nerdexam
Isaca

CISA · Question #168

What should an IS auditor do FIRST when a follow-up audit reveals some management action plans have not been initiated?

The correct answer is C. Confirm whether the identified risks are still valid. Before escalating the issue or taking further action, the auditor should first confirm whether the risks that prompted the original action plans are still relevant or if circumstances have changed. This ensures that any subsequent actions, such as reporting to the audit committee

Submitted by hans_de· Apr 18, 2026Information System Auditing Process

Question

What should an IS auditor do FIRST when a follow-up audit reveals some management action plans have not been initiated?

Options

  • AProvide a report to the audit committee
  • BEscalate the lack of plan completion to executive management
  • CConfirm whether the identified risks are still valid
  • DRequest an additional action plan review to confirm the findings

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    10% (5)
  • C
    71% (36)
  • D
    16% (8)

Explanation

Before escalating the issue or taking further action, the auditor should first confirm whether the risks that prompted the original action plans are still relevant or if circumstances have changed. This ensures that any subsequent actions, such as reporting to the audit committee or escalating to executive management, are based on accurate and current risk assessments. If the risks are still valid, then further actions like escalation or reporting may be necessary, but confirming the risk is a critical first step.

Topics

#Follow-up audits#Risk validation#Audit procedures#Management action plans

Community Discussion

No community discussion yet for this question.

Full CISA Practice