CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An IS auditor is reviewing a post-implementation review report for a new ERP system. Which of the following findings would be of greatest concern to the auditor?
⚠ Common exam trap
CISA often tests the auditor's ability to distinguish between control deficiencies and project management variances, tempting candidates to select budget or schedule overruns over unresolved SoD conflicts that directly impact control effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Several segregation of duties conflicts were identified and not resolved.
Unresolved segregation of duties (SoD) conflicts in an ERP system pose a significant risk of fraud, unauthorized transactions, and financial misstatement. SoD is a fundamental internal control that prevents any single individual from having control over all aspects of a transaction. Unresolved conflicts indicate a control deficiency that could lead to material misstatement and is of greatest concern to an IS auditor.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Several segregation of duties conflicts were identified and not resolved.
Why this is correct
Unresolved segregation of duties conflicts leave incompatible functions, such as creating a vendor and approving its payment, with one person. Unlike tuning or training issues, this is a live control failure that enables fraud or error, so it is the finding of greatest concern in a post-implementation review.
- ✗
The implementation took three months longer than planned.
Why it's wrong here
A three-month schedule overrun is a project management variance that does not by itself compromise the system's integrity, availability or control environment. It is tempting because overruns often signal weak governance, so an auditor would note it, but it ranks below findings showing the system went live with inadequate assurance.
- ✗
The project exceeded the budget by 15%.
Why it's wrong here
A 15% budget overrun is a financial variance, not evidence that the ERP's controls, data integrity or processing are unreliable. It is tempting because cost breaches attract audit attention and may indicate poor estimating, but the auditor's greatest concern is a control weakness affecting the live system, not spend.
- ✗
User acceptance testing (UAT) was completed with only 80% test coverage.
Why it's wrong here
UAT completed at only 80% coverage means 20% of functionality was never validated before go-live, leaving untested controls and defects in production. It is tempting to dismiss coverage percentages as a metric, but incomplete acceptance testing directly undermines assurance that the system meets requirements and operates correctly.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.