Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is planning an audit of a financial system. The auditor identifies that the inherent risk is high due to the complexity of transactions, but control risk is low because of strong automated controls. Which component of audit risk will be MOST affected by the auditor's testing strategy?

⚠ Common exam trap

The trap is thinking that inherent or control risk can be changed by testing; candidates may confuse the assessed risks with the risk that testing can influence, which is detection risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detection risk

Detection risk is the risk that the auditor's procedures will not detect a material misstatement. It is directly influenced by the auditor's testing strategy: the nature, timing, and extent of audit procedures. When inherent risk is high and control risk is low, the auditor can accept a higher detection risk, but the testing strategy (e.g., more substantive testing) affects detection risk. Inherent and control risks are assessed, not affected by testing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inherent risk

    Why it's wrong here

    Inherent risk is assessed from the nature of the business and transactions, independently of any controls or testing; the auditor's testing strategy cannot change it. It is tempting because inherent risk is high here, but it is a fixed input to the audit risk model, whereas detection risk is the component the auditor adjusts through substantive testing.

  • ✓

    Detection risk

    Why this is correct

    Detection risk is the component the auditor directly controls through the nature, timing and extent of substantive testing. With inherent risk high and control risk low, the auditor adjusts testing to keep detection risk at a level that holds overall audit risk within acceptable bounds.

  • ✗

    Control risk

    Why it's wrong here

    Control risk is the likelihood that controls fail to prevent or detect a material misstatement; it is assessed from the control environment, not changed by the auditor's testing strategy. It is tempting because strong automated controls lower it, but detection risk is the component the auditor's procedures directly influence.

  • ✗

    Audit risk

    Why it's wrong here

    Audit risk is the overall product of inherent risk, control risk and detection risk, so it is the outcome being managed rather than the component the testing strategy directly alters. It is tempting because auditors ultimately bound audit risk, but detection risk is what substantive testing changes.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.