Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is preparing the audit report. According to ISACA standards, which of the following should be included in the final audit report?

⚠ Common exam trap

CISA often tests the misconception that the audit report should only include findings or recommendations, or that the audit program is part of the report, when in fact ISACA standards require the triad of findings, recommendations, and management action plans.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Findings, recommendations, and management action plans

According to ISACA's IT Audit Framework and the ISACA Code of Professional Ethics, the final audit report must include the audit findings, recommendations, and management's action plans. Findings describe the condition, criteria, cause, and effect; recommendations provide guidance for remediation; and management action plans document the agreed-upon corrective steps and timelines. This triad ensures the report is complete, actionable, and supports follow-up.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Only the audit findings

    Why it's wrong here

    Findings alone omit the auditor's opinion, scope, and management responses that ISACA standards require in a final report. Reporting only findings is tempting because findings are the report's most visible output, and a findings-only memo suits interim updates or working papers rather than the formal issued report.

  • ✗

    Only the recommendations

    Why it's wrong here

    Recommendations alone omit findings, scope, and the auditor's overall opinion, so the report cannot evidence the basis for its conclusions as ISACA standards require. A recommendations-only deliverable suits a management action plan or remediation tracker, not the formal audit report.

  • ✓

    Findings, recommendations, and management action plans

    Why this is correct

    ISACA standards require the final report to document findings, their risk implications, recommendations, and management's agreed action plans with target dates. Including all three elements ensures the report is complete, actionable, and supports follow-up of remediation.

  • ✗

    The audit program and procedures

    Why it's wrong here

    The audit program and procedures are working papers supporting the engagement, not report content; including them obscures findings and breaches ISACA reporting standards. They are retained as evidence of work performed. The final report requires conclusions, risk ratings and management responses instead.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.