Isaca Certified Information Systems Auditor CISA Question # 252 Topic 26 Discussion
CISA Exam Topic 26 Question 252 Discussion:
Question #: 252
Topic #: 26
During a follow-up audit, an IS auditor learns that management has deferred the implementation of a previously agreed-upon recommendation. What is the responsibility of the auditor?
A.
Assess the impact of any risks the decision may pose to the organization.
B.
Amend the final report to reflect the decision to defer the implementation.
C.
Obtain commitment from management to implement the recommendation.
D.
Report the decision to defer the implementation to the steering committee.
The correct answer is A. Assess the impact of any risks the decision may pose to the organization.
During follow-up, the auditor’s responsibility is to determine whether management’s actions have sufficiently addressed the identified risk. If management defers an agreed corrective action, the auditor should assess whether the remaining risk is acceptable or whether the deferral exposes the organization to unacceptable risk.
ISACA guidance on audit follow-up states that IS audit and assurance professionals should monitor relevant information to conclude whether management has planned or taken appropriate and timely action to address reported audit findings and recommendations. It also identifies deferring follow-up activities and assuming the risk of not taking corrective action as part of the follow-up process.
Option B is not the best answer because simply amending the final report does not evaluate the risk impact. Option C is not the best answer because management, not the auditor, owns corrective action. The auditor can recommend and follow up but should not force management commitment. Option D may be appropriate later if the risk is significant or exceeds risk appetite, but the auditor should first assess the impact.
This question maps to Information Systems Auditing Process, because ISACA’s CISA Exam Content Outline includes conducting post-audit follow-up to evaluate whether identified risk has been sufficiently addressed.
[References: ISACA CISA Exam Content Outline, Domain 1; ISACA Journal, Enhancing the Audit Follow-up Process Using COBIT 5., ===================, ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit