CISA - Information Systems Auditing Process - Section 1.1

Plan IS audits using ISACA standards, guidelines and the code of ethics, selecting audit types and applying risk-based planning.

Describe the ISACA IS audit standards, guidelines and code of ethics that govern auditor conduct and planning decisions. Apply risk-based audit planning to select appropriate audit types and control types for a given engagement.

IS audit standardscode of ethicsrisk-based audit planningtypes of audits and reviewscontrol types

Practice question for this objective

Free sampleInformation Systems Auditing Processmedium

While planning a risk-based audit of a payments processor, the IS auditor finds that an outsourced settlement function has not been audited in four years, has no current process documentation, and processes roughly forty per cent of daily transaction value. The chief audit executive suggests deferring it again because the provider supplies a quarterly assurance summary. What should the IS auditor recommend as the PRIMARY basis for the planning decision?

  • ADefer the review for another cycle on the basis that the quarterly provider summary already gives independent comfort over settlement processing.
  • BSchedule the review immediately on the basis that the four-year gap since the last audit is the strongest indicator that coverage is overdue.
  • CLimit the review to a walkthrough of the provider's quarterly summary, escalating only if the walkthrough identifies a control weakness in the summary itself.
  • DInclude the review and prioritise it based on the inherent risk, control risk and residual risk of the settlement function relative to other auditable units. Correct
Apply risk-based audit planning by prioritising auditable units according to inherent, control and residual risk rather than rotation or provider summaries. Risk-based planning allocates audit effort to the units with the highest residual risk relative to the organisation's objectives. A high-volume outsourced settlement function with no current documentation has elevated inherent and control risk, and that combination should drive its place in the plan rather than rotation timing or provider-issued summaries.

Why A is wrong: A provider-issued summary is management information from the auditee's perspective and does not substitute for independent audit assurance, especially where inherent risk is material and unverified.

Why B is wrong: Time since last audit is a useful input but it is not the primary driver in a risk-based plan, which should weight inherent and residual risk rather than rotation alone.

Why C is wrong: Restricting work to a walkthrough of management's own summary fails to gather sufficient and reliable evidence over a high-value process and treats provider assurance as a substitute for independent testing.

Why D is correct: Risk-based audit planning requires the auditor to rank auditable units by inherent and control risk and to allocate effort to areas of highest residual risk, which the settlement function's volume and documentation gaps clearly signal.

See more CISA practice questions, answers explained.

More in this domain

Back to all Information Systems Auditing Process objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.