The four-level model for reviewing application controls follows a hierarchy:
Level 1 - Activity: Smallest unit of work within a process.
Level 2 - Subprocess: A collection of related activities that accomplish a part of the process.
Level 3 - Major Process: A significant business function consisting of multiple subprocesses.
Level 4 - Mega Process: The highest level, representing an end-to-end business process, often spanning multiple departments or systems.
Mega processes encompass entire business functions (e.g., order-to-cash or procure-to-pay cycles).
They involve multiple major processes and provide a high-level perspective on business operations.
At level 4, the focus is on strategic alignment of IT application controls with enterprise-wide objectives.
A. Activity – Too detailed and only represents individual tasks.
B. Subprocess – A subset of a major process, not a high-level business function.
C. Major Process – A significant function but not the highest-level view.
IIA’s GTAG on Business Process Controls – Recommends a hierarchical review model to assess IT application controls.
COBIT 2019 (Governance and Management of IT) – Defines mega processes as enterprise-wide workflows.
ISO 27001 Annex A.12 (Operational Security) – Highlights process-based security in IT controls.
Why "Mega Process" is the Correct Answer?Why Not the Other Options?IIA References:✅ Final Answer: D. Mega process.