CISA: Certified Information Systems Auditor - IS Audit Quality Review

IS Audit Quality Review

Prev Question Next Question

Question

An IS audit manager has been asked to perform a quality review on an audit that the same manager also supervised.

Which of the following is the manager's BEST response to this situation?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

A.

The situation described in the question presents a conflict of interest for the IS audit manager, as they are being asked to perform a quality review on an audit that they supervised themselves. In such a scenario, the manager should take steps to ensure that the review process is unbiased and objective.

Option A: Notify the audit committee of the situation.

This option suggests that the IS audit manager should inform the audit committee of the conflict of interest. This action may be appropriate if the manager believes that the situation is serious enough to warrant escalation to higher management. However, it is not the best response in this situation since there is no indication that the situation is so severe that it needs to be escalated.

Option B: Escalate the situation to senior audit leadership.

This option suggests that the IS audit manager should escalate the situation to senior audit leadership. This action may be appropriate if the manager believes that the situation is serious enough to warrant escalation to higher management. However, it is not the best response in this situation since there is no indication that the situation is so severe that it needs to be escalated.

Option C: Determine whether audit evidence supports audit conclusions.

This option suggests that the IS audit manager should review the audit evidence to ensure that it supports the audit conclusions. This action is appropriate and should be part of the quality review process for any audit. However, it is not the best response in this situation since the IS audit manager may not be able to perform an unbiased review of the audit that they supervised.

Option D: Discuss with the audit team to understand how conclusions were reached.

This option suggests that the IS audit manager should discuss with the audit team to understand how conclusions were reached. This action is the best response in this situation since it allows the manager to gain a better understanding of the audit process and the evidence used to support the audit conclusions. This discussion can help the manager identify any potential biases that may have affected the audit and can also help them provide feedback to the audit team to improve the quality of future audits.

In conclusion, the best response for the IS audit manager in this situation is to discuss with the audit team to understand how conclusions were reached. This action allows the manager to gain a better understanding of the audit process and can help them identify any potential biases that may have affected the audit.