ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessMedium

An IS auditor has completed fieldwork for an audit of an organization's new enterprise resource planning (ERP) system implementation. Several high-risk findings related to data integrity and access control weaknesses were identified. The auditor is now preparing to communicate these findings to senior management and the board of directors. Which of the following should be the IS auditor's PRIMARY consideration when presenting these audit results?

  1. ASuggesting specific vendors and solutions for remediating the identified weaknesses.
  2. BEnsuring all audit procedures performed are meticulously documented in the presentation.
  3. CFocusing on the potential business impact and strategic risks associated with the findings.
  4. DProviding a detailed technical explanation of each vulnerability found.
Show answer & explanation

Correct answer: C. Focusing on the potential business impact and strategic risks associated with the findings.

When communicating high-risk findings to senior management and the board, the primary consideration should be the business impact and strategic risks. This approach ensures that the audience, who typically focuses on strategic objectives and organizational well-being, understands the gravity and relevance of the audit results.

Why the other options are wrong

  • A. Suggesting specific vendors can compromise auditor independence and is generally not the primary role of an IS auditor when presenting findings.
  • B. Detailed documentation of audit procedures is for audit working papers and internal review, not the executive presentation.
  • D. While technical details are important for remediation, senior management and the board primarily need to understand the business implications, not granular technical specifics.

Communicating Audit Results

The process of formally presenting audit findings, conclusions, and recommendations to relevant stakeholders, tailored to their level of understanding and responsibility.

  • Report should be clear, concise, and constructive.
  • Focus on business impact for executive audiences.
  • Include recommendations for remediation.

Memory trick: Communicate Clearly, Connect to Consequences, Convince with Context.

More Domain 1: Information System Auditing Process questions