ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessMedium

An IS auditor is reviewing an organization's change management process for critical production systems. The auditor observes that a significant number of emergency changes are implemented without prior testing in a non-production environment. What type of risk does this situation PRIMARILY represent?

  1. AAudit risk
  2. BDetection risk
  3. CControl risk
  4. DInherent risk
Show answer & explanation

Correct answer: C. Control risk

Control risk is the risk that a material misstatement or control weakness will not be prevented, or detected and corrected, on a timely basis by the organization's internal controls. Implementing emergency changes without prior testing indicates a weakness in the change management controls, directly impacting control risk.

Why the other options are wrong

  • A. Audit risk is the risk that the IS auditor expresses an inappropriate audit opinion when the financial statements or information systems are materially misstated or contain significant control weaknesses.
  • B. Detection risk is the risk that the IS auditor's procedures will not detect a material misstatement or control weakness.
  • D. Inherent risk is the susceptibility of an assertion to a material misstatement, assuming there are no related controls.

Control Risk

Control risk is the risk that a material misstatement or error in information systems or financial statements will not be prevented, or detected and corrected, on a timely basis by the entity's internal control system.

  • Directly relates to the effectiveness of an organization's internal controls.
  • High control risk indicates weak or absent controls.
  • IS auditors assess control risk to determine the nature, timing, and extent of substantive testing.

Memory trick: I Can't Detect Anything - that's Audit Risk!

More Domain 1: Information System Auditing Process questions