Study sets
English

Certified Information Systems Auditor (CISA) | Domain 1 Audit Planning and Risk Assessment 01

1 / 90.0s

Problem 1 ・ Question 1 / 9

Which reporting relationship best secures the independence of the IS audit function?

View explanation

Reporting functionally to a governing body such as the audit committee strengthens independence from executive management.

Problem 1 ・ Question 2 / 9

What is the most appropriate basis for prioritising audit subjects in the annual audit plan?

View explanation

Risk-based auditing prioritises on the basis of the impact on enterprise objectives and the likelihood of occurrence.

Problem 1 ・ Question 3 / 9

When starting a new audit engagement, what should the IS auditor clarify first?

View explanation

Once the objectives and scope are clear, the procedures, resources and schedule can be worked out.

Problem 1 ・ Question 4 / 9

An IS auditor is asked to audit a system whose design they were responsible for until recently. What is the most appropriate response?

View explanation

Disclose the self-review threat and protect objectivity, for example by moving the work to an independent auditor.

Problem 1 ・ Question 5 / 9

What is the main purpose of considering materiality in audit planning?

View explanation

Materiality is used to identify matters that would affect users' judgement and to allocate audit resources appropriately.

Problem 1 ・ Question 6 / 9

Which risk exists where there are no controls and nothing is done about it?

View explanation

Inherent risk is the risk an activity or asset carries in itself, before controls are taken into account.

Problem 1 ・ Question 7 / 9

Which control stops errors arising in the first place?

View explanation

Preventive controls such as input checks and segregation of duties reduce the likelihood of error and fraud.

Problem 1 ・ Question 8 / 9

The department being audited has no formal approval control, but an independent after-the-event review reduces the risk to a comparable degree. What is that review?

View explanation

A control that makes up for the absence of the intended control to a comparable degree is a compensating control.

Problem 1 ・ Question 9 / 9

An IS auditor has judged the risk of fraud to be high. What should they do next?

View explanation

Design audit procedures that respond to the risk assessed and gather sufficient evidence.