CISA - Information Systems Auditing Process - Section 1.2

Apply reporting and communication techniques to convey audit findings to stakeholders.

Recognise the reporting techniques and communication formats used to present audit findings clearly to different stakeholder audiences. Choose the appropriate level of detail and tone for management summaries versus technical findings sections.

reporting techniquescommunication techniquesaudit findingsstakeholder reporting

Practice question for this objective

Free sampleInformation Systems Auditing Processeasy

An IS auditor has finalised fieldwork on a regional insurer's identity and access management review and is about to issue a draft report containing four high-severity findings. Before the report is circulated to the audit committee, what should the IS auditor do FIRST?

  • AIssue the draft directly to the audit committee chair so that the severity of the findings is escalated without delay.
  • BSend the draft to the chief information security officer and request that proposed management responses be appended to each finding. Correct
  • CReduce the rating of two findings to medium so that the report is more likely to be accepted without protracted negotiation.
  • DShare the draft informally with the chief executive over a private call, then proceed straight to final issuance.
Recognise that the IS auditor must obtain a documented management response from accountable owners before finalising and issuing the audit report. Reporting standards require findings to be accompanied by management responses so that those charged with governance see the accountable owner, the proposed remediation, and the target date; circulating the draft to the auditee is the mechanism that produces this evidence and protects the report's balance.

Why A is wrong: Bypassing the auditee removes management's right of reply, weakens balance, and is tempting only when findings feel urgent; ISACA guidance still requires a response cycle before formal issuance.

Why B is correct: Industry-standard reporting practice requires giving auditee management the opportunity to respond before the report is finalised, so that the committee sees both the finding and the accountable manager's action plan side by side.

Why C is wrong: Downgrading severity to ease acceptance compromises objectivity and misleads the committee; rating must reflect risk evidence, not the auditor's appetite for debate.

Why D is wrong: A private executive briefing is not a substitute for documented management responses from the accountable control owners and skips the audit trail the committee expects.

See more CISA practice questions, answers explained.

More in this domain

Back to all Information Systems Auditing Process objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.