โ† All CISA Flashcard Decks

IS Audit Planning Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 IS Audit Planning flashcards as text
  1. An IS auditor is planning an audit of an organization that recently implemented an AI-based fraud detection system. Which audit area deserves the MOST attention in the initial planning phase?

    Answer: Algorithm bias, model validation, and governance of AI decision-making

    AI systems introduce risks around model accuracy, bias, and lack of explainability, making algorithm validation and governance the most critical areas for an IS auditor to plan around.

  2. Which of the following scenarios BEST illustrates an inappropriate restriction on audit scope that an IS auditor should escalate?

    Answer: Management requests the auditor avoid reviewing a specific high-risk system due to 'sensitivity'

    When management restricts access to a high-risk area without valid justification, it represents a scope limitation that must be escalated to the audit committee as it impairs audit independence.

  3. During IS audit planning, the auditor reviews prior audit workpapers. The PRIMARY benefit of this review is to:

    Answer: Understand previously identified risks, findings, and remediation status to inform current planning

    Reviewing prior workpapers helps identify historical risk areas, outstanding findings, and whether remediation was completed, all of which inform current audit risk assessment and focus.

  4. Which IS audit planning concept ensures that audit conclusions are supported by sufficient, reliable, relevant, and useful evidence?

    Answer: Audit evidence standards

    Audit evidence standards require that the evidence gathered be sufficient (enough), reliable (trustworthy), relevant (pertinent to the objective), and useful (supportive of conclusions).

  5. An IS auditor plans to rely on the work of an internal audit team. Which condition MUST be assessed before placing reliance on their work?

    Answer: The competence and objectivity of the internal audit function

    Before relying on internal audit work, an IS auditor must evaluate the internal audit team's technical competence and organizational objectivity to ensure their work meets adequate standards.

  6. In IS audit planning, which approach helps an auditor identify control gaps by mapping risks to existing controls?

    Answer: Control matrix (risk-control matrix)

    A risk-control matrix maps identified risks to the controls designed to mitigate them, making it easy to spot areas where controls are absent, weak, or duplicated.

  7. An IS auditor is planning an audit in an environment where management has implemented continuous monitoring tools. The auditor should PRIMARILY:

    Answer: Evaluate the design and effectiveness of the continuous monitoring tools as part of the audit plan

    The auditor must assess whether the continuous monitoring tools themselves are properly designed and operating effectively before placing any reliance on their output.