The correct answer is D. Risks are identified in a timely manner because the main purpose of continuous auditing is to allow audit to evaluate risk and controls on a more frequent or ongoing basis, rather than relying only on periodic, retrospective audits. ISACA explains that continuous auditing enables internal auditors to report on subject matter within a much shorter time frame than traditional auditing and uses technology-based audit techniques to measure and report on risk indicators.
Option A is not the best answer because reviewing evidence for completeness and accuracy is part of audit work, but it is not the primary reason for implementing continuous auditing. Continuous auditing is broader than evidence checking; it is intended to improve the timeliness of risk and control assurance.
Option B is not the best answer because management awareness in real time is more closely associated with continuous monitoring, which is a management responsibility. ISACA specifically distinguishes continuous auditing from continuous monitoring: continuous monitoring is performed by management, while continuous auditing is performed by audit.
Option C is not correct because continuous auditing is not implemented primarily because it is incorporated into continuous monitoring. The two may use similar data or tools, but they have different owners and purposes.
This question maps mainly to Information Systems Auditing Process, because ISACA’s CISA Exam Content Outline includes audit planning, audit execution, audit evidence collection techniques, audit data analytics, reporting, communication, and quality improvement of the audit process under Domain 1.
[References: ISACA CISA Exam Content Outline, Domain 1; ISACA Journal, Defining Targets for Continuous IT Auditing Using COBIT 2019., ===================, ]
Submit