Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is executing a compliance test of change management controls over a core banking application. The audit programme requires evidence that all production changes were approved before implementation. Which of the following techniques provides the MOST persuasive evidence for this test?

⚠ Common exam trap

The trap here is treating review of the approved change management policy as sufficient evidence, when a compliance test of operating effectiveness requires evidence that approvals actually occurred before each deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inspecting the change tickets for documented approvals and comparing approval dates to deployment dates

Documentary evidence of approvals linked to deployment records directly addresses the control objective: approvals occurring before implementation. Comparing dates on the change tickets themselves allows the auditor to identify exceptions rather than relying on what people say or what policy intends. Interviews, policy review, and single-meeting observation each provide weaker or incomplete evidence for concluding on operating effectiveness across the change population.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Observing the change advisory board during one weekly meeting

    Why it's wrong here

    Observation provides evidence about one point in time and only for changes discussed at that meeting. It cannot show whether every production change to the core banking application received approval before deployment, and staff aware of being observed may behave differently. While useful as corroborating evidence, observation alone is insufficient for a compliance test that must conclude on approval of all changes during the audit period.

  • ✗

    Reviewing the change management policy approved by the IT steering committee

    Why it's wrong here

    The approved policy is documentary evidence, but it only proves that a control is designed and mandated, not that it operated for individual changes. A policy can be perfectly worded while change tickets go unapproved in practice. For a compliance test asking whether production changes were approved before implementation, policy review alone does not demonstrate operating effectiveness on the core banking application's actual change population.

  • ✓

    Inspecting the change tickets for documented approvals and comparing approval dates to deployment dates

    Why this is correct

    Inspecting change tickets produces documentary evidence and directly tests the control: the audit programme asks whether approvals preceded implementation. By comparing the approval timestamp on each ticket with the deployment timestamp in the same record, the auditor can detect changes deployed before authorization. This is the most persuasive technique available here because it is independent of verbal assertions and covers the actual population of changes.

  • ✗

    Interviewing the change manager about the approval workflow

    Why it's wrong here

    Interviewing the change manager yields testimonial evidence, the weakest and least persuasive form. It reflects one person's perception of the workflow rather than proving that approvals actually occurred before each implementation. Because the manager could describe the intended process while exceptions existed in practice, this technique cannot substantiate whether individual production changes were authorized prior to deployment in the core banking application.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.