nerdexam
Isaca

CISA · Question #610

An IS auditor is assigned to perform a post-implementation review of an application system. Which of the following would impair the auditor's independence?

The correct answer is A. The auditor implemented a specific control during the development of the system.. If an auditor implemented a control, they would later be reviewing their own work, which creates a self-review threat and compromises independence. Participating in the project without operational responsibilities (B) or providing advice (C) is acceptable as long as the auditor d

Submitted by femi9· Apr 18, 2026Information System Auditing Process

Question

An IS auditor is assigned to perform a post-implementation review of an application system. Which of the following would impair the auditor's independence?

Options

  • AThe auditor implemented a specific control during the development of the system.
  • BThe auditor participated as a member of the project team without operational responsibilities.
  • CThe auditor provided advice concerning best practices.
  • DThe auditor designed an embedded audit module exclusively for audit.

How the community answered

(36 responses)
  • A
    72% (26)
  • B
    3% (1)
  • C
    8% (3)
  • D
    17% (6)

Explanation

If an auditor implemented a control, they would later be reviewing their own work, which creates a self-review threat and compromises independence. Participating in the project without operational responsibilities (B) or providing advice (C) is acceptable as long as the auditor does not take ownership of decisions. Designing audit modules (D) is also permissible since they are for audit use and do not affect operational processes. ISACA's Code of Professional Ethics and IS Audit Standards emphasize independence and objectivity as fundamental requirements to maintain credibility and avoid conflicts of interest.

Topics

#Auditor independence#Professional ethics#Conflict of interest#Post-implementation review

Community Discussion

No community discussion yet for this question.

Full CISA Practice