ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessEasy
An IS auditor is performing a follow-up audit on previously identified control weaknesses related to user access management. The original audit report recommended implementing a quarterly user access review process. The auditor finds that the organization has implemented an automated tool to facilitate these reviews, but only 50% of department managers are completing their reviews on time. What should be the IS auditor's PRIMARY conclusion regarding the effectiveness of the corrective action?
- AThe corrective action is partially effective, but further action is needed to ensure full compliance.
- BThe corrective action is effective for the managers who complete their reviews, so no further action is required.
- CThe corrective action is fully effective because an automated tool has been implemented.
- DThe corrective action is ineffective because 50% compliance is unacceptable.
Show answer & explanationAnswer & explanation
Correct answer: A. The corrective action is partially effective, but further action is needed to ensure full compliance.
While the organization has taken a step towards addressing the weakness by implementing an automated tool, the low completion rate (50%) indicates that the control is not consistently operating as intended. Therefore, the action is partially effective, but improvements are necessary to achieve full effectiveness.
Why the other options are wrong
- B. This conclusion ignores the 50% non-compliance, which is a significant risk and requires further action.
- C. Implementation of a tool alone does not guarantee effectiveness; the control must operate as intended.
- D. Stating it's 'ineffective' is too strong, as there's some positive movement (tool implemented, 50% compliance). 'Partially effective' is more accurate.
Follow-up Audit Effectiveness
Assessing whether previously recommended corrective actions have been properly implemented and are operating effectively to mitigate identified risks.
- Focuses on the operational effectiveness of controls.
- Determines if risks are sufficiently reduced.
- Leads to further recommendations if controls are not fully effective.
Memory trick: Did the fix work? Look at the results, not just the intent.