Isaca Certified Information Systems Auditor CISA Question # 20 Topic 3 Discussion
CISA Exam Topic 3 Question 20 Discussion:
Question #: 20
Topic #: 3
An IS auditor is analyzing a sample of accounts payable transactions for a specific vendor and identifies one transaction with a value five times as high as the average transaction. Which of the following should the auditor do NEXT?
A.
Report the variance immediately to the audit committee
B.
Request an explanation of the variance from the auditee
C.
Increase the sample size to 100% of the population
D.
Exclude the transaction from the sample population
An IS auditor is analyzing a sample of accounts payable transactions for a specific vendor and identifies one transaction with a value five times as high as the average transaction. The next step that the auditor should do is to request an explanation of the variance from the auditee. This is because the variance may indicate an error, fraud, or an unusual but legitimate transaction that requires further investigation. The auditor should not report the variance immediately to the audit committee without verifying its cause and significance. The auditor should not increase the sample size to 100% of the population without considering the cost-benefit analysis and the sampling methodology. The auditor should not exclude the transaction from the sample population without justification, as itmay affect the validity and reliability of the audit results. References: CISA Review Manual (Digital Version), [ISACA Auditing Standards]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit