CISA - Information Systems Acquisition, Development and Implementation - Section 3.2

Assess system migration, infrastructure deployment, data conversion and post-implementation review.

Describe the risks associated with system migration, infrastructure deployment and data conversion, and the controls used to ensure completeness and accuracy of transferred data. Apply post-implementation review techniques to confirm that the system meets business requirements and that outstanding issues are tracked to resolution.

system migrationinfrastructure deploymentdata conversionpost-implementation review

Practice question for this objective

Free sampleInformation Systems Acquisition, Development and Implementationmedium

During a data conversion audit for a new customer relationship management system, the IS auditor finds that the project team has reconciled record counts between the legacy extract and the new database and reported a 100 percent match. The team has cited this as evidence that conversion is complete. How should the IS auditor evaluate this evidence?

  • AAccept the reconciliation as sufficient, because matching counts on both sides of the conversion demonstrate that no records were lost or duplicated in transit.
  • BConclude that the evidence is insufficient and request additional testing of data accuracy on a sample of converted records, including key financial and reference fields. Correct
  • CTreat the reconciliation as a compensating control and document that no further substantive testing of the converted data is required for the engagement.
  • DRecommend that the project team re-run the conversion in a parallel environment for one month before signing off on the migration as accurate.
Recognise that data conversion evidence must cover both completeness and accuracy; record counts alone do not justify a clean conversion opinion. Audit evidence for data conversion has two distinct dimensions: completeness, which is typically tested through record-count and control-total reconciliations, and accuracy, which is tested through field-level comparison or recalculation on a sample. A count match is necessary but not sufficient, because translation errors, truncated fields and code-table remappings can leave counts intact while corrupting values.

Why A is wrong: Record counts confirm completeness of transfer but do not test whether field values, relationships or derived attributes survived the conversion intact; accepting counts alone risks signing off on silent data corruption.

Why B is correct: Sufficient conversion evidence must address completeness AND accuracy; sampling converted records to compare field-level values against the source is the standard audit response when only a count reconciliation has been performed.

Why C is wrong: A reconciliation of counts is a detective control over completeness, not a compensating control for missing accuracy testing; labelling it as compensating misuses the control taxonomy and weakens the audit conclusion.

Why D is wrong: A month-long parallel conversion is disproportionate when the only gap is accuracy testing; the auditor should request targeted substantive evidence first rather than mandate a costly re-engineering of the cutover approach.

See more CISA practice questions, answers explained.

More in this domain

Back to all Information Systems Acquisition, Development and Implementation objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.