ME
MetricRiskMap2026-05-20
ciaCoreMetricsControl Environmentand Behavioral Risk
Why can defect metrics create behavioral risk?
- Management tracks defects by developer and wants to use those counts for accountability. Why might that be risky?
42 upvotes
Verified ExpertVerified Expert
AcadiFi Certified Professionalauthor: Verified Expert
- Related article:
cia-software-defect-root-cause-controls-map - Related question-bank placeholders:
["quality-metric-behavioral-risk", "recurring-defect-remediation"] - Question:
Why can defect metrics create behavioral risk? - Question detail:
- Management tracks defects by developer and wants to use those counts for accountability. Why might that be risky?
- Answer:
- Metrics influence behavior. If defect counts are used mainly to blame individuals, people may avoid difficult work, underreport issues, delay logging defects, overestimate tasks, or spend time arguing about attribution instead of fixing root causes.
- Internal audit should ask whether the metric supports the control objective. A better metric set may track severity, recurrence by defect class, escaped defects, test coverage, age of unresolved defects, root-cause themes, and whether remediation actions prevent repeat issues.
- The point is not to remove accountability. The point is to align accountability with the process that produces quality.
🔍
Master Core with our CIA Course
45 lessons · 90+ hours· Expert instruction
#metrics#behavioral-risk#control-environment#software-quality
Related Questions
What should an auditor do if a supervisor weakens a supported finding?
cia·CIA Part 2·46 upvotes
How should auditors prepare for a technical exit meeting?
cia·CIA Part 2·35 upvotes
When should audit quality concerns be escalated beyond the engagement team?
cia·CIA Part 2·56 upvotes
How does business knowledge affect internal audit quality?
cia·CIA Part 2·51 upvotes
Where should an auditor begin a full-company internal control audit?
cia·CIA Part 2·51 upvotes
Related Articles
Join the Discussion
Ask questions and get expert answers.