ExamGecko
Question list
Search
Search

Related questions

Question 165 - CISA discussion

Report
Export

During the discussion of a draft audit report. IT management provided suitable evidence fiat a process has been implemented for a control that had been concluded by the IS auditor as Ineffective. Which of the following is the auditor's BEST action?

A.
Explain to IT management that the new control will be evaluated during follow-up
Answers
A.
Explain to IT management that the new control will be evaluated during follow-up
B.
Re-perform the audit before changing the conclusion.
Answers
B.
Re-perform the audit before changing the conclusion.
C.
Change the conclusion based on evidence provided by IT management.
Answers
C.
Change the conclusion based on evidence provided by IT management.
D.
Add comments about the action taken by IT management in the report.
Answers
D.
Add comments about the action taken by IT management in the report.
Suggested answer: B

Explanation:

The auditor's best action when IT management provides suitable evidence for a control that had been concluded as ineffective is to re-perform the audit before changing the conclusion. This means that the auditor should verify the validity, completeness, and timeliness of the evidence provided by IT management and test the effectiveness of the new control in meeting the audit objectives. The auditor should not change the conclusion based on evidence provided by IT management without re-performing the audit, as this could compromise the auditor's independence and objectivity. The auditor should also not explain to IT management that the new control will be evaluated during follow-up or add comments about the action taken by IT management in the report, as these actions do not address the original audit finding.Reference:CISA Review Manual, 27th Edition, page 439

asked 18/09/2024
Sanaa CHOKIRI
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first