CISA Exam Questions (1-100)
The internal audit department has written some scripts that are used for continuous auditing of
some information systems. The IT department has asked for copies of the scripts so that they c
...
CISA Exam Questions (1-100)
The internal audit department has written some scripts that are used for continuous auditing of
some information systems. The IT department has asked for copies of the scripts so that they can
use them for setting up a continuous monitoring process on key systems. Would sharing these
scripts with IT affect the ability of the IS auditors to independently and objectively audit the IT
function?
Select an answer:
A.
Sharing the scripts is not permitted because it would give IT the ability to pre-audit systems and
avoid an accurate, comprehensive audit.
B.
Sharing the scripts is required because IT must have the ability to review all programs and
software that runs on IS systems regardless of audit independence.
C.
Sharing the scripts is permissible as long as IT recognizes that audits may still be conducted in
areas not covered in the scripts.
D.
Sharing the scripts is not permitted because it would mean that the IS auditors who wrote the
scripts would not be permitted to audit any IS systems where the scripts are being used for
monitoring. - ANS - A. The ability of IT to continuously monitor and address any issues on IT
systems would not affect the ability of IS audit to perform a comprehensive audit.
B. Sharing the scripts may be required by policy for the sake of quality assurance and
configuration management, but that would not impair the ability to audit.
CORRECT C. IS audit can still review all aspects of the systems. They may not be able to
review the effectiveness of the scripts themselves, but they can still audit the systems.
D. An audit of an IS system would encompass more than just the controls covered in the scripts.
An audit charter should:
A.
be dynamic and change to coincide with the changing nature of technology and the audit
profession.
B.
clearly state audit objectives for, and the delegation of, authority to the maintenance and review
of internal controls.
C.
document the audit procedures designed to achieve the planned audit objectives.
D.
outline the overall authority, scope and responsibilities of the audit function. - ANS - A. The
audit charter should not be subject to changes in technology and should not significantly change
over time. The charter should be approved at the highest level of management.
B. An audit charter will state the authority and reporting requirements for the audit but not the
details of maintenance of internal controls.
C. An audit charter would not be at a detailed level and, therefore, would not include specific
audit objectives or procedures.
CORRECT D. An audit charter should state management's objectives for and delegation of
authority to IS auditors.
The PRIMARY advantage of a continuous audit approach is that it:
[Show More]