Isaca Certified Information Systems Auditor CISA Question # 162 Topic 17 Discussion
CISA Exam Topic 17 Question 162 Discussion:
Question #: 162
Topic #: 17
An IS auditor is assigned to perform a post-implementation review of an application system. Which of the following would impair the auditor’s independence?
A.
The auditor implemented a specific control during the development of the system.
B.
The auditor participated as a member of the project team without operational responsibilities.
C.
The auditor provided advice concerning best practices.
D.
The auditor designed an embedded audit module exclusively for audit.
If an auditor implemented a control, they would later be reviewing their own work, which creates a self-review threat and compromises independence. Participating in the project without operational responsibilities (B) or providing advice (C) is acceptable as long as the auditor does not take ownership of decisions. Designing audit modules (D) is also permissible since they are for audit use and do not affect operational processes. ISACA’s Code of Professional Ethics and IS Audit Standards emphasize independence and objectivity as fundamental requirements to maintain credibility and avoid conflicts of interest.
References (ISACA): ISACA Standards for IS Audit and Assurance; ISACA Code of Professional Ethics.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit