From Isaca Q&A database: The information systems (IS) auditor should perform additional testing to ensure that it is a finding. An auditor can quickly lose credibility if it is later discovered that the finding was not justified or accurate.
This option emphasizes responding quickly to potential misconduct. Notifying the audit committee raises the issue's importance so that appropriate action can be taken.
Answer B suggests sharing the potential audit finding with the security administrator. This is a good option, as the security administrator is responsible for maintaining the security of the organization's information systems. They may be able to help investigate the potential fraud and take appropriate actions to prevent further damage.
In conclusion, the best course of action for the IS auditor is to share the potential audit finding with the security administrator, perform more detailed tests to verify the findings, and then review the audit finding with the audit committee. This ensures that the investigation is conducted effectively and efficiently while minimizing the risk of alerting the suspected fraudster.
When an IS auditor identifies potential fraud activity, the first step should be to perform more detailed tests to gather additional evidence and validate the findings. It is crucial to ensure the accuracy and completeness of the audit findings before taking further actions.
Performing additional tests before disclosing audit results helps ensure that the auditor has a comprehensive and accurate understanding of the situation, allowing for more informed communication with relevant stakeholders. This approach strengthens the credibility of the audit findings and supports a more effective and timely resolution.
Answer C suggests performing more detailed tests before disclosing the audit results. This is a prudent course of action, as it ensures that the audit findings are accurate and reliable before any further actions are taken. However, it may delay the investigation
A comes first,It is important to notify the audit committee as soon as possible to ensure a timely resolution of the issue and to minimize the risk of further harm to the organization.
IS auditor can only notify audit management and not audit committee
upvoted 1 times
...
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
PurpleParrot
1 month, 1 week agoSwallows
4 months agoSwallows
6 months ago3008
11 months, 2 weeks agoFAGFUR
1 year ago3008
11 months, 2 weeks agoBabaP
1 year, 6 months agoswmasinde
1 year, 6 months agosaado9
1 year, 6 months agoswmasinde
1 year, 6 months ago