ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessMedium
An IS auditor is reviewing an organization's change management process for critical production systems. The auditor observes that a significant number of emergency changes are implemented without prior testing in a non-production environment. What type of risk does this situation PRIMARILY represent?
- AAudit risk
- BDetection risk
- CControl risk
- DInherent risk
Show answer & explanationAnswer & explanation
Correct answer: C. Control risk
Control risk is the risk that a material misstatement or control weakness will not be prevented, or detected and corrected, on a timely basis by the organization's internal controls. Implementing emergency changes without prior testing indicates a weakness in the change management controls, directly impacting control risk.
Why the other options are wrong
- A. Audit risk is the risk that the IS auditor expresses an inappropriate audit opinion when the financial statements or information systems are materially misstated or contain significant control weaknesses.
- B. Detection risk is the risk that the IS auditor's procedures will not detect a material misstatement or control weakness.
- D. Inherent risk is the susceptibility of an assertion to a material misstatement, assuming there are no related controls.
Control Risk
Control risk is the risk that a material misstatement or error in information systems or financial statements will not be prevented, or detected and corrected, on a timely basis by the entity's internal control system.
- Directly relates to the effectiveness of an organization's internal controls.
- High control risk indicates weak or absent controls.
- IS auditors assess control risk to determine the nature, timing, and extent of substantive testing.
Memory trick: I Can't Detect Anything - that's Audit Risk!