
CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Acquisition, Development and Implementation.
Question
A mid-sized bank is deploying a new customer onboarding system. Business users attended a live demonstration and indicated they were satisfied, but no formal UAT test cases, execution records, or mapped results exist. The project manager asks the audit team to approve go-live. As an IS auditor, what is the most appropriate recommendation?
Show the answer and explanation
Correct answer: B. Require formal UAT documentation: defined test cases mapped to requirements, executed test results showing acceptance criteria were met, and documented business sign-off before production deployment.
The best recommendation is to require documented UAT mapped to requirements with executed results and formal business sign-off. This provides traceable evidence that acceptance criteria were met and reduces the risk of undetected defects or unmet requirements moving to production. Option 1 (rollback plan and monitoring) is inadequate alone because it treats failures reactively rather than verifying requirements were satisfied. Option 3 (vendor/developer demo) relies on parties with potential bias and lacks independent, repeatable test evidence. Option 4 (verbal confirmation) is informal and non‑traceable, offering poor coverage and auditability of acceptance testing.
Want more practice?
Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.
