When reviewing the extent and nature of the risks to internal controls associated with IT, an auditor should consider which of the following?
I.Whether the entity has responded adequately to the risks arising from IT by establishing effective controls
II.Whether controls over IT systems are effective when they maintain the integrity of information and the security of the data such systems process
III.Whether IT controls are automated or manual in nature
A. I
B. I and II
C. I and III
D. I, II, and III
Guys. Answer is B. But isn't III important to understand risks involved ? ( If major operations are run with manual controls, isn't that a risk )??