CISA - Information Systems Auditing Process - Section 1.2

Execute audits by managing the audit project, applying testing and sampling methodology, and collecting sufficient audit evidence.

Apply audit project management techniques to schedule, resource and supervise an IS audit engagement within scope. Use testing and sampling methodology and audit data analytics to gather sufficient, appropriate audit evidence.

audit project managementtesting and sampling methodologyaudit evidence collectionaudit data analytics

Practice question for this objective

Free sampleInformation Systems Auditing Processmedium

An IS auditor is allocating effort within a fixed audit budget across planning, fieldwork, reporting and follow-up. Which approach to managing the engagement BEST aligns with ISACA performance standards?

  • AFront-load the budget into fieldwork because the largest volume of testing occurs at that phase and reporting can be compressed to fit remaining hours.
  • BDistribute the budget equally across the four phases so that no single phase consumes a disproportionate share of available hours.
  • CSpend the planning hours on detailed substantive testing so that fieldwork can focus entirely on documenting and packaging the results.
  • DAllocate effort based on the assessed risk and the procedures necessary to obtain sufficient appropriate evidence, adjusting the budget as the audit progresses. Correct
Allocate audit project effort according to assessed risk and evidence needs, revising the budget as the engagement progresses. Performance standards require risk-based planning, supervision and execution. Effort allocation across planning, fieldwork, reporting and follow-up flows from the assessed risk and the evidence required to support the conclusion, not from arbitrary splits or phase volume. The IS auditor monitors progress and revises the budget if the risk picture changes during fieldwork.

Why A is wrong: Compressing the reporting phase undermines clear communication of findings and severity, which is itself a performance standard requirement; effort allocation cannot follow volume alone.

Why B is wrong: Equal distribution is administratively tidy but is not risk-based; some engagements need heavier planning while others need heavier reporting, depending on subject matter complexity.

Why C is wrong: Substantive testing during planning conflates the phases and bypasses the risk assessment that drives the scope, the procedures and the evidence the auditor will rely on.

Why D is correct: ISACA performance standards require the auditor to plan and supervise the engagement so that procedures match the assessed risk and the evidence objective, with the budget reviewed and adjusted as understanding develops.

See more CISA practice questions, answers explained.

More in this domain

Back to all Information Systems Auditing Process objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.