CISA Information System Auditing Process Practice Question
An IS auditor is documenting the audit programme for an engagement and must decide how specific the procedures should be. Which of the following BEST describes the appropriate level of detail for procedures recorded in the audit programme?
⚠ Common exam trap
The trap here is equating a well-written control objective with an audit programme step, when objectives describe what must be achieved while programme steps describe exactly what the auditor will do to test it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Specific steps identifying what is to be tested, how, and by whom
An audit programme converts engagement objectives into executable procedures. Each step should state the procedure, the items or population to which it applies, the evidence expected, and who performs it, so that work can be supervised, reviewed, and evidenced. Objectives, prior findings, and criteria inform the programme but do not replace the specific procedural detail that makes the engagement repeatable and defensible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Specific steps identifying what is to be tested, how, and by whom
Why this is correct
An audit programme should specify the procedures to be performed, the population or sample, the evidence to be obtained, and the responsibility for each step. This level of detail enables supervision, supports consistent execution, and provides a basis for confirming that the planned work was actually carried out before conclusions are drawn.
- ✗
Broad control objectives that allow the auditor to choose procedures during fieldwork
Why it's wrong here
Recording only control objectives leaves the nature, timing, and extent of testing undefined, which undermines supervision and consistency and makes it difficult to demonstrate that planned work was completed. The audit programme should translate objectives into concrete procedures, not defer that design to fieldwork where documentation and review become harder.
- ✗
The final audit opinion and the criteria against which it will be measured
Why it's wrong here
The opinion is the output of the engagement and cannot be documented in advance. Criteria belong in the engagement objectives and scope, but recording them as the programme would not tell the auditor which procedures to perform, on what population, or how evidence should be evaluated and retained.
- ✗
A list of prior audit findings to be re-verified in the current engagement
Why it's wrong here
Follow-up of prior findings is one input to engagement planning, not the structure of the audit programme. A programme built only around re-verification would omit new risk areas and would not define how current control objectives are to be tested, leaving the engagement without a complete, risk-based set of procedures.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.