CISA Information System Auditing Process Practice Question
An IS auditor is performing a compliance audit of data privacy regulations. The auditor finds that the organization's privacy policy is not fully aligned with regulatory requirements. Which of the following is the auditor's BEST course of action?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the finding as a non-compliance issue and recommend updates to the policy.
The auditor should report the non-compliance finding and recommend corrective actions, as the primary goal of a compliance audit is to identify gaps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ignore the issue because the policy is only a minor deviation.
Why it's wrong here
Ignoring a known policy gap leaves the non-compliance undocumented and unremediated, so the auditor fails to report findings and recommend corrective action. It is tempting because immaterial deviations may be accepted, but only after the auditor has formally raised the issue and management has accepted the risk.
- ✓
Report the finding as a non-compliance issue and recommend updates to the policy.
Why this is correct
Because the policy fails to meet regulatory requirements, the auditor must document this as a non-compliance finding and recommend remediation. Reporting and recommending updates satisfies the compliance audit objective, giving management a basis to align the policy with the applicable privacy regulations.
- ✗
Draft a new privacy policy for the organization.
Why it's wrong here
Drafting the policy moves the auditor into a management role, impairing the independence required to later audit that same policy. It is tempting because auditors possess the regulatory knowledge to write it, yet policy authorship belongs to management; the auditor should report the gap and recommend remediation.
- ✗
Conclude that the organization is compliant because the policy exists.
Why it's wrong here
Concluding compliance from the mere existence of a policy ignores whether its content actually meets regulatory requirements, which is precisely the misalignment found. It is tempting because an approved, published policy suggests control, but existence is not alignment; the auditor must report the gap.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.