exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 664 discussion

Actual exam question from Isaca's CISA
Question #: 664
Topic #: 1
[All CISA Questions]

During the discussion of a draft audit report, IT management provided suitable evidence that a process has been implemented for a control that had been concluded by the IS auditor as ineffective. Which of the following is the auditor's BEST action?

  • A. Explain to IT management that the new control will be evaluated during follow-up.
  • B. Add comments about the action taken by IT management in the report.
  • C. Change the conclusion based on evidence provided by IT management.
  • D. Re-perform the audit before changing the conclusion.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
2 months, 1 week ago
Selected Answer: A
Hear me out: the auditor's best action is to acknowledge that the new control has been put in place, but explain that it will be evaluated during a follow-up audit. The auditor should not change the conclusion of the current audit, as the control's effectiveness has not yet been fully verified. A follow-up audit or evaluation will allow the auditor to assess whether the control is functioning effectively over time so A is the answer.
upvoted 1 times
8 months ago
Selected Answer: C
Since suitable evidence has been presented, the audit opinion will be modified accordingly.
upvoted 1 times
8 months, 1 week ago
Selected Answer: D
somehow mor ecomfort with option D, we need further verify the new evidence and comment is not necessary to put on the drat report, since its just a draft and the final report should reflect the real conditions
upvoted 1 times
8 months, 1 week ago
The best action is to re-perform the audit (Option D) before changing the conclusion. This allows the auditor to independently confirm that the new or revised control is effective and addresses the previously identified issues. Only after this verification can the auditor update the audit report to reflect the current state of the control environment accurately. In summary, while Option C might seem efficient, it does not provide the necessary level of assurance that the control is effective. The auditor's responsibility is to maintain independence and objectivity, and this is best achieved by re-performing the audit (Option D) to verify the effectiveness of the new control before changing any conclusions in the report
upvoted 1 times
1 year, 2 months ago
Selected Answer: B
During the audit, finding has been fixed. So auditors cannot remove the finding from the report but can add the comments about the action taken by auditees.
upvoted 1 times
1 year, 3 months ago
C. Change the conclusion based on evidence provided by IT management.
upvoted 1 times
1 year, 7 months ago
D should be the answer. By re-performing the audit, the auditor ensures that their conclusion is based on the most up-to-date and accurate information. It allows for a more comprehensive evaluation of the control's effectiveness and provides a more reliable basis for reporting and decision-making. adding comments about the action taken by IT management in the report (option B) may be appropriate actions, they should be accompanied by a thorough REASSESSMENT of the control's effectiveness.
upvoted 3 times
2 years, 1 month ago
Selected Answer: B
should be B
upvoted 4 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago