CISA - Information Systems Auditing Process (18% of the exam) - Section 1.2

Execute audits by managing the audit project, applying testing and sampling methodology, and collecting sufficient audit evidence.

Apply audit project management techniques to schedule, resource and supervise an IS audit engagement within scope. Use testing and sampling methodology and audit data analytics to gather sufficient, appropriate audit evidence.

audit project managementtesting and sampling methodologyaudit evidence collectionaudit data analytics

Practice question for this objective

Free sampleInformation Systems Auditing Processmedium

An IS auditor is allocating effort within a fixed audit budget across planning, fieldwork, reporting and follow-up. Which approach to managing the engagement BEST aligns with ISACA performance standards?

  • AFront-load the budget into fieldwork because the largest volume of testing occurs at that phase and reporting can be compressed to fit remaining hours.
  • BDistribute the budget equally across the four phases so that no single phase consumes a disproportionate share of available hours.
  • CSpend the planning hours on detailed substantive testing so that fieldwork can focus entirely on documenting and packaging the results.
  • DAllocate effort based on the assessed risk and the procedures necessary to obtain sufficient appropriate evidence, adjusting the budget as the audit progresses. Correct
Allocate audit project effort according to assessed risk and evidence needs, revising the budget as the engagement progresses. Performance standards require risk-based planning, supervision and execution. Effort allocation across planning, fieldwork, reporting and follow-up flows from the assessed risk and the evidence required to support the conclusion, not from arbitrary splits or phase volume. The IS auditor monitors progress and revises the budget if the risk picture changes during fieldwork.

Why A is wrong: Compressing the reporting phase undermines clear communication of findings and severity, which is itself a performance standard requirement; effort allocation cannot follow volume alone.

Why B is wrong: Equal distribution is administratively tidy but is not risk-based; some engagements need heavier planning while others need heavier reporting, depending on subject matter complexity.

Why C is wrong: Substantive testing during planning conflates the phases and bypasses the risk assessment that drives the scope, the procedures and the evidence the auditor will rely on.

Why D is correct: ISACA performance standards require the auditor to plan and supervise the engagement so that procedures match the assessed risk and the evidence objective, with the budget reviewed and adjusted as understanding develops.

See more CISA practice questions, answers explained.

Exam traps in Information Systems Auditing Process

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • Accept the self-assessment as a working baseline and focus fieldwork on any controls that management has rated as marginal or partially effective.

    Why it is wrong: Treating a management self-assessment as a baseline without corroboration relies on insufficient and unreliable evidence, because the auditor has not validated either the criteria used or how ratings were assigned.

  • Variables sampling using mean-per-unit estimation across the 12,000 recertification records

    Why it is wrong: Variables sampling targets monetary or quantitative misstatement and is appealing because the population is large, but it does not test a yes or no compliance attribute such as correct approver.

  • Accept the screenshot as appropriate evidence because it bears the controller's electronic approval marking

    Why it is wrong: Accepting a screenshot is tempting because it is contemporaneous and signed, but evidence produced and selected by the auditee is less reliable than independently obtained system records and is not corroborated.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.