Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is evaluating the design of controls over a critical financial application. The auditor performs a walkthrough and identifies that a control is missing but management has compensating controls. Which of the following is the auditor's BEST next step?

⚠ Common exam trap

CISA often tests the misconception that the existence of compensating controls automatically eliminates the need for further auditor action, when in fact the auditor must test those controls to validate their effectiveness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Test the compensating controls to determine if they adequately mitigate the risk.

When a control gap is identified but management asserts compensating controls exist, the auditor cannot simply accept the assertion — the auditor must obtain evidence that the compensating controls actually operate effectively and reduce the risk to an acceptable level. Testing the compensating controls is the only way to determine whether the residual risk is adequately mitigated before concluding on the control environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the sample size for substantive testing to compensate.

    Why it's wrong here

    Increasing substantive testing addresses detection of misstatement, not the design gap created by a missing control. It is tempting because more testing feels responsive, but the auditor's next step is to evaluate whether the compensating controls adequately mitigate the risk before deciding on further procedures.

  • ✓

    Test the compensating controls to determine if they adequately mitigate the risk.

    Why this is correct

    Testing the compensating controls establishes whether they actually reduce the risk arising from the missing control, which is the evidence needed before concluding on control adequacy. Walkthroughs alone only confirm design; substantive testing of the compensating control's operating effectiveness satisfies the auditor's obligation to assess residual risk.

  • ✗

    Immediately report the missing control as a material weakness.

    Why it's wrong here

    Reporting a material weakness is premature: compensating controls may reduce the risk to an acceptable level, and materiality requires evaluation before escalation. It is tempting because a missing control sounds severe, but the auditor must first assess the compensating controls' effectiveness and document findings through normal reporting channels.

  • ✗

    Ignore the missing control since compensating controls exist.

    Why it's wrong here

    Compensating controls reduce risk but do not eliminate the design gap, so the auditor must still document and report the missing control in the findings. Ignoring it would breach audit evidence standards. This approach would only be defensible if the control were truly redundant, not merely compensated for.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.