Management has agreed to perform multiple remediation actions in response to an audit issue, including the implementation of a new control.
Which of the following is the BEST time for an IS auditor to perform an audit follow-up of this issue?
Click on the arrows to vote for the correct answer
A. B. C. D.A.
The best time for an IS auditor to perform an audit follow-up of an issue, after management has agreed to perform multiple remediation actions, including the implementation of a new control, is after management has completed the required actions.
Explanation:
The purpose of an audit follow-up is to evaluate the effectiveness of management's remediation actions to address previously identified issues. Therefore, it is important for the auditor to ensure that the required actions have been completed before conducting the follow-up. If the auditor conducts the follow-up before management has completed the required actions, it would not be possible to evaluate the effectiveness of the remediation actions.
Option B ("When audit resources are available") is not the best answer because the availability of audit resources is not the most important factor when determining the timing of an audit follow-up. The primary consideration should be whether the required actions have been completed.
Option C ("When management resources are available") is also not the best answer because the availability of management resources is not the most important factor when determining the timing of an audit follow-up. The primary consideration should be whether the required actions have been completed.
Option D ("After the new control has been in place for one year") is not the best answer because waiting for one year after the implementation of a new control may be too long. The auditor should conduct the follow-up as soon as possible after management has completed the required actions to evaluate the effectiveness of the remediation actions. If the auditor waits for one year, it may be too late to make any adjustments if the new control is not effective.
In summary, the best time for an IS auditor to perform an audit follow-up of an issue is after management has completed the required actions.