Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is planning the use of computer-assisted audit techniques (CAATs) to test a large transaction population for duplicate payments. Which of the following is the MOST important consideration before relying on the CAAT results?

⚠ Common exam trap

The trap here is focusing on the tool and its permissions while overlooking that the reliability of the analysis depends first on the integrity of the extracted data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verifying the completeness and accuracy of the data extracted from the source system

Before relying on CAAT output, the auditor must be satisfied that the data analysed is complete and accurate, typically by reconciling extract record counts and control totals to the source system. Only then can duplicate-payment exceptions be attributed to the population rather than to extraction errors. Licensing, approvals, and documentation support the work but do not validate the data itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensuring the CAAT scripts are documented in the permanent audit file

    Why it's wrong here

    Documenting scripts supports review and reproducibility, which matters for the working papers, but documentation alone does not establish that the data analysed was complete. A well-documented script run against a truncated extract still yields misleading results, so this is secondary to data validation.

  • ✓

    Verifying the completeness and accuracy of the data extracted from the source system

    Why this is correct

    CAAT results are only as reliable as the data analysed. The auditor must establish that the extract is complete and accurate, for example by reconciling record counts and control totals to the source system. Without this validation, duplicates or omissions in the extract could produce false conclusions about the transaction population.

  • ✗

    Obtaining management's written approval to run queries against production data

    Why it's wrong here

    Approval and access arrangements are necessary to perform the work, but they are procedural safeguards rather than determinants of result reliability. Approval does not validate the extracted data, so it cannot substitute for testing completeness and accuracy before the CAAT findings are used as audit evidence.

  • ✗

    Confirming that the CAAT software is licensed to the audit organization

    Why it's wrong here

    Licensing is an administrative prerequisite, but it does not affect whether the extracted data or the analysis is sound. A properly licensed tool applied to incomplete or inaccurate data still produces unreliable results, so licensing is not the most important consideration for relying on the CAAT output.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.