Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An IS auditor is reviewing the implementation of a new payroll system that was developed in-house. The project team followed a traditional waterfall SDLC. During the post-implementation review, the auditor found that the system was delivered on time and within budget, but several critical payroll calculations were incorrect, leading to employee underpayments. The root cause was traced to a misunderstanding of tax law changes that occurred during the requirements phase. Which of the following is the MOST likely control weakness that contributed to this issue?

⚠ Common exam trap

The trap here is focusing on testing or change management as the primary control, when the root cause is flawed requirements due to missing stakeholder input.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Insufficient involvement of tax experts and business stakeholders in requirements definition and validation.

The payroll errors stemmed from a misunderstanding of tax law changes during requirements. The most likely control weakness is insufficient involvement of tax experts and business stakeholders in defining and validating requirements. Their participation ensures that requirements are accurate and complete. While UAT, change management, and segregation of duties are important, they do not directly prevent requirements misunderstandings. Thus, the correct answer is the lack of expert involvement in requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inadequate segregation of duties between developers and testers, allowing developers to test their own code.

    Why it's wrong here

    Segregation of duties is important for preventing fraud and ensuring quality, but it is not related to the misunderstanding of tax law changes. The issue was not about who tested, but about whether the requirements were correct. Even with proper segregation, if requirements are wrong, the system will be incorrect. Therefore, this option does not address the specific root cause of the payroll calculation errors.

  • ✓

    Insufficient involvement of tax experts and business stakeholders in requirements definition and validation.

    Why this is correct

    The root cause was a misunderstanding of tax law changes, which indicates that the requirements were not accurately captured or validated. Involving tax experts and business stakeholders would have ensured that the requirements reflected current tax laws. This is a critical control in the requirements phase. Without their input, the system was built on incorrect assumptions, leading to payroll errors. Thus, this is the most likely control weakness.

  • ✗

    Inadequate user acceptance testing (UAT) that did not include valid tax scenarios.

    Why it's wrong here

    While UAT is important, the root cause was a misunderstanding of tax law changes during requirements. If requirements are wrong, even comprehensive UAT based on those requirements may not catch the error unless testers independently verify tax calculations. UAT typically validates against requirements; if requirements are flawed, UAT may pass. Thus, UAT weakness is a symptom, not the primary cause. The more fundamental issue is in requirements gathering and validation.

  • ✗

    Lack of a formal change management process to handle tax law updates during development.

    Why it's wrong here

    Change management is crucial, but the scenario states the misunderstanding occurred during the requirements phase, before development. A change management process would address changes after baseline, but here the issue was that the initial requirements did not incorporate the tax law changes. The weakness is in requirements elicitation and validation, not change control. Therefore, this option does not address the root cause.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.