nerdexam
Isaca

CISA · Question #158

Which of the following is MOST important for an IS auditor to validate when reviewing the controls for an organization's quality management system (QMS)?

The correct answer is C. Whether there is a process to monitor continuous improvement areas and necessary targets. A core principle of a quality management system is the focus on continuous improvement. Ensuring that the organization has a process in place to monitor areas for improvement and set necessary targets is critical to maintaining and enhancing the quality of services or products…

Submitted by marco_it· Apr 18, 2026Governance and Management of IT

Question

Which of the following is MOST important for an IS auditor to validate when reviewing the controls for an organization’s quality management system (QMS)?

Options

  • AWhether root cause analysis is performed on all failed and rejected changes
  • BWhether critical services are delivered in a timely and sustainable manner
  • CWhether there is a process to monitor continuous improvement areas and necessary targets
  • DWhether the organization follows an industry-recognized service management framework

How the community answered

(20 responses)
  • A
    10% (2)
  • B
    5% (1)
  • C
    80% (16)
  • D
    5% (1)

Explanation

A core principle of a quality management system is the focus on continuous improvement. Ensuring that the organization has a process in place to monitor areas for improvement and set necessary targets is critical to maintaining and enhancing the quality of services or products. This aligns with the fundamental goals of QMS frameworks such as ISO 9001, which emphasize continual improvement and meeting customer expectations. While the other options are important elements of a quality management approach, validating the process for continuous improvement is essential for the long-term effectiveness and sustainability

Topics

#Quality Management System (QMS)#Continuous Improvement#IS Audit Validation#IT Controls Review

Community Discussion

No community discussion yet for this question.

Full CISA Practice