Certified Information Systems Auditor Practice Exam

Disable ads (and more) with a premium pass for a one time $4.99 payment

Question: 1 / 175

What should an IS auditor do if the sample of program changes is insufficient for assurance?

Conduct a full review of all changes

Develop an alternate testing procedure

When an IS auditor finds that the sample of program changes is insufficient for providing adequate assurance, developing an alternate testing procedure is a proactive response. This approach allows the auditor to still gather relevant evidence without needing to conduct a full review of every single change.

Using alternate testing procedures can involve various methods such as expanding the sample size, reviewing documentation related to the changes, or employing analytical procedures. This flexibility ensures that the auditor can still fulfill their responsibilities while addressing the inadequacy of the original sample.

Choosing to conduct a full review of all changes may be impractical and resource-intensive, often not feasible given the time constraints of audits. Completely discarding the audit is not a realistic option, as it neglects the need for accountability and assurance in the audit process. Requesting additional changes for sampling could lead to a misunderstanding of the sampling process, as it doesn’t necessarily address the underlying issue of insufficient data.

Thus, developing an alternate testing procedure is a well-reasoned and effective solution that maintains the integrity of the audit and can still yield valuable insights into the changes being evaluated.

Get further explanation with Examzify DeepDiveBeta

Completely discard the audit

Request additional changes for sampling

Next

Report this question

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy