ExamGecko
Question list
Search
Search

Related questions











Question 502 - CISA discussion

Report
Export

An IS auditor conducts a review of a third-party vendor's reporting of key performance indicators (KPIs) Which of the following findings should be of MOST concern to the auditor?

A.
KPI data is not being analyzed
Answers
A.
KPI data is not being analyzed
B.
KPIs are not clearly defined
Answers
B.
KPIs are not clearly defined
C.
Some KPIs are not documented
Answers
C.
Some KPIs are not documented
D.
KPIs have never been updated
Answers
D.
KPIs have never been updated
Suggested answer: B

Explanation:

KPIs are not clearly defined is the most concerning finding for an IS auditor, because it implies that the third-party vendor does not have a clear understanding of what constitutes success or failure in their performance. This can lead to inaccurate or misleading reporting, poor decision making, and lack of accountability.KPIs should be SMART (specific, measurable, achievable, relevant, and time-bound) and aligned with the business objectives and expectations of the stakeholders12.Reference:1: CISA Review Manual (Digital Version), Chapter 5, Section 5.3.22: CISA Online Review Course, Module 5, Lesson 3

asked 18/09/2024
Marcos Losa Torviso
53 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first