CISA preparation guide
Read the audit task before choosing the control
Identify the audit objective, the criterion and the evidence available. Then ask what the auditor can reasonably conclude or do next. A technically effective control is not automatically the best audit action, and requesting more evidence is not automatically correct when the question already establishes the facts.
On this page
21-day free access after onboarding · No credit card required
Begin with what the question asks you to establish
An audit of whether a review occurred is different from advice about designing a better review. The same system can appear in both questions, but the objective changes which facts matter. Read the actor and requested decision before reaching for a familiar technical solution.
Ask whether the scenario concerns control design, operation over a period, an exception, a finding, or follow-up. These labels organize your reading; they are not magic words that determine an answer without evidence.
This is a CertArc teaching approach, not an official answer-selection formula. ISACA’s outline includes audit planning, testing, evidence collection and reporting; candidates still need the underlying subject knowledge.
Approval exists, but did the review occur?
The useful next step is to seek corroborating evidence of the review’s operation and evaluate it against the procedure. The signature and assertion are evidence to consider, but the stated gap is whether the underlying activity occurred. This example supplies no emergency condition requiring the auditor to act as an operator.
Why not accept the signature and conclude the control worked? That treats an approval indicator as sufficient proof of the whole activity. It does not resolve the missing evidence described in this example.
Why not remove the users’ access personally? That changes the system without first establishing which access is inappropriate, and it takes over an operational task. It does not answer the audit objective.
Why not declare the control effective because the procedure is sound? A design that could work is different from evidence that it operated during the period.
Why not immediately claim that no review occurred? The supplied evidence does not yet establish that conclusion. Document the evidence gap and pursue the audit work needed to support the finding, rather than inventing facts.
This is an original teaching vignette, not a scored public question, operational-bank item, or official ISACA explanation.
Change one fact and test the conclusion
If reliable records already show that the required review did not occur, repeating the same request for proof is not automatically the strongest next action. The task may instead be to evaluate the exception’s significance and communicate a supported finding under the audit process.
If the question is about designing a new review, assessing proposed responsibilities and evidence requirements may be appropriate. If it states an urgent condition and an established escalation obligation, consider that obligation. “Always investigate more” ignores the facts just as much as “always implement the control.”
Separate the responsibilities
Role boundaries depend on the engagement and stated authority. This table is a reading aid for the example, not a replacement for professional standards or a universal ban on advisory work.
| Task in the scenario | Distinction to preserve |
|---|---|
| Choose or operate a corrective control | Do not silently assign management’s operational work to the auditor |
| Evaluate whether a control operated | Match evidence to the period, activity and criterion being tested |
| Report a finding | Make the conclusion traceable to the evidence; do not overstate the scope |
| Follow up on remediation | Verify what changed rather than treating an action plan as completed work |
Use review to identify the error you actually made
When you miss a scenario, compare your answer with the strongest alternative. Write one sentence naming the decisive difference. If your answer took over the control owner’s task, “Answered as management, not as an auditor” may be an appropriate missed-reason tag. If the real gap was subject knowledge, choose that reason instead.
CertArc connects this reflection to your practice review. The value is an explanation you can use in another situation, not accumulating tags for their own sake. Open the relevant explanation and compare the alternatives before deciding you need more questions.
Questions before you start
Should I always choose the answer that gathers more evidence?
No. First determine whether the scenario already establishes the relevant facts and what stage of the audit it describes.
Are technical answers always wrong?
No. Technical understanding may be essential to evaluating a control or interpreting evidence. The problem is choosing a technically plausible action that does not answer the audit task.
Can an auditor recommend improvements?
Recommendations can be part of audit work. Recommending action is different from taking over the operation of the control; use the stated role and engagement context.
What if two answers sound reasonable?
Identify what extra assumption each requires. Prefer the answer justified by the given facts and requested task, not the one that solves the broadest imagined problem.
How can I practise this?
Use the CISA baseline, then review the distinction behind each miss. Follow with focused practice and the study-plan guide. The baseline is an initial signal, not a readiness verdict.
Find your CISA starting point
Begin with guided practice, then review your own baseline.
Start free CISA assessmentLast updated: