ExamGecko
Question list
Search
Search

Related questions











Question 567 - CISA discussion

Report
Export

When planning an audit, it is acceptable for an IS auditor to rely on a third-party provider's external audit report on service level management when the

A.
scope and methodology meet audit requirements
Answers
A.
scope and methodology meet audit requirements
B.
service provider is independently certified and accredited
Answers
B.
service provider is independently certified and accredited
C.
report confirms that service levels were not violated
Answers
C.
report confirms that service levels were not violated
D.
report was released within the last 12 months
Answers
D.
report was released within the last 12 months
Suggested answer: A

Explanation:

It is acceptable for an IS auditor to rely on a third-party provider's external audit report on service level management when the scope and methodology meet audit requirements. This means that the external audit report covers the same objectives, criteria, standards and procedures that the IS auditor would use to assess the service level management. This way, the IS auditor can avoid duplication of work and reduce audit costs and efforts. The service provider's certification and accreditation, the report's confirmation of service levels and the report's release date are not sufficient to justify reliance on the external audit report.Reference:CISA Review Manual (Digital Version) , Chapter 2, Section 2.3.3.

asked 18/09/2024
Nishan Perera
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first