In a risk-based audit approach, an IS auditor should FIRST complete :
A. inherent risk assessment. B. control risk assessment. C. test of control assessment. D. substantive test assessment.