nerdexam
Isaca

CISA · Question #25

Which of the following should be the PRIMARY basis for prioritizing follow-up audits?

The correct answer is C. Residual risk from the findings of previous audits. The primary basis for prioritizing follow-up audits should be the residual risk identified from the findings of previous audits, ensuring that the highest risks are addressed first.

Submitted by deeparc· Apr 18, 2026Information System Auditing Process

Question

Which of the following should be the PRIMARY basis for prioritizing follow-up audits?

Options

  • AAudit cycle defined in the audit plan
  • BRecommendation from executive management
  • CResidual risk from the findings of previous audits
  • DComplexity of management's action plans

How the community answered

(38 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    87% (33)
  • D
    3% (1)

Why each option

The primary basis for prioritizing follow-up audits should be the residual risk identified from the findings of previous audits, ensuring that the highest risks are addressed first.

AAudit cycle defined in the audit plan

An audit cycle defines regular audits but doesn't specifically prioritize follow-up on critical findings based on their risk level.

BRecommendation from executive management

While executive management recommendations are important, risk-based prioritization ensures objectivity and alignment with the most significant organizational exposures, rather than subjective input.

CResidual risk from the findings of previous auditsCorrect

Follow-up audits are conducted to verify that management has implemented corrective actions for identified deficiencies and to assess whether these actions have effectively mitigated the associated risks. Prioritizing based on residual risk ensures that areas with the greatest potential impact or likelihood of harm to the organization are re-evaluated promptly, aligning audit efforts with the organization's overall risk management strategy.

DComplexity of management's action plans

The complexity of management's action plans might influence scheduling but should not be the primary factor for prioritizing the audit itself, which should fundamentally focus on risk reduction.

Concept tested: Audit prioritization based on risk

Source: https://www.isaca.org/resources/isaca-journal/2006/volume-1/it-audit-a-risk-based-approach

Topics

#Audit Prioritization#Follow-up Audits#Residual Risk#Risk-based Auditing

Community Discussion

No community discussion yet for this question.

Full CISA Practice