ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessHard

An IS auditor is conducting an audit of a critical financial application. The organization uses a complex, custom-developed batch processing system for daily transactions. The auditor wants to ensure the integrity of the data processed by this system. Which of the following audit techniques would be MOST effective for verifying the completeness and accuracy of batch processing?

  1. AUtilizing an integrated test facility (ITF) to process dummy transactions alongside live data.
  2. BPerforming a surprise audit of manual data entry procedures.
  3. CReviewing system logs for error messages and access violations.
  4. DInterviewing system operators about their daily routines and controls.
Show answer & explanation

Correct answer: A. Utilizing an integrated test facility (ITF) to process dummy transactions alongside live data.

An Integrated Test Facility (ITF) involves processing fictitious transactions through the live system along with actual transactions. This allows the auditor to verify the completeness and accuracy of processing, as the expected results for the dummy transactions can be precisely predicted and compared to actual output, without affecting live data.

Why the other options are wrong

  • B. Surprise audits for manual entry are relevant for input controls, but not for the integrity of an automated batch processing system.
  • C. Reviewing logs helps identify errors but doesn't directly verify completeness and accuracy of all transactions.
  • D. Interviews provide understanding but are not a direct testing technique for processing integrity.

Integrated Test Facility (ITF)

An audit technique where fictitious transactions are processed through the client's live system, alongside actual transactions, to test system controls and processing accuracy.

  • Tests live system functionality.
  • Allows for precise prediction of results.
  • Does not interfere with real data.

Memory trick: ITF is like a 'ghost test' in the live system; you know what the ghost should do.

More Domain 1: Information System Auditing Process questions