nerdexam
Isaca

CISA · Question #240

As part of an audit response, an auditee has concerns with the recommendations and is hesitant to implement them. Which of the following would be the BEST course of action for the IS auditor?

The correct answer is C. Conduct further discussions with the auditee to develop a mitigation plan.. When an auditee expresses concerns about audit recommendations, the best course of action for an IS auditor is to engage in further discussions to collaboratively develop a suitable mitigation plan.

Submitted by daniela_cl· Apr 18, 2026Information System Auditing Process

Question

As part of an audit response, an auditee has concerns with the recommendations and is hesitant to implement them. Which of the following would be the BEST course of action for the IS auditor?

Options

  • ASuggest hiring a third-party consultant to perform a current state assessment.
  • BIssue a final report without including the opinion of the auditee.
  • CConduct further discussions with the auditee to develop a mitigation plan.
  • DAccept the auditee's response and perform additional testing.

How the community answered

(43 responses)
  • A
    7% (3)
  • B
    12% (5)
  • C
    77% (33)
  • D
    5% (2)

Why each option

When an auditee expresses concerns about audit recommendations, the best course of action for an IS auditor is to engage in further discussions to collaboratively develop a suitable mitigation plan.

ASuggest hiring a third-party consultant to perform a current state assessment.

Suggesting a third-party consultant adds an unnecessary layer of complexity and cost before the auditor has fully engaged with the auditee to understand and address their concerns.

BIssue a final report without including the opinion of the auditee.

Issuing a final report without the auditee's opinion undermines the collaborative nature of an audit, can lead to resistance, and fails to leverage the auditee's operational insights for practical solutions.

CConduct further discussions with the auditee to develop a mitigation plan.Correct

Conducting further discussions with the auditee to develop a mitigation plan demonstrates collaboration, helps understand the auditee's specific concerns or constraints, and fosters a more practical and mutually agreeable solution. This approach increases the likelihood of recommendations being effectively implemented while ensuring risks are appropriately addressed.

DAccept the auditee's response and perform additional testing.

Accepting the auditee's response without addressing the underlying hesitation or performing additional testing to validate concerns might compromise the integrity of the audit and leave identified risks unmitigated.

Concept tested: Audit follow-up, auditor-auditee relationship, risk mitigation

Topics

#Auditor-auditee interaction#Audit recommendations#Mitigation planning#Audit follow-up

Community Discussion

No community discussion yet for this question.

Full CISA Practice