CISA - Information Systems Auditing Process - Section 1.2

Apply quality assurance and continuous improvement practices to the IS audit process.

Understand the purpose of a quality assurance and improvement programme (QAIP) and how it supports ongoing audit quality. Distinguish between internal and external quality assessments and identify actions that drive continuous audit process improvement.

quality assuranceQAIPaudit process improvementaudit quality

Practice question for this objective

Free sampleInformation Systems Auditing Processmedium

Which statement BEST describes the purpose of a Quality Assurance and Improvement Programme (QAIP) within an IS audit function?

  • ATo replace the need for external regulatory inspection of the audit function by demonstrating that internal controls operate effectively across the organisation.
  • BTo verify that auditees implement corrective actions within agreed deadlines and to escalate overdue actions to the executive committee for resolution.
  • CTo benchmark the IS audit budget against industry peers so that resource allocation requests to the audit committee can be substantiated with comparable data.
  • DTo provide reasonable assurance that the IS audit activity conforms with professional standards and is continuously improving its performance. Correct
Recognise that a QAIP exists to give assurance of standards conformance and to drive continuous improvement in the IS audit function. Professional guidance defines the QAIP as covering both internal and external assessments that evaluate conformance with the standards and code of ethics, plus mechanisms to identify and act on improvement opportunities. Its scope is the audit function itself, not auditee remediation, regulators, or budgeting.

Why A is wrong: Regulatory inspection is independent of the QAIP and is not displaced by internal quality programmes, although strong QAIP outputs may inform regulators' confidence in the function.

Why B is wrong: Tracking corrective actions is part of audit follow-up and reporting, not the central purpose of a QAIP, which targets the audit function's own conformance and improvement.

Why C is wrong: Budget benchmarking may be a by-product of mature quality programmes, but it is not the defined purpose of a QAIP as set out in professional guidance.

Why D is correct: A QAIP is designed precisely to give the chief audit executive and oversight body assurance of standards conformance and to drive ongoing improvement of audit practice.

See more CISA practice questions, answers explained.

More in this domain

Back to all Information Systems Auditing Process objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.