nerdexam
Isaca

CISA · Question #196

An auditee has informed the IS auditor that there is not enough funding to implement an agreed- upon recommendation in the audit report and that there is no estimated time frame for resolution. What i

The correct answer is C. Assess the risk given the full solution cannot be implemented. When an agreed-upon recommendation cannot be fully implemented, the auditor's core responsibility is risk management - assessing what residual risk remains given the gap between the ideal solution and what can actually be done. This allows the auditor to determine whether partial

Submitted by mike_84· Apr 18, 2026Information System Auditing Process

Question

An auditee has informed the IS auditor that there is not enough funding to implement an agreed- upon recommendation in the audit report and that there is no estimated time frame for resolution. What is the BEST way for the auditor to respond to this situation?

Options

  • AObtain internal audit approval to remove the finding from the report
  • BMake a recommendation to increase the IT budget
  • CAssess the risk given the full solution cannot be implemented
  • DClose the finding and note the auditee's explanation

How the community answered

(39 responses)
  • A
    21% (8)
  • B
    5% (2)
  • C
    67% (26)
  • D
    8% (3)

Explanation

When an agreed-upon recommendation cannot be fully implemented, the auditor's core responsibility is risk management - assessing what residual risk remains given the gap between the ideal solution and what can actually be done. This allows the auditor to determine whether partial mitigations exist, escalate appropriately, or formally document the accepted risk, which is the professional and standards-aligned response.

Why the distractors are wrong:

  • A - Removing a finding requires more than budget constraints as justification; internal audit approval alone doesn't make a risk disappear, and this would misrepresent the audit report.
  • B - Recommending a budget increase is outside the auditor's scope; the auditor identifies and assesses risk, not financial planning decisions.
  • D - Closing the finding without a resolution or risk assessment is improper; an unexplained funding gap does not constitute remediation.

Memory tip: Think of the auditor as a risk translator - when a control can't be fixed, your job shifts to quantifying what that means, not rubber-stamping excuses or fixing budgets. If you can't fix it, assess it.

Topics

#Audit follow-up#Risk assessment#Audit recommendations

Community Discussion

No community discussion yet for this question.

Full CISA Practice