ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessEasy

An IS auditor is planning an audit of a critical financial system. During the risk assessment phase, the auditor identifies that the system processes highly sensitive customer data and is subject to stringent regulatory compliance requirements. Management has also indicated that the system's previous audit uncovered several material weaknesses that were never fully remediated due to budget constraints. Which of the following factors should the IS auditor consider MOST significant when determining the scope and approach for this audit?

  1. AThe availability of system documentation and previous audit reports.
  2. BThe system's processing volume and transaction rates.
  3. CThe high inherent risk associated with sensitive data and unaddressed prior audit findings.
  4. DThe experience level and availability of the audit team members.
Show answer & explanation

Correct answer: C. The high inherent risk associated with sensitive data and unaddressed prior audit findings.

The most significant factor influencing audit scope and approach is the inherent risk, which is elevated by sensitive data and unaddressed prior findings. These elements directly impact the likelihood and impact of control failures, necessitating a more comprehensive audit.

Why the other options are wrong

  • A. While important for efficiency, the availability of documentation does not define the fundamental risk level of the system.
  • B. Processing volume is a factor but less critical than the fundamental risks associated with the data itself and control weaknesses.
  • D. Team experience is an operational constraint for the audit, not a primary factor in determining the inherent risk of the system being audited.

Inherent Risk

The susceptibility of an assertion or an account balance to a material misstatement, assuming there are no related internal controls.

  • Exists independently of the audit.
  • Higher for complex transactions or sensitive data.
  • Directly influences the scope and nature of audit procedures.

Memory trick: Risk Rises, Audit Responds: inherent risk dictates the audit's scope.

More Domain 1: Information System Auditing Process questions