Courseiva

CISA Information System Auditing Process Practice Question

According to ISACA IT Audit Standards, which of the following is a key requirement for audit documentation?

⚠ Common exam trap

CISA often tests specific ISACA standards; candidates may assume a fixed retention period like 10 years, but ISACA does not specify a number, leaving it to other requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Documentation must support the audit findings and conclusions.

According to ISACA IT Audit Standards, audit documentation must support the audit findings and conclusions. This is a fundamental requirement to ensure that the work performed is verifiable and that conclusions are based on sufficient evidence. It allows for review and re-performance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Documentation must support the audit findings and conclusions.

    Why this is correct

    ISACA standards require audit documentation to substantiate the auditor's findings and conclusions, so working papers must evidence the procedures performed, the evidence obtained and the judgements made. This supports the stem's requirement by enabling an independent reviewer to reperform the work and reach the same conclusions.

  • ✗

    Documentation must be retained for at least 10 years.

    Why it's wrong here

    ISACA standards require documentation be retained per legal, regulatory and organisational policy, not a fixed ten-year period. A prescribed decade is tempting because many jurisdictions mandate long retention, but the standard sets no universal duration.

  • ✗

    Documentation must be reviewed by the audit committee.

    Why it's wrong here

    ISACA standards require review by an appropriate independent party, not specifically the audit committee, which is a governance body. It is tempting because committee oversight of audit work is common, and committee review would be correct where the engagement's charter or governance policy explicitly assigns that approval.

  • ✗

    Documentation must be prepared in the local language of the auditee.

    Why it's wrong here

    ISACA standards require documentation sufficient to support conclusions, with no mandate that it be written in the auditee's local language. It is tempting because local-language records can aid auditee understanding, and this would be correct where regulation or engagement terms impose such a language requirement.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.