CISA - Certified Information Systems Auditor IS Audit Planning Questions and Answers — Questions and Answers
Question 1: An IS auditor is developing a risk-based audit plan. Which of the following is the FIRST step the auditor should perform?
- Identify the organization's critical assets and business processes. (Correct answer)
- Review the findings and workpapers from the previous year's audit.
- Develop the audit scope and objectives for specific high-risk areas.
- Interview senior management to understand their perspective on risk.
Correct answer: Identify the organization's critical assets and business processes.
The foundational step in a risk-based audit approach is to understand what is most important to the organization. By identifying critical assets and key business processes, the auditor can then effectively assess the threats and vulnerabilities associated with them to determine areas of highest risk.
Question 2: During the audit planning phase for a financial institution, an IS auditor discovers that a new online banking platform was implemented without a formal risk assessment. Which of the following is the MOST appropriate action for the auditor to take?
- Immediately report a significant finding of non-compliance to the audit committee.
- Expand the audit scope to include a thorough risk assessment of the new platform. (Correct answer)
- Proceed with the original audit plan but note the lack of a risk assessment in the final report.
- Recommend that management commission an independent risk assessment post-implementation.
Correct answer: Expand the audit scope to include a thorough risk assessment of the new platform.
The discovery of a significant change to the IT environment, especially one implemented without a risk assessment, requires the auditor to adjust the audit plan. Expanding the scope to assess the risks associated with the new platform is the most proactive and responsible action to ensure potential vulnerabilities are identified and evaluated.
Question 3: Which of the following is the PRIMARY purpose of an IS audit charter?
- To document the detailed audit procedures and testing methodologies.
- To outline the annual budget and resource allocation for the IS audit function.
- To establish the authority, scope, and responsibilities of the IS audit function. (Correct answer)
- To list the specific systems and applications to be audited during the fiscal year.
Correct answer: To establish the authority, scope, and responsibilities of the IS audit function.
The audit charter is a high-level document that establishes the authority, independence, scope, and overall responsibility of the audit function. It is approved by the highest level of management and the audit committee and provides the foundation for all audit activities.
Question 4: In a risk-based audit approach, the IS auditor's decisions on the nature, timing, and extent of testing should be PRIMARILY based on the:
- availability of skilled audit staff and resources.
- complexity of the organization's IT environment.
- previous year's audit findings and recommendations.
- assessment of inherent and control risks. (Correct answer)
Correct answer: assessment of inherent and control risks.
A risk-based approach requires the auditor to focus resources on areas with the greatest potential for material misstatement or control failure. The assessment of inherent risk (the susceptibility of an area to error) and control risk (the risk that controls will fail to prevent or detect an error) is the key driver for determining how, when, and how much testing is needed.
Question 5: When planning an IS audit, an auditor should review the organization's IT policies, standards, and procedures to:
- design specific substantive tests to detect fraud.
- determine the required sample sizes for compliance testing.
- understand the control environment and established control objectives. (Correct answer)
- evaluate the technical competence of the IT staff.
Correct answer: understand the control environment and established control objectives.
Reviewing governance documents like policies, standards, and procedures gives the auditor a clear understanding of management's intent and the established control framework. This forms the basis for evaluating the adequacy and effectiveness of internal controls.
Question 6: An IS auditor is planning to audit a cloud-based customer relationship management (CRM) system. Which of the following is the MOST important initial step?
- Requesting and reviewing the Service Organization Control (SOC) 2 report from the cloud vendor. (Correct answer)
- Conducting a vulnerability scan of the cloud provider's infrastructure.
- Interviewing the organization's sales team to understand their use of the CRM.
- Verifying the encryption standards used for data in transit to the cloud provider.
Correct answer: Requesting and reviewing the Service Organization Control (SOC) 2 report from the cloud vendor.
When auditing a system hosted by a third party, the most efficient and critical first step is to review the vendor's SOC 2 report. This report provides an independent assessment of the vendor's controls related to security, availability, processing integrity, confidentiality, and privacy, which is essential for scoping the audit and understanding the control environment.
An IS auditor is developing a risk-based audit plan.
Which of the following is the FIRST step the auditor should perform?