ExamGecko
Question list
Search
Search

Related questions

Question 128 - CISA discussion

Report
Export

While executing follow-up activities, an IS auditor is concerned that management has implemented corrective actions that are different from those originally discussed and agreed with the audit function. In order to resolve the situation, the IS auditor's BEST course of action would be to:

A.
re-prioritize the original issue as high risk and escalate to senior management.
Answers
A.
re-prioritize the original issue as high risk and escalate to senior management.
B.
schedule a follow-up audit in the next audit cycle.
Answers
B.
schedule a follow-up audit in the next audit cycle.
C.
postpone follow-up activities and escalate the alternative controls to senior audit management.
Answers
C.
postpone follow-up activities and escalate the alternative controls to senior audit management.
D.
determine whether the alternative controls sufficiently mitigate the risk.
Answers
D.
determine whether the alternative controls sufficiently mitigate the risk.
Suggested answer: D

Explanation:

The IS auditor's best course of action in this situation is to determine whether the alternative controls sufficiently mitigate the risk. Alternative controls are different from those originally discussed and agreed with the audit function, but they may still achieve the same objective of addressing the audit issue or reducing the risk to an acceptable level. The IS auditor should evaluate whether the alternative controls are appropriate, effective, and sustainable before closing the audit finding or escalating it to senior management. The other options are not appropriate for resolving this situation, as they do not consider whether the alternative controls are adequate or reasonable. Re-prioritizing the original issue as high risk and escalating to senior management is a drastic step that may undermine the relationship between the auditor and management, and it should be done only after exhausting other means of resolving the issue. Scheduling a follow-up audit in the next audit cycle is unnecessary, as follow-up activities should be performed as soon as possible after management has implemented corrective actions. Postponing follow-up activities and escalating the alternative controls to senior audit management is premature, as follow-up activities should be completed before reporting any findings or recommendations to senior audit management.Reference:CISA Review Manual (Digital Version), Chapter 2, Section 2.4

asked 18/09/2024
chalapathy naidu
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first