CISA Information System Auditing Process Practice Question
An IS auditor is planning the use of computer-assisted audit techniques (CAATs) to test a large transaction population for duplicate payments. Which of the following is the MOST important consideration before relying on the CAAT results?
⚠ Common exam trap
The trap here is focusing on the tool and its permissions while overlooking that the reliability of the analysis depends first on the integrity of the extracted data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verifying the completeness and accuracy of the data extracted from the source system
Before relying on CAAT output, the auditor must be satisfied that the data analysed is complete and accurate, typically by reconciling extract record counts and control totals to the source system. Only then can duplicate-payment exceptions be attributed to the population rather than to extraction errors. Licensing, approvals, and documentation support the work but do not validate the data itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensuring the CAAT scripts are documented in the permanent audit file
Why it's wrong here
Documenting scripts supports review and reproducibility, which matters for the working papers, but documentation alone does not establish that the data analysed was complete. A well-documented script run against a truncated extract still yields misleading results, so this is secondary to data validation.
- ✓
Verifying the completeness and accuracy of the data extracted from the source system
Why this is correct
CAAT results are only as reliable as the data analysed. The auditor must establish that the extract is complete and accurate, for example by reconciling record counts and control totals to the source system. Without this validation, duplicates or omissions in the extract could produce false conclusions about the transaction population.
- ✗
Obtaining management's written approval to run queries against production data
Why it's wrong here
Approval and access arrangements are necessary to perform the work, but they are procedural safeguards rather than determinants of result reliability. Approval does not validate the extracted data, so it cannot substitute for testing completeness and accuracy before the CAAT findings are used as audit evidence.
- ✗
Confirming that the CAAT software is licensed to the audit organization
Why it's wrong here
Licensing is an administrative prerequisite, but it does not affect whether the extracted data or the analysis is sound. A properly licensed tool applied to incomplete or inaccurate data still produces unreliable results, so licensing is not the most important consideration for relying on the CAAT output.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.