← All CISA Flashcard Decks

IS Audit Planning Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 IS Audit Planning flashcards as text
  1. An IS auditor notices that a key IT system has not been audited in three years. According to risk-based planning, this fact PRIMARILY affects which planning element?

    Answer: Audit frequency prioritization

    A long gap since the last audit increases the priority of that system in audit frequency planning, as unaudited areas may have accumulated undetected risks.

  2. During IS audit planning, which of the following is the BEST source for understanding an organization's IT risk posture?

    Answer: The organization's enterprise risk management (ERM) framework and IT risk register

    The ERM framework and IT risk register document the organization's identified risks, their likelihood and impact, and existing mitigations — making them the primary source for risk-based audit planning.

  3. An IS auditor is planning an audit and must evaluate whether to use Computer-Assisted Audit Techniques (CAATs). The PRIMARY advantage of CAATs is:

    Answer: They enable analysis of entire data populations rather than just samples

    CAATs allow auditors to analyze complete data populations rather than relying on samples, providing greater coverage and statistical confidence in findings.

  4. When planning an IS audit for a regulated financial institution, which external requirement should MOST influence the audit plan?

    Answer: Applicable regulatory requirements and compliance mandates (e.g., FFIEC, SOX)

    Regulatory requirements define mandatory compliance areas that must be covered in the audit plan, taking precedence over internal preferences or vendor guidance.

  5. Which of the following BEST describes the relationship between audit objectives and audit procedures in IS audit planning?

    Answer: Audit objectives drive the design of audit procedures used to gather evidence

    Audit objectives define what the auditor seeks to determine, and audit procedures are then designed specifically to gather the evidence needed to meet those objectives.

  6. During IS audit planning, an auditor reviews organizational charts and job descriptions. The PRIMARY purpose is to:

    Answer: Understand segregation of duties and the assignment of IT responsibilities

    Reviewing organizational charts and job descriptions helps the auditor understand how IT responsibilities are assigned and whether proper segregation of duties exists.

  7. An IS auditor concludes that the planned audit cannot be completed within budget due to expanded scope. The auditor should FIRST:

    Answer: Inform management and obtain approval for additional resources or a revised scope

    When audit constraints arise, the auditor must communicate transparently with management to either secure additional resources or formally revise the scope through proper approval.