The best answer is C. Review audit planning documents.
Before an audit project starts, senior audit leadership must ensure the engagement has been adequately planned. Reviewing planning documents is the control point that lets leadership confirm the objective, scope, risk focus, resourcing, timing, and methodology are appropriate before fieldwork begins. This is the broadest and most essential oversight activity among the choices.
Option A can be part of governance in some audit functions, but direct scope signoff is narrower than review of the full planning package. Option B and D may occur depending on the audit approach, but they are not mandatory leadership actions in every case. The most defensible answer is leadership review of the planning documents because it establishes readiness and oversight before the project begins.
References (Official ISACA):
ISACA, CISA Exam Content Outline — audit planning and execution are structured and risk-based.
ISACA, Now Is the Time for IT Auditors to Perform Advisory Pre-Implementation Reviews — emphasizes engaging leadership and planning around risk and control deficiencies.
ISACA, An Appropriate Approach for Program and Project Management — supports structured planning and oversight before execution.
Submit