ExamGecko
Question list
Search
Search

Related questions











Question 532 - CISA discussion

Report
Export

An IS auditor is assigned to review the IS department s quality procedures. Upon contacting the IS manager, the auditor finds that there is an informal unwritten set of standards Which of the following should be the auditor's NEXT action1?

A.
Make recommendations to IS management as to appropriate quality standards
Answers
A.
Make recommendations to IS management as to appropriate quality standards
B.
Postpone the audit until IS management implements written standards
Answers
B.
Postpone the audit until IS management implements written standards
C.
Document and lest compliance with the informal standards
Answers
C.
Document and lest compliance with the informal standards
D.
Finalize the audit and report the finding
Answers
D.
Finalize the audit and report the finding
Suggested answer: C

Explanation:

The auditor's next action after finding that there is an informal unwritten set of standards in the IS department is to document and test compliance with the informal standards. This is because the auditor's role is to evaluate the adequacy and effectiveness of the existing controls, regardless of whether they are formal or informal, written or unwritten. The auditor should also assess the risks and implications of having informal standards, such as lack of consistency, accountability, or traceability. The auditor should not make recommendations, postpone the audit, or finalize the audit without performing the audit procedures.Reference:

CISA Review Manual (Digital Version), Chapter 2, Section 2.21

CISA Online Review Course, Domain 1, Module 1, Lesson 12

asked 18/09/2024
Hammad Chandio
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first