Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is planning an audit of a data center and must decide whether to test controls or rely on the work of the organization's internal audit function. Which of the following is the MOST important activity before the auditor can rely on that work?

⚠ Common exam trap

The trap here is assuming that a favorable structural fact, such as a direct reporting line or a shared audit tool, is by itself sufficient to justify reliance on internal audit work.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Evaluating the competence, objectivity, and quality of the internal auditors' work

Before relying on the work of internal audit, the IS auditor must determine that the function is competent and objective and that its work is of adequate quality. This evaluation supports a decision to reduce, but not eliminate, the auditor's own procedures. The other listed activities do not establish the professional reliability of the internal audit work being considered.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Obtaining a representation letter from the internal audit director confirming all findings were reported

    Why it's wrong here

    A representation letter is not the mechanism for establishing reliance on another audit function. Representations address management's assertions, not the professional quality of internal audit work. Reliance requires the auditor to evaluate competence, objectivity, and the work performed, and to perform sufficient procedures on the specific items or controls being relied upon.

  • ✓

    Evaluating the competence, objectivity, and quality of the internal auditors' work

    Why this is correct

    ISACA standards require the external auditor to assess the internal audit function's competence and objectivity and to evaluate the quality of its work before relying on it. A favorable assessment allows the auditor to reduce direct testing, but the reliance decision must be documented and supported by evidence gathered about the internal function itself.

  • ✗

    Confirming that the internal audit function uses the same audit software tools as the IS auditor

    Why it's wrong here

    Tool commonality is not a criterion for reliance. An internal audit function may use different CAATs, scripts, or platforms and still produce reliable, well-documented work. What matters is whether the evidence gathered is sufficient, competent, and produced under adequate planning, supervision, and quality control, not whether the software matches the auditor's own toolkit.

  • ✗

    Verifying that the internal audit function reports administratively to the audit committee of the board

    Why it's wrong here

    Reporting lines are relevant to objectivity, but this single structural fact is not sufficient to permit reliance. The auditor must also evaluate competence and the quality of the actual work performed. A strong reporting line alone does not demonstrate that the specific evidence gathered for the engagement is reliable or that the tests were adequately designed and supervised.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.