
CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Auditing Process.
Question
An internal auditor is evaluating the controls of a client that uses a cloud provider for data processing. The client provides a recent SOC 2 Type II report covering the relevant period. What should the auditor do before reducing their own control testing based on the SOC report?
Show the answer and explanation
Correct answer: A. Evaluate the SOC report’s scope, period, opinion, and whether complementary user entity controls are required; then test the client’s implementation of those user controls as necessary before reducing audit procedures.
Option 0 is best because reliance on a SOC report requires evaluation of its relevance: scope, period, and the service auditor’s opinion, and identification of complementary user entity controls (CUECs). The auditor must obtain evidence that the client implemented those CUECs (by testing them or using other procedures) before reducing their own testing. Option 1 is wrong because accepting the report without assessing relevance and CUECs is insufficient. Option 2 is incorrect and impractical: the service auditor’s engagement scope cannot be retroactively extended to test client-specific transactions. Option 3 is inappropriate because replacing audit work solely with a management representation does not provide independent evidence.
Want more practice?
Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.
