ExamGecko
Question list
Search
Search

Related questions











Question 524 - CISA discussion

Report
Export

An IS auditor engaged in developing the annual internal audit plan learns that the chief information officer (CIO) has requested there be no IS audits in the upcoming year as more time is needed to address a large number of recommendations from the previous year. Which of the following should the auditor do FIRST

A.
Escalate to audit management to discuss the audit plan
Answers
A.
Escalate to audit management to discuss the audit plan
B.
Notify the chief operating officer (COO) and discuss the audit plan risks
Answers
B.
Notify the chief operating officer (COO) and discuss the audit plan risks
C.
Exclude IS audits from the upcoming year's plan
Answers
C.
Exclude IS audits from the upcoming year's plan
D.
Increase the number of IS audits in the clan
Answers
D.
Increase the number of IS audits in the clan
Suggested answer: A

Explanation:

The auditor should first escalate to audit management to discuss the audit plan. This is because the audit plan should be based on a risk assessment and aligned with the organization's objectives and strategies. The auditor should not accept the CIO's request without proper justification and approval from the audit management, who are responsible for ensuring the audit plan's quality and independence. The auditor should also communicate the potential risks and implications of not conducting IS audits in the upcoming year, such as missing new or emerging threats, vulnerabilities, or compliance issues.Reference:

CISA Review Manual (Digital Version), Chapter 2, Section 2.11

CISA Online Review Course, Domain 1, Module 1, Lesson 22

asked 18/09/2024
Tania Trif
50 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first