ExamGecko
Question list
Search
Search

Related questions

Question 113 - CISA discussion

Report
Export

An IS auditor is following up on prior period items and finds management did not address an audit finding. Which of the following should be the IS auditor's NEXT course of action?

A.
Note the exception in a new report as the item was not addressed by management.
Answers
A.
Note the exception in a new report as the item was not addressed by management.
B.
Recommend alternative solutions to address the repeat finding.
Answers
B.
Recommend alternative solutions to address the repeat finding.
C.
Conduct a risk assessment of the repeat finding.
Answers
C.
Conduct a risk assessment of the repeat finding.
D.
Interview management to determine why the finding was not addressed.
Answers
D.
Interview management to determine why the finding was not addressed.
Suggested answer: D

Explanation:

If an IS auditor finds that management did not address a prior period audit finding, the next course of action should be to interview management to determine why the finding was not addressed, as this would help to understand the root cause, the impact, and the risk level of the issue.Noting the exception in a new report, recommending alternative solutions, or conducting a risk assessment are possible subsequent steps, but they should not precede interviewing management.Reference:CISA Review Manual (Digital Version), Chapter 1, Section 1.6

asked 18/09/2024
Sumit Sengupta
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first