Courseiva
hardMultiple Select

CISA Developing a new financial application Practice Question

A company is developing a new financial application. Which THREE of the following are valid reasons to involve internal audit during the development phase?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To ensure compliance with regulatory requirements

Option A is correct because internal audit involvement during development helps verify that the financial application meets applicable regulatory requirements (e.g., SOX, PCI DSS, GDPR, or financial-industry regulations), since audit's independence lets it assess compliance obligations before the system goes live. Option C is correct because internal audit can validate that security controls are designed and built into the application from the start, rather than retrofitted later, which is far more effective and less costly. Option E is correct because internal audit provides guidance on internal controls, advising on control design and risk mitigation without taking ownership of the controls themselves. Option B is not correct because designing the application architecture is the responsibility of the development and architecture teams, not internal audit, whose role must remain independent of design decisions. Option D is not correct because approving all user requirements is a business/user responsibility, and audit should not approve requirements it may later have to independently review.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    To ensure compliance with regulatory requirements

    Why this is correct

    Internal audit's independence and regulatory knowledge let it assess whether the application's design and data handling will satisfy financial-sector mandates before build costs escalate. Involvement during development satisfies the stem's compliance constraint, since remediation after go-live is far costlier and may breach reporting deadlines.

  • ✗

    To design the application architecture

    Why it's wrong here

    Designing application architecture is a solution delivery task performed by architects and developers. Internal audit's development-phase role is to review controls, risks and compliance independently; it would design architecture only when acting as a consultant, which compromises the objectivity its assurance depends on.

  • ✓

    To validate that security controls are built in

    Why this is correct

    Embedding internal audit during development lets it examine design artefacts and confirm that security controls such as access management, encryption and audit logging are actually specified, not retrofitted. This directly satisfies the stem's requirement to validate that controls are built in rather than tested only after deployment.

  • ✗

    To approve all user requirements

    Why it's wrong here

    Approving user requirements is a business and user assurance activity owned by the business sponsor and users; internal audit provides independent assurance and advice, not sign-off. It would approve requirements only if it also owned them, which destroys its independence.

  • ✓

    To provide guidance on internal controls

    Why this is correct

    Internal audit advises on the design of internal controls — segregation of duties, authorisation flows, reconciliation — while the financial application is still being specified. This satisfies the stem's development-phase constraint, since control gaps identified in design can be corrected cheaply, whereas post-implementation redesign is disruptive.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.