nerdexam
Isaca

CISA · Question #93

Which of the following would be MOST important to include in an IS audit report?

The correct answer is D. The level of unmitigated risk along with business impact. The most important information in an IS audit report is the level of unmitigated risk and its business impact, as this informs management about critical exposures requiring attention.

Submitted by parkjh· Apr 18, 2026Information System Auditing Process

Question

Which of the following would be MOST important to include in an IS audit report?

Options

  • AObservations not reported as findings due to inadequate evidence
  • BThe roadmap for addressing the various risk areas
  • CSpecific technology solutions for each audit observation
  • DThe level of unmitigated risk along with business impact

How the community answered

(62 responses)
  • A
    6% (4)
  • B
    10% (6)
  • C
    3% (2)
  • D
    81% (50)

Why each option

The most important information in an IS audit report is the level of unmitigated risk and its business impact, as this informs management about critical exposures requiring attention.

AObservations not reported as findings due to inadequate evidence

Observations with inadequate evidence are typically excluded from formal findings to maintain the credibility and objectivity of the audit report.

BThe roadmap for addressing the various risk areas

A roadmap for addressing risk areas is typically developed by management in response to audit findings, rather than being a primary component of the audit report itself.

CSpecific technology solutions for each audit observation

While an audit may suggest general control improvements, specific technology solutions are usually the responsibility of management or IT teams to implement, not the auditor to prescribe in detail.

DThe level of unmitigated risk along with business impactCorrect

An IS audit's primary purpose is to identify risks and evaluate controls. By reporting the level of unmitigated risk along with its business impact, the audit report provides management with clear, actionable information about the most significant exposures, enabling informed decision-making regarding remediation priorities.

Concept tested: Essential elements of an IS audit report

Topics

#IS audit report#Risk reporting#Business impact#Unmitigated risk

Community Discussion

No community discussion yet for this question.

Full CISA Practice