ExamGecko
Question list
Search
Search

Related questions

Question 285 - CISA discussion

Report
Export

An IS auditor performs a follow-up audit and learns the approach taken by the auditee to fix the findings differs from the agreed-upon approach confirmed during the last audit. Which of the following should be the auditor's NEXT course of action?

A.
Evaluate the appropriateness of the remedial action taken.
Answers
A.
Evaluate the appropriateness of the remedial action taken.
B.
Conduct a risk analysis incorporating the change.
Answers
B.
Conduct a risk analysis incorporating the change.
C.
Report results of the follow-up to the audit committee.
Answers
C.
Report results of the follow-up to the audit committee.
D.
Inform senior management of the change in approach.
Answers
D.
Inform senior management of the change in approach.
Suggested answer: A

Explanation:

The auditor's next course of action should be to evaluate the appropriateness of the remedial action taken by the auditee. The auditor should assess whether the alternative approach taken by the auditee is effective, efficient, and aligned with the audit objectives and recommendations. The auditor should also consider the impact of the change on the audit scope, criteria, and risk assessment. Conducting a risk analysis incorporating the change, reporting results of the follow-up to the audit committee, and informing senior management of the change in approach are possible subsequent actions that the auditor may take after evaluating the appropriateness of the remedial action taken.Reference:CISA Review Manual (Digital Version): Chapter 1 - Information Systems Auditing Process

asked 18/09/2024
janet phillips
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first