An IS auditor performs a follow-up audit and learns the approach taken by the auditee to fix the findings differs from the agreed-upon approach confirmed during the last audit.
Which of the following should be the auditor's NEXT course of action?
Click on the arrows to vote for the correct answer
A. B. C. D.C.
When an IS auditor performs a follow-up audit and discovers that the approach taken by the auditee to fix the findings differs from the agreed-upon approach confirmed during the last audit, the NEXT course of action for the auditor should be to evaluate the appropriateness of the remedial action taken.
Option D is the correct answer because, as an IS auditor, it is important to evaluate the remedial action taken by the auditee to ensure that it is appropriate and effective. The auditor should examine the changes made by the auditee to determine whether they adequately address the findings from the previous audit.
Option A, informing senior management of the change in approach, may be necessary in some cases, but it is not the NEXT course of action. Before escalating the matter to senior management, the auditor should first evaluate the appropriateness of the remedial action taken by the auditee.
Option B, conducting a risk analysis incorporating the change, is not the NEXT course of action because the auditor should first evaluate the remedial action taken by the auditee before conducting a risk analysis. It is important to first determine whether the remedial action is appropriate before assessing the potential risks associated with the change in approach.
Option C, reporting the results of the follow-up to the audit committee, is not the NEXT course of action because the auditor should first evaluate the appropriateness of the remedial action taken by the auditee. Once the auditor has determined that the remedial action is appropriate, they can then report the results to the audit committee.