Which of the following best describes RISK ASSESSMENT in a system of internal control?
a) The IT system produces a warning to the system administrator when someone has 3 failed attempts to login.
b) Managers review financial statements quarterly to identify irregularities.
c) The board of directors evaluates potential risks to the organization's objectives.
d) All employees are required to undergo security training annually.