Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An IS auditor is reviewing a systems acquisition project that involves purchasing an ERP system. Which of the following is the MOST significant risk related to data migration during implementation?

⚠ Common exam trap

CISA often tests whether candidates prioritize data integrity over training or security in migration contexts—candidates may pick training because it feels user-centric, but the question asks about the most significant data migration risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incomplete or inaccurate data conversion from legacy systems

Incomplete or inaccurate data conversion from legacy systems is the most significant data migration risk because it directly corrupts the new ERP's foundational data, leading to erroneous transactions, reporting failures, and compliance issues. Data integrity is the core objective of migration, and failures here cascade across all modules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inadequate security controls in the new system

    Why it's wrong here

    Security controls govern protection of the new system, not the accuracy and completeness of migrated records. Data migration risk centres on mapping, cleansing and reconciliation of legacy data. Inadequate security controls would be the primary concern when assessing the target ERP's access management design, not the migration activity itself.

  • ✗

    Insufficient training of end users on the new system

    Why it's wrong here

    End-user training affects adoption and operational proficiency after go-live, not the fidelity of transferred data. Migration risk concerns field mapping, duplicate records and reconciliation between legacy and ERP tables. Insufficient training would be the leading risk during the changeover and hypercare phase, once data has already been loaded.

  • ✓

    Incomplete or inaccurate data conversion from legacy systems

    Why this is correct

    Incomplete or inaccurate conversion transfers corrupt, missing or duplicated records into the ERP, directly undermining financial reporting, payroll accuracy and subsequent processing. This is the most significant migration risk because defects introduced silently during conversion are difficult to detect and costly to remediate once live.

  • ✗

    Lack of integration testing between modules

    Why it's wrong here

    Integration testing between modules validates end-to-end business process flows after data is loaded, not the migration itself. Migration risk lies in extraction, transformation, cleansing and reconciliation of legacy records. Missing integration testing would be the principal concern during the testing phase, before go-live sign-off.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.