CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An IS auditor is reviewing a contract with a vendor for a new financial system. Which of the following clauses is MOST critical to ensure auditability?
⚠ Common exam trap
CISA often tests the difference between contractual protections that address consequences (penalties, SLAs) and those that enable verification (right to audit); candidates pick SLAs or penalties because they sound like strong controls but do not provide auditability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Right to audit the vendor's operations and controls
The right-to-audit clause is the most critical for ensuring auditability because it contractually grants the organization and its auditors the ability to examine the vendor's controls, records, and operations. Without this clause, the organization cannot independently verify that the vendor meets security, compliance, and operational requirements, regardless of other contractual protections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Penalties for non-performance
Why it's wrong here
Penalties for non-performance enforce remedies after a breach of agreed terms; they grant no right to examine the vendor's controls, logs or evidence, which is what auditability demands. It tempts because penalties appear to strengthen accountability, and it would be correct where the concern is contractual compliance rather than independent verification.
- ✗
Service level agreements (SLAs) for system uptime
Why it's wrong here
Uptime SLAs define availability targets and credits, not the auditor's right to inspect records, processes and controls; auditability needs a right-to-audit clause. It tempts because availability is measurable and contractual, and it would be correct where the requirement is service performance assurance rather than examination of the vendor's environment.
- ✓
Right to audit the vendor's operations and controls
Why this is correct
The right-to-audit clause contractually grants the IS auditor access to the vendor's operations, records and controls, enabling independent verification of the financial system's processing. Without it, assurance over outsourced processing relies solely on vendor assertions and third-party reports.
- ✗
Data ownership and confidentiality provisions
Why it's wrong here
Ownership and confidentiality protect data rights, not the auditor's ability to inspect vendor records, systems and controls; auditability requires a right-to-audit clause. It tempts because confidentiality is a standard contract concern, and it would be correct where the risk is unauthorised disclosure rather than unverifiable processing.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.