CISA · Question #610
An IS auditor is assigned to perform a post-implementation review of an application system. Which of the following would impair the auditor's independence?
The correct answer is A. The auditor implemented a specific control during the development of the system.. If an auditor implemented a control, they would later be reviewing their own work, which creates a self-review threat and compromises independence. Participating in the project without operational responsibilities (B) or providing advice (C) is acceptable as long as the auditor d
Question
An IS auditor is assigned to perform a post-implementation review of an application system. Which of the following would impair the auditor's independence?
Options
- AThe auditor implemented a specific control during the development of the system.
- BThe auditor participated as a member of the project team without operational responsibilities.
- CThe auditor provided advice concerning best practices.
- DThe auditor designed an embedded audit module exclusively for audit.
How the community answered
(36 responses)- A72% (26)
- B3% (1)
- C8% (3)
- D17% (6)
Explanation
If an auditor implemented a control, they would later be reviewing their own work, which creates a self-review threat and compromises independence. Participating in the project without operational responsibilities (B) or providing advice (C) is acceptable as long as the auditor does not take ownership of decisions. Designing audit modules (D) is also permissible since they are for audit use and do not affect operational processes. ISACA's Code of Professional Ethics and IS Audit Standards emphasize independence and objectivity as fundamental requirements to maintain credibility and avoid conflicts of interest.
Topics
Community Discussion
No community discussion yet for this question.