CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 642


What should an IS auditor do FIRST when management responses to an in-person internal control questionnaire indicate a key internal control is no longer effective?

Show Answer
Correct Answer: CD

When management responses indicate that a key internal control is no longer effective, the IS auditor's primary concern should be to understand the consequences of this deficiency. Therefore, the first step should be to verify the impact of the control no longer being effective. This helps in assessing the potential risks and determining the urgency and extent of further actions needed to address the issue.

Discussion

6 comments
Sign in to comment
DeeplaxmiOption: D
Sep 20, 2022

at first anyone will chek if there are any compensating controls.. in absence of these, then only they will go and check for the impact of not having such control

jsalambaOption: C
Feb 27, 2023

correct answer is C

bones1008Option: A
Jan 21, 2024

why not A

MunaMOption: C
Sep 7, 2022

I think answer should be C because Impact analysis will be done first

starzuuOption: C
Jul 29, 2023

According to GPT4: "In general, understanding the risk (impact) first and then assessing mitigating factors (compensating controls) is a common approach in risk management and auditing processes."

SwallowsOption: A
Jul 21, 2024

The auditor should first comprehensively verify the overall effectiveness of internal controls. This includes the following steps: Reassessment and testing Scope of reassessment Understand the impact Therefore, verifying the overall effectiveness of internal controls is the first step for the IS auditor.