CISA Information System Auditing Process Practice Question
An IS auditor is executing a compliance test of change management controls over a core banking application. The audit programme requires evidence that all production changes were approved before implementation. Which of the following techniques provides the MOST persuasive evidence for this test?
⚠ Common exam trap
The trap here is treating review of the approved change management policy as sufficient evidence, when a compliance test of operating effectiveness requires evidence that approvals actually occurred before each deployment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inspecting the change tickets for documented approvals and comparing approval dates to deployment dates
Documentary evidence of approvals linked to deployment records directly addresses the control objective: approvals occurring before implementation. Comparing dates on the change tickets themselves allows the auditor to identify exceptions rather than relying on what people say or what policy intends. Interviews, policy review, and single-meeting observation each provide weaker or incomplete evidence for concluding on operating effectiveness across the change population.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Observing the change advisory board during one weekly meeting
Why it's wrong here
Observation provides evidence about one point in time and only for changes discussed at that meeting. It cannot show whether every production change to the core banking application received approval before deployment, and staff aware of being observed may behave differently. While useful as corroborating evidence, observation alone is insufficient for a compliance test that must conclude on approval of all changes during the audit period.
- ✗
Reviewing the change management policy approved by the IT steering committee
Why it's wrong here
The approved policy is documentary evidence, but it only proves that a control is designed and mandated, not that it operated for individual changes. A policy can be perfectly worded while change tickets go unapproved in practice. For a compliance test asking whether production changes were approved before implementation, policy review alone does not demonstrate operating effectiveness on the core banking application's actual change population.
- ✓
Inspecting the change tickets for documented approvals and comparing approval dates to deployment dates
Why this is correct
Inspecting change tickets produces documentary evidence and directly tests the control: the audit programme asks whether approvals preceded implementation. By comparing the approval timestamp on each ticket with the deployment timestamp in the same record, the auditor can detect changes deployed before authorization. This is the most persuasive technique available here because it is independent of verbal assertions and covers the actual population of changes.
- ✗
Interviewing the change manager about the approval workflow
Why it's wrong here
Interviewing the change manager yields testimonial evidence, the weakest and least persuasive form. It reflects one person's perception of the workflow rather than proving that approvals actually occurred before each implementation. Because the manager could describe the intended process while exceptions existed in practice, this technique cannot substantiate whether individual production changes were authorized prior to deployment in the core banking application.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.