ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessEasy

An IS auditor is performing a follow-up audit on previously identified control weaknesses related to user access management. The original audit report recommended implementing a quarterly user access review process. The auditor finds that the organization has implemented an automated tool to facilitate these reviews, but only 50% of department managers are completing their reviews on time. What should be the IS auditor's PRIMARY conclusion regarding the effectiveness of the corrective action?

  1. AThe corrective action is partially effective, but further action is needed to ensure full compliance.
  2. BThe corrective action is effective for the managers who complete their reviews, so no further action is required.
  3. CThe corrective action is fully effective because an automated tool has been implemented.
  4. DThe corrective action is ineffective because 50% compliance is unacceptable.
Show answer & explanation

Correct answer: A. The corrective action is partially effective, but further action is needed to ensure full compliance.

While the organization has taken a step towards addressing the weakness by implementing an automated tool, the low completion rate (50%) indicates that the control is not consistently operating as intended. Therefore, the action is partially effective, but improvements are necessary to achieve full effectiveness.

Why the other options are wrong

  • B. This conclusion ignores the 50% non-compliance, which is a significant risk and requires further action.
  • C. Implementation of a tool alone does not guarantee effectiveness; the control must operate as intended.
  • D. Stating it's 'ineffective' is too strong, as there's some positive movement (tool implemented, 50% compliance). 'Partially effective' is more accurate.

Follow-up Audit Effectiveness

Assessing whether previously recommended corrective actions have been properly implemented and are operating effectively to mitigate identified risks.

  • Focuses on the operational effectiveness of controls.
  • Determines if risks are sufficiently reduced.
  • Leads to further recommendations if controls are not fully effective.

Memory trick: Did the fix work? Look at the results, not just the intent.

More Domain 1: Information System Auditing Process questions