CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 60


What would be an IS auditor's BEST course of action when an auditee is unable to close all audit recommendations by the time of the follow-up audit?

Show Answer
Correct Answer: C

When an auditee is unable to close all audit recommendations by the time of the follow-up audit, it is crucial to evaluate the residual risk due to the open issues. This allows the auditor to understand the impact of the unresolved issues on the organization's risk posture and helps in determining the urgency and priority of corrective actions. It ensures that the auditor provides a clear picture of the remaining vulnerabilities and their implications, enabling management to make informed decisions on how to address these risks.

Discussion

7 comments
Sign in to comment
SBD600Option: C
May 3, 2023

When an auditee is unable to close all audit recommendations by the time of the follow-up audit, the IS auditor's best course of action is to evaluate the residual risk due to open issues. This allows the auditor to understand the remaining risks that the organization faces due to unresolved audit findings and helps management make informed decisions regarding the need for further action or accepting the residual risk.

MohamedAbdelaalOption: A
Apr 12, 2023

If its a follow up issue, which was previously raised, whats changes is supposed to be happened to the residual risk ?

Slurpistist
Mar 23, 2023

I’d pick A

CISA2021Option: C
Jan 23, 2024

Best course of action in this scenario is to evaluate the residual risk

5b56aaeOption: C
Apr 20, 2024

C for me

Pumeza
Nov 6, 2024

C. Evaluate the residual risk due to open issues.

JZ1710Option: C
Feb 27, 2025

Reaso for thisis that residual risk is the level of risk remaining after controls have been applied. If audit issues remain unresolved, the IS auditor must assess the potential impact of these open issues on business operations, security, and compliance.