ExamGecko
Question list
Search
Search

Related questions











Question 485 - CISA discussion

Report
Export

An IS auditor is preparing a plan for audits to be carried out over a specified period. Which of the following activities should the IS auditor perform FIRST?

A.
Allocate audit resources.
Answers
A.
Allocate audit resources.
B.
Prioritize risks.
Answers
B.
Prioritize risks.
C.
Review prior audit reports.
Answers
C.
Review prior audit reports.
D.
Determine the audit universe.
Answers
D.
Determine the audit universe.
Suggested answer: D

Explanation:

An audit universe is a comprehensive list of all the auditable entities, processes, and activities within an organization. It helps the IS auditor to identify the scope, objectives, and priorities of the audit plan, as well as the resources and methodologies required to conduct the audits. An audit universe can also help the IS auditor to ensure that all the key risks, controls, and regulations are covered by the audit plan, and that there are no gaps or overlaps in the audit coverage.

The first activity that the IS auditor should perform when preparing a plan for audits to be carried out over a specified period is to determine the audit universe. This involves defining the criteria and methods for identifying and categorizing the auditable units, such as by business function, process, system, location, or risk level. The IS auditor should also consult with the management and other stakeholders to obtain their input and expectations for the audit plan. The IS auditor should then document and validate the audit universe, and update it regularly to reflect any changes in the organization's structure, operations, or environment.

The other three activities are also important for preparing an audit plan, but they should be performed after determining the audit universe. Allocating audit resources involves assigning staff, time, budget, and tools to each audit based on their complexity, priority, and availability. Prioritizing risks involves assessing the likelihood and impact of each risk associated with each auditable unit, and ranking them according to their significance and urgency. Reviewing prior audit reports involves analyzing the findings, recommendations, and actions from previous audits related to each auditable unit, and evaluating their current status and relevance.

Therefore, determining the audit universe is the best answer.

Audit Universe -- UPDATED 2022 -- Examples, Templates & More!

01 February 2023 Audit universe - IIA

asked 18/09/2024
Brent Varona
25 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first