b. Relevant guidance is in Practice Advisory 2210.A1-1, Risk Assessment in Engagement Planning:
1) Internal auditors consider management's assessment of risks relevant to the activity under review. The internal auditor also considers:
The reliability of management's assessment of risk.
Management's process for monitoring, reporting, and resolving risk and control issues.
Management's reporting of events that exceeded the limits of the organization's risk appetite and management's response to those reports.
Risks in related activities relevant to the activity under review" (para. 1).
2) “Internal auditors summarize the results from the reviews of management's assessment of risk, the background information, and any survey work” (para. 4).