ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationEasy
During a post-implementation review of a new financial reporting system, an IS auditor observes that several critical reports are generated using data that is manually extracted, manipulated in spreadsheets, and then re-uploaded to the system. Which of the following is the MOST significant risk associated with this practice?
- AIncreased processing time for financial reports.
- BReliance on specific personnel for report generation.
- CDifficulty in auditing the manual data manipulation steps.
- DPotential for unauthorized access to sensitive financial data.
Show answer & explanationAnswer & explanation
Correct answer: C. Difficulty in auditing the manual data manipulation steps.
Manual manipulation of data outside of the controlled system environment creates significant auditability challenges, making it difficult to verify data integrity and accuracy.
Why the other options are wrong
- A. While true, increased processing time is an operational inefficiency, not the MOST significant risk compared to data integrity and auditability.
- B. Reliance on specific personnel is a business continuity risk, but the direct impact of manual data manipulation on financial reporting is primarily data integrity and auditability.
- D. While possible, unauthorized access is a general security risk. The direct and most significant risk of manual manipulation is the loss of data integrity and auditability.
Manual Data Manipulation Risk
The risk associated with data being processed or altered outside of automated, controlled system environments, leading to potential inaccuracies and audit trail gaps.
- Compromises data integrity and accuracy.
- Breaks the automated audit trail.
- Increases risk of human error and fraud.
Memory trick: After launch, watch for manual gaps, they hide the traps.