CISA Question of the Day: User Acceptance Testing Governance

CISA exam practice question — CISA Question of the Day: User Acceptance Testing Governance

CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Acquisition, Development and Implementation.

Question

A mid-sized bank is deploying a new customer onboarding system. Business users attended a live demonstration and indicated they were satisfied, but no formal UAT test cases, execution records, or mapped results exist. The project manager asks the audit team to approve go-live. As an IS auditor, what is the most appropriate recommendation?

  • A. Approve production deployment if the project manager documents a tested rollback plan and a post-deployment monitoring schedule.
  • B. Require formal UAT documentation: defined test cases mapped to requirements, executed test results showing acceptance criteria were met, and documented business sign-off before production deployment.
  • C. Accept the developers’ and vendor’s demonstration as sufficient evidence of functionality if the defect backlog is low and a remediation timeline is provided.
  • D. Accept verbal confirmation from business users who attended the demo as UAT sign-off, and require tracking of any defects discovered after go-live.
Show the answer and explanation

Correct answer: B. Require formal UAT documentation: defined test cases mapped to requirements, executed test results showing acceptance criteria were met, and documented business sign-off before production deployment.

The best recommendation is to require documented UAT mapped to requirements with executed results and formal business sign-off. This provides traceable evidence that acceptance criteria were met and reduces the risk of undetected defects or unmet requirements moving to production. Option 1 (rollback plan and monitoring) is inadequate alone because it treats failures reactively rather than verifying requirements were satisfied. Option 3 (vendor/developer demo) relies on parties with potential bias and lacks independent, repeatable test evidence. Option 4 (verbal confirmation) is informal and non‑traceable, offering poor coverage and auditability of acceptance testing.

Want more practice?

Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.