Exam CISA All QuestionsBrowse all questions from this exam
Question 691

Which of the following must be in place before an IS auditor initiates audit follow-up activities?

    Correct Answer: A

    Before an IS auditor initiates audit follow-up activities, it is essential to have a management response in the final report with a committed implementation date. This indicates management's acknowledgment of the audit findings and their commitment to addressing the identified issues within a specified timeframe. This commitment provides a clear plan of action, ensuring accountability and facilitating an effective follow-up process.

Discussion
3008Option: C

c is answer

3008

a is correct

ChaBum

C doesn't make any sense Supporting evidence for the gaps are listed in the audit report, that how the auditor was able to build the report. Recommendations are also mentioned in the report, based on the evidence the auditor has gather to demonstrate the gaps.

RS66Option: A

A. A management response in the final report with a committed implementation date

SwallowsOption: A

Having a management response in the final report with a committed implementation date is crucial before initiating audit follow-up activities. This response indicates that the management has acknowledged the audit findings and committed to addressing them within a specified timeframe. It provides a clear plan of action for resolving the identified issues and ensures accountability. While supporting evidence for the gaps and recommendations mentioned in the audit report (option C) is also important for validating the findings, the commitment from management with a specific timeline for implementation is a foundational requirement for effective follow-up activities.

Swallows

While having available resources for the activities included in the action plan (option D) is important for executing follow-up activities, it is secondary to ensuring a management response with a committed implementation date. Without a clear commitment and timeline from management, follow-up activities lack the necessary direction and accountability needed to verify the resolution of audit findings. Therefore, option A is the critical requirement that must be in place before an IS auditor initiates audit follow-up activities—to have a management response in the final report with a committed implementation date.