ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessHard

An IS auditor is planning an audit of a newly deployed customer relationship management (CRM) system that handles personally identifiable information (PII). The organization operates globally and is subject to various data privacy regulations (e.g., GDPR, CCPA). Which of the following should be the auditor's PRIMARY focus during the planning phase?

  1. AInterviewing sales and marketing teams to gauge their satisfaction with the new CRM features.
  2. BAssessing the efficiency of data input processes to minimize user errors.
  3. CReviewing the project's budget adherence and cost-effectiveness of the CRM implementation.
  4. DEvaluating the system's compliance with applicable data privacy regulations and internal PII handling policies.
Show answer & explanation

Correct answer: D. Evaluating the system's compliance with applicable data privacy regulations and internal PII handling policies.

Given that the CRM system handles PII for a global organization subject to various data privacy regulations, ensuring compliance with these regulations and internal policies is the most critical and primary focus during the planning phase. Non-compliance can lead to severe legal, financial, and reputational consequences, outweighing other considerations.

Why the other options are wrong

  • A. User satisfaction is a business benefit but not the primary audit focus when regulatory compliance of PII handling is at stake.
  • B. Data input efficiency is an operational concern, but less critical than regulatory compliance for PII.
  • C. Budget adherence is important but secondary to regulatory compliance when sensitive data and multiple jurisdictions are involved.

Audit Planning - Regulatory Compliance

A critical aspect of audit planning, especially for systems handling sensitive data or operating globally, focusing on ensuring adherence to relevant laws, regulations, and industry standards.

  • Non-compliance carries significant legal and financial risks.
  • Requires understanding jurisdiction-specific requirements.
  • Often involves reviewing policies, controls, and data handling practices.

Memory trick: When sensitive data is involved, compliance is king.

More Domain 1: Information System Auditing Process questions