During a CFSA practice engagement at a regional bank integrating a fintech loan-origination platform two months before year-end, the audit team notes that privileged-access reviews are quarterly, incident response exercises omit payment operations, and vendor access is approved outside the IAM workflow. The engagement objective is to evaluate whether controls are designed and operating effectively under current financial-services expectations. Which action best addresses which audit conclusion is best supported?