An IS auditor has finalised fieldwork on a regional insurer's identity and access management review and is about to issue a draft report containing four high-severity findings. Before the report is circulated to the audit committee, what should the IS auditor do FIRST?
- AIssue the draft directly to the audit committee chair so that the severity of the findings is escalated without delay.
- BSend the draft to the chief information security officer and request that proposed management responses be appended to each finding. Correct
- CReduce the rating of two findings to medium so that the report is more likely to be accepted without protracted negotiation.
- DShare the draft informally with the chief executive over a private call, then proceed straight to final issuance.
Why A is wrong: Bypassing the auditee removes management's right of reply, weakens balance, and is tempting only when findings feel urgent; ISACA guidance still requires a response cycle before formal issuance.
Why B is correct: Industry-standard reporting practice requires giving auditee management the opportunity to respond before the report is finalised, so that the committee sees both the finding and the accountable manager's action plan side by side.
Why C is wrong: Downgrading severity to ease acceptance compromises objectivity and misleads the committee; rating must reflect risk evidence, not the auditor's appetite for debate.
Why D is wrong: A private executive briefing is not a substitute for documented management responses from the accountable control owners and skips the audit trail the committee expects.