nerdexam
Isaca

CISA · Question #561

Which of the following is an IS auditor's BEST recommendation after identifying that HR staff create new employees in the payroll system as well as process payroll due to limited staffing?

The correct answer is D. Implement independent periodic review of payroll transactions. The core issue is a segregation of duties (SoD) conflict: the same HR staff both create employees in the payroll system and process payroll, creating a fraud risk (e.g., adding ghost employees and paying them). When SoD cannot be fully enforced due to staffing constraints, the…

Submitted by tom_us· Apr 18, 2026Information System Auditing Process

Question

Which of the following is an IS auditor's BEST recommendation after identifying that HR staff create new employees in the payroll system as well as process payroll due to limited staffing?

Options

  • AImplement a payroll system user awareness training program.
  • BRotate payroll responsibilities within HR.
  • CDocument roles and responsibilities of payroll staff.
  • DImplement independent periodic review of payroll transactions.

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    12% (4)
  • C
    6% (2)
  • D
    79% (26)

Explanation

The core issue is a segregation of duties (SoD) conflict: the same HR staff both create employees in the payroll system and process payroll, creating a fraud risk (e.g., adding ghost employees and paying them). When SoD cannot be fully enforced due to staffing constraints, the best compensating control is an independent periodic review of payroll transactions by someone outside the conflicted process. This detective control can identify unauthorized or fraudulent activity after the fact. Training (A) and documentation (C) do not mitigate the SoD risk. Rotating responsibilities within HR (B) keeps the conflict within the same department and does not eliminate it.

Topics

#Segregation of Duties#Compensating Controls#Internal Controls#Payroll Systems Audit

Community Discussion

No community discussion yet for this question.

Full CISA Practice