CISA Question of the Day: Audit Sampling and Evidence

CISA exam practice question — CISA Question of the Day: Audit Sampling and Evidence

CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Auditing Process.

Question

While auditing user provisioning controls, you select a random sample of 50 provisioning transactions from a population of 5,000 and find 4 instances where access was granted without documented approval. What is the most appropriate next step?

  • A. Extrapolate the sample exception rate to the entire population and report the control as ineffective.
  • B. Report a significant deficiency immediately based solely on the sample exceptions.
  • C. Increase the sample size and perform additional targeted testing to determine whether exceptions are pervasive.
  • D. Conclude the control is operating effectively because the majority of sampled transactions were compliant.
Show the answer and explanation

Correct answer: C. Increase the sample size and perform additional targeted testing to determine whether exceptions are pervasive.

Finding exceptions in a sample indicates a potential issue, but professional auditing standards require determining whether exceptions are pervasive before drawing population-level conclusions. Expanding the sample and performing additional targeted procedures helps assess the extent, root causes, and whether errors are isolated. Extrapolating immediately risks over- or under-stating the issue because the initial sample may not be sufficiently precise. Reporting a significant deficiency without further evaluation may be premature; the auditor should first determine scope and materiality. Concluding the control is effective ignores the observed exceptions and fails to evaluate their significance across the population.

Want more practice?

Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.