ExamGecko
Question list
Search
Search

Related questions











Question 423 - CISA discussion

Report
Export

What should an IS auditor do FIRST when management responses to an in-person internal control questionnaire indicate a key internal control is no longer effective?

A.
Determine the resources required to make the control effective.
Answers
A.
Determine the resources required to make the control effective.
B.
Validate the overall effectiveness of the internal control.
Answers
B.
Validate the overall effectiveness of the internal control.
C.
Verify the impact of the control no longer being effective.
Answers
C.
Verify the impact of the control no longer being effective.
D.
Ascertain the existence of other compensating controls.
Answers
D.
Ascertain the existence of other compensating controls.
Suggested answer: D

Explanation:

The first thing that an IS auditor should do when management responses to an in-person internal control questionnaire indicate a key internal control is no longer effective is to ascertain the existence of other compensating controls. Compensating controls are alternative controls that provide reasonable assurance of achieving the same objective as the original control. The IS auditor should verify whether there are any compensating controls in place that can mitigate the risk of the key control being ineffective, and evaluate their adequacy and effectiveness.The other options are not the first steps, because they either require more information about the compensating controls, or they are actions to be taken after identifying and assessing the compensating controls.Reference:CISA Review Manual (Digital Version)1, Chapter 2, Section 2.2.3

asked 18/09/2024
Kelvin Ogwu
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first