CISA Information System Auditing Process Practice Question
An IS auditor is planning an audit of a data center and must decide whether to test controls or rely on the work of the organization's internal audit function. Which of the following is the MOST important activity before the auditor can rely on that work?
⚠ Common exam trap
The trap here is assuming that a favorable structural fact, such as a direct reporting line or a shared audit tool, is by itself sufficient to justify reliance on internal audit work.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evaluating the competence, objectivity, and quality of the internal auditors' work
Before relying on the work of internal audit, the IS auditor must determine that the function is competent and objective and that its work is of adequate quality. This evaluation supports a decision to reduce, but not eliminate, the auditor's own procedures. The other listed activities do not establish the professional reliability of the internal audit work being considered.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Obtaining a representation letter from the internal audit director confirming all findings were reported
Why it's wrong here
A representation letter is not the mechanism for establishing reliance on another audit function. Representations address management's assertions, not the professional quality of internal audit work. Reliance requires the auditor to evaluate competence, objectivity, and the work performed, and to perform sufficient procedures on the specific items or controls being relied upon.
- ✓
Evaluating the competence, objectivity, and quality of the internal auditors' work
Why this is correct
ISACA standards require the external auditor to assess the internal audit function's competence and objectivity and to evaluate the quality of its work before relying on it. A favorable assessment allows the auditor to reduce direct testing, but the reliance decision must be documented and supported by evidence gathered about the internal function itself.
- ✗
Confirming that the internal audit function uses the same audit software tools as the IS auditor
Why it's wrong here
Tool commonality is not a criterion for reliance. An internal audit function may use different CAATs, scripts, or platforms and still produce reliable, well-documented work. What matters is whether the evidence gathered is sufficient, competent, and produced under adequate planning, supervision, and quality control, not whether the software matches the auditor's own toolkit.
- ✗
Verifying that the internal audit function reports administratively to the audit committee of the board
Why it's wrong here
Reporting lines are relevant to objectivity, but this single structural fact is not sufficient to permit reliance. The auditor must also evaluate competence and the quality of the actual work performed. A strong reporting line alone does not demonstrate that the specific evidence gathered for the engagement is reliable or that the tests were adequately designed and supervised.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.