nerdexam
Isaca

CISA · Question #136

To help determine whether a controls-reliant approach to auditing financial systems in a company should be used, which sequence of IS audit work is MOST appropriate?

The correct answer is A. Review of the general IS controls followed by a review of the application controls. To determine whether a controls-reliant audit approach is appropriate, an IS auditor must first evaluate general IT controls (e.g., access management, change management, operations controls), because these form the foundation upon which application controls depend. If general con

Submitted by tunde_lagos· Apr 18, 2026Information System Auditing Process

Question

To help determine whether a controls-reliant approach to auditing financial systems in a company should be used, which sequence of IS audit work is MOST appropriate?

Options

  • AReview of the general IS controls followed by a review of the application controls
  • BReview of application controls followed by a test of key business process controls
  • CReview of major financial applications followed by a review of IT governance processes
  • DDetailed examination of financial transactions followed by review of the general ledger

How the community answered

(17 responses)
  • A
    94% (16)
  • D
    6% (1)

Explanation

To determine whether a controls-reliant audit approach is appropriate, an IS auditor must first evaluate general IT controls (e.g., access management, change management, operations controls), because these form the foundation upon which application controls depend. If general controls are weak, application controls cannot be trusted regardless of how they appear. Only after confirming general controls are sound does it make sense to review application controls. Option B skips the general control layer. Option C reverses the logical order by starting with applications before governance. Option D describes a substantive testing approach, not a controls-reliant one.

Topics

#IS audit methodology#Controls-reliant approach#General controls#Application controls

Community Discussion

No community discussion yet for this question.

Full CISA Practice