nerdexam
Isaca

CISA · Question #416

An organization used robotic process automation (PRA) technology to develop software bots that extract data from various sources for input into a legacy financial application. Which of the following s

The correct answer is D. Unauthorized modifications were made to the scripts to improve performance. Unauthorized modifications to RPA scripts - even if made with good intentions to improve performance - represent a critical change management control failure. RPA bots extract and input financial data, so any unapproved script change could introduce errors, alter data flows, or p

Submitted by manish99· Apr 18, 2026Information Systems Acquisition, Development and Implementation

Question

An organization used robotic process automation (PRA) technology to develop software bots that extract data from various sources for input into a legacy financial application. Which of the following should be of GREATEST concern to an IS auditor when reviewing the software bot job scheduling and production process automation?

Options

  • ASoftware bots were incapable of learning from training data
  • BSoftware bots were programmed to record all user interactions, including mouse tracking
  • CMinor overrides were not authorized by the business
  • DUnauthorized modifications were made to the scripts to improve performance

How the community answered

(59 responses)
  • A
    25% (15)
  • B
    12% (7)
  • C
    5% (3)
  • D
    58% (34)

Explanation

Unauthorized modifications to RPA scripts - even if made with good intentions to improve performance - represent a critical change management control failure. RPA bots extract and input financial data, so any unapproved script change could introduce errors, alter data flows, or produce incorrect outputs that affect financial integrity, all without a proper audit trail or risk assessment. This bypasses change control entirely. Option A is a non-issue because standard RPA bots are rule-based and are not designed to learn from training data. Option B (recording interactions) may be intentional for audit purposes. Option C (minor unauthorized overrides) is a concern but is less severe than unauthorized script modifications affecting the core automation logic.

Topics

#RPA#Change Management#Application Controls#IS Audit

Community Discussion

No community discussion yet for this question.

Full CISA Practice