CISA - Information Systems Auditing Process (18% of the exam) - Section 1.2

Apply reporting and communication techniques to convey audit findings to stakeholders.

Recognise the reporting techniques and communication formats used to present audit findings clearly to different stakeholder audiences. Choose the appropriate level of detail and tone for management summaries versus technical findings sections.

reporting techniquescommunication techniquesaudit findingsstakeholder reporting

Practice question for this objective

Free sampleInformation Systems Auditing Processeasy

An IS auditor has finalised fieldwork on a regional insurer's identity and access management review and is about to issue a draft report containing four high-severity findings. Before the report is circulated to the audit committee, what should the IS auditor do FIRST?

  • AIssue the draft directly to the audit committee chair so that the severity of the findings is escalated without delay.
  • BSend the draft to the chief information security officer and request that proposed management responses be appended to each finding. Correct
  • CReduce the rating of two findings to medium so that the report is more likely to be accepted without protracted negotiation.
  • DShare the draft informally with the chief executive over a private call, then proceed straight to final issuance.
Recognise that the IS auditor must obtain a documented management response from accountable owners before finalising and issuing the audit report. Reporting standards require findings to be accompanied by management responses so that those charged with governance see the accountable owner, the proposed remediation, and the target date; circulating the draft to the auditee is the mechanism that produces this evidence and protects the report's balance.

Why A is wrong: Bypassing the auditee removes management's right of reply, weakens balance, and is tempting only when findings feel urgent; ISACA guidance still requires a response cycle before formal issuance.

Why B is correct: Industry-standard reporting practice requires giving auditee management the opportunity to respond before the report is finalised, so that the committee sees both the finding and the accountable manager's action plan side by side.

Why C is wrong: Downgrading severity to ease acceptance compromises objectivity and misleads the committee; rating must reflect risk evidence, not the auditor's appetite for debate.

Why D is wrong: A private executive briefing is not a substitute for documented management responses from the accountable control owners and skips the audit trail the committee expects.

See more CISA practice questions, answers explained.

Exam traps in Information Systems Auditing Process

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • Detection risk only, since inherent risk and control risk are management's responsibility and fall outside the IS audit function's planning remit during annual scoping work.

    Why it is wrong: Tempting because detection risk is the dimension auditors directly modulate through procedures, but a risk-based plan must consider inherent and control risk to decide where to apply procedures in the first place.

  • Reproducing the detailed working-paper references for every test performed so the audit committee can re-perform each procedure independently.

    Why it is wrong: Working-paper detail belongs in the appendices and the auditor's files, not in an executive summary intended for time-pressured readers.

  • The length of time the control weakness has existed in the application since the platform was first deployed in production.

    Why it is wrong: Age of a weakness can inform context but does not by itself describe the risk to the organisation, so it should not drive the severity rating.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.