2500 / GIAS 15.2, which covers confirming that recommendations or action plans have been implemented), or
• other sources, such as risk assessments or discussions with staff.
How It Works: The Sequence of Steps
Step 1 – Identify the accepted risk. Through an engagement, follow-up, or monitoring, the auditor finds that management has not addressed a risk, or has explicitly chosen to accept it.
Step 2 – Understand and evaluate. The CAE does two things:
• learns management's rationale (for example, cost-benefit reasons, compensating controls, or strategic priorities), and
• assesses whether the remaining risk is beyond what the organization can tolerate.
Relevant criteria include the organization's risk appetite, its tolerance levels, and the potential impact and likelihood of the risk. If the risk is within appetite, no escalation is needed, although the matter may still be noted.
Step 3 – Discuss with senior management. If the CAE concludes the risk is unacceptable, the first required action is to discuss the matter with senior management. The aim is to:
• make sure management fully understands the exposure, and
• give management the opportunity to reconsider, add mitigation, or properly justify the decision.
Step 4 – Escalate to the board if unresolved. If the discussion does not resolve the matter, the CAE must communicate it to the board (for example, the audit committee). The communication should explain:
• the risk and its potential consequences,
• management's position and rationale, and
• the CAE's concern.
Step 5 – The board decides; the CAE documents. The board, as the ultimate oversight body, decides whether to accept the risk or direct management to act. The CAE does not overrule management or the board. The CAE should document:
• the risk,
• management's reasons for accepting it,
• the discussions held, and
• the board's decision.
The matter may also feed into future risk assessments and audit planning.
Summary of the sequence: Identify → Evaluate against risk appetite → Discuss with senior management → If unresolved, communicate to the board → Board decides → Document and monitor.
Key Responsibilities
• Management: owns the risk and decides whether to mitigate or accept it.
• CAE: evaluates the risk, communicates and escalates it, and documents the outcome. The CAE does not resolve the risk personally.
• Board: provides final oversight and makes the decision on unresolved matters.
Exam Tips: Answering Questions on Sequence of Steps for Communicating Risk Acceptance
Tip 1 – Know the FIRST step. When a question asks what the CAE should do first after concluding that management accepted an unacceptable risk, the answer is almost always discuss the matter with senior management. Going straight to the board is a common distractor.
Tip 2 – Board escalation is conditional. The board is involved only if the matter is not resolved with senior management. Look for wording such as "after discussing with senior management, the issue remains unresolved." In that case, the answer is to communicate with the board.
Tip 3 – Reject external reporting. Options such as reporting to regulators, external auditors, or law enforcement are rarely correct. The Standards keep escalation within the organization's governance structure unless law or regulation requires otherwise.
Tip 4 – The CAE does not fix or override. Eliminate answers where the CAE:
• implements controls,
• forces management to act,
• issues an ultimatum, or
• takes ownership of the risk.
Doing so would impair independence and objectivity.
Tip 5 – Accepting risk is not automatically wrong. If the scenario says the accepted risk is within the organization's risk appetite, no escalation is required. Read carefully for the trigger: unacceptable risk, or risk exceeding appetite or tolerance.
Tip 6 – Link to follow-up. Questions often describe a follow-up review where management has not implemented corrective action. Recognize this as a possible risk acceptance situation. The CAE should first find out why the action was not taken, then follow the escalation sequence if the risk is unacceptable.
Tip 7 – Watch for the final authority. If asked who ultimately decides on an unresolved risk acceptance, the answer is the board, not the CAE and not the external auditor.
Tip 8 – Documentation matters. If an option mentions documenting management's rationale and the board's decision, it is usually part of the correct process.
Tip 9 – Use ordering logic. For "put these steps in order" questions, remember: Identify → Evaluate → Senior Management → Board → Document. Steps involving the board never come before discussion with senior management.
Tip 10 – Know both versions of the Standards. Recognize both references: 2600 (2017 IPPF) and 11.5 (2024 GIAS). Note the 2024 wording about risk appetite and tolerance. The underlying sequence is the same in both.
Sample Question
During follow-up, the CAE finds that management chose not to implement a recommended control. The CAE believes the resulting risk exceeds the organization's risk appetite. What should the CAE do first?
A) Report the matter to the audit committee.
B) Discuss the matter with senior management.
C) Notify the external auditor.
D) Design and implement the control.
Answer: B. Discussion with senior management comes first. The audit committee is involved only if the matter remains unresolved.
Key Takeaway
The CAE's role is to communicate and escalate, not to decide. Evaluate the risk, discuss it with senior management, escalate to the board only if it remains unresolved, and document everything.