🇺🇸 Certified Information Systems Auditor (CISA) · flashcards

Certified Information Systems Auditor (CISA) Information Systems Auditing Process Flashcards

50 question-and-answer cards covering Information Systems Auditing Process as it is examined in Certified Information Systems Auditor (CISA). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

50Cards in deck
24Free preview
24Syllabus topics
~240Chars per answer
FreePrice

24 sample cards from the Information Systems Auditing Process deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What are the four general attributes (elements) every audit finding should contain?

    Condition (what was found), Criteria (the standard/expectation), Cause (why the gap exists), and Effect/Consequence (the impact/risk). A recommendation is then added to address it.

  2. Distinguish the four main types of audit evidence by reliability considerations.

    Evidence is stronger when from independent/external sources rather than internal, obtained directly by the auditor rather than indirectly, in documentary/written form rather than oral, and from a strong control environment. Auditor-generated and corroborated evidence is most reliable.

  3. What is the difference between substantive testing and compliance (controls) testing?

    Compliance testing verifies that controls exist and are operating as intended. Substantive testing verifies the integrity/accuracy of actual data and transactions. Weak control test results typically lead to expanded substantive testing.

  4. Differentiate statistical from non-statistical (judgmental) sampling.

    Statistical sampling uses random selection and probability theory, allowing the auditor to quantify and project results to the population with measurable confidence. Non-statistical/judgmental sampling relies on the auditor's judgment and cannot be statistically projected.

  5. Compare attribute sampling and variable sampling and when each is used.

    Attribute sampling tests for the rate of occurrence of a characteristic (yes/no, e.g., control deviations) and is used in compliance testing. Variable sampling estimates a numeric amount or monetary value of a population and is used in substantive testing.

  6. What is stop-or-go (sequential) sampling used for?

    A sampling method that allows the auditor to stop testing as early as possible; it is used when few errors are expected, reducing sample size when the population is believed to have a low deviation rate.

  7. What is discovery sampling and when is it appropriate?

    A form of attribute sampling designed to find at least one occurrence of a critical (often fraud-related) deviation. It is used when even a single instance would be significant, such as in fraud investigations.

  8. Define sampling risk and the two errors associated with it.

    Sampling risk is the risk the sample is not representative of the population. The two errors are: alpha risk (Type I)—incorrectly concluding a control is not reliable (overreliance avoided but inefficiency), and beta risk (Type II)—incorrectly concluding a control is reliable when it is not (the more serious error).

  9. What are Computer-Assisted Audit Techniques (CAATs) and why are they used?

    Software tools and techniques (e.g., generalized audit software, data analytics, scripts) used to extract, analyze, and test large volumes of electronic data. They enable 100% testing of populations, improve efficiency, and detect anomalies/exceptions that manual testing could miss.

  10. Give examples of CAATs an IS auditor might use.

    Generalized audit software (e.g., ACL, IDEA), utility software, test data/test decks, integrated test facility (ITF), embedded audit modules (SCARF), parallel simulation, and custom scripts/queries (SQL, Python).

  11. What is an Integrated Test Facility (ITF) as a continuous audit technique?

    A technique that creates a fictitious (dummy) entity within the live production system; the auditor processes test transactions against it alongside real transactions to verify that the system processes data correctly, without affecting real records.

  12. What is the purpose of audit working papers?

    To document the audit evidence gathered, procedures performed, analyses, and conclusions reached. They support the findings/opinion, provide a record for supervision and quality review, and enable another auditor to understand the work done.

  13. What documentation standards/attributes should working papers meet?

    They should be complete, accurate, clear, relevant, dated, indexed/cross-referenced, prepared and reviewed (signed off), and securely retained per retention policy. They must demonstrate the basis for conclusions and a clear audit trail.

  14. How should audit findings/observations be structured and prioritized in a report?

    Each finding states condition, criteria, cause, effect, and a recommendation, and is rated by risk/severity (e.g., high/medium/low). Findings are typically ranked so management can prioritize remediation of the highest-risk issues first.

  15. What key elements should the formal IS audit report contain?

    Scope and objectives, period covered, applicable standards, methodology, findings/observations with risk ratings, recommendations, management's responses, the auditor's overall conclusion/opinion, and any scope limitations.

  16. What is the difference between a finding and a recommendation in an audit report?

    A finding describes the issue/control weakness identified (the condition vs. criteria, with cause and effect). A recommendation is the auditor's suggested corrective action to remediate the finding and reduce the associated risk.

  17. To whom should IS audit results be communicated, and why include governance bodies?

    Results are communicated to relevant management (process/control owners) and to governance bodies such as the audit committee/board. Reporting to governance preserves independence, ensures oversight, and ensures significant risks reach decision-makers.

  18. What is the purpose of an audit closing/exit meeting before issuing the report?

    To present and validate findings with management, confirm factual accuracy, resolve disagreements, obtain management's responses/action plans, and agree on remediation before the final report is issued.

  19. What should a management response to an audit finding include?

    Agreement or disagreement with the finding, a corrective action plan, the responsible owner, and a target completion date. If management accepts the risk instead of remediating, that risk acceptance should be formally documented.

  20. What is remediation tracking (follow-up) and why is it part of the audit process?

    It is the monitoring of management's agreed corrective actions to verify they are implemented and effective by their due dates. It ensures findings are actually resolved and that residual risk is reduced, closing the audit loop.

  21. What is the purpose of a Quality Assurance and Improvement Program (QAIP) for an audit function?

    To ensure the audit function conforms to standards and operates effectively, through ongoing internal monitoring, periodic internal self-assessments, and external assessments—driving continuous improvement of audit quality and adding credibility.

  22. How often should an external quality assessment of the internal audit function typically occur?

    At least once every five years, performed by a qualified, independent assessor/team from outside the organization, complementing ongoing and periodic internal assessments.

  23. What is the audit risk model and its components?

    Audit risk = Inherent risk × Control risk × Detection risk. Inherent risk is the susceptibility to error absent controls; control risk is the risk controls fail to prevent/detect errors; detection risk is the risk the auditor's procedures miss a material issue. Detection risk is the only component the auditor directly controls.

  24. Why must an IS auditor exercise professional skepticism and due professional care?

    To remain alert to conditions indicating possible error, fraud, or control weakness, critically assessing evidence rather than assuming management's representations are correct, thereby supporting reliable, defensible audit conclusions.

What this deck covers

The Information Systems Auditing Process deck follows the Certified Information Systems Auditor (CISA) Information Systems Auditing Process syllabus — 5 chapters and 24 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 10.0 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 240 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Information Systems Auditing Process flashcards FAQ

How many Information Systems Auditing Process flashcards are in this Certified Information Systems Auditor (CISA) deck?

50 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Certified Information Systems Auditor (CISA) flashcards free?

Yes. The preview here is free to read with no signup, and the full 50-card deck is free inside the Examius app.

What do the Information Systems Auditing Process cards cover?

They follow the Certified Information Systems Auditor (CISA) Information Systems Auditing Process syllabus — 5 chapters and 24 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.