ExamGecko
Question list
Search
Search

Related questions











Question 581 - CISA discussion

Report
Export

During the discussion of a draft audit report IT management provided suitable evidence that a process has been implemented for a control that had been concluded by the IS auditor as ineffective Which of the following is the auditor's BEST action?

A.
Explain to IT management that the new control will be evaluated during follow-up
Answers
A.
Explain to IT management that the new control will be evaluated during follow-up
B.
Add comments about the action taken by IT management in the report
Answers
B.
Add comments about the action taken by IT management in the report
C.
Change the conclusion based on evidence provided by IT management
Answers
C.
Change the conclusion based on evidence provided by IT management
D.
Re-perform the audit before changing the conclusion
Answers
D.
Re-perform the audit before changing the conclusion
Suggested answer: D

Explanation:

The auditor's best action is to re-perform the audit before changing the conclusion, because the auditor needs to obtain sufficient and appropriate evidence to support the audit opinion. The evidence provided by IT management may not be reliable or relevant, and it may not reflect the actual effectiveness of the control during the audit period. Therefore, the auditor should verify the evidence independently and test the control again to ensure that it meets the audit criteria and objectives. The other options are not appropriate, because they either ignore or accept the evidence provided by IT management without verification, which may compromise the quality and integrity of the audit.Reference:

ISACA, CISA Review Manual, 27th Edition, chapter 1, section 1.51

ISACA, IT Audit and Assurance Standards, Guidelines and Tools and Techniques for IS Audit and Assurance Professionals, section 12062

asked 18/09/2024
Easwari Lakshminarayanan
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first